Get started
Security

How to Tell if Your WordPress Site Has Been Hacked

Hacked WordPress sites often look normal on the surface. Learn the common warning signs and the safe checks you can do yourself, plus what to avoid and when to call an expert.

WebXSentry guide: how to tell if a WordPress site has been hacked

Most hacked WordPress sites do not look hacked. The home page loads, the logo is in place, and nothing seems wrong. Yet the site may be sending visitors somewhere else or hosting pages you never made. This guide lists the common warning signs and the safe checks you can do yourself, without any technical skills.

The most common warning signs

No single sign proves a hack. Several together are a strong hint. Watch for these:

  • Unexpected redirects. Visitors click your link and land on an unrelated site. Sometimes this only happens on phones or only when people arrive from Google, so you may not see it yourself.
  • Strange pages or links. Pages about products or topics you never wrote, or odd links tucked into your footer or old posts.
  • New admin users. An account you do not recognise, especially one with the Administrator role.
  • Changes you did not make. Your theme looks different, plugins appear that you did not install, or settings have changed.
  • Slow or unstable performance. A site that was fine yesterday and now crawls can be running unwanted code.

Warnings from browsers, search engines and your host

Outside tools often notice a problem before you do. A red warning page in your browser, a message in Google results saying the site may be harmful, or a notice in Google Search Console are all worth taking seriously. Your hosting company may also email you to say your account was suspended or flagged for malware.

Other outside signs include a sudden drop in traffic, customers telling you your emails land in spam, or bounce messages for emails you never sent. If your site is sending spam, the mail server may have been misused.

Five safe checks anyone can do

None of these change anything on your site. They only look.

  1. Search Google for your own site. Type site:yourdomain.com into Google, using your real domain. Scan the results. Titles in another language, pages about pills, casino or fake brands, or a long list of pages you do not recognise are red flags.
  2. Read your search snippets. Search for your business name. If the title or description under your link looks spammy or has changed, that is a sign something is injecting content.
  3. Check your users list. In the WordPress dashboard, open Users. Look at every Administrator. Do you know each person? If not, note the name but do not delete anything yet.
  4. Open Google Search Console. If your site is verified there, look for the Security issues report. It will tell you if Google has detected hacked content or malware. If you have never set up Search Console, that is a good thing to do after the emergency passes.
  5. Test in a private window and on your phone. Open your site in a private browser window, and on a phone using mobile data. Some redirects only appear to first time visitors or on mobile.

What not to do straight away

When people panic, they often make recovery harder. Try to avoid these:

  • Do not delete everything. Wiping the site can destroy the evidence of how the attacker got in, and the same hole stays open.
  • Do not restore an old backup blindly. The backup may already contain the problem, or the attacker may walk back in the same way.
  • Do not ignore the warning. Hoping it goes away usually lets the damage grow, and search engines may keep warning visitors.
  • Do not reuse your old passwords. If you change passwords, make them new and unique. Do it from a computer you trust.
  • Do not pay random strangers who message you. Be careful of anyone who contacts you out of the blue offering a quick fix.

For a calm, step by step plan, read what to do in the first hour after your website is hacked. It covers the order of actions so you do not need to repeat them here.

When to call an expert

You do not need to be sure it is a hack before asking for help. Reach out to a professional if any of these are true:

  • Google or your browser is showing a security warning for your site.
  • Your host has suspended the account or sent a malware notice.
  • You found admin users, files or pages you cannot explain.
  • The site takes orders, bookings or customer details, so the risk to others is higher.
  • You cleaned something and the problem came back.

Cleaning a site properly means finding every hidden file and closing the way in. That is detailed work, and it is easy to miss something. Our website malware removal page explains what this involves, and emergency website recovery is the route for a site that is hacked or down right now.

How to lower the chance of it happening again

Most WordPress hacks come through out of date plugins, themes or weak passwords. Keeping everything updated, using strong unique passwords, limiting admin accounts and keeping tested backups removes most of the easy routes in. The WordPress security documentation is a good place to read more. If you are unsure what ongoing care should cover, see what website maintenance includes.

At WebXSentry, Emergency Recovery is a one-time engagement for hacked or down sites. Our monthly plans are Essential at $99, Business at $199 and Priority at $399, with 2, 6 or 12 hands-on hours. Security scans, a firewall and backups are part of the plans, they run month to month, and there is a 30-day money-back guarantee. Our engineers work Monday to Saturday on India time, and a person replies by your next business morning.

What to do next

Run the five checks above today. They take about fifteen minutes. If anything looks wrong, write down what you saw, take screenshots, and follow the first hour guide. If you would like a second pair of eyes first, you can request a free website maintenance audit.

Keep reading

Add-ons

Fixes related to this guide

Fixed-price add-ons, bought separately from a plan.

Security

WordPress Security Optimisation Service

One-time deep security hardening for your WordPress or WooCommerce website

$99 per site, one-time

Security

Website Firewall Hardening Service (WAF Setup)

One-time WAF setup on Cloudflare Pro that blocks attacks before they reach your website

$249 per site, one-time

Speed and search

WordPress Speed Optimisation Service

Faster pages on mobile and desktop: caching, image, database and render-blocking fixes, with a before and after PageSpee...

$149 per site, one-time

See all add-ons

Straight answers

Questions this article answers

Can a WordPress site be hacked without me noticing?

Yes. Many hacks stay hidden from the owner. Redirects may only show to visitors from Google or on phones, and spam pages can sit unseen in the background. That is why checking Google results and your users list matters.

Does a Google warning always mean my site was hacked?

Not always, but treat it seriously. Google may flag hacked content, malware or deceptive pages. The Security issues report in Search Console usually names the problem type and sample URLs, which helps you or an expert decide what to do next.

Should I delete suspicious admin users myself?

Note them down first and take screenshots. Deleting too early can remove clues about how the attacker got in. It is safer to follow a recovery plan or ask an expert, so the way in is closed at the same time.

Website care for businesses in every country

This guide applies wherever your business is. Pick your country to see how we work with your time zone.

All countries and time zones

Want someone to look after your website?

Pick a plan and a real person takes over the updates, security and backups, with hours for the changes you ask for. Month to month, and a 30-day money-back guarantee.

  • From $99/mo with hours included
  • Month to month
  • 30-day money-back guarantee
From $99/mo · hours included See plans