Website & Development
WordPress Hacked? A Step-by-Step Plan to Restore and Secure Your Site
Copy for AI
Has your WordPress site been hacked? Then work in this order: isolate the site, first make a backup of the infected state, then clean up (core files, plugins, themes and unknown admins), restore to a clean version and only re-secure at the end. Never start by randomly deleting suspicious code until it “works again”, because that way you miss the backdoor the attacker uses to come back. In this article you will find the full step-by-step plan, how to get the Google warning removed and how to prevent it from happening again.
How do you know for sure your WordPress is hacked?
A hack usually shows up through a few recognisable signals: visitors get redirected to spam, gambling or dubious sites, your homepage is defaced, unknown admin accounts appear in your dashboard, or Google Search Console sends you a notice about hacked content. Sometimes it is subtler: your site is suddenly slow, your host warns you about suspicious traffic, or your rankings collapse because Google found hidden spam pages that you cannot see.
In doubt? View your site in a clean browser while logged out, and search for your domain in Google. Hidden spam (the so-called “SEO hack”) is often only visible to search engines and not to the logged-in administrator. A quick test: request your homepage and a few existing URLs through a tool like cURL and check whether there is code or there are links in it that you did not put there.
Important to stay realistic: not every glitch is a hack. A white page or an error message after an update is usually a plugin conflict, not a break-in. First establish what is really going on before you start deleting things in a panic.
What is the first step when your WordPress is hacked?
The very first step is to isolate the site and delete nothing in a rush. Put WordPress into maintenance mode or take the site temporarily offline, so visitors and Google no longer receive infected pages and the damage does not grow.
Then do the following, in this order, before you clean anything up:
- Make a full backup of the infected state. It sounds counterintuitive, but you want to preserve the files and the database exactly as they are now. You need them to investigate what happened, and if a cleanup goes wrong, you can go back.
- Collect evidence. Note when you discovered it, which notifications you received and what is visibly wrong. Keep the server logs from your hosting; they often contain the time and the entry point of the attack.
- Notify your hosting provider. On a shared server your infection can affect other sites, and the other way around. Many hosts can help with logs, a scan or a temporary quarantine.
- Do not change anything in the content yet. It is tempting to immediately delete that one odd line, but without an overview you only make the investigation harder.
Only once the site is safely isolated and you have a backup of the evidence do you move on to cleaning up.
How do you thoroughly clean a hacked WordPress site?
You clean up by replacing infected components with clean originals, not by endlessly hunting for and deleting suspicious code. That is how you make sure you do not overlook anything.
Work through this systematically:
- Scan the entire installation. A security scanner such as Wordfence, Sucuri or MalCare searches your files and database for known malware and modified core files. Use it as a compass, not as the only truth.
- Replace the WordPress core. Download a fresh copy from WordPress.org and fully restore the core folders (
wp-adminandwp-includes) and the individual core files in the root. Do not edit infected files by hand; replacing is safer and faster. - Reinstall plugins and themes. Remove every plugin and every theme and reinstall them from the official source. Software you can no longer download anywhere (expired or “nulled” plugins) goes in the bin for good; that is often exactly where the leak is.
- Check the suspicious places. Look specifically in
wp-config.php,.htaccessandindex.phpfor injected code and redirects. In the database, watch thewp_usersandwp_optionstables. - Remove unknown admin accounts and rogue cron jobs. A leftover administrator or scheduled task is THE way an attacker comes back after you have cleaned up.
- Reset all passwords and keys. All WordPress logins, your database password, FTP/SFTP, hosting panel and the secret keys (salts) in
wp-config.php. Assume that everything the attacker could see has been compromised.
Not sure you have really caught it all? With a deep or repeated infection, professional malware removal is not a luxury. A half-cleaned site that is reinfected a week later ends up costing you more than having it done properly straight away.
How do you restore your site and get the Google warning removed?
Restoring can be done in two ways: rolling back to a clean backup from before the hack, or thoroughly cleaning the current site as described above. An older, guaranteed clean backup is often the fastest and most reliable route, provided you know it dates from before the break-in. If you are not sure when the hack started, cleaning up is safer than restoring a backup that may already have been infected.
Was your site flagged by Google with “this site may be hacked”? Then you solve it like this:
- Check the Security Issues report in Google Search Console to see what exactly Google found, with example URLs.
- Make sure every reported issue is genuinely resolved. Test the example URLs again and confirm they are clean.
- Click Request review and clearly explain what you found and which steps you took to fix it.
Only request that review once you are certain the site is clean. An early request will be rejected and only extends the period in which your site is marked as unsafe. A review can take from a few days to a few weeks, depending on the type of infection. So count on some patience, and use that time to get your security in order.
After recovery, keep an eye on your rankings too. Hidden spam and a security warning can temporarily hurt your organic positions. The approach to rebuilding them looks a lot like what we describe in keeping your rankings after a website redesign, and you will find the broader SEO basics in our WordPress SEO checklist.
How do you prevent WordPress from being hacked again?
Most hacks are not sophisticated attacks but the result of neglected maintenance: an outdated plugin, a weak password or a missing backup. So the real fix is not in cleaning up, but in structural security. Want to cover this fully? Then work through our WordPress security checklist with 12 measures. This is the foundation:
- Keep everything up to date. WordPress core, plugins and themes. Attackers mainly exploit known vulnerabilities in outdated software, so updating on time closes the vast majority of doors.
- Shrink your attack surface. Remove plugins and themes you do not use. Every component you do not have cannot be hacked either.
- Turn on two-factor authentication (2FA). Even if someone knows your password, they will not get in without the second code. This blocks the vast majority of brute-force attacks on your login.
- Use strong, unique logins and limit admin rights. Do not give everyone an admin account and clean up old users.
- Arrange reliable, automated backups. Store them separately from your server and test now and then whether you can actually restore them. A backup you cannot restore is not a backup.
- Deploy a firewall or security plugin. It blocks suspicious traffic and known attack patterns before they reach your site.
Maintenance is not a one-off action but a rhythm. At our web design agency we build sites that not only convert but also stay manageable and secure, on WordPress or on another platform that fits your situation. Which choice is right for you depends on your team, your content and your growth plans, as we explain in the B2B website guide.
The short summary
You restore a hacked WordPress site in a fixed order: isolate, make a backup of the infected state, clean up by replacing files instead of deleting them, remove unknown admins and tasks, reset all passwords, and only then request a review in Search Console. But the real work starts after recovery: without updates, strong logins with 2FA and tested backups, you will be back in the same place before you know it. A site you trust is also a site that keeps delivering leads.
Would you like help cleaning up, restoring or structurally securing your WordPress site? Book your free intake call.
Free website scan
Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.
We only use your details for your scan. No spam, unsubscribe anytime.