Bharathan
Markets Chennai India Kuwait Dubai Abu Dhabi UK Canada
I reply within one working day
Covered Updates Backups SSL Malware clean-up Uptime PageSpeed
I reply within one working day
Fixes

My WordPress site got hacked, how to recover and prevent it.

Spam pages, strange redirects or a red warning screen? Don’t panic. Here’s what to do in the first hour, how a clean-up works, and how to stop it happening again.

Bharathan.P
Bharathan.PFreelance WordPress developer & SEO specialist
Published 6 min read
My WordPress site got hacked, how to recover and prevent it
Key takeaways
  • Change every password first.
  • Don’t just delete files, find how they got in.
  • Request removal of Google warnings after cleaning.
  • Updates, backups and a firewall prevent most hacks.

Signs your site has been hacked

  • Unfamiliar pages appear in Google search results.
  • Visitors are redirected to other sites.
  • Browsers show a “deceptive site” warning.
  • New admin users you didn’t create.
  • Your host suspends the account.

What to do in the first hour

  1. 01 Change all passwordsWordPress admin, hosting, FTP, database and email.
  2. 02 Contact your hostThey may have logs and backups that help.
  3. 03 Don’t delete things randomlyYou may remove evidence of how the attacker got in.
  4. 04 Check your backupsFind the most recent clean backup, if one exists.

How a proper clean-up works

  • Scan and remove malicious files and database entries.
  • Replace WordPress core, themes and plugins with clean copies.
  • Remove unknown admin users.
  • Find and close the entry point, usually an outdated plugin.
  • Request review from Google to remove warnings.

If malware is removed but the entry point isn’t closed, most sites are reinfected within weeks.

How to prevent it happening again

  • Keep WordPress, themes and plugins updated.
  • Remove plugins and themes you don’t use.
  • Use strong, unique passwords and two-factor login.
  • Add a firewall and keep off-site backups.

Frequently asked questions

Look for spam pages in Google, unexpected redirects, browser warnings, unknown admin users or a hosting suspension.

Usually, yes, by removing malware, replacing core files, closing the entry point and requesting review from Google.

Most often through outdated plugins or themes, weak passwords or nulled (pirated) premium plugins.

Regular updates, strong passwords, two-factor login, a firewall and off-site backups prevent most attacks.

Bharathan.P
Written by Bharathan.P Chennai-based freelance WordPress developer and SEO & AEO specialist, building for the web since 2014, with teams in London and Kuwait and clients across India and the Gulf.