Hacked WordPress rarely "looks" hacked at first glance. It's more often discovered when the site starts redirecting visitors to foreign sites, when spam appears in Google results under the title, or when your hosting provider notifies you that malicious code has been found. The sooner you act, the less damage to your reputation and SEO.
Signs that WordPress has been hacked
- Redirects to unknown sites (often only from mobile or only for visitors from Google)
- Japanese / pharma SEO spam — in Google, foreign spam is displayed under your page, which you cannot see in the admin
- "This page may have been hacked" warning or red Google Safe Browsing screen
- Unknown administrator users in
Korisnici - New PHP files (backdoor), often in
wp-content/uploads - Sudden slowdown or spike in traffic (site is sending spam)
How they got in — the most common entrances
- Outdated vulnerable plugin or theme — by far the most common vector. All it takes is one outdated plugin with a known vulnerability.
- Weak or leaked password (brute-force on
/wp-login.php) - Outdated WordPress core
- Infection from another site on the same hosting account
Emergency steps (if you know how)
- Change all passwords — WordPress, hosting/cPanel, FTP, and database.
- Turn off the page or put it in "maintenance".
- Check administrators and delete unknown users.
- Scan and review suspicious
.phpinuploads. - Restore a clean copy , and only then update the core, theme and all plugins.
- Request a review from Google (Search Console).
Important: restoring a backup without closing the vulnerability that entered it means that you will be infected again. The cause — usually a specific vulnerable plugin — must be removed or updated.
When it's time for an expert
If the infection returns, if you don't know which plugin it entered, or if you're losing traffic due to the blacklist — we clean it, find the entrance and close it.
Send us the link — the diagnosis is free, and we'll get back to you within 5 minutes. Urgent repair →
WMD — Super fast support.