Fix It Yourself

How to Tell If Your WordPress Site Has Been Hacked (And What to Do First)

Most hacked WordPress sites aren’t targeted — they’re swept up by bots scanning for outdated plugins. That’s oddly good news: the damage follows patterns, and the cleanup is well understood.

The tell-tale signs

  • Your site redirects visitors to pharmacy, gambling or crypto pages.
  • Google search results show pages you never created (often in another language).
  • Browsers show a red “deceptive site ahead” warning.
  • New admin users you didn’t create appear under Users.
  • Your host emails you about malware or suspended service.

First 30 minutes

  1. Don’t delete anything yet. You may destroy evidence of how they got in — which means they’ll get in again.
  2. Change every password: WordPress admins, hosting control panel, FTP, and database. Do it from a clean device.
  3. Scan the site with a security plugin like Wordfence, and check it against Google Safe Browsing.
  4. Tell your host. Good hosts have malware-cleanup tooling and can check neighbouring accounts.

Cleaning up properly

A proper cleanup means: restoring from a known-clean backup or removing injected code, updating everything to current versions, removing unused plugins and themes entirely, deleting rogue admin accounts, and re-securing with two-factor authentication. Then request a review in Google Search Console if you were flagged.

The uncomfortable truth

Sites get hacked through outdated software, weak passwords, and abandoned plugins — all preventable with boring, regular maintenance. Every WP Hero plan includes security scans, and Standard and up include malware cleanup. It’s much cheaper as prevention than as a rescue.

Rather have a hero handle it?

WP Hero keeps your WordPress site updated, backed up and monitored — with unlimited small fixes included. Flat fee, no hourly billing, from R499/month.

See plans How it works

Keep reading