WordPress ·
Hacked WordPress Site? What to Do, Step by Step
By Manu Mathew, Technical Lead Engineer · Last updated 8 October 2026

You open your website and it redirects to a page you’ve never seen. Or a customer tells you Google shows a warning next to your business name. Either way, your stomach drops.
A hacked WordPress site is stressful, but it’s fixable. The order in which you do things matters more than speed, and a calm, careful clean-up is what stops the problem coming back.
Quick answer
If your WordPress site has been hacked, work in order: note what you see, take a copy of the site as it is, and change every password. Then restore a clean backup or carefully replace infected files. Finally, update everything, find how the attacker got in, and ask Google to review the site.
How do you know your WordPress site has been hacked?
The clearest signs are things you didn’t do yourself: strange pages, redirects, new users or warnings from Google or your host.
- Redirects. Visitors, often only those arriving from Google or on mobile, are sent to a spam or scam site.
- Warnings. Google Search or the browser shows a “this site may be hacked” or “dangerous site” message.
- Spam pages. Search results for your site show pages in other languages or selling things you don’t sell.
- New admin users. Accounts appear in Users that nobody on your team created.
- A message from your host. Your site has been suspended or flagged for malware or sending spam.
Some hacks hide from logged-in owners, so a site that looks fine to you may still be affected. The WordPress.org guide for hacked sites calls these signs indicators of compromise, and suggests writing them down.
What should you do first when your site is hacked?
Contain the damage and keep a record before you delete anything. Rushing to remove files can destroy the clues you need.
- Write down what you’ve seen. What looks wrong, when you noticed it, and anything that changed recently, such as a new plugin.
- Tell your host. They may see the problem in server logs, and some will help with the clean-up.
- Take a copy of the hacked site. Back up the files and database as they are now. It’s evidence, not something to restore.
- Change every password. WordPress admin users, hosting, FTP or SFTP, the database, and the email accounts linked to the site.
- Remove accounts you don’t recognise. Check WordPress users and hosting users, and turn on two-factor sign-in for the rest.
If the site is collecting payments or personal details, consider putting it into maintenance mode until it’s clean.
How do you clean a hacked WordPress site?
You have three realistic choices: restore a clean backup, clean the existing site, or rebuild. The right one depends on how good your backups are.

| Option | When it suits | Watch out for |
|---|---|---|
| Restore a clean backup | You have a backup from before the hack | It may already be infected; you lose newer changes |
| Clean the existing site | No clean backup, or recent content matters | Takes care and time; easy to miss a hidden file |
| Rebuild | The site is old, heavily infected or due a refresh | More work, but you start from a known clean state |
Whichever you choose, the clean-up should cover the same ground:
- WordPress core. Replace the core files with a fresh copy from wordpress.org.
- Plugins and themes. Reinstall each one from its official source, and delete any you don’t use. Remove any “nulled” (pirated) premium plugins completely.
- The uploads folder. It should hold images and documents, so PHP files hiding there are a red flag.
- The database. Look for unknown admin users, injected scripts in posts and widgets, and odd scheduled tasks.
- Configuration. Check
wp-config.phpand.htaccessfor code you didn’t add, and replace the security keys so every old login session ends.
A security plugin’s scan helps you find things, but treat its “all clear” as a starting point, not proof.
How do you remove Google’s hacked site warning?
Fix the site first, then ask Google to check it again from Search Console. The warning won’t lift on its own straight away.
Open the Security issues report in Search Console to see what Google found and which pages it flagged. Once you’re sure the problem is fixed, request a review from that report. Google says a review can take from a few days to a few weeks.
Requesting a review before the site is really clean can slow things down, so check the sample pages carefully first. It’s also worth searching site:yourdomain.com for spam pages and removing any that remain.
How do WordPress sites usually get hacked?
Usually through a known weakness that was never fixed, rather than a clever new attack. Finding which one applies to you is what prevents a repeat.
The usual causes are:
- Out-of-date plugins or themes with security fixes that were never installed.
- Abandoned plugins that no longer receive updates.
- Weak or reused passwords, especially without two-factor sign-in.
- Nulled plugins and themes, which often come with hidden code.
- Too many people with admin access, including old staff and past developers.
If you can’t find the cause, assume it’s still open. Cleaning without closing the gap is how sites end up hacked again a few weeks later.
How do you stop it happening again?
Keep things updated, limit who can sign in, and make sure you can restore a clean copy. Those habits cover the most common ways in.
- Update regularly. Core, plugins and themes, after a quick check on a staging copy where possible.
- Use fewer plugins. Every plugin is code you need to trust and maintain.
- Turn on two-factor sign-in for every admin account.
- Give people only the access they need. An editor doesn’t need to be an administrator.
- Keep off-site backups and test a restore. A backup you’ve never restored is a hope, not a plan.
WordPress’s own hardening guide goes further, and your hosting matters too.
How do I handle a hacked site with a client?
I treat it as an incident with a written record, not a quick fix. The owner should understand what happened and what changed.
My usual steps are:
- A short call first. What the owner has seen, who has access, and what the site does for the business.
- A copy before any change. Files and database are saved, so nothing is lost if we need to look back.
- A written choice. Restore, clean or rebuild, with the trade-offs in plain words, agreed before work starts.
- Credentials changed together. The owner keeps control of their own accounts throughout.
- A summary afterwards. The likely cause, what I fixed and what to keep doing, followed by a later check that the site is still clean.
Frequently asked questions
Can I just restore yesterday’s backup?
Only if you’re sure the backup was taken before the hack, and even then you must fix the weakness the attacker used. Many hacks sit quietly for weeks before anyone notices, so recent backups can be infected too. After restoring, update everything and change all passwords straight away.
Will a security plugin fix a hacked WordPress site?
A security plugin can help you find infected files and block some attacks, but it rarely removes everything on its own. Hidden files, rogue admin users and injected database content are easy to miss. Use the scan as a guide, then check core files, plugins, uploads and users yourself.
Will being hacked hurt my Google rankings?
It can, especially if Google shows a warning or finds spam pages on your site, because visitors avoid flagged results. Once the site is clean and Google has reviewed it, the warning is removed. Cleaning up spam pages and checking Search Console afterwards helps your normal results return.
How much does it cost to fix a hacked WordPress site?
It depends on how badly the site is affected, whether clean backups exist and whether a rebuild makes more sense. A quick restore is very different from a deep clean of a large shop. Ask for an honest look at the site first, then a quote for the work it actually needs.
Do I need to tell my customers?
If the site stores customer details, such as orders, accounts or form entries, those details may have been exposed. Take advice on any legal duty to inform people, and tell your payment provider if payments were involved. For a simple brochure site with no stored data, a clean-up is usually enough.
Need help with a hacked or fragile site?
Whether your site has been hacked or you’d like to make it harder to break into, I’m happy to talk it through. I work on WordPress sites for small businesses as a WordPress developer in Kozhikode, across Kerala and remotely, and the WordPress websites page covers the kinds of work I take on.
You can reach me through the contact section or email me at manu@manu.co.in. Tell me a little about your business and the site, and we’ll go from there.