Quick Route

What do you need today?

Choose the closest route and see the most useful pages straight away.

Protect

Stop small WordPress problems becoming business problems.

Maintenance, security, monitoring, backups and practical protection for websites that need to keep working.

Grow

Launch better, improve what you already have and generate more enquiries.

Website packages, ongoing growth support and useful interactive tools for businesses that want their website to do more.

Partner

Agency support without growing your internal support team.

Silent support, overflow help and white label WordPress maintenance for client websites.

Industries

Find the page that fits how your business uses its website.

Twenty sector-specific WordPress support pages, grouped by the way each website earns trust, enquiries, bookings or sales.

Pricing

Plans, fixes and add-ons without making it a puzzle.

Find the right route for ongoing protection, hosting or emergency work.

WordPress Security Guide

What To Do If Your WordPress Site Is Hacked

If your WordPress site has been hacked, the first priority is staying calm and acting in the right order. Rushing into random fixes can make recovery harder. This guide explains what to do, what to avoid and how to reduce the chance of it happening again.

Joe York
Written by Joe York Founder of PressGuard
Reading time: 10 minutes
Updated May 2026

Finding out your WordPress site has been hacked is stressful. Most business owners are not security specialists. They are trying to run a business, serve customers and keep enquiries coming in.

The good news is that many hacked WordPress websites can be recovered. The important part is handling the issue properly from the start.

If you are looking at strange redirects, unknown admin users, spam pages, warnings from Google or messages from your hosting company, do not start deleting things at random. You need a controlled response.

Immediate first steps

If you believe your WordPress site has been hacked, start here.

  • Take screenshots of warnings or unusual behaviour
  • Make a backup before making changes
  • Change WordPress administrator passwords
  • Check for unknown admin users
  • Contact your hosting provider
  • Avoid installing multiple security plugins at once
  • Do not delete files until you know what they are

How Do You Know If Your WordPress Site Has Been Hacked?

Some hacked websites are obvious. The homepage may be replaced. Visitors may be redirected to another website. Your browser may show a warning.

Other cases are harder to spot. The website may look normal while unwanted pages, files or scripts sit behind the scenes. That is why a proper check matters.

Common warning signs

  • Unexpected redirects
  • Google security warnings
  • New admin users you do not recognise
  • Spam pages appearing in search results
  • Website defacement
  • Sudden traffic drops

Less obvious signs

  • Slow WordPress admin area
  • Plugins changing without explanation
  • Hosting abuse notices
  • Strange files in website folders
  • Unexpected outbound emails
  • Search Console security warnings

One of the biggest mistakes is assuming the website is fine because the homepage loads. A website can load and still have security problems.

What To Do In The First Hour

The first hour should be about evidence, containment and access control. Do not rush into cosmetic fixes. A hacked website needs investigation, not guesswork.

Start by recording what you can see. Take screenshots. Note when the issue started. Write down which pages are affected. Check whether the problem appears for all users or only on certain devices.

Then secure access. Change passwords for WordPress, hosting, FTP, SFTP, database access and any email accounts connected to the website. If there are old admin accounts, remove them or reduce their permissions.

Do not immediately wipe the website

Deleting files before understanding the problem can remove evidence, make recovery harder and leave the original entry point open.

Should You Take The Website Offline?

Sometimes yes. Sometimes no. It depends on the type of hack and the damage being caused.

If visitors are being redirected, malware warnings are showing, customer data may be at risk or the website is sending spam, taking the site offline temporarily may be sensible.

If the issue is contained and being investigated, a maintenance mode page may be enough while recovery work takes place. The decision should be based on risk, not panic.

Check Admin Users And Access

Go to your WordPress users area and check administrator accounts. Look for names or email addresses you do not recognise.

If an unknown admin account exists, that is a serious warning. Remove it only after recording the details. Also check whether any known accounts have suspicious email addresses or unexpected permissions.

After that, review access outside WordPress. This includes hosting logins, FTP accounts, SFTP accounts and database users. A WordPress cleanup is not complete if the attacker still has access elsewhere.

Check Whether Google Has Flagged The Website

Search for your website in Google. Look for warnings in the search result. Check whether unfamiliar pages appear under your domain.

If you use Google Search Console, check the security section. Warnings there can indicate malware, unwanted content or unsafe behaviour detected on the site.

If Google has flagged the website, cleaning the website is only one part of recovery. You may also need to request a review after the issue is resolved.

Business impact

A security warning can reduce trust immediately. Even loyal customers may leave if the browser says your website is unsafe.

How Do WordPress Websites Usually Get Hacked?

Most hacked WordPress websites are not personally targeted. Many attacks are automated. They look for known weaknesses across large numbers of websites.

This is why small websites are not automatically safe. A small local business website can be attacked in exactly the same way as a larger website if it has a known weakness.

Common causes

  • Outdated plugins
  • Outdated themes
  • Weak passwords
  • Compromised admin accounts
  • Poor file permissions

Also common

  • Unused plugins left installed
  • Old administrator accounts
  • Nulled plugins or themes
  • Missing security hardening
  • No monitoring in place

A recovery process should not stop at removing visible malware. It should also ask how the attacker got in. If the entry point remains open, the site can be compromised again.

Can You Clean A Hacked WordPress Site Yourself?

Sometimes. It depends on the issue and your experience.

If you know WordPress well, understand file structures and can identify suspicious code, you may be able to handle smaller issues. If the compromise affects files, database content, users, scheduled tasks and redirects, professional support is usually safer.

The risk with a partial cleanup is that the site looks fixed but still contains a backdoor. That means the attacker can return.

A proper cleanup should include:

  • Identifying malicious files and code
  • Checking WordPress core files
  • Checking plugins and themes
  • Reviewing admin users
  • Searching for backdoors
  • Checking database content
  • Updating vulnerable software
  • Hardening security afterwards

What Not To Do After A Hack

When a website is hacked, it is tempting to try every quick fix at once. That can cause more problems.

Avoid this

  • Deleting files without checking them
  • Installing lots of security plugins
  • Restoring an old backup without checking it
  • Ignoring hosting warnings
  • Assuming the issue is fixed because the homepage works

Do this instead

  • Record what happened
  • Secure access
  • Investigate the cause
  • Remove malicious content
  • Patch the weakness
  • Monitor the site afterwards

What Happens If You Ignore A Hacked Website?

Ignoring a hacked website can turn a technical issue into a business issue.

Visitors may stop trusting the site. Search visibility may be affected. Emails from the domain may be treated suspiciously. Hosting may suspend the account if the website is sending spam or harming other users.

A hacked website can also damage the reputation of the business. People do not usually separate the website from the company behind it. If the website feels unsafe, the business feels unsafe.

How To Reduce The Risk Of It Happening Again

No provider can honestly promise that a website will never be attacked. That is not how website security works. The aim is to reduce risk, detect problems earlier and recover faster if something does happen.

The most effective protection is usually a combination of sensible maintenance, security hardening and monitoring.

  • Keep WordPress updated
  • Update plugins and themes carefully
  • Remove unused plugins and themes
  • Use strong passwords
  • Enable multi-factor authentication
  • Review administrator accounts
  • Monitor uptime and security
  • Keep tested backups
  • Harden WordPress security settings

This is where WordPress Security Hardening helps. It reduces common weaknesses and improves the baseline security of the website.

Ongoing WordPress Maintenance also matters because outdated software is one of the most common risk factors.

Good security is layered

One plugin is not a full security plan. Security comes from updates, access control, monitoring, backups, hardening and proper response when something changes.

When Should You Bring In Professional Help?

If the website generates enquiries, sales or customer trust, it is usually worth getting help quickly.

Professional support is especially important if:

  • Google is showing security warnings
  • The website redirects visitors elsewhere
  • Unknown admin accounts exist
  • Malware keeps coming back
  • The site is sending spam
  • You do not know when the issue started
  • The website handles payments or customer accounts

The longer a compromise remains active, the more complicated recovery can become.

Need help with a hacked WordPress website?

PressGuard provides malware removal, emergency WordPress fixes, security hardening and ongoing maintenance to help recover and protect business websites.

Final Advice

If your WordPress site has been hacked, do not guess your way through recovery. Secure access, preserve information, investigate the cause and remove the threat properly.

A clean website is only half the job. You also need to reduce the chance of the same issue returning.

That means updates, monitoring, backups, access control and security hardening. Not glamorous, but very useful.

Frequently Asked Questions

Should I take my hacked WordPress site offline?

Sometimes. If visitors are being redirected, malware warnings appear or customer data may be at risk, taking the site offline temporarily can be sensible.

Can WordPress be hacked even if I have hosting?

Yes. Hosting and WordPress security are different. Hosting does not automatically prevent plugin vulnerabilities, weak passwords or compromised admin accounts.

Will Google remove my website if it is hacked?

Google may show warnings or reduce visibility if harmful content is detected. After cleanup, you may need to request a review.

Can malware come back after removal?

Yes. If the original entry point remains open, the website can be compromised again.

How do I stop it happening again?

Use regular updates, monitoring, backups, strong access controls, multi-factor authentication and security hardening.