- Change every password first.
- Don’t just delete files, find how they got in.
- Request removal of Google warnings after cleaning.
- Updates, backups and a firewall prevent most hacks.
Signs your site has been hacked
- Unfamiliar pages appear in Google search results.
- Visitors are redirected to other sites.
- Browsers show a “deceptive site” warning.
- New admin users you didn’t create.
- Your host suspends the account.
What to do in the first hour
- 01 Change all passwordsWordPress admin, hosting, FTP, database and email.
- 02 Contact your hostThey may have logs and backups that help.
- 03 Don’t delete things randomlyYou may remove evidence of how the attacker got in.
- 04 Check your backupsFind the most recent clean backup, if one exists.
How a proper clean-up works
- Scan and remove malicious files and database entries.
- Replace WordPress core, themes and plugins with clean copies.
- Remove unknown admin users.
- Find and close the entry point, usually an outdated plugin.
- Request review from Google to remove warnings.
If malware is removed but the entry point isn’t closed, most sites are reinfected within weeks.
How to prevent it happening again
- Keep WordPress, themes and plugins updated.
- Remove plugins and themes you don’t use.
- Use strong, unique passwords and two-factor login.
- Add a firewall and keep off-site backups.
Frequently asked questions
Look for spam pages in Google, unexpected redirects, browser warnings, unknown admin users or a hosting suspension.
Usually, yes, by removing malware, replacing core files, closing the entry point and requesting review from Google.
Most often through outdated plugins or themes, weak passwords or nulled (pirated) premium plugins.
Regular updates, strong passwords, two-factor login, a firewall and off-site backups prevent most attacks.


