Hacked WordPress
Hacked. Ugly word, fixable problem — if the first hour goes right.
Spam pages in your search results, browser warnings, strange admin users, customers reporting redirects to sites you'd never touch. Breathe. The damage is containable, and panic is the only move that reliably makes it worse.
Same-day diagnosis. Flat quote before any fix.
What’s actually happening
A hacked WordPress site usually isn't a personal attack — it's automation. Bots scan the web for known vulnerabilities in outdated plugins, themes, and weak passwords, then inject their payload: spam pages for someone's SEO, redirects to scam sites, phishing kits, or a quiet backdoor for later. Your site was a target the way an unlocked car is a target.
The cleanup has two non-negotiable halves: removing every trace of the infection — including the backdoors designed to survive the obvious cleanup — and closing the door it came through. Skip the second half and the reinfection typically arrives within weeks, which is why 'my nephew cleaned it twice' is a story we hear so often.
The usual causes, ranked
After twenty-seven years of these calls, the odds are well mapped. Start at the top.
An outdated plugin or theme with a known hole
The majority case. Vulnerability disclosed, patch released, site never updated, bots arrive. The gap between disclosure and exploitation is now measured in hours.
Weak or reused admin passwords
Credential-stuffing bots try leaked passwords against wp-admin around the clock. If your admin password has ever appeared in a breach, assume it's been tried.
Nulled themes and plugins
'Free' copies of paid plugins routinely ship with the backdoor pre-installed. The hack was the download.
A compromised neighbor on shared hosting
Poorly isolated shared servers let one infected site crawl into others. Rarer, but real — and diagnosable from the file timestamps.
What you can safely try first
Nothing below can make things worse — that’s the selection criterion. Anything riskier belongs in professional hands, on a backup.
- 1
Change passwords from a clean device
Hosting, WordPress admin, database, FTP, and the email tied to them — in that order, from a computer you trust. If the attacker holds the recovery email, everything else is theater.
- 2
Screenshot the evidence
The warning pages, the spam URLs in search results, the strange admin user. Cleanup erases the trail; evidence speeds both diagnosis and Google's later review.
- 3
Don't delete things yet
Deleting visible spam files feels productive and usually misses the backdoor while destroying the timestamps that reveal the entry point. Contain first — investigate before demolition.
Stop and call when…
- Google has flagged the site — 'This site may be hacked' or a red interstitial
- Customers are reporting redirects or password prompts that aren't yours
- The site takes payments or holds customer data — this is now an incident, not an inconvenience
From there it’s our job: same-day look, flat quote, and the $579 flat repair covers most cases of exactly this.
Malware Cleanup — buy it now, skip the hunt.
Hacked site cleaned, secured, and submitted for blacklist review — done right, done once.
Covers one WordPress or PHP site: infection removal, core and plugin integrity restore, admin lockdown, and Google review submission. Includes a 30-day recheck.
Questions we hear a lot.
How do I know it's really hacked and not just broken?
Hacks announce themselves in specific ways: search results showing pages you never wrote (pharmacy spam is the classic), redirects that only hit visitors from Google, admin users you didn't create, or a browser warning. Plain breakage doesn't create content — infections do.
What does the $579 cleanup include?
Infection removal across files and database, core and plugin integrity restore, backdoor hunt, admin lockdown, the entry-point fix, and submission to Google for blacklist review — plus a 30-day recheck. Flat price, and the scope is written down before we start.
Will Google unflag my site?
Yes, once it's genuinely clean — we submit the review request as part of the cleanup, and Google typically clears verified-clean sites within days. The flag that lingers is the one on a site that still has a backdoor, which is exactly why the hunt matters.
Should I just restore a backup?
Only if you know when the infection started — restoring an already-infected backup is the most common way cleanups fail. And a restore alone leaves the vulnerable plugin in place, so the bots simply return. Diagnose, clean, patch, then restore has a place.
How do I keep it from happening again?
The cleanup closes the door it came through, and the exit note lists the rest: updates on a schedule, real passwords, and dropping the plugins that exist only to be vulnerabilities. If the site keeps demanding this attention, we'll say honestly when a rebuild costs less than the habit.
Related symptoms & help
Errors travel in packs. If this one visited, check its friends.
- Rankings DroppedThe hack's echo — often the reason you noticed.
- Deindexed / Not IndexedWhen Google removed you for your own good.
- Locked Out of WordPressWhen the attacker changed the locks.
- Emergency RepairActive infection = emergency lane. Starts today.
- WordPress Done RightBuilds without the plugin roulette that caused this.
Clean it once. Close the door it came through.
Send the symptom, get a same-day look and a flat quote from the developer who's fixed this exact thing more times than either of us can count.