Most WordPress hacks are not dramatic. There is rarely a skull on the homepage. Instead, attackers quietly use your site to send spam, redirect visitors, host phishing pages or create thousands of spam pages for search engines. Owners often find out weeks later, when Google shows a warning, traffic collapses or a customer mentions something strange. The sooner you recognise the signs, the less damage there is to your reputation and rankings. Here are the twelve signs we see most often in our malware clean-up work.
This article is part of our complete guide: WordPress Security and Malware Removal: The Complete Guide.
Signs visitors and customers notice
1. Redirects to spam or scam sites
Visitors are sent to gambling, pharmacy, adult, fake prize or tech-support scam pages. Often this only happens on mobile, only for visitors arriving from Google, or only once per visitor, so you may not see it when you type your address directly. Test from a phone, on mobile data, by clicking your site in Google results.
2. Browser or Google warnings
Chrome shows “Deceptive site ahead” or “The site ahead contains malware”, or Google results show “This site may be hacked” under your listing.
3. Pop-ups and ads you did not add
Unexpected pop-ups, banners or push notification prompts appear.
4. Customers receiving spam from your domain
Your domain sends spam or phishing emails, or your hosting company reports outgoing spam.
Signs in Google
5. Spam pages in search results
Search site:yourdomain.com. If you see pages in Japanese, Chinese or other languages you do not use, or pages about pharmaceuticals, replica goods or casinos, your site has likely been injected with spam. See the Japanese keyword hack guide.
6. Strange titles and descriptions for your real pages
Your genuine pages show spammy titles or descriptions in Google, even though they look normal when you visit them. Some malware shows different content to Googlebot (cloaking).
7. Security issues or manual actions in Search Console
Check Security & Manual Actions in Search Console. “Hacked content”, “Malware” or “Deceptive pages” notices confirm a problem.
8. Sudden spikes in indexed pages or sudden traffic drops
The Page indexing report jumps by thousands of URLs you did not create, or organic traffic drops sharply. See the Page indexing report explained.
Signs inside WordPress and hosting
9. Unknown administrator accounts
Check Users and filter by Administrator. Any account you do not recognise is a red flag.
10. Unfamiliar plugins, files or code
Plugins you did not install, files with random names in the root or uploads folders, PHP files inside /wp-content/uploads/, or obfuscated code (long strings of random characters, eval, base64_decode) in theme files.
11. You cannot log in, or settings change by themselves
Your password stops working, the site URL changes, or new scheduled tasks appear.
12. The site becomes slow or the host suspends it
Malware can consume server resources, send spam or mine cryptocurrency. Hosts may suspend accounts for abuse.
What to do in the first hour
Stay calm. Acting methodically limits the damage.
- Do not delete everything in panic. You may destroy evidence of how the attacker got in, and lose good content.
- Take a full backup of the current state (files and database), labelled as infected. It is useful for analysis.
- Change passwords for WordPress admins, hosting, FTP/SFTP, database and email. Use a password manager and unique passwords.
- Remove unknown admin users, after noting their usernames and creation dates.
- Put the site in maintenance mode if it is redirecting visitors to harmful sites, to protect customers.
- Contact your host. They may have logs, malware scans and clean backups.
- Check Search Console for security issues and note affected URLs.
- Decide on clean-up: restore a known-clean backup (only if you know when the hack started and can close the hole) or perform a full clean-up.
What a proper clean-up involves
- Scanning and comparing core files against official WordPress versions, and replacing them.
- Reinstalling plugins and themes from official sources, removing nulled or abandoned ones.
- Searching the uploads folder and database for injected code, spam posts, rogue options and malicious scheduled tasks.
- Finding and closing the entry point: an outdated plugin, a weak password, a vulnerable theme or a compromised hosting account.
- Hardening: updates, file editing disabled, PHP execution blocked in uploads, XML-RPC restricted, security headers, login protection. See our WordPress security checklist.
- Requesting a review in Search Console after the site is clean, and removing spam URLs from Google. See removing hacked spam URLs.
Quick self-checks you can do in ten minutes
- Search
site:yourdomain.comand scroll through several pages of results for anything unfamiliar. - Open your site on a phone using mobile data, by tapping your listing in Google rather than typing the address.
- Check Users in WordPress for unknown administrators and recently created accounts.
- Look at Plugins for anything you do not recognise, including must-use plugins.
- Open Search Console’s Security & Manual Actions section.
- Check the Google Safe Browsing site status tool for your domain.
If any of these checks shows something unexpected, treat it as a confirmed incident and follow the first-hour plan above.
Why “just restore a backup” is not enough
If you restore a backup without fixing the vulnerability, attackers often return within days, sometimes using a backdoor that was already in the backup. Many backups also predate the hack by only a short time, so they may already contain hidden malicious files. Identify how the attacker got in before relying on a restore.
The SEO impact of a hack
Hacks damage SEO through spam pages that dilute your site, cloaked content that changes how Google sees your pages, warnings that scare visitors away, and manual actions that can remove pages from results. Recovery is usually possible once the site is cleaned and the review is approved, but the faster you act, the smaller the impact.
Prevention in brief
- Keep WordPress, themes and plugins updated.
- Remove unused plugins and themes.
- Use strong unique passwords and two-factor authentication for admins.
- Use reputable hosting with isolation and malware scanning.
- Keep automated off-site backups. See WordPress backup strategy.
- Monitor Search Console and uptime.
We can help immediately
Our WordPress malware removal service handles the full process: clean-up, root cause, hardening and Google review. You can read about a real recovery in our guide to a hacked WooCommerce store.
Related guides and services
- Hacked WooCommerce store recovery: how we clean malware and restore trust after a hack.
- Japanese keyword hack: how to remove Japanese spam pages from WordPress and Google.
- WordPress malware removal: emergency clean-up and hardening for hacked WordPress sites.
- Technical SEO audit checklist: the 40-point technical checklist we use on every site.
- WordPress services: fast, secure WordPress builds and maintenance.
Get expert help
If you see any of these signs, act now. We clean the infection, close the entry point, harden the site and help you get Google warnings removed. Start with our WordPress malware removal service, browse real client results in our case studies, or contact us for a free, no-pressure review of your website.
Frequently asked questions
How do hackers get into WordPress sites?
Most often through outdated or vulnerable plugins and themes, weak or reused passwords, nulled software and compromised hosting accounts.
Can a security plugin remove all malware?
Scanners help detect problems, but complex infections and backdoors often need manual clean-up.
Will Google remove the hacked warning automatically?
After cleaning, request a review in Search Console. Warnings are usually removed within days once the site is clean.
Is my customer data at risk?
It can be, depending on the attack. If you run a store or collect personal data, take advice on your data protection obligations.