WordPress security checklist
7 Warning Signs Your WordPress Site Has Been Hacked
Spot suspicious users, redirects, malware warnings, rogue files and performance issues before they damage revenue, trust or search visibility.
Key takeaways
- Unexpected admin users, file changes, redirects or performance drops are often early signs of a compromised WordPress site.
- Google Search Console warnings and sudden traffic losses can indicate malware, spam pages or hacked content.
- Most WordPress hacks are easier to fix when they are found early, before search engines, customers or email providers lose trust.
- Strong passwords, updates, offsite backups, security monitoring and regular audits reduce the risk of repeat infections.
In this article
- Why WordPress sites get hacked
- Unexpected admin users or changed passwords
- Suspicious redirects
- Google warnings or blacklisting
- Suspicious files or code
- Dramatic performance drops
- Unexpected pop-ups, ads or content changes
- Spam activity or suspicious emails
- What to do if your site has been hacked
- How to prevent future hacks
- FAQs
If you run a business website on WordPress, a hack is not just a technical inconvenience. It can affect customer confidence, search visibility, enquiries, revenue and your team’s ability to operate normally.
The challenge is that many hacks are not obvious at first. Your homepage may still load. Your admin dashboard may still work. Behind the scenes, however, attackers may be adding spam pages, creating hidden accounts, sending emails or redirecting visitors.
If you are working with a wordpress web design agency, security should be part of the conversation from the start. A professional wordpress web designer or wordpress website designer should think beyond visuals and help build a site that is easier to maintain, update and protect. For business-critical websites, choosing a reliable wordpress web design company can reduce the risk of avoidable security issues.
Why WordPress Sites Get Hacked
WordPress is popular, flexible and widely used. That makes it a practical target for automated attacks. Hackers often look for outdated plugins, weak passwords, abandoned themes, insecure hosting and poorly maintained sites.
For businesses, the impact can be immediate. A hacked site can lose enquiries, trigger browser warnings, affect email deliverability and damage brand trust. If customer data is exposed, there may also be privacy and legal considerations.
Most hacks become more expensive the longer they remain hidden. Early detection gives you a better chance of containing the issue, restoring safely and protecting your organic visibility.
Warning Sign 1: Unexpected Admin Users or Changed Passwords
Start with the WordPress user list. Go to Users > All Users and check every account. Look for usernames you do not recognise, especially accounts with administrator access.
Hackers often create backdoor accounts with names that look harmless, such as “support”, “admin2” or random character strings. These accounts allow them to return even if you change your own password.
If your admin password suddenly stops working and nobody on your team changed it, treat that as a serious warning sign. Someone may be trying to lock you out while they exploit the site.
Pro tip
Keep a simple record of legitimate WordPress users and review it monthly. It is much easier to spot a suspicious account when you know exactly who should have access.
Warning Sign 2: Your Site Redirects to Suspicious Websites
One of the most common WordPress hacks sends visitors to gambling pages, fake pharmaceutical sites, adult content or malware pages. The tricky part is that the redirect may not show when you are logged in as an administrator.
Redirect malware can target only certain visitors, such as people coming from Google, mobile users or first-time visitors. That helps the hack stay hidden for longer.
Test your site in incognito mode, on mobile and from a different network if possible. If customers report strange redirects, take it seriously even if everything looks normal from your own browser.
Warning Sign 3: Google Search Console Warnings or Blacklisting
Google Search Console is one of the most important places to check. Go to the Security Issues section and look for warnings about malware, hacked content or deceptive pages.
If Google flags your site, search results may show warnings such as “This site may be hacked”. Chrome may also display full-page security warnings before visitors can reach your site. That can reduce traffic and conversions almost immediately.
A sudden disappearance from search results can also be a sign of a security problem. Before assuming it is an algorithm update, check whether Google has detected malware or spam content.
Watch out
Set up email alerts in Google Search Console. Security warnings are time-sensitive, and delays can cost traffic, leads and customer confidence.
Warning Sign 4: Suspicious Files or Code in Your WordPress Installation
Suspicious files are another strong sign of compromise. Use FTP, SFTP or your hosting control panel to inspect your WordPress folders.
Be especially careful with random PHP files in wp-content, unknown files in the uploads directory, recently modified core files and plugin or theme folders you did not install.
Malicious code is often disguised. You might see long encoded strings or functions such as base64_decode, eval, gzinflate or str_rot13. These do not always mean a file is malicious, but they are worth investigating.
Pro tip
Use reputable tools such as Wordfence or Sucuri to compare your files against known clean versions. This saves time and reduces the risk of missing hidden changes.
Warning Sign 5: Dramatic Drop in Website Performance or Speed
If your website suddenly becomes slow, times out or triggers hosting resource warnings, security should be part of your investigation.
Compromised WordPress sites can be abused for spam distribution, cryptocurrency mining, brute-force activity or other resource-heavy tasks. These activities can consume CPU, memory and bandwidth.
Check your hosting dashboard for unusual spikes. Review access logs for strange patterns, repeated requests or traffic from suspicious sources. If you are unsure what the logs mean, ask your hosting provider to help interpret them.
Warning Sign 6: Unexpected Pop-Ups, Ads or Content Changes
Some hacks are visible on the front end of the site. Watch for pop-ups you did not configure, spam links inside pages, unexpected homepage changes, hidden links in the footer or posts publishing without approval.
The Japanese keyword hack is another common example. It can create large numbers of spam pages promoting counterfeit goods, often designed to appear mainly to search engines.
Do not rely only on visual checks. Use site search, analytics, Search Console and a crawler to look for pages or content that should not exist.
Warning Sign 7: Increased Spam Activity or Suspicious Emails
A compromised website can also be used to send spam. Check your hosting email logs if customers report suspicious emails from your domain or if legitimate emails start bouncing.
Contact forms can be abused to send spam at scale. If your domain gets blacklisted by email providers, it can take time to rebuild trust even after the hack is cleaned.
Look for sudden spikes in outgoing email, unfamiliar recipients, strange subject lines or messages that nobody on your team sent.
What to Do If Your WordPress Site Has Been Hacked
If you confirm a hack, act quickly but avoid panic-cleaning without a process. You need to remove the infection and understand how it happened.
- Document the issue: take screenshots of warnings, suspicious users, redirects and files.
- Protect visitors: use maintenance mode or temporarily restrict access if malware is active.
- Contact your host: they can help isolate the account and provide server-level evidence.
- Change credentials: update WordPress, hosting, FTP, database and email passwords.
- Scan and clean: use security tools or professional malware removal if the issue is complex.
- Restore safely: if you have a clean backup from before the hack, restore it carefully.
- Close the vulnerability: update software, remove unused assets and harden access.
- Request review: if Google has flagged the site, request a review after cleanup.
Watch out
Do not simply reinstall WordPress without finding the entry point. If the same vulnerable plugin, password or hosting issue remains, the site may be reinfected.
How to Prevent Future WordPress Hacks
Prevention comes down to consistent hygiene. Most security improvements are not glamorous, but they dramatically reduce risk.
- Keep everything updated: WordPress core, themes and plugins should be patched quickly.
- Use strong authentication: long unique passwords and two-factor authentication are essential.
- Install security monitoring: use a reputable firewall and malware scanner.
- Automate offsite backups: store backups away from your hosting account.
- Remove unused assets: delete inactive plugins and themes you no longer need.
- Limit admin access: give users only the permissions they genuinely need.
- Schedule audits: review users, plugins, file integrity and security settings regularly.
Worth knowing
Many WordPress compromises exploit known vulnerabilities that could have been reduced with routine updates, stronger passwords and basic monitoring.
Check your WordPress site against these 7 warning signs today. The earlier you catch a compromise, the easier it is to protect revenue, reputation and search visibility.
Frequently Asked Questions
Can a hacked WordPress site be fixed?
Yes. Most hacked WordPress sites can be cleaned and restored. The process usually involves removing malicious code, closing the vulnerability, changing credentials and restoring from a clean backup if one is available.
How much does WordPress hack removal cost in Australia?
Costs vary depending on the size of the site and severity of the compromise. Simple cleanups may be lower, while complex infections, blacklist recovery and server-level issues can cost more.
Will my site be hacked again after it is cleaned?
Not necessarily. Reinfection usually happens when the original vulnerability remains open. After cleanup, update software, remove unused plugins, strengthen passwords and add monitoring.
How long does it take to remove a Google blacklist warning?
Once the site is fully cleaned, you can request a review in Google Search Console. Review times vary, but the process is usually faster when all malware and hacked content has been properly removed.
Should I rebuild my WordPress site after a hack?
Only if the compromise is severe or the site is already outdated. In many cases, a clean restore, professional cleanup and proper hardening are enough.