Is My WordPress Site Hacked? 7 Warning Signs

Something feels off with your website, but you're not sure if it's actually been hacked. Learn the 7 telltale signs of a compromised WordPress site and what to do next.

Updated on January 1, 2026

12 minutes read

    Key Points

  • Mysterious redirects to spam sites are a classic hack sign, check your .htaccess file first.

  • Admin users you didn't create mean hackers have a backdoor, delete them and keep investigating.

Something’s not right with your website. Maybe it’s loading slowly. Maybe you noticed something strange. Maybe a customer said something looked “off.” Now you’re wondering: has my WordPress site been hacked?

It’s an unsettling question. The good news is that a WordPress site hacked by attackers usually shows clear warning signs. The bad news is that many site owners miss these signs until the damage is done.

In this guide, you’ll learn the seven most common indicators that your WordPress site has been compromised, how to verify if you’ve actually been hacked, and exactly what steps to take if you discover a breach. The sooner you identify a hack, the faster you can fix it and limit the damage.

Why Hackers Target WordPress Sites

Before diving into the warning signs, it helps to understand what hackers actually want. This context makes the symptoms make sense.

Hackers don’t usually target your specific business. They use automated tools that scan millions of websites looking for vulnerabilities. When they find one, they exploit it. Your site is valuable to them because:

  • Server resources: They can use your hosting to send spam or mine cryptocurrency
  • SEO manipulation: They inject hidden links to boost their own sites in search rankings
  • Malware distribution: Your site becomes a delivery vehicle for infecting your visitors
  • Data theft: Customer information, emails, and payment data have value
  • Ransom: Some attackers lock you out and demand payment to restore access

Most hacks aren’t obvious vandalism. Attackers often prefer to stay hidden, using your site quietly for as long as possible. That’s why knowing what to look for is so important.

The 7 Warning Signs Your WordPress Site Is Hacked

Watch for these indicators. Any single sign doesn’t guarantee you’ve been hacked, but multiple signs together are a strong signal that something is wrong.

1. Your Site Redirects to Another Website

This is one of the most obvious signs. You type in your website address, and instead of seeing your site, you end up somewhere else entirely, often a spam site, fake pharmacy, or adult content.

What to check:

  • Try visiting your site from a different device or network
  • Ask a friend to visit your site and tell you what they see
  • Check if the redirect happens on all pages or just some
  • Note whether it happens every time or only sometimes

Why it happens: Hackers inject code that redirects visitors. Sometimes they only redirect certain visitors (like those from Google search results) to avoid detection by the site owner.

Severity: High. This actively harms your visitors and destroys trust. Fix immediately.

2. Google Shows a “This Site May Be Hacked” Warning

When you search for your website on Google, you see a warning message like “This site may be hacked” or “This site may harm your computer” beneath your listing. Or when you visit your site, your browser shows a red warning screen.

What to check:

  • Search Google for your website name or domain
  • Look for warning messages in the search results
  • Try visiting your site in Chrome (it shows Google’s security warnings)
  • Check Google Search Console for security notifications

Why it happens: Google scans websites for malware and hacked content. When they detect something malicious, they warn users. This protects visitors but devastates your traffic.

Severity: Critical. You’re losing visitors and damaging your reputation every minute this warning is live.

Google Warnings Are Serious

If Google is warning visitors away from your site, you’re losing traffic right now. Even after you fix the hack, it can take days or weeks for Google to remove the warning. Act immediately.

3. Strange Content Appears on Your Site

You notice pages, posts, or content that you didn’t create. This might be spam content about pharmaceuticals, gambling, or adult topics. Sometimes it’s hidden from the homepage but exists on random URLs.

What to check:

  • Search Google for: site:yourdomain.com (replace with your actual domain)
  • Look through the results for pages you don’t recognize
  • Check your WordPress dashboard for unfamiliar posts or pages
  • Look for strange content in your sidebar or footer

Why it happens: Attackers create spam content to boost their own SEO or to redirect your visitors. They often hide this content so you don’t notice it during normal use.

Severity: High. This damages your reputation and SEO, and may trigger Google warnings.

4. You Can’t Log Into Your WordPress Dashboard

Your password suddenly doesn’t work, even though you’re certain it’s correct. Or you can log in, but you find you no longer have administrator access. Someone changed your permissions.

What to check:

  • Try the “Lost your password?” reset option
  • Check if you can access other accounts on the site
  • Look for password reset emails you didn’t request
  • Try accessing your hosting control panel (cPanel, Plesk, etc.)

Why it happens: Hackers change passwords to lock you out while they use your site. They may also create new admin accounts for themselves and delete or demote yours.

Severity: Critical. If you can’t access your site, you can’t fix it. Use hosting-level access to regain control.

5. Unknown User Accounts Appear

You log into WordPress and see user accounts you didn’t create, especially administrator accounts with generic names like “admin2” or random strings of characters.

What to check:

  • Go to Users → All Users in your WordPress dashboard
  • Look for accounts you don’t recognize
  • Check when accounts were created (hover over the username)
  • Pay special attention to Administrator-level accounts

Why it happens: Hackers create admin accounts as a backdoor. Even if you discover and fix one entry point, they can still get back in through the account they created.

Severity: High. Delete unknown accounts immediately and change all existing passwords.

6. Your Site Is Extremely Slow or Keeps Crashing

Your website suddenly loads much slower than normal, or it keeps going down entirely. Your hosting provider might contact you about excessive resource usage.

What to check:

  • Test your site speed with a tool like GTmetrix or Google PageSpeed
  • Check your hosting dashboard for CPU or memory warnings
  • Look for error messages in your site’s error logs
  • See if the problem happens at specific times

Why it happens: Hackers might be using your server to send spam, mine cryptocurrency, or attack other websites. These activities consume server resources, slowing down your site or crashing it.

Severity: Medium to High. The slowness itself harms your business, and it’s a symptom of something worse happening behind the scenes.

7. Your Email Is Being Used for Spam

You receive bounce-back messages for emails you never sent. Customers ask about messages they received from you that you didn’t send. Your email suddenly stops working because your server has been blacklisted.

What to check:

  • Look for bounce-back emails in your inbox or spam folder
  • Check if your domain is blacklisted using a tool like MXToolbox
  • Ask your hosting provider about outgoing email activity
  • Review your sent folder for messages you didn’t send

Why it happens: Hackers use compromised websites to send spam emails. Your domain’s reputation makes spam more likely to reach inboxes, at least until you get blacklisted.

Severity: High. Email blacklisting disrupts your business communications and can take weeks to resolve.

How to Verify If You’ve Actually Been Hacked

Seeing one warning sign doesn’t necessarily mean you’ve been hacked. Slow sites can result from traffic spikes. Strange content could be from a plugin you forgot about. Here’s how to confirm:

Use a Malware Scanner

Several free tools can scan your site for known malware:

  • Sucuri SiteCheck: Free online scanner at sitecheck.sucuri.net
  • VirusTotal: Checks your URL against multiple security databases
  • Your security plugin: Most security plugins include scanning features

These scanners check for known malware signatures, blacklist status, and suspicious code. They’re not perfect, some sophisticated hacks can hide from scanners, but they catch most common infections.

Scan Your Site for Free

Stack Guard includes malware scanning to help detect compromised files. Install the free plugin to scan your site and identify potential security issues before they become major problems.

Download Stack Guard Free

Check Google Search Console

If you have Google Search Console set up (you should), check the Security & Manual Actions section. Google will tell you directly if they’ve detected security issues on your site.

If you don’t have Search Console set up, you can still search for your site on Google and look for warning messages in the results.

Review Your Files for Changes

If you have FTP or file manager access, look for recently modified files that you didn’t change. Pay special attention to:

  • wp-config.php (WordPress configuration)
  • index.php files in your root and theme directories
  • .htaccess file (server configuration)
  • Files in /wp-includes/ that shouldn’t change

Look for files with strange names, especially in your uploads folder. PHP files in the uploads folder are almost always malicious since that folder should only contain images and documents.

Check Your Database

If you have database access (through phpMyAdmin or similar), look at the wp_users table for unfamiliar accounts. Also check wp_options for suspicious entries, though this requires more technical knowledge.

What to Do If Your WordPress Site Is Hacked

Confirmed you’ve been hacked? Don’t panic. Follow these steps in order:

Step 1: Stay Calm and Document

Take a breath. Most hacks are fixable. Before you change anything, document what you’re seeing:

  • Screenshot the problems
  • Note which pages are affected
  • Record any error messages
  • Write down when you first noticed issues

This information helps if you need professional help and helps prevent the same attack from happening again.

Step 2: Take Your Site Offline (If Necessary)

If your site is actively harming visitors (spreading malware, redirecting to dangerous sites), take it offline. You can:

  • Enable maintenance mode through your hosting
  • Ask your hosting provider to suspend the site temporarily
  • Rename the main index.php file to prevent the site from loading

This limits damage while you work on the fix.

Step 3: Change All Passwords Immediately

Change passwords for:

  • All WordPress user accounts (especially administrators)
  • Your hosting control panel
  • FTP/SFTP access
  • Your database
  • Any connected services (email, payment processors, etc.)

Use strong, unique passwords for each. This prevents attackers from simply logging back in.

Step 4: Restore from a Clean Backup

If you have backups from before the hack, restoring is often the fastest path to recovery:

  1. Identify when the hack occurred (check file modification dates)
  2. Find a backup from before that date
  3. Restore the backup
  4. Immediately update everything (WordPress, themes, plugins)
  5. Change all passwords again

If you don’t have backups, you’ll need to clean the infection manually or hire help.

No Backup? Learn From This

If you don’t have a clean backup to restore from, let this be the lesson that makes you set up automatic backups immediately after recovering. Future you will be grateful.

Step 5: Scan and Clean (If No Backup Available)

Without a backup, you’ll need to remove the malware manually:

  1. Use a malware scanner to identify infected files
  2. Replace core WordPress files with fresh copies from wordpress.org
  3. Reinstall your theme from a clean source
  4. Reinstall all plugins from fresh downloads
  5. Review your uploads folder and remove any PHP files
  6. Check your database for suspicious content

This process is tedious and requires some technical knowledge. If you’re not comfortable, consider hiring a professional malware removal service. Expect to pay $150-500 depending on severity.

Step 6: Find and Fix the Vulnerability

Cleaning the infection isn’t enough. You need to figure out how they got in, or they’ll just hack you again:

  • Weak password? Use strong passwords and enable two-factor authentication
  • Outdated software? Update WordPress, themes, and plugins immediately
  • Vulnerable plugin? Check if any of your plugins have known security issues
  • Insecure hosting? Consider upgrading to better hosting

Step 7: Request Review from Google

If Google flagged your site, you need to request a review after cleaning up:

  1. Log into Google Search Console
  2. Go to Security & Manual Actions → Security Issues
  3. Click “Request Review”
  4. Describe what you found and what you did to fix it

Google typically reviews within a few days, but it can take up to two weeks for warnings to be removed.

Step 8: Prevent Future Attacks

Once you’ve recovered, put protections in place so this doesn’t happen again:

  • Install a security plugin if you don’t have one
  • Enable two-factor authentication for all admin accounts
  • Set up automatic backups
  • Keep everything updated
  • Use strong, unique passwords
  • Consider hiding your login page with a custom URL

When to Hire a Professional

Some situations call for professional help:

  • You can’t identify or remove all the malware
  • The site keeps getting reinfected
  • You handle sensitive customer data
  • You don’t have the time or technical comfort to do it yourself
  • Your business depends heavily on the website

Professional malware removal services typically cost $150-500 and include cleaning, hardening, and sometimes monitoring. Many hosting providers also offer cleanup services for their customers.

Frequently Asked Questions

Can I tell exactly when my site was hacked?

Sometimes. Check the modification dates on suspicious files, look at your access logs for unusual activity, and review when unknown user accounts were created. If you have a security plugin with activity logging, that data is invaluable. You may not pinpoint the exact moment, but you can usually narrow it down to a timeframe.

Will I lose my content if I restore from a backup?

You’ll lose any content added after the backup date. If the backup is from last week, you’ll lose a week of changes. This is why frequent backups matter. In most cases, losing a few days of content is better than spending hours manually cleaning malware.

Can hackers come back after I clean the site?

Yes, if you don’t fix the vulnerability they used. Many site owners clean the infection but forget to update the outdated plugin that let hackers in. Always identify how they got in and close that door.

Should I contact my hosting provider?

Yes, especially if you’re unsure what to do. Good hosting providers have experience with hacked sites and can offer guidance, resources, or professional cleanup services. They may have already detected the issue and can provide information about what happened.

How do I prevent this from happening again?

Follow security basics: keep everything updated, use strong passwords with two-factor authentication, install a security plugin, maintain regular backups, and delete plugins or themes you’re not using. Most hacks exploit known vulnerabilities or weak passwords. Address these, and you’ve blocked the most common attack paths.

Conclusion

Discovering your WordPress site hacked is stressful, but it’s a solvable problem. The key is recognizing the warning signs early:

  1. Redirects to other websites
  2. Google security warnings
  3. Strange content you didn’t create
  4. Login problems or lost access
  5. Unknown user accounts
  6. Severe slowness or crashes
  7. Email being used for spam

If you spot these signs, verify with a malware scanner, document what you find, and follow the recovery steps: change passwords, restore from backup if possible, clean the infection, fix the vulnerability, and request Google’s review.

Most importantly, use this experience to strengthen your security going forward. Set up the protections that would have prevented this hack, and you likely won’t face the same situation again.

Protect Your Site From Future Attacks

Stack Guard helps prevent hacks before they happen. Login protection, two-factor authentication, security hardening, and malware scanning, all in one free plugin. Don’t wait for the next attack.

Get Stack Guard Free

A hacked website is a wake-up call. Answer it by building better security today.

Malicious redirects are a classic sign of a hacked site. Hackers inject code into your .htaccess file, theme files, or database that sends visitors to spam sites, usually to make money from ad clicks or spread malware. Sometimes it only happens on mobile devices or when visitors come from search engines, making it harder to detect. If you see this, your site needs immediate cleanup.

Google actively scans websites for malware and spam content. When they detect problems, they add warning labels to protect searchers. Check Google Search Console for specific security issues they’ve found. Common triggers include hidden links, spam pages created by hackers, and malware downloads. You’ll need to clean your site and request a review from Google to remove the warning.

Yes, this is a major red flag. Hackers create admin accounts so they can maintain access even if you change your password or remove their initial entry point. Delete these accounts immediately, but understand they’re a symptom, not the cause. You still need to find and fix how they got in initially, or they’ll just create new accounts.

First, don’t panic, this happens more than you’d think. Contact your host for details about what they found. Most hosts will give you access to clean the site (via FTP or a limited panel) before restoring it. Some offer malware removal services for a fee. Once cleaned, you’ll need to prove to your host that the site is secure before they’ll bring it back online. Use this as motivation to add proper security going forward.

Search Google for site:yourwebsite.com and look through the indexed pages. Hackers often create hundreds of hidden pages selling pharmaceuticals, designer goods, or adult content. You might also check your sitemap for unexpected URLs. In your database, look for unfamiliar posts, pages, or custom post types. File-based spam might live in directories like /wp-content/uploads/—look for PHP files that shouldn’t be there.

0

Subtotal