WordPress Site Hacked? A Step-by-Step Recovery Guide (2026)

A calm, ordered runbook for a hacked WordPress site: the warning signs, what to do in the first hour, how to find hidden backdoors, when to restore or clean, and how to get Google’s hacked label removed.
Navy card with a cracked WordPress shield, a warning triangle and a checklist leading to a restored website with a green padlock

If your WordPress site was hacked, work in this order: contain the damage, save a copy for evidence, find how far the attacker got, restore a clean backup or clean the files, close the hole they used, then ask Google to remove its warnings. Google warns that a site is likely to be reinfected if the original weakness isn’t fixed.

This runbook reflects how WordPress sites were actually attacked in 2026, including backdoors that hide from the dashboard and hacked sites that show visitors fake CAPTCHA pages. It works whether you fix the site yourself or brief a professional.

Not sure you’ve been hacked? Start with the signs below. Once you’ve recovered, our WordPress security checklist covers how to keep attackers out.

Key takeaways

  • Contain first: put the site behind a maintenance page served by your host, change every password and tell your host before cleaning.
  • Take a snapshot of the infected site before changing it; you’ll need it to work out how the attacker got in.
  • Restoring a clean backup is fastest, but only if the backup predates the infection and you then fix the weakness.
  • Malware can hide admin users and plugins from the dashboard, so inspect the server’s files and database directly.
  • After cleanup, request a review in Search Console’s Security issues report; Google says reviews take a few days to a few weeks.

What are the signs your WordPress site is hacked?

The clearest signs are a Google warning, redirects you didn’t set up, pages you didn’t write and administrator accounts you don’t recognize. Many hacks only show themselves to some visitors, such as people arriving from Google or on a phone, so a normal visit from your office can look fine.

SignHow to check
“This site may be hacked” in search results, or a red “Dangerous site” browser warningSearch Console: Security issues report and Messages
Visitors redirected to spam, scam or adult sitesClick through from a Google result on a phone, or fetch the page with cURL using a Google referrer
Spam pages indexed under your domain, often pharmacy or Japanese keyword pagesSearch site:yourdomain.com plus terms like pharmacy, casino or viagra
A “verify you are human” box asking visitors to paste a commandOpen the site in a private window on another device; this is the fake CAPTCHA technique
Administrator accounts or plugins you didn’t addCompare Users and Plugins screens with the database and the wp-content folder
Host suspension, bounced emails or antivirus alerts from customersYour host’s notices, email delivery reports, customer messages
Common signs of a hacked WordPress site and how to check

Google’s Search help says the “This site may be hacked” label appears when Google believes pages were changed or spam pages added, and that it stays until the owner fixes the site and requests a review. A blank page or a crashed site is not always a hack, so ask your host to rule out a failed update or an outage.

What should you do in the first hour after a WordPress hack?

Stop the damage and preserve evidence before you delete anything. Rushing to remove files destroys the clues you need to find the entry point.

  1. Write down what you see. Note the symptoms, when you noticed them and any recent changes, such as a new plugin or a new developer login. The WordPress.org hacked-site FAQ calls this the baseline of your incident report.
  2. Take the site offline properly. Ask your host to serve a 503 maintenance page from outside your WordPress files. A maintenance-mode plugin runs inside the infected install, and web.dev notes that harmful content can still reach visitors if the response comes from infected directories.
  3. Tell your host. They can check server logs, see whether other accounts on the server are affected and may hold restore points you don’t have.
  4. Snapshot the infected site. Download a full copy of the files and database as they are now, and label it clearly as infected.
  5. Change every password. That means WordPress administrators, the hosting control panel, SFTP and SSH, the database user and the email account tied to the admin login. Run a malware scan on the computers you log in from, since stolen credentials often start there.
  6. Log everyone out. Generate new security keys with the WordPress key generator and replace the values in wp-config.php, which ends every active session, including the attacker’s.

How do you find out how badly the site is compromised?

Check four places: Google’s view of the site, the user accounts, the files and the database. Assume the attacker left more than one way back in, and trust what’s on the server over what the dashboard shows.

Check Google and your accounts

In Search Console, open the Security issues report and the Messages panel for Google’s findings and sample URLs. Then open Settings > Users and permissions: web.dev advises removing any owner you don’t recognize along with their verification token, such as a meta tag or an HTML file.

Compare the WordPress Users screen with the wp_users table in phpMyAdmin (your table prefix may differ). In the June 2026 supply-chain attack on OptinMonster, TrustPulse and PushEngage scripts, Sansec found malware that created administrator accounts and a backdoor plugin designed to hide from the admin screens, and advised trusting the disk over the dashboard.

Check the files and database

  • Core and plugin files: compare them with the official WordPress.org checksums, which flags modified and extra files.
  • wp-content/mu-plugins: must-use plugins load on every request and don’t appear in the normal Plugins list. Check Point Research found a 2026 campaign planting a backdoor there.
  • wp-content/uploads: this folder should hold media, not PHP files. Any .php file there needs explaining.
  • .htaccess and wp-config.php: attackers often add redirects or code to these because they affect every request.
  • The database: check the site and home URLs in wp_options, and search posts and options for injected script tags or terms like eval( and base64_decode, which Google’s help suggests looking for.

If you or your developer have SSH access, WP-CLI speeds this up. These example commands run from the site’s root folder:

# Example checks for a hacked WordPress site (run over SSH from the site root)
wp core verify-checksums --include-root    # modified or extra core files
wp plugin verify-checksums --all           # plugins from WordPress.org only
wp db query "SELECT ID, user_login, user_email, user_registered FROM wp_users;"
find wp-content/uploads -name "*.php"       # PHP files hiding among media
ls -la wp-content/mu-plugins               # must-use plugins
find . -name "*.php" -mtime -14            # PHP files changed in the last 14 days

Add a scan from a security plugin or your host’s malware scanner, and an external scan of the public pages. The WordPress.org FAQ notes that no single scanner is best, but using several improves your odds. If the site handled customer data, such as forms or WooCommerce orders, check your legal obligations before deleting anything.

Should you restore a backup or clean the site manually?

Restore a backup if you have one from before the infection and can accept losing changes made since. Clean manually, or rebuild from fresh copies, when you don’t know when the infection started or every backup is infected.

RouteWhen it worksMain risk
Restore a clean backupYou know roughly when the hack began and have a backup from before itThe backup may already contain a dormant backdoor; the weakness is still open
Manual cleanupNo clean backup exists and the infection is limitedMissing one backdoor means reinfection
Rebuild from fresh copiesHeavy or repeated infection, or an unknown start dateTakes longer; content and uploads must be checked before import
Choosing a hacked WordPress site recovery route

How to clean a hacked WordPress site

  1. Work on a copy or with the site offline, and keep the infected snapshot separate.
  2. Replace wp-admin and wp-includes with fresh files from the same WordPress version. The WordPress.org FAQ advises uploading them over SFTP rather than using the dashboard’s reinstall, because installers overwrite existing files while hacks usually add new ones.
  3. Delete every plugin and theme folder and reinstall fresh copies from WordPress.org or the vendor. Don’t reuse the old folders.
  4. Remove unknown files from mu-plugins and uploads, and restore clean versions of .htaccess and wp-config.php, keeping only your own settings.
  5. Delete unknown administrator accounts, spam posts and injected database content.
  6. Update WordPress, plugins and themes to their latest versions, then change every password again, as the FAQ recommends once the site is clean.

How do you remove Google’s “This site may be hacked” warning?

Clean the whole site, then request a review in Search Console’s Security issues report. Google removes the label and browser warnings only after a review confirms the problem is gone.

  • Fix every issue in the report across the whole site; Google says fixing only some pages earns no partial return.
  • Check sample URLs with the URL Inspection tool, which shows the page as Google sees it, including content hidden from normal visitors.
  • Make sure cleaned pages aren’t blocked by robots.txt or a noindex tag, so Google can crawl them.
  • Click Request Review and describe the issue, the steps you took and the result.
  • Wait for the email decision without resubmitting. Google says a review can take a few days to a few weeks.

Example

A review request might read: “Hacked content: attackers injected spam pages through an outdated form plugin. We removed the pages and the backdoor files, reinstalled core, plugins and themes from fresh copies, updated everything, reset all passwords and added two-factor authentication. All sample URLs now return 404 or clean content.”

Spam pages the attacker created should return a 404 or 410 status. For urgent cases, the Removals tool in Search Console hides them faster, but web.dev warns against using it on your own pages that were only damaged. If rankings or indexed pages stay low after the review, work through our guide to why a website isn’t showing on Google.

What should you do after the cleanup?

Find and close the entry point, then watch the site closely for at least a month. Cleaning without closing the hole just resets the clock.

  • Name the likely entry point: an outdated plugin or theme, a reused or stolen password, an old developer account, or a compromised third-party script. Your infected snapshot and server logs are where you look.
  • Harden the basics: two-factor login for every administrator, fewer admin accounts, unused plugins deleted and the dashboard file editor disabled.
  • Monitor for reinfection: alerts for new administrators and file changes, a weekly malware scan and a weekly look at Search Console. Files that reappear after deletion usually mean a backdoor or scheduled task is still present.
  • Check email reputation: the WordPress.org FAQ warns that hacked sites are often used to send spam, which can get the server’s IP address blocklisted.

Then fold the routine checks, updates and backup tests into a regular schedule. Our WordPress maintenance checklist sets out what to do weekly, monthly and yearly.

When should you call a professional for WordPress malware removal?

Call one when the stakes or the complexity are beyond your comfort zone. Google’s Search Console help says fixing malware requires reading code and possibly server configuration. Get help if any of these apply:

  • You can’t find how the attacker got in, or the infection came back after a cleanup.
  • The site takes payments or stores customer data.
  • Your host has suspended the account, or you have no clean backup.
  • Google’s warning remains after a review, or you need the site back online today.

Ask any provider to explain what they found, how the attacker got in and what they changed. A cleanup without a named entry point is only half the job. For a site that keeps getting reinfected, a rebuild on a clean install by our WordPress developers can be quicker than another round of cleanup.

How TechZone can help

TechZone helps businesses in Pakistan, the UK, the UAE, the USA, Canada and Australia recover hacked WordPress sites and keep them clean. We contain the site, trace the entry point, clean or rebuild from fresh copies, handle the Search Console review and set up monitoring, and we tell you honestly if a rebuild makes more sense. Learn more about our WordPress development and support work, or contact us with your site address and the warning you’re seeing.

Frequently asked questions

Why do hackers target small WordPress sites?

Hackers target small WordPress sites because automated tools scan the web for any site running a known vulnerable plugin or a weak password, whatever its size. A hacked small site is still useful for sending spam, hosting phishing pages, redirecting search traffic or spreading malware. In 2026, Check Point Research found close to 2,000 hacked WordPress sites being used together as one criminal operation’s infrastructure.

Can I recover a hacked WordPress site without a backup?

A hacked WordPress site can usually be recovered without a backup by cleaning it manually or rebuilding it from fresh copies. You replace WordPress core, reinstall every plugin and theme from official sources, check uploads and the database for injected code, and keep your content. It takes longer than restoring a backup, and missing a single backdoor can mean reinfection.

How long does it take to recover a hacked WordPress site?

Recovering a hacked WordPress site can take a few hours when a clean backup exists and the entry point is obvious, or several days when the infection is widespread. Clearing Google’s warnings adds more time, because Google says a Security issues review can take from a few days to a few weeks after you request it in Search Console.

Will a hacked WordPress site lose its Google rankings?

A hacked WordPress site can lose Google traffic while warnings show in search results or browsers, because many visitors won’t click through a warning. Google may also drop spam pages and affected pages from its results. Traffic can return once the site is clean and the review succeeds, but spam pages left online and slow cleanups extend the damage.

Do I need to tell my customers my WordPress site was hacked?

Whether you must tell customers after a WordPress hack depends on what the attacker could reach and the data protection laws where you and your customers are. If forms, accounts or orders with personal data were exposed, check your legal obligations, and consider warning customers so they can watch for phishing. If no personal data was reachable, a formal notice may not be needed, but confirm that with a legal adviser.

Sources and further reading

Written by

TechZone Team

TechZone is a digital agency in Islamabad, Pakistan. We design and build websites, online stores, mobile apps and AI automation for businesses in the UK, UAE, USA, Canada, Australia and Pakistan, and mentor interns through our virtual internship program. On this blog we share what we use in that work every day.

Last updated

Keep reading

Related articles

Branded navy card with the headline beside a 90-day calendar, a rising search results chart and a map pin

SEO

A week-by-week SEO plan for small businesses with limited time: what to set up first, which pages to fix, what to publish, how to earn reviews and links, and how to tell if it’s working.

13 min read

Navy card with a ticked checklist beside a map pin and a local results panel listing three nearby businesses

Local SEO

Thirty local SEO steps in seven phases, from your Google Business Profile and location pages to citations, reviews, local links and tracking, each with why it matters, how to check it and what to do first.

13 min read

Navy card with the headline beside a search results page showing a sponsored ad, a budget dial and a checklist for keywords, ads and tracking

Google Ads & PPC

A plain-English guide to running Google Ads as a small business in 2026: how the auction works, why Search usually comes first, how to set up keywords, ads and tracking, and what to do in the first 30 days.

14 min read

Want expert help putting this into practice?

Tell us what you’re working on. We’ll reply with honest advice, clear next steps and a written quote.