Maybe your homepage is sending visitors to a website you have never heard of. Maybe Google is showing a red warning screen where your content used to be, an administrator account you did not create has appeared in your dashboard, or your host has filed a ticket and pulled the site offline. Whatever brought you to this page, you need a plan and not a lecture about stronger passwords.
First things first. Isolate the site, reset every password from a clean computer, save an infected snapshot before you delete anything, then replace core files the safe way. Clearing a Google warning and closing the entry point come after that.
And take a breath. Sites in far worse shape get cleaned up and put back online every day, and yours can be one of them. Deep scanning, plugin by plugin, is a separate job with its own guide, so this page sticks to getting you through the emergency.
What should you do first if your WordPress site is hacked?
If your WordPress site has been hacked, put it in maintenance mode or ask your host to block public traffic, then reset every password from a computer you know is clean. Isolation comes before cleanup because it stops the site serving malware to visitors while you work.
The clean-computer part is not fussiness. Attackers sometimes plant software on an owner’s laptop and read login details as they are typed, so a fresh password entered on an infected machine is stolen the moment you save it.
Reset access everywhere, not only in the dashboard:
- WordPress accounts, starting with every administrator.
- Your hosting control panel.
- SFTP or SSH logins.
- The database user in wp-config.php.
WordPress.org calls these your access points and recommends changing all of them, for every user with access, rather than just your own.
Next, open a ticket with your host. Ask them to check server logs for when the intrusion started and whether other sites on the same server were affected. While you wait, write down what you saw, the time you noticed it, and any plugin or theme change you made recently. That record becomes your incident report.
Do not start by deleting files. Take a full copy of the files and database exactly as they are now, infection included, because that snapshot is the only version you can work back from if cleanup goes sideways. It is also what anyone investigating the entry point will ask for first.
Do not reach for a backup yet either. A backup taken after the break-in carries the backdoor along with it, so the snapshot comes first and the restore decision comes later.
From there the sequence runs the same way every time. Remove administrators you did not add, replace core files from a fresh copy, rotate your security salts, switch on two-factor authentication, and ask Google for a review only once the site is clean. Most hacked WordPress sites are recovered by working through that order without skipping a step.
How do you know your WordPress site has been hacked?
A hacked WordPress site shows documented symptoms, such as spam redirects, administrator accounts nobody on your team created, a Google malware warning on your domain, or PHP files sitting in folders that should only hold images and uploads.
WordPress.org calls these indicators of compromise, and its list is broader than most owners expect:
- Search engines such as Google or Bing have blocklisted the domain.
- Your host has switched the site off or reported it for distributing malware.
- Visitors say their antivirus software is blocking your pages.
- Someone has contacted you because your site is attacking theirs.
- User accounts or settings changed without anyone approving them.
- The page itself has been defaced and you can see it in the browser.
What does not count is a slow homepage, a single 500 error, or a feature that broke right after an update. Those point to a plugin conflict far more often than a break-in, and the difference is easy to check. A conflict fails the same way every time and clears when you deactivate the plugin behind it. A compromise keeps changing what visitors see, often showing spam only to people who are not logged in.
Should you clean the files or restore a backup?
Clean the files first, because restoring a backup does not remove a backdoor that was already sitting inside that backup. A rollback can hand the site straight back to whoever took it. Restore only a copy you can date to before the first indicator appeared, and keep the infected snapshot either way.
Liam Bailey, a WordPress developer and Codeable expert, has watched this pattern repeat:
In some cases the hack’s actually already been there and it’s not been noticed. So, even though you’ve got backups for two weeks and you put this backup back in place, you’ve still actually got malware on your site, or what they call ‘backdoors’.
WordPress.org documents a safer way to rebuild the parts of the site you can replace outright:
- Download the same WordPress version your site is running from wordpress.org, never a newer or older one.
- Delete wp-admin and wp-includes, then upload the fresh folders over SFTP.
- Avoid the reinstall button in the dashboard, because it overwrites existing files and leaves any new ones the attacker added.
- Leave wp-content and wp-config.php in place and go through them separately, since your theme, plugins, and settings live there.
- Generate fresh security salts, paste them into wp-config.php, and every active login session ends immediately.
- Open wp-content/uploads and delete any .php files you did not put there, since an uploads folder should hold media rather than code that runs.
From there, remove administrators you did not add, reinstall plugins and themes from their official sources instead of trusting the copies already on the server, and run a scanner such as Wordfence or MalCare. Both are named on quality, irrespective of any affiliation Codeable may have, and our malware removal guide walks through the scan itself.
What if Google has flagged your site?
Once the site is genuinely clean, request a review in Google Search Console and the Safe Browsing warning comes down after Google recrawls the pages. The order is what matters. A review requested while malicious files are still on the server simply fails, and you start the wait over.
Google is not the only place that keeps a list. WordPress.org recommends registering your site with the other webmaster consoles too, including Bing, Yandex, and Norton Safe Web, since a warning can sit with any of them long after Google has cleared you.
Verify the site yourself before you ask anyone to re-check it. Load it while logged out, in a private window, and on mobile data rather than your office network.
How did they get in and how do you stop it happening again?
A WordPress site that keeps getting hacked still has its entry point open, and it is usually an outdated plugin, an abandoned one that no longer receives patches, or a nulled theme picked up outside the official repository. Find that door and close it before you call the incident finished, or the cleanup only buys a few quiet weeks.
Most repeat breaches are stopped by unglamorous habits:
- Update core, themes, and plugins as releases arrive, and delete anything you stopped using.
- Give every account a long, unique password generated by a password manager.
- Switch on two-factor authentication, starting with administrators.
- Refuse nulled or cracked themes and plugins, since those copies often ship with a backdoor already installed.
- Change all passwords one final time after the site is confirmed clean, because credentials created mid-incident may already have been captured.
- Put a web application firewall in front of the site to block automated exploit attempts before they reach your server.
Hosting belongs to this stage rather than the emergency. Managed WordPress hosts such as Kinsta and WP Engine keep tested backups and watch traffic at server level, and they are named here on quality, irrespective of any affiliation Codeable may have.
Ongoing hardening deserves its own schedule. Our security audit guide covers what to review, and a maintenance package handles staging-first updates, daily backups, and scheduled vulnerability scans month to month.
When DIY cleanup cannot finish the job
Codeable is a WordPress-only expert platform that matches hacked-site cleanups to pre-vetted developers when an owner cannot finish the recovery alone.
That covers attacks that lock the owner out of the admin entirely, infections that come back days after a restore because the backdoor was never found, malware that sits on a store holding live orders and customer records, and much more.
Codeable’s WordPress security experts take those cases from the first look at the entry point through to confirming the site is clean. You see one fixed price before any work starts, built on the $80–$120 hourly expert rate, and completed project work carries a 28-day bug-fix warranty. Our team works weekday hours, so treat this as planned recovery rather than an overnight hotline.
Post your project for a free estimate, with no obligation to hire.
Dream It