How to Tell If Your WordPress Site Has Been Hacked

How to tell if your WordPress site has been hacked

If something about your website feels wrong (a customer mentions a strange redirect, Google shows odd results, or your host sends a warning), the first question is simple: has it actually been hacked? This guide walks through the signs in order of certainty, the checks you can run in a couple of minutes, and what to avoid doing while you work it out. Resist the urge to start deleting things. The evidence matters.

What are the most common signs a WordPress site has been hacked?

The clearest signs are visitors being redirected to sites you don’t own, Google warning people away from your site, and administrator accounts you didn’t create. Any one of these is enough to treat the site as compromised until proven otherwise. Other signs, such as a slow site or odd emails, deserve a closer look but can have ordinary explanations.

Here is what each sign looks like in practice, and how much weight to give it.

Visitors are redirected to spam, scams or adult sites

This is the sign most owners hear about first, often from a customer. The redirect is rarely constant: many infections only fire for visitors arriving from Google, or only on mobile, or only once per visitor. That’s why the site can look perfectly normal when you type the address into your own browser while logged in.

What it means: treat a confirmed redirect as a compromise. It is almost never a plugin bug. Our guide to websites redirecting to spam covers the patterns we see most.

Google shows a warning or strange search results for your site

There are two versions. The first is a red browser warning or a “This site may be hacked” label under your listing, which means Google has detected a problem. The second is quieter: your search results show pages you never wrote, often selling pharmaceuticals, replica goods or written in Japanese. Those pages are generated by malicious code so attackers can borrow your domain’s reputation.

What it means: both point to a compromise. Search Console’s Security issues report will usually say what Google found.

New admin users you did not create

Open Users in your WordPress dashboard and filter by Administrator. An account you don’t recognise, especially one created recently with a generic name or an unfamiliar email address, is a strong sign someone has had control of the site.

What it means: assume compromise. Don’t just delete the account. Note its username, email and creation date first, because those details help show how and when the attacker got in.

Your host has suspended the account or flagged malware

Australian hosts routinely scan accounts and will suspend a site that is sending spam or serving malware, to protect their other customers. The notice usually lists the files that triggered it.

What it means: take it seriously, but keep in mind that the host’s scan found something, not everything. Cleaning only the listed files is a common reason sites get reinfected.

Unfamiliar files, plugins or code in your site

Plugins you didn’t install, PHP files with random names in your uploads folder, or blocks of unreadable code at the top of theme files are classic signs. Attackers often disguise a plugin with a believable name so it blends in on the Plugins screen.

What it means: likely compromise. If you’re not comfortable reading code, don’t edit or delete these files. Removing the visible piece while a hidden backdoor stays behind is how a one-off hack turns into a recurring one.

Your site sends spam emails or gets blocked by email providers

If customers stop receiving your form notifications, or your host reports unusual outgoing mail, the site may be being used to send spam. This one has innocent explanations too, such as misconfigured email settings or DNS changes, so check alongside the other signs rather than on its own.

What it means: investigate, but don’t assume the worst on this sign alone.

How can I check my site in two minutes without logging in?

Start from the outside, the way a customer or Google sees the site. Three quick checks (a site: search, a logged-out visit on mobile and a free external scan) will confirm most visible hacks without touching anything that could destroy evidence.

Search Google for site:yourdomain.com.au

Type site: followed by your domain into Google, with no space. Scroll through the results. You’re looking for page titles you never wrote, product names that have nothing to do with your business, or text in another language. If a few pages look odd, click the “Cached” or “More results” options and compare against your real sitemap.

Visit on mobile data, logged out, from a Google search result

Many redirects are set up to skip logged-in administrators and people who type the address directly. Turn off Wi-Fi on your phone, search for your business name in Google, and tap your own listing. Try it two or three times from different searches. If you land anywhere other than your site, even once, you’ve confirmed a redirect.

Run a free external scan

Our free WordPress Hack Checker looks at your site from the outside for common infection signs. You can also check Google’s Safe Browsing site status in the Google Transparency Report, which shows whether Google currently considers your site unsafe. An external scan only sees what’s publicly visible, so a clean result is reassuring, not a guarantee.

What should I check inside WordPress and my hosting account?

If the outside checks raise concerns, look at users, plugins, Google Search Console and recently changed files. Look, take notes and screenshots, and don’t change anything yet.

Users and roles

Under Users, filter by Administrator and compare the list with the people who genuinely need access. Check the Editor role too. Attackers sometimes create lower-level accounts that look less suspicious.

Plugins and themes you don’t recognise

Go through Plugins → Installed Plugins and Appearance → Themes. Anything you can’t account for deserves a question. Pay attention to plugins with no description, no author link, or a name that is almost, but not quite, a well-known plugin.

Google Search Console → Security issues

If your site is verified in Search Console, the Security issues report tells you whether Google has detected hacked content or malware, and often lists example URLs. If you haven’t set Search Console up, now is a good time. It’s free and it’s where you’ll eventually request a review once the site is clean.

Hosting file manager: recently modified files

In cPanel or your host’s file manager, sort the WordPress folders by modification date. WordPress core files normally only change during updates. A core file modified on a day you didn’t update anything, or PHP files sitting inside wp-content/uploads, are strong indicators. Note the dates. They often line up with the attacker’s first visit.

Could it be something other than a hack?

Yes. Some problems look like a hack but aren’t. A site that is slow, broken or offline is more often suffering from a failed update, an expired domain or a hosting issue than from an attacker.

Plugin conflicts and failed updates

A white screen, a “critical error” message or a broken layout straight after an update usually points to a compatibility problem, not an intruder. Our emergency WordPress repair service handles these, and they are generally quicker to fix than a compromise.

Expired domains or SSL certificates

If the domain registration lapses, your site can disappear or be replaced by a registrar’s parking page full of ads, which can look alarmingly like a hijack. An expired SSL certificate produces a browser security warning that owners sometimes mistake for a hack warning. Check the expiry dates before assuming the worst.

Hosting outages and caching

Hosting problems can make a site slow or intermittently unavailable, and aggressive caching can show old or mixed-up content. Your host’s status page and a quick support ticket will usually rule these in or out.

What should I do if the signs point to a hack?

Contain the damage, preserve the evidence and get the entry point identified. Cleaning the visible symptoms without finding how the attacker got in is the most common reason sites are reinfected within weeks.

Contain: change passwords and note what you have seen

Change the passwords for WordPress administrators, your hosting account, FTP/SFTP and the database, from a device you trust. Write down what you’ve observed and when, with screenshots. If customer data may be involved, the Australian Cyber Security Centre’s ReportCyber service (cyber.gov.au) is the place to report the incident.

Don’t restore or delete yet

Restoring a backup feels like the fastest fix, but if the backup was taken after the attacker got in, you’re restoring the problem. Deleting suspicious files destroys the evidence that shows how they arrived. Both are best done as part of a structured clean-up, not as a first reaction.

Get the entry point found, not just the symptoms cleaned

A proper recovery answers three questions: how did they get in, what did they change, and how do we know it’s all gone? That’s the process behind our hacked WordPress and malware removal service, and it’s documented in our anonymised Recovery Files so you can see what the work involves.

How do I stop it happening again?

Most compromises we clean up trace back to the same basics: outdated plugins, weak or reused passwords, abandoned admin accounts and no one watching. Keeping WordPress updated, backed up and monitored removes most of that risk. If you’d rather not manage it yourself, a security-focused WordPress care plan covers it, and our Business and Commerce plans include a hack-cleanup guarantee.

Frequently asked questions

Yes. Many hacks are designed to stay hidden from the site owner: some redirect only mobile visitors arriving from Google, or only inject spam pages for search engines. Check your site logged out, on mobile, and with a site: search in Google.

Use Google Search Console’s Security issues report, or check your domain in Google’s Safe Browsing site status tool. A “This site may be hacked” label in search results also means Google has detected a problem.

Sometimes. Scanners catch known malware signatures and modified core files, but custom backdoors and database injections can be missed, and malware can disable the plugin itself. A clean scan is reassuring, not proof.

Not straight away. A backup may already contain the malware or backdoor, and restoring doesn’t close the hole the attacker used. Identify the entry point first, then restore from a known-clean point.

Anywhere from hours to months. Attackers who use a site for SEO spam or hidden redirects have every reason to stay undetected, which is why ongoing monitoring matters more than a one-off check.

Not sure what you’re looking at? Run the free Hack Checker, or get your website checked by Dr Web. There’s no payment to submit a request.