Compromised WordPress sites do not always show obvious signs. Suspicious activity can include injected spam, redirects, unknown users, altered files, abnormal server usage or unauthorised email sending. These warning signs help identify when deeper investigation is justified.
🚨 If several signs point to compromise, preserve logs and backups, restrict risky access where appropriate, and contact your hosting provider or WordPress support before making broad changes. Whether the site should be taken offline depends on the type and severity of the incident.
If visitors see a Google warning before reaching your site, Google's Safe Browsing has flagged you. This happens when Google detects malware, phishing pages, or spam content. Check your status at Google Safe Browsing and in Google Search Console under Security Issues.
One of the most common hack patterns: visitors are silently redirected to spam, scam, or adult sites. This often only happens for mobile users or first-time visitors, which is why site owners can miss it for weeks. Test your site using a browser in private/incognito mode or from a different device.
Go to Users → All Users in your WordPress dashboard. If you see administrator accounts you do not recognise, especially with generic names or suspicious email addresses, treat that as a serious compromise indicator and investigate how the account was created. Attackers add backdoor admin accounts to maintain access even after you change your password.
Hosts monitor for malware and spam. If your account is suddenly suspended with a message about "malicious activity," "spam sending," or "resource abuse," treat it as a serious incident signal and review the host's evidence, recent account activity, affected files and outbound traffic before deciding what was compromised.
Connect via FTP or cPanel File Manager and look for PHP files in unusual places — inside /uploads/, with random names like "x7r2k.php" or "config.php" duplicates in odd directories. Legitimate WordPress files have predictable names and locations. Anything suspicious warrants investigation.
A major unexplained drop in Google Search traffic — especially when not correlated with any change you made — can justify checking whether spam pages, security warnings, indexing changes, manual actions or unrelated SEO issues are involved. Check Google Search Console for manual actions and Coverage issues.
If you start receiving bounce emails you didn't send, or your domain gets blacklisted by email providers, attackers may have installed a mail script on your server. Check your hosting control panel for mail logs showing unusual outbound volume.
Attackers often inject spam pages targeting pharmaceutical, gambling, or adult keywords — known as "pharma hacks" or "SEO spam." These pages are designed to be invisible to logged-in admins but visible to Google. Search your site in Google for: site:yoursite.com and look for pages you don't recognise.
If your site suddenly slows down dramatically, or your hosting dashboard shows unusually high CPU or memory usage, malware may be running processes in the background — cryptocurrency mining scripts are increasingly common on compromised servers.
Check the last modified date of your wp-config.php and .htaccess files via FTP or File Manager. If they've been recently modified and you didn't touch them, look inside carefully for injected code — often base64-encoded strings that look like random characters.
No clean backup? The malware is deep in the database or encrypted? That's when professional investigation and cleanup may be appropriate when the compromise cannot be confidently isolated or recovered from a known-clean backup. See our WordPress security hardening guide to prevent future attacks.
How do WordPress sites get hacked?
The most common entry points are outdated plugins or themes with known vulnerabilities, weak admin passwords, compromised themes from unofficial sources, and hosting accounts with insecure configurations. Keeping software updated, using strong unique passwords and limiting privileged access can reduce common compromise risk, but no single control prevents every attack.
Will restoring a backup remove the hack?
Only if the backup predates the infection. If the malware was present in the backup, restoring it brings the infection back. After restoring, immediately update all plugins, themes, and WordPress core, and change all passwords.
How much does WordPress malware removal cost?
Malware-removal pricing depends on the affected files, database changes, access available, recovery options and reinfection risk. WPFixMate confirms the scope and pricing after an initial assessment rather than publishing a one-size-fits-all cleanup price.
WPFixMate can investigate the compromise, clean affected WordPress files and database content where appropriate, and document the findings and recovery steps.
Request Malware Assessment