Most people don't find out their site is compromised from a security dashboard — they find out from an angry customer, a Google warning, or a sudden drop in sales. By then the damage is already spreading. The good news is that a hacked WordPress website almost always leaves clues. Below are seven of the clearest signs of a hacked WordPress website, what each one usually means, and exactly what to do next.
1. Your site redirects visitors to a strange website
You (or your customers) click through to your site and land on a spammy pharmacy, betting, or adult page instead. Redirect hacks are one of the most common attacks we clean up, and they're sneaky: they often only trigger for visitors coming from Google, or only on mobile, so the site looks fine when you check it directly.
What to do: test your site from a phone, from an incognito window, and by searching your brand on Google and clicking the result. If any of those redirect somewhere unexpected, the malicious code is usually hidden in your theme files, your database, or a rogue plugin — and it needs to be removed at the source, not just patched over.
2. Google flags your site as "deceptive" or "dangerous"
A red warning screen in Chrome, a "This site may be hacked" label under your search result, or a message in Google Search Console are all signs Google has detected malware or spam on your pages. This is one of the most costly signs of a hacked WordPress website, because it scares away every visitor and can crater your rankings within days.
What to do: don't just request a review — the warning will come straight back if the infection is still there. Clean the site completely first, then submit for re-review through Search Console.
3. Pages or spam content you never created
You find hundreds of pages selling counterfeit goods, or your posts are stuffed with hidden links to sites you've never heard of. Attackers inject this "SEO spam" to piggyback on your domain's reputation. Often these pages are invisible to you but fully visible to Google.
A single injected spam page is rarely alone. When we find one, we assume there's a backdoor generating more — and we hunt that down too.
4. Your site suddenly got slow — or keeps going down
Malware and unauthorised scripts consume server resources. If your once-snappy site is now crawling, timing out, or throwing 500 errors for no obvious reason, a compromise (or an attacker using your server to attack others) is a real possibility.
What to do: check your hosting resource usage and error logs. Unexplained spikes in CPU, outbound traffic, or PHP errors are red flags worth investigating properly.
5. New admin users you didn't add
Log in to Users → All Users and look for accounts you don't recognise, especially ones with the Administrator role. A rogue admin account is how attackers keep their access even after you change your password. This is one of the most serious signs of a hacked WordPress website, because it means someone else has the keys.
What to do: remove unknown admins, force a password reset for every legitimate user, and rotate your hosting and database passwords too.
6. Unexpected changes to files, or files that shouldn't be there
Modified core files, strange .php files in your uploads folder, or a recently-changed wp-config.php or .htaccess are classic infection markers. Attackers hide small "backdoor" scripts in obscure folders so they can re-infect the site after a clean-up.
What to do: compare your core files against a fresh copy of WordPress, and scan for recently modified files. If you're not comfortable doing this, it's exactly the kind of job to hand to a specialist — one missed backdoor undoes the whole clean-up.
7. Your host suspends your account or sends a malware notice
Hosting providers scan for malware and phishing content, and they will suspend a site (or your whole account) to protect their network. An email from your host about "malicious content" or "abuse" is not spam to ignore — it's a direct sign your WordPress website has been hacked and needs urgent attention.
What to do if your WordPress website has been hacked
If any of the above sounds familiar, work through these steps rather than panicking:
- Don't just delete the visible symptom. Redirects and spam pages are downstream of a backdoor. Remove the symptom only, and it returns within days.
- Take a backup of the current (infected) state before you change anything — it's useful evidence and a safety net.
- Clean the files and the database. Infections live in both. This is the step most DIY clean-ups miss, which is why so many sites get re-hacked.
- Change every password — WordPress admins, hosting, FTP/SFTP, and database.
- Update everything — WordPress core, themes and plugins — and delete anything you no longer use.
- Harden the site so the same hole can't be reused, then request Google review if you were flagged.
We do exactly this every day. If you'd rather hand it over, our WordPress security & error fixing service removes malware and backdoors from the files and the database, then hardens the site — with a clean-or-free guarantee.
How to stop it happening again
Cleaning a site is only half the job. Sites that get hacked once tend to get hacked again unless something changes — because the same outdated plugins, weak passwords and unmonitored files are still there. That's why the real fix is ongoing protection: continuous malware scanning, a firewall, automatic updates and someone actually watching.
Our security monitoring keeps your site scanned, hardened and monitored around the clock, so a small problem is caught before it becomes a hacked homepage. Many of the businesses we protect came to us after a nasty hack — and haven't had a single issue since.
Not sure where your site stands? Get in touch and we'll take a look. No jargon, no pressure — just a straight answer on whether you're dealing with a hacked WordPress website, and what to do about it.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.