Hacked WordPress sites don't always show obvious signs. Attackers often stay hidden for months, quietly stealing data, sending spam, or using your server for crypto mining. Here are 10 warning signs to check right now — and what to do if you find them.
🚨 If you spot multiple signs on this list, take your site offline immediately and contact your hosting provider. The longer a hacked site runs, the harder the cleanup and the worse the SEO damage.
If visitors see a Google warning before reaching your site, Google's Safe Browsing has flagged you. This happens when Google detects malware, phishing pages, or spam content. Check your status at Google Safe Browsing and in Google Search Console under Security Issues.
One of the most common hack patterns: visitors are silently redirected to spam, scam, or adult sites. This often only happens for mobile users or first-time visitors, which is why site owners can miss it for weeks. Test your site using a browser in private/incognito mode or from a different device.
Go to Users → All Users in your WordPress dashboard. If you see admin accounts you don't recognise — especially with generic names or suspicious email addresses — your site has almost certainly been compromised. Attackers add backdoor admin accounts to maintain access even after you change your password.
Hosts monitor for malware and spam. If your account is suddenly suspended with a message about "malicious activity," "spam sending," or "resource abuse," it's a strong indicator your site has been hacked and is being used to attack others.
Connect via FTP or cPanel File Manager and look for PHP files in unusual places — inside /uploads/, with random names like "x7r2k.php" or "config.php" duplicates in odd directories. Legitimate WordPress files have predictable names and locations. Anything suspicious warrants investigation.
A major unexplained drop in Google Search traffic — especially when not correlated with any change you made — can mean Google has deindexed your pages after detecting spam content. Check Google Search Console for manual actions and Coverage issues.
If you start receiving bounce emails you didn't send, or your domain gets blacklisted by email providers, attackers may have installed a mail script on your server. Check your hosting control panel for mail logs showing unusual outbound volume.
Attackers often inject spam pages targeting pharmaceutical, gambling, or adult keywords — known as "pharma hacks" or "SEO spam." These pages are designed to be invisible to logged-in admins but visible to Google. Search your site in Google for: site:yoursite.com and look for pages you don't recognise.
If your site suddenly slows down dramatically, or your hosting dashboard shows unusually high CPU or memory usage, malware may be running processes in the background — cryptocurrency mining scripts are increasingly common on compromised servers.
Check the last modified date of your wp-config.php and .htaccess files via FTP or File Manager. If they've been recently modified and you didn't touch them, look inside carefully for injected code — often base64-encoded strings that look like random characters.
No clean backup? The malware is deep in the database or encrypted? That's when professional cleanup is the fastest and safest option. See our WordPress security hardening guide to prevent future attacks.
How do WordPress sites get hacked?
The most common entry points are outdated plugins or themes with known vulnerabilities, weak admin passwords, compromised themes from unofficial sources, and hosting accounts with insecure configurations. Keeping everything updated and using strong passwords prevents the vast majority of attacks.
Will restoring a backup remove the hack?
Only if the backup predates the infection. If the malware was present in the backup, restoring it brings the infection back. After restoring, immediately update all plugins, themes, and WordPress core, and change all passwords.
How much does WordPress malware removal cost?
Professional cleanup typically ranges from $100–$300 for a standard site, depending on complexity. WPFixMate offers malware removal from $99 — contact us for a free assessment first.
I'll scan, diagnose, and clean your WordPress site fast — with a full report of what was found and fixed.
Get Malware Removed — from $99