Your WordPress site has been hacked
Redirects to an unknown site, pharmacy or casino pages indexed under your domain in Google, a warning from your host: fixing a WordPress hack means finding the entry point, not just deleting the visible files.
Signs pointing to a hack
- Automatic redirect to another site when opening certain pages
- Google shows a "this site may be hacked" warning in search results
- Unknown pages indexed in Google under your domain (pharmacy, casino, counterfeit goods)
- A new admin user appears in WordPress that you didn’t create
- Host alert for mass spam sending or suspicious activity
- Unknown PHP files in wp-content/uploads, a folder meant to hold only media
How I work
-
Containment
I first limit access to the site or switch it to maintenance mode to stop active exploitation, without erasing evidence useful for diagnosis.
-
Finding the entry point
I check for outdated plugins and themes, pirated ("nulled") extensions, weak passwords, and access logs to identify how the intrusion happened.
-
Full cleanup
I remove injected files, fraudulently created admin accounts, and compare the WordPress core files to a clean version to spot unauthorised changes.
-
Closing the flaw
I update or replace what allowed the intrusion. Cleaning up without fixing the flaw guarantees reinfection within days.
-
Post-cleanup check
I check for any remaining backdoors and request a re-review from Google Search Console if the site had been flagged.
How the intrusion usually happens
The vast majority of WordPress hacks come through an outdated plugin or theme with a known, published flaw, or through a "nulled" extension downloaded for free outside the official repository, which often carries a backdoor from the moment it’s installed.
Once access is gained, injected files typically hide in wp-content/uploads (a folder normally reserved for media, often less closely watched) or mimic core file names to go unnoticed. An extra admin account is sometimes created directly in the database, bypassing the interface, to keep access even after a first superficial cleanup.
Login credentials and the security keys defined in wp-config.php should be regenerated after an incident, to invalidate any session or access that may have been copied during the intrusion.
Worth reading next
-
What to do in the first two hours
The order of actions when a hack has just been found.
-
Checking whether my site is compromised
The signs to look for before calling it a false alarm.
-
Cleaning an infected site
What a full clean-up involves, files and database.
-
Staying protected after a clean-up
Without this step, the same hole gets reused within days.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.