Finding out your WordPress site has been hacked is stressful, but most hacked sites can be cleaned and back to normal the same day. This guide explains the signs of a hacked WordPress site, what to do first, and how to restore a clean copy and stop it happening again.
Want it done for you? Malware cleanup is handled by our dedicated service, FixMyHackedWebsite.com. It's run under the same oversight as yInstant Access Internet Services hosting and can remove malware, repair the damage and get your site off blacklists. See Website Infected with Malware? How to Get It Cleaned.
Signs your WordPress site has been hacked
- Visitors are redirected to spam, gambling, pharmacy or "you won a prize" pages, often only on phones or only when arriving from Google.
- Google shows "This site may be hacked" in search results, or Chrome shows a red "Dangerous site" warning.
- Strange pages, links or Japanese/Chinese text appear in Google results for your domain.
- New admin users you didn't create, or you can suddenly no longer log in.
- Unknown plugins, or odd PHP files with random names in your folders.
- Your site suddenly sends spam, or your emails start bouncing because your domain was blacklisted.
- We contact you about malware found on your account.
Step 1: Contact us first
Open a support ticket as soon as you suspect a hack. Our server scans for malware automatically, so we can check what it found on your account, tell you which files are affected, and help you work out roughly when the hack started. That date matters when you pick a backup to restore.
Tell us what you've noticed and when it started. Don't delete files at random before we've had a look -- that can remove the evidence we need.
Step 2: Change every password
Assume any password connected to the site may be known to the attacker. Change them all, using a new, strong password for each:
- WordPress -- every administrator account.
- cPanel -- in Preferences > Password & Security. Consider turning on two-factor authentication too.
- FTP accounts -- in Files > FTP Accounts. Delete any you don't use.
- Database user -- in Databases > Manage My Databases, then put the new password in
wp-config.phpso the site keeps working.
If you use the same password on your own computer, email or other sites, change it there as well. It's also worth running a virus scan on the computers you use to manage the site.
Step 3: Restore a clean copy with JetBackup 5
Restoring a backup from before the hack is the quickest and most reliable way to clean WordPress. We back up your account three times a week and keep the last 7 backups (about two weeks).
- In cPanel, go to Files > JetBackup 5.
- Pick a backup dated before the first signs of the hack. If you're not sure, ask us -- we can help you choose.
- Restore the site's files and its database from that same date.
Anything added to the site after that date (posts, orders, form entries) will be lost, so note it down first if you can. If the hack is older than your oldest backup, the site needs a professional cleanup instead. Start at FixMyHackedWebsite.com.
Step 4: Update everything
Most WordPress hacks come through an out-of-date plugin or theme. Straight after restoring, update WordPress itself and every plugin and theme, and turn on automatic updates. A restored site that isn't updated can be hacked again the same way within days.
Step 5: Remove what you don't need
- In WordPress, go to Users and delete any administrator you don't recognize. When asked, give their content to your own account.
- Delete plugins and themes you don't use. Deactivated plugins can still be exploited; keep only one spare default theme.
- Remove plugins or themes from unofficial "nulled" or free-premium download sites. These often contain hidden malware.
Step 6: Harden WordPress with WP Toolkit
In cPanel, go to Domains > WordPress Management (WP Toolkit), click Security on your site's card and turn on the recommended security measures. Also check the site card for vulnerability warnings about any remaining plugins or themes.
Step 7: Check your site in Google Search Console
If Google noticed the hack, it may warn visitors or hide your pages until you prove the site is clean.
- Sign in to Google Search Console and select your site (add and verify it if you haven't already).
- Open Security & Manual Actions > Security issues, and also check Manual actions.
- If problems are listed, fix them, then click Request Review and briefly explain what you cleaned and what you changed. Reviews usually take a few days.
- Use the Pages report to look for spam URLs that were created on your domain.
Common questions
Can I just delete the bad files instead of restoring?
You can, but it's easy to miss a hidden back door, and the site gets reinfected. A restore from before the hack, followed by updates and new passwords, is much more reliable.
How did they get in?
Usually an outdated plugin or theme, a weak or reused password, or a nulled plugin. Updating, strong unique passwords and WP Toolkit hardening close off most of these.
My site was cleaned but Google still shows a warning
Warnings only go away after Google reviews the site again. Make sure you requested a review in Search Console.
Related guides
- How to Restore Your Whole Account to an Earlier Date (JetBackup 5)
- How to Restore a File or Folder with JetBackup 5
- How to Restore a MySQL Database with JetBackup 5
- How to Update WordPress, Plugins and Themes (and Turn On Auto-Updates)
- How to Secure WordPress with WP Toolkit Security Hardening
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
