Charles Web Works
Security · WordPress

Your WordPress site has been hacked. Here's what to do first.

Spam redirects, a Google warning, admin users you don't recognize, or a login that no longer works. A hacked site is stressful, but it's fixable. Start with the steps below, then clean it properly so it doesn't happen again.

Do these 5 things right now

  1. Don't delete the site or start over yet. You'd lose the evidence of how the attacker got in, and often your content too.
  2. Change your passwords. Your WordPress admin, your hosting account, and any FTP or database passwords. Use a new password for each.
  3. Check for admin users you don't recognize. In WordPress, go to Users and filter by Administrator. Note any you didn't create, but let the cleanup remove them, so nothing else breaks.
  4. Check Google Search Console. Under Security & Manual Actions, look at Security issues. It shows what Google found and on which pages.
  5. Tell your hosting company. They can often confirm what changed and when, and some will pause a suspension while it's being cleaned.

Signs your WordPress site has been hacked

  • Visitors are redirected to spam, pharmacy or scam sites, often only when they arrive from Google or on a phone.
  • Google shows “This site may be hacked” under your listing, or Chrome shows a red “Deceptive site ahead” page.
  • Pages you didn't write, often in Japanese or full of product names, show up when you search site:yourbusiness.com.
  • Admin accounts you didn't create, or you can't log in at all.
  • Your hosting company suspends the account or warns you about spam being sent from it.

Why WordPress sites get hacked

WordPress itself is well maintained. Most hacks get in through something around it:

  • Outdated plugins and themes. This is the most common way in. When a security hole in a popular plugin is announced, automated attacks scan the internet for sites that haven't updated.
  • Abandoned plugins. Plugins the developer no longer updates never get their holes fixed. Piles of old plugins also make a site slow to load.
  • Pirated “free” premium themes and plugins. They often come with a backdoor built in.
  • Weak or reused passwords, with no two-step login.

Outdated but not hacked yet? That's the best time to fix it. If your dashboard shows a list of available updates and you've been afraid to click them in case something breaks, that's exactly what the Full Tune-Up is for: I update everything on a copy first, test it, then apply it to the live site.

What a hacked site costs you

A hacked site can send your customers to scam pages, get your domain blocked by email providers so your own emails and contact form messages stop arriving, and get flagged by Google, which can push you down or out of search results until it's cleaned. The longer it runs, the more damage it does to the trust you've built.

How I fix it

A proper cleanup removes the hack and the way in. Deleting the obvious spam without closing the hole is why so many sites get hacked again within weeks.

  1. Contain it

    I take a full backup of the site as it is, then change every password and security key so the attacker is locked out.

  2. Clean it

    I replace WordPress, plugins and themes with clean copies, remove injected code from files and the database, and delete accounts that aren't yours.

  3. Close the hole

    I update everything, remove abandoned plugins, and harden the site: two-step login for admins, login limits and file protections.

  4. Clear the warnings

    I check Google Search Console, request a review if Google flagged the site, set up automatic backups, and send you a before-and-after report.

Flat price · Done in 7 business days

Full Tune-Up · $997

Keeping WordPress updated, backed up and hardened is part of the Full Tune-Up. If your site is already hacked, the cleanup is quoted as a flat price on your findings list before any work starts, so you know the full cost upfront.

Get your free findings list

The fix-first guarantee

You pay only after you've checked the work and you're happy with it. If anything I fixed breaks within 30 days, I fix it again at no charge.

Questions owners ask

How do I know if my WordPress site has been hacked?

Common signs: visitors are sent to spam or scam sites, Google shows “This site may be hacked” or a red warning page, strange pages in another language appear in your Google results, you find admin users you didn't add, you can't log in, or your hosting company suspends the account.

Why does my WordPress site keep getting hacked?

Almost always because the original way in was never closed, or a hidden backdoor was left behind. Removing the visible spam doesn't remove a backdoor. The fix is a full cleanup from clean copies plus updates and hardening.

Why can't I see the hack when I visit my own site?

Many hacks hide from logged-in owners and only show to visitors who arrive from Google or on a phone. Search for your business on your phone, in a private window, and click your own listing.

Should I update WordPress and plugins myself?

Yes, updates are the best protection there is. Back up first, and ideally test updates on a copy of the site, because a plugin update can occasionally break a page. That's how I do it on every Care Plan.

Will I lose my content?

Not with a proper cleanup. I keep your pages, posts, images and settings, and remove only what the attacker added.

Melissa Charles
Written by

Melissa Charles

Founder of Charles Web Works, with a background as a Sr. Software Engineer, an M.S. in AI and machine learning and a bachelor's in accounting. I fix small business websites for one flat price, and you pay after you've checked the work.

Get a free findings list for your site

Tell me your website address. I'll check it for this problem and everything else that's costing you customers, then email you a plain-English list and a flat price, usually within one business day. No sales call.

Free, no obligation. Pay only after you've checked the work.

Prefer to talk?