If your website redirects to spam, shows pages you never wrote or has admin users you don't recognize, don't start deleting files or restoring a backup yet. Write down what you see, take the site offline, copy it exactly as it is, and change every password from a computer you've checked. Cleaning comes after that, and it only holds if you also find out how they got in.
The order matters because the obvious moves make things worse. Restoring a backup straight away overwrites the evidence and may bring back a copy that was already infected. Changing only the WordPress admin password leaves the FTP account, the database and the other users open.
Is it really hacked?
Clear signs: visitors get sent to another site, pages or links appear that nobody on your side added, a new admin user exists or your own role has changed, your host has suspended the site for malware, visitors' antivirus software blocks it, or Google shows a warning in search results or a full-page red warning in the browser.
Signs that more often have another cause: a "critical error" message right after an update, a site that is simply down, or the browser saying "Not secure" next to the address. Those have their own fixes. If you're not sure, ask your host; they may be able to tell an attack from an outage.
Before you touch anything, write down what you see, when you first noticed it, and what changed on the site recently (a new plugin, a theme edit, a new user). That note helps you date a clean backup later, and it saves time if you end up paying someone to fix it.
The safe order
- Take the site offline. The aim is that visitors stop receiving whatever the attacker added. Google's guidance for hacked sites suggests stopping the web server or pointing the domain at a simple temporarily-unavailable (503) page served from somewhere other than the infected site. An error page from the infected server itself isn't enough, and blocking search engines in robots.txt doesn't protect visitors. If you don't know how to do this, ask your host. Tell them you'll need to switch the site on and off a few times while you test.
- Tell your host. On shared hosting the problem may reach beyond your site. If you have several sites on one account, treat them all as suspect until checked.
- Copy the site as it is, infected. Download the files and the database, and label the copy "infected" with the date. You won't put it back online; it's your reference if the cleanup breaks something, and it holds any content added since your last clean backup.
- Change every access point, from a clean computer. First run a full antivirus scan on the computer you'll use: both WordPress and Google list an infected admin computer as a way in, because malware on a laptop can record the passwords typed on it. Then change the passwords for the hosting control panel, every FTP or SFTP account, the database password (and the matching line in wp-config.php), every WordPress user with admin rights, and the email accounts tied to the site. Note the names of any users you didn't create, then delete them. Generate new WordPress secret keys with the WordPress key generator and replace the old ones in wp-config.php; that logs everyone out, including an attacker with a saved session. Turn on two-factor login where you can.
- Check Search Console. If you use Google Search Console, open its users and permissions settings and remove anyone you don't recognize. An unknown owner also needs their verification removed, such as a meta tag on your home page or an HTML file on your server.
- Find how they got in. Look for outdated plugins, themes or WordPress versions with known security fixes, users you didn't create, and recently changed files. The .htaccess file is a frequent target, as are index.php and the theme's header.php, footer.php and functions.php. Check the database too: scripts or iframes in ordinary text fields are a sign of an injected database. There can be more than one way in, so keep looking after you find the first.
- Restore or clean (see the next section), then update WordPress, every plugin and theme, and delete the plugins and themes you don't use.
- Change the passwords again. The WordPress guide is explicit: if you changed them when you found the hack, change them once more after the site is clean.
- Rescan, then put the site back online. Run a security plugin scan and check the user list once more. Once the site is back up, run an online scanner against it too, then deal with any Google warning (below).
Restore or clean: how to decide
| What you have | What to do |
|---|---|
| A backup made before the first sign of the hack | Restore files and database from that date, then update everything and close the way in. |
| A clean but old backup | Restore it, update everything, then bring across only the content you need from the infected copy (new posts, images), checking each item. |
| No clean backup | Clean in place: replace WordPress core with fresh files of the same version, reinstall plugins and themes from their official sources, check every changed file. This is where professional help earns its fee. |
The hard part is knowing which backup is clean. The date of the earliest sign of the hack is your cut-off: a backup from the week before you noticed spam may already contain the attacker's files. At hosts such as Hostinger a restore replaces the current files and database, which is why the copy in step 3 comes first.
When replacing WordPress core by hand, upload the files over SFTP rather than using the reinstall button in the dashboard. The WordPress guide warns that the dashboard installer only overwrites existing files, so files an attacker added stay in place.
Why it keeps coming back
When a cleaned site is reinfected within days, check these before cleaning again:
- another site on the same hosting account is still infected;
- only the admin password changed, and the FTP, database or other user passwords didn't;
- the secret keys weren't reset, so an old login session still works;
- the restored backup already contained the attacker's files;
- the plugin they came in through is still outdated;
- the database still holds injected content that a file scan doesn't see;
- the computer used to log in is infected.
Google warnings and the review
If Google flagged the site, the Security Issues report in Search Console shows what it found. Once you've fixed everything, request a review from that report and describe what you did, for example which plugin you updated and which files you removed.
Don't request it early: Google's guidance is to ask only once the site is cleaned, the way in is fixed and the clean site is back online. After you send it, wait for the decision; Google asks you not to resubmit while a request is pending. Google's hacked-site guidance gives rough review times of about a day for phishing, a few days for malware and up to several weeks for spam, and says warnings are removed within 72 hours once the site is found clean.
Pages the attacker created can be deleted so they return a "not found" (404) error; they drop out of Google over time.
Keep a copy off your host
The WordPress hardening guide recommends regular backups of the files and database kept in a trusted place. For a small business, the practical version is a regular download to your own computer or cloud storage, and one after every larger change. If the host suspends your account, backups that only exist on that account may be out of reach exactly when you need them.
What your host's tools do and don't cover
Many hosts include a scanner and backups. Take Hostinger: its malware scanner checks the files in your site's folder, not the database, so injected posts or settings won't show up. It can remove or clean files on its own, and its documentation notes that it sometimes flags legitimate code, so have your own copy before relying on it. Hostinger also sells a one-time cleanup by its security team for WordPress sites. Its automatic backups run weekly by default, daily on some plans; restoring one overwrites your current files or database and can't be undone, and email mailboxes aren't included in website backups.
None of these tools change your passwords elsewhere, check your laptop, clear unknown users out of Search Console or tell you how the attacker got in. Treat them as part of the steps above, not a replacement for them.
When to pay for professional cleanup
Get help when the infection came back after you cleaned it, when several sites on the account are affected, when there is no clean backup and you're not comfortable reading PHP files, or when the attacker set up fake login or payment pages. In that last case, customer data may be involved: Google's guidance says to consider your business, regulatory and legal responsibilities before you clean up or delete files, and what those are depends on where you operate. Give whoever you hire your notes from the first step and the infected copy; both save them time.