You can usually tell a WordPress site has been hacked from one of five signs: it redirects visitors to a site you have never heard of, Google may show “This site may be hacked” or lists pages you never wrote under a site:yourdomain.com search, Search Console has a message under Security Issues, there is an administrator in Users you did not create, or the site has become slow and throws errors for no reason you changed. None of those alone is proof, and plenty of things that look like a hack are not, so below is the five-minute check that settles it, then what to do in the first hour if it is real.

What are the signs a WordPress site has been hacked?

SignWhat you seeHow strong a signal
RedirectsVisitors, or only mobile visitors, or only visitors from Google, land on a spam, pharmacy or “you have won” pageVery strong. Conditional redirects are among the most common WordPress hacks
Spam pages in GoogleA site:yourdomain.com search shows pages selling things you do not sell, often in another languageVery strong
Google or browser warnings“This site may be hacked” under your result, or a red Safe Browsing screen in ChromeVery strong
Search Console Security IssuesA message under Security & Manual Actions, Security issuesConfirmation, not a suspicion
Unknown admin usersUsers, filter by Administrator, a name you do not recogniseVery strong
Files you did not add.php files inside wp-content/uploads, or core files with a modified date from last weekStrong
You are locked outYour password stops working and the reset email never arrivesStrong
Slow site, high server load, emails bouncingHost warns about resource use or outgoing spamModerate; can also be a bad plugin
Traffic dropSearch traffic halves in a weekWeak on its own; check the other signs

Things that look like a hack and usually are not: a broken layout after a plugin update, a “there has been a critical error” screen, comment spam, a spike in failed login attempts (that is bots knocking, not a break-in), and an expired SSL certificate warning. Why WordPress keeps crashing covers those.

How do you confirm it in five minutes?

  1. Search Google for site:yourdomain.com. Read the titles. Anything you did not write is the hack talking.
  2. Open Search Console, Security & Manual Actions, Security issues. Google reports hacked content, malware and deceptive pages here.
  3. Run Sucuri SiteCheck (sitecheck.sucuri.net), free and no login. It fetches your pages the way a visitor does and flags injected scripts and blacklistings.
  4. Open Users in wp-admin and filter by Administrator. Count them. Then check Users, All Users sorted by registration for anything from the last month you did not add.
  5. Open the site in a private window on your phone, from a Google search rather than by typing the address. Redirect hacks often only fire for that path.

If you have a security plugin such as Wordfence or Solid Security installed, run its scan too; it compares WordPress core, theme and plugin files against the originals from WordPress.org and lists anything modified or added. That comparison is the single most reliable test, because attackers hide payloads inside legitimate-looking files.

Where do hacks usually hide?

PlaceWhat to look for
wp-content/uploads/Any .php file. Uploads should only contain images and documents
wp-config.php and .htaccessExtra lines you did not add, especially redirects or base64 strings
Theme functions.php and header.phpLong encoded strings, eval(, or a script tag pointing at an unknown domain
Plugins folderA plugin you did not install, often with a generic name like “wp-core-helper”
Database, wp_optionsChanged siteurl or home, or injected scripts in widget or theme option rows
Cron jobsA scheduled task (WP Crontrol shows WordPress’s; the hosting panel shows the server’s) that re-downloads the malware after every clean
Users tableAn administrator created directly in the database that does not show in wp-admin

What should you do in the first hour?

  1. Take a backup of the hacked site as it is, before touching anything, so nothing is lost if a cleanup goes wrong. Where your existing backups are stored tells you whether you also have a clean one to go back to.
  2. Change every password: WordPress admin, hosting panel, SFTP, database (then update wp-config.php), and your email if it uses the same one.
  3. Remove users you did not create and downgrade anyone who does not need Administrator.
  4. Tell your host. Managed hosts often clean malware for free and can see server logs you cannot.
  5. Restore a clean backup from before the first sign if you have one, then update everything before the site goes live again. If you do not, clean it: a scanner removes known malware, then a manual pass over the places in the table above.
  6. Update WordPress, every theme and every plugin, and delete anything inactive. The large majority of WordPress vulnerabilities are in plugins (Patchstack’s yearly report puts it above 90 percent), and an unpatched one is the usual way in.
  7. Request a review in Search Console once clean, so the warning is lifted, and re-request indexing for your key pages.

Why do hacked sites get reinfected?

Because the cleanup removed the payload and left the door. Backdoors are small files, sometimes a single line, that let the attacker back in after you have changed every password. That is why restoring a backup from before the breach beats cleaning in place when the option exists, and why the plugin that let them in has to be updated or removed rather than just scanned. If the site is reinfected within days of a clean, the backdoor is still there, and that is the point to pay for a professional cleanup rather than a third attempt.

How do you stop it happening again?

Updates within a week of release, a security plugin with file-change alerts, two-factor authentication on every administrator account, no shared logins (see which WordPress role to give your designer), and automatic off-site backups you have tested a restore from. That is the whole list; sites that follow it rarely appear in the first table. It is part of the handover on every WordPress site I build, because a site nobody maintains will be hacked eventually, and the owner is usually the last to find out.

Frequently asked questions

How do I know if my WordPress site has been hacked?

Search Google for site:yourdomain.com and look for pages you did not write, check Search Console under Security Issues, run a free Sucuri SiteCheck scan, look for administrator users you did not create, and open the site from a Google search on your phone to catch redirects.

What are the most common signs of a hacked WordPress site?

Redirects to spam sites, unknown pages in Google, a “this site may be hacked” warning, new administrator users, PHP files in the uploads folder, being locked out of wp-admin, and sudden slowness or bounced emails.

What should I do first if my WordPress site is hacked?

Back up the site as it is, change every password including hosting, SFTP and database, remove unknown users, contact your host, then restore a clean backup or clean the files and update everything before going live again.

Can Google tell me if my site is hacked?

Yes. Search Console shows hacked content, malware and deceptive pages under Security Issues and emails the property owner. Google Search may also label the result “This site may be hacked”.

Why does my WordPress site keep getting hacked again?

A backdoor file was left behind after the first cleanup, or the vulnerable plugin that let the attacker in was never updated or removed. Restore from a clean backup and update or delete the plugin.

Does a critical error mean my site was hacked?

Usually not. A “critical error” or white screen after an update is normally a plugin or theme conflict or a memory limit. Check the signs above before assuming a hack.