Most hacked WordPress sites aren’t targeted — they’re swept up by bots scanning for outdated plugins. That’s oddly good news: the damage follows patterns, and the cleanup is well understood.
The tell-tale signs
- Your site redirects visitors to pharmacy, gambling or crypto pages.
- Google search results show pages you never created (often in another language).
- Browsers show a red “deceptive site ahead” warning.
- New admin users you didn’t create appear under Users.
- Your host emails you about malware or suspended service.
First 30 minutes
- Don’t delete anything yet. You may destroy evidence of how they got in — which means they’ll get in again.
- Change every password: WordPress admins, hosting control panel, FTP, and database. Do it from a clean device.
- Scan the site with a security plugin like Wordfence, and check it against Google Safe Browsing.
- Tell your host. Good hosts have malware-cleanup tooling and can check neighbouring accounts.
Cleaning up properly
A proper cleanup means: restoring from a known-clean backup or removing injected code, updating everything to current versions, removing unused plugins and themes entirely, deleting rogue admin accounts, and re-securing with two-factor authentication. Then request a review in Google Search Console if you were flagged.
The uncomfortable truth
Sites get hacked through outdated software, weak passwords, and abandoned plugins — all preventable with boring, regular maintenance. Every WP Hero plan includes security scans, and Standard and up include malware cleanup. It’s much cheaper as prevention than as a rescue.