When a WordPress site is hacked, the damage can look like defacement, unexpected redirects, spam links in search results, a Google Search Console security warning, or a host that suspended the account. The goal of the first hour is to stop further damage and preserve evidence—not to install every security plugin at once.
Work this checklist in order. Prefer a clean device (not the possibly compromised admin PC) for password changes. Take a full backup before deleting files if the host still allows access. Once the site is stable again, restore only what you intentionally changed for triage and recheck login, forms, and checkout if you use them. If one covered WordPress issue is clearly to blame and you want help, use the $99 one-time fix after you can authorize access—we confirm scope first when malware cleanup may exceed a single covered issue.
Recognize the signs
- Homepage or random URLs redirect to spam, pharma, or scam sites.
- New admin users, unknown plugins/themes, or files you did not install.
- Search Console or browser warnings that the site was hacked or serves malware.
- Host notice that the account was suspended for abuse or malware.
- Outbound spam from the site’s forms or mail, or a sudden SEO crash with foreign doorway pages.
A slow site, a plugin conflict, or a 403/500/502 alone is not proof of compromise. If the site is simply offline without security warnings, start with the site down checklist.
Safe immediate steps
- Do not delete evidence yet. Avoid mass-deleting plugins, themes, or uploads until you have a backup and a note of what looks wrong. Deleted files can remove the only clue to how access was gained.
- Change critical passwords from a clean device. Hosting panel, WordPress admin accounts you still trust, FTP/SFTP, database, and DNS/registrar if those credentials were reused. Enable multi-factor authentication where the host offers it. Coordinate database-password changes with your host so WordPress’s database connection settings are updated too; changing only the password can take the site offline.
- Contact the host. Ask whether the account is suspended, whether they see malware paths, and whether they offer a restore point from before the incident. Follow their incident instructions when they conflict with generic web advice.
- Put the site in a maintenance or offline state if the host agrees. That can reduce visitor exposure while you work. Do not leave a known-bad checkout or login page public longer than needed.
- Inventory access. List who had Admin, which agencies or plugins had API keys, and whether
xmlrpc, unused admin accounts, or old staging copies were exposed. Revoke keys you cannot explain.
What cleanup usually involves
- Identifying malicious or modified core, plugin, theme, and upload files with the host or a professional—not by guessing from filenames alone.
- Removing unauthorized admin users and unknown scheduled tasks (cron) the host can show you.
- Resetting secrets, rotating salts/keys with a host-approved method, and checking
wp-config.php for unfamiliar code.
- Restoring from a known-clean backup when one exists, then re-applying only needed content updates.
- Before reopening the site, have the host or cleanup professional fix the entry point, update WordPress, plugins, and themes from trusted sources, and remove unsupported components. Once the site is confirmed clean, change passwords again and revoke or rotate affected keys and sessions; passwords changed during the infection may have been exposed.
- Requesting review in Search Console after the host confirms the malware vectors are cleared—not before.
This article does not recommend a specific scanner product or claim that any plugin alone “guarantees” a clean site. Host tools, professional cleanup, and careful restores are the reliable path when the infection is real.
When to call a professional
- You cannot reach Admin or SFTP, or every restore comes back infected.
- Customer data, payments, or email accounts may have been exposed.
- The host requires a cleanup report before unsuspending the account.
- Multiple sites on the same hosting account show the same spam.
If the only problem is a broken plugin after an update—not malware indicators—see plugin not working or plugin update broke WordPress site instead.
When a $99 one-time fix fits
Request the $99 one-time WordPress fix if you want help with one clearly defined issue on one WordPress site. Name the symptoms (redirect, defacement, Search Console warning, host suspension), when it started, and what access you still have. We confirm the scope before work begins—full malware cleanup, multi-site infections, and forensic/legal work are often outside this offer. Send credentials only through the private access link provided after your request is accepted.
Full rebuilds, new custom features, full migrations, account-wide host outages, and multiple unrelated issues are outside this offer.
Related checks
If the checks do not identify the cause, send your host the first symptom time, any Search Console or suspension notice, and a list of recent admin users and plugins. Suspected compromise needs a security investigation as well as restoring normal pages.