12 Signs Your WordPress Site Has Been Hacked (and What to Do in the First Hour)

Spam pages in Google, redirects on mobile, unknown admins or a sudden traffic drop can all mean a hack. Here are 12 warning signs and exactly what to do in the first hour.
12 Signs Your WordPress Site Has Been Hacked (and What to Do in the First Hour), MIVAQ guide cover

Most WordPress hacks are not dramatic. There is rarely a skull on the homepage. Instead, attackers quietly use your site to send spam, redirect visitors, host phishing pages or create thousands of spam pages for search engines. Owners often find out weeks later, when Google shows a warning, traffic collapses or a customer mentions something strange. The sooner you recognise the signs, the less damage there is to your reputation and rankings. Here are the twelve signs we see most often in our malware clean-up work.

This article is part of our complete guide: WordPress Security and Malware Removal: The Complete Guide.

Signs visitors and customers notice

1. Redirects to spam or scam sites

Visitors are sent to gambling, pharmacy, adult, fake prize or tech-support scam pages. Often this only happens on mobile, only for visitors arriving from Google, or only once per visitor, so you may not see it when you type your address directly. Test from a phone, on mobile data, by clicking your site in Google results.

2. Browser or Google warnings

Chrome shows “Deceptive site ahead” or “The site ahead contains malware”, or Google results show “This site may be hacked” under your listing.

3. Pop-ups and ads you did not add

Unexpected pop-ups, banners or push notification prompts appear.

4. Customers receiving spam from your domain

Your domain sends spam or phishing emails, or your hosting company reports outgoing spam.

Signs in Google

5. Spam pages in search results

Search site:yourdomain.com. If you see pages in Japanese, Chinese or other languages you do not use, or pages about pharmaceuticals, replica goods or casinos, your site has likely been injected with spam. See the Japanese keyword hack guide.

6. Strange titles and descriptions for your real pages

Your genuine pages show spammy titles or descriptions in Google, even though they look normal when you visit them. Some malware shows different content to Googlebot (cloaking).

7. Security issues or manual actions in Search Console

Check Security & Manual Actions in Search Console. “Hacked content”, “Malware” or “Deceptive pages” notices confirm a problem.

8. Sudden spikes in indexed pages or sudden traffic drops

The Page indexing report jumps by thousands of URLs you did not create, or organic traffic drops sharply. See the Page indexing report explained.

Signs inside WordPress and hosting

9. Unknown administrator accounts

Check Users and filter by Administrator. Any account you do not recognise is a red flag.

10. Unfamiliar plugins, files or code

Plugins you did not install, files with random names in the root or uploads folders, PHP files inside /wp-content/uploads/, or obfuscated code (long strings of random characters, eval, base64_decode) in theme files.

11. You cannot log in, or settings change by themselves

Your password stops working, the site URL changes, or new scheduled tasks appear.

12. The site becomes slow or the host suspends it

Malware can consume server resources, send spam or mine cryptocurrency. Hosts may suspend accounts for abuse.

What to do in the first hour

Stay calm. Acting methodically limits the damage.

  1. Do not delete everything in panic. You may destroy evidence of how the attacker got in, and lose good content.
  2. Take a full backup of the current state (files and database), labelled as infected. It is useful for analysis.
  3. Change passwords for WordPress admins, hosting, FTP/SFTP, database and email. Use a password manager and unique passwords.
  4. Remove unknown admin users, after noting their usernames and creation dates.
  5. Put the site in maintenance mode if it is redirecting visitors to harmful sites, to protect customers.
  6. Contact your host. They may have logs, malware scans and clean backups.
  7. Check Search Console for security issues and note affected URLs.
  8. Decide on clean-up: restore a known-clean backup (only if you know when the hack started and can close the hole) or perform a full clean-up.

What a proper clean-up involves

  • Scanning and comparing core files against official WordPress versions, and replacing them.
  • Reinstalling plugins and themes from official sources, removing nulled or abandoned ones.
  • Searching the uploads folder and database for injected code, spam posts, rogue options and malicious scheduled tasks.
  • Finding and closing the entry point: an outdated plugin, a weak password, a vulnerable theme or a compromised hosting account.
  • Hardening: updates, file editing disabled, PHP execution blocked in uploads, XML-RPC restricted, security headers, login protection. See our WordPress security checklist.
  • Requesting a review in Search Console after the site is clean, and removing spam URLs from Google. See removing hacked spam URLs.

Quick self-checks you can do in ten minutes

  • Search site:yourdomain.com and scroll through several pages of results for anything unfamiliar.
  • Open your site on a phone using mobile data, by tapping your listing in Google rather than typing the address.
  • Check Users in WordPress for unknown administrators and recently created accounts.
  • Look at Plugins for anything you do not recognise, including must-use plugins.
  • Open Search Console’s Security & Manual Actions section.
  • Check the Google Safe Browsing site status tool for your domain.

If any of these checks shows something unexpected, treat it as a confirmed incident and follow the first-hour plan above.

Why “just restore a backup” is not enough

If you restore a backup without fixing the vulnerability, attackers often return within days, sometimes using a backdoor that was already in the backup. Many backups also predate the hack by only a short time, so they may already contain hidden malicious files. Identify how the attacker got in before relying on a restore.

The SEO impact of a hack

Hacks damage SEO through spam pages that dilute your site, cloaked content that changes how Google sees your pages, warnings that scare visitors away, and manual actions that can remove pages from results. Recovery is usually possible once the site is cleaned and the review is approved, but the faster you act, the smaller the impact.

Prevention in brief

  • Keep WordPress, themes and plugins updated.
  • Remove unused plugins and themes.
  • Use strong unique passwords and two-factor authentication for admins.
  • Use reputable hosting with isolation and malware scanning.
  • Keep automated off-site backups. See WordPress backup strategy.
  • Monitor Search Console and uptime.

We can help immediately

Our WordPress malware removal service handles the full process: clean-up, root cause, hardening and Google review. You can read about a real recovery in our guide to a hacked WooCommerce store.

Related guides and services

Get expert help

If you see any of these signs, act now. We clean the infection, close the entry point, harden the site and help you get Google warnings removed. Start with our WordPress malware removal service, browse real client results in our case studies, or contact us for a free, no-pressure review of your website.

Frequently asked questions

How do hackers get into WordPress sites?

Most often through outdated or vulnerable plugins and themes, weak or reused passwords, nulled software and compromised hosting accounts.

Can a security plugin remove all malware?

Scanners help detect problems, but complex infections and backdoors often need manual clean-up.

Will Google remove the hacked warning automatically?

After cleaning, request a review in Search Console. Warnings are usually removed within days once the site is clean.

Is my customer data at risk?

It can be, depending on the attack. If you run a store or collect personal data, take advice on your data protection obligations.

Keep reading

How to Start a Shopify Store – MIVAQ complete guide cover
ShopifyWeb
Step-by-step guide to starting a Shopify store in 2026: costs, plans, themes, products, payments, shipping, SEO and a full launch checklist.
Wix & Squarespace SEO – MIVAQ complete guide cover
SEOWeb
The complete 2026 guide to Wix SEO and Squarespace SEO: setup, titles, images, speed, local SEO, schema, redirects and fixing sites not
How to Build a WordPress Website – MIVAQ complete guide cover
WebWordPress
Step-by-step guide to building a WordPress website for your business in 2026: costs, hosting, themes, plugins, SEO, speed, security and a launch

Need help putting this into practice?

We turn ideas like these into working websites, stores and growth plans. Tell us what you are working on.