First, breathe
A hacked WordPress site feels like a disaster, and it is stressful, but it is almost always recoverable. Sites get cleaned and restored every day, yours included. What matters now is acting in the right order and not making it worse in a panic.
If you are on our WP Security Manager service, stop here and open a support ticket. Cleaning this up is what you pay us for, it is covered, and we would rather you let us handle it than start pulling things apart. The rest of this article is for everyone else, and for understanding what happened.
How to tell you have actually been hacked
The common signs, from obvious to subtle:
- Your site redirects visitors somewhere else, often something dubious.
- Content you did not write appears, or pop-up adverts you did not add.
- Your browser or Google warns visitors that the site is unsafe.
- You cannot log in to wp-admin though the password is correct.
- Your host, ourselves included, notifies you of malicious activity or suspends the account, as our article on accounts suspended for spam or abuse describes.
- The site is suddenly slow, or sending spam, because a compromised site is often quietly working for someone else.
What to do, in order
- Do not delete everything in a panic. The instinct to wipe it all and start over destroys the evidence of how they got in, which means it can simply happen again, and it may destroy the only copy of content you have no backup of. Slow down.
- Change your passwords, all of them: your WordPress admin, your cPanel, and your hosting database. Do this from a device you trust. If a compromised computer is how they got your password in the first place, changing it from that same machine hands them the new one too.
- Take a backup of the site as it is now, hacked and all. This sounds odd, but a copy of the compromised site preserves both your content and the evidence, and a professional cleanup works from it. Our article on backups covers how, cPanel's full backup is the quickest route.
- Get it cleaned properly. This is not a job for guesswork. Modern WordPress malware hides in multiple files, recreates itself from a single missed fragment, and buries itself in the database. Removing what you can see rarely removes all of it, and a site that looks clean but is not gets re-flagged within days.
Getting it cleaned
Two honest routes:
- Let us clean it. Open a support ticket. For WP Security Manager clients this is covered. For everyone else it is a paid, per-event cleanup, quoted to the specific case, and it comes with the thoroughness that stops the reinfection cycle. Our article on WP Security Manager explains both.
- Restore from a clean backup, if you have one from before the compromise. This is the fastest recovery of all, and it is the entire argument for keeping your own backups, covered in our backups article. The catch is that you must be sure the backup predates the hack, restoring a backup that was already compromised simply reinstates the problem.
Afterwards: close the door they came through
A cleaned site that is not then secured is a site waiting to be hacked again, often by the same people, who know it was vulnerable. Once you are clean:
- Update everything, core, themes, and plugins, since outdated software is how the overwhelming majority of compromises happen. Our article on the WordPress update service covers this, and is the reason we offer to do it for you.
- Delete plugins and themes you do not use, including deactivated ones. An inactive plugin still sitting in the files is still an attack surface.
- Get proper security in place, so the next attempt is stopped rather than merely survived. This is exactly what WP Security Manager exists for.
Good to know
Nearly every WordPress hack traces back to one of three things: outdated software, a weak or reused password, or a plugin nobody was maintaining. All three are preventable, and prevention costs a fraction of a cleanup in both money and stress. If you have been hacked once, treat it as the expensive lesson that the update service and a security layer are worth having, because the sites that get hacked repeatedly are almost always the ones where nothing changed after the first time.