You open your site and something is wrong. Maybe it redirects to a strange page, or a customer messages to say Google is showing a warning. Maybe you search your own domain and find hundreds of casino pages you never created.
Don’t panic, and don’t start deleting things. What you do in the first hour decides whether the cleanup takes a day or a month, and whether the attacker gets back in a week later. This guide covers how to confirm the hack, what to preserve, what to avoid and how to recover properly.
How to Tell Your WordPress Site Has Been Hacked
Hacked sites don’t always look hacked, and that’s the problem. The most damaging attacks are invisible to you when you visit your own site. Check for these signs:
- Pages in Google you never made. Search
site:yourdomain.comand look for gambling, pharmaceutical or foreign-language pages. Attackers often hide them from logged-in owners and show them only to search engines. - Visitors redirected somewhere else, often only on mobile or when arriving from Google.
- Admin users you don’t recognise under Users in your WordPress dashboard.
- A browser or Google warning such as “Deceptive site ahead” or “This site may be hacked.”
- Your hosting provider suspended the account or sent a malware notice.
- Your email suddenly stops arriving, or your invoices bounce. A compromised account may be sending spam, which gets your server blacklisted.
- A defaced homepage, or a plain blank page.
If any of these match, treat it as a real incident until proven otherwise.
Step 1: Don’t Delete Anything Yet
This is the hardest instruction to follow, because every instinct says to remove the bad files immediately. Resist it.
Deleting files destroys the evidence of how the attacker got in. If you don’t know the entry point, you can’t close it. A site cleaned without finding the way in gets reinfected, often within days, because the same vulnerable plugin or stolen credential is still sitting there.
Step 2: Preserve the Logs and Take a Copy
Server logs are your best record of what happened, and they roll over. On many hosting setups, the evidence of the original break-in disappears within days.
Before you change anything, ask your host to preserve your access and error logs, or download them yourself if you can. Then take a full copy of the site files and database, stored somewhere off the server. This forensic copy lets an investigator work out how the attacker got in, and it protects you if a cleanup goes wrong.
Step 3: Don’t Rush to Change Passwords
This surprises most people. Changing passwords is good practice, but doing it too early can backfire. If the attacker has left a backdoor or a keylogger, they can capture your new password the moment you set it, and you’ve given them fresh credentials.
The better order is to contain first (cut the attacker’s access), then reset every credential the attacker could have reached. That includes WordPress admin accounts, hosting panel, FTP and SSH, database passwords and API keys. If you must act before help arrives, do it from a clean, malware-free device.
Step 4: Don’t Restore an Old Backup and Call It Done
Restoring a backup feels like the obvious fix, but it usually restores the problem. If the attacker got in through an outdated plugin, a backup from last week still contains that plugin, and quite possibly the backdoor too.
A backup is useful as a reference point, not a cure. It’s worth keeping, but a clean-looking restore without finding the root cause just resets the clock until the next attack.
Step 5: Check How Far It Has Spread
A hacked WordPress site is often not the only thing compromised. Check whether:
- Other sites in the same hosting account were infected. Attackers move sideways.
- Email accounts are sending spam or phishing from your domain.
- Your site appears on Google Safe Browsing or on mail blacklists.
- Customer data, such as WooCommerce orders or a contact-form database, may have been exposed. If it has, you may have legal and notification obligations depending on where you operate.
What a Proper Cleanup Includes
“We removed the virus” isn’t a cleanup. A thorough job covers these steps, in order:
- Contain the attacker’s access before anything else.
- Preserve the logs and a forensic copy.
- Remove injected pages, web shells and backdoors, all of them rather than just the obvious ones.
- Reset every credential the attacker could have reached.
- Delist the site from Google Safe Browsing and any mail blacklists.
- Report in writing what happened, how they got in and what was changed.
- Harden the site so that same route closes permanently.
- Follow up with a scan a couple of weeks later to confirm the site stayed clean.
If someone offers you a cleanup that skips the report or the root-cause step, you’re buying a temporary fix.
Getting Off Google’s Warning List
If Google has flagged your domain, every visitor sees a red warning page, and your search traffic collapses. Removal requires the site to be genuinely clean first. After that, a review request goes through Google Search Console, and approval can take days. Requesting a review before the cleanup is complete usually gets rejected and can lengthen the process, so clean thoroughly first.
How to Stop It Happening Again
Most WordPress compromises trace back to a short list of causes: outdated plugins and themes, pirated (“nulled”) themes carrying hidden malware, weak or reused passwords, and abandoned admin accounts.
Keep everything updated, delete plugins you don’t use, never install nulled software and enable two-factor authentication on every admin account. A web application firewall adds a strong layer in front of the site, but be clear about what it does. A firewall blocks attacks it can see. It doesn’t patch a vulnerable plugin and it can’t clean a site that’s already infected. Protection and cleanup are two different jobs, and you need both.
Get Help Now: Armor SOS
If your site is hacked right now, Armor SOS is Tremhost’s emergency cleanup service. Triage is free and usually starts the same day, often within the hour. We work on sites hosted anywhere, not just with us. We contain the attack, remove every injected page, shell and backdoor, reset compromised credentials, handle your Google and blacklist delisting, and give you a written report on how they got in. We clean up infections like these across our own fleet every week, so nothing you’re about to describe will surprise us.
Make Sure It’s the Last Time: Armor Shield
If your site takes payments or holds client data, the smartest move after a cleanup is to make sure you never pay for one again. Armor Shield is $29 per site per month and includes unlimited malware cleanup whenever you’re compromised, firewall rules written for your specific application, blacklist and Google delisting handled by us, a monthly report and a named engineer with a four-hour response time. At that price, Shield costs less than a single emergency cleanup, which is why most clients who call us once end up on it afterwards.
For simpler informational sites, Armor Guard gives you the firewall, DDoS protection and SSL for $9 a month. Cleanup is quoted separately on that plan.
Frequently Asked Questions
How do I know if my WordPress site has been hacked?
Common signs include unfamiliar pages in Google results, redirects, unknown admin users, security warnings in browsers, a suspended hosting account or blocked email. Search site:yourdomain.com to check for pages you didn’t create.
Should I restore a backup if my WordPress site is hacked?
Not as your first move. A backup often contains the same vulnerability or backdoor, so restoring can reinstate the infection. Use backups as a reference after you’ve found and closed the entry point.
Should I change my passwords straight away?
Contain the attacker’s access first. If a backdoor or keylogger is still active, new passwords can be captured immediately. Reset every credential once access is cut off, using a clean device.
How long does WordPress malware removal take?
It depends on how deep the compromise goes. A single infected site is usually a faster job than a server compromised at root level. Delisting from Google or mail blacklists adds extra time after the cleanup.
Can a firewall clean a hacked website?
No. A firewall blocks attacks before they reach your site, but it can’t remove malware that is already there. Cleanup and protection are separate services.
Will I lose my website during a cleanup?
Rarely. A proper cleanup works in place wherever possible and takes a forensic copy first, so nothing is lost even if a rollback is needed.
How much does hacked website cleanup cost?
Emergency work is often billed hourly and negotiated while your site is down. With Tremhost, triage is free and cleanup is quoted after we see what we’re dealing with. On Armor Shield, cleanup is included at no extra charge, every time.


