
🔍 16 Signs that WordPress is hacked: from obvious to hidden
The site seems to be working. But traffic has dropped by half, unknown user accounts have appeared in the admin panel, and the host keeps sending emails with alarming subject lines. A WordPress hack rarely looks like a smashed storefront. More often, it's quiet, subtle changes that go unnoticed for months.
According to Wordfence, over 11,000 vulnerabilities in plugins and themes were recorded in 2025, and bots scan fresh holes on average within five hours of a patch being published. The good news: if you know where to look, you can catch an infection at an early stage.
Below, 16 specific signs, from glaring to barely noticeable, and a step-by-step recovery plan.
💡 Quick overview:
- Check your hosting email, the user list, and the site's root folder via FTP: these are three points where a hack is immediately visible.
- Inspect the front end: altered content, redirects to third-party sites, a Google Safe Browsing warning, and spam mailings.
- Look into traffic, search results, and a security scanner: a drop in visits, foreign meta tags in Google, and Wordfence alerts.
- Indirect symptoms: slowdowns, server overload, suspicious cron jobs, and unexplained errors are grounds for an immediate check.
Why WordPress is the number one target
WordPress powers 41% of all websites, according to W3Techs data for July 2026. Tens of thousands of plugins and themes create a huge attack surface. A bot finds a vulnerability in a popular plugin and sweeps through hundreds of thousands of installations overnight: nine out of ten infections happen without human involvement.
1-4. Access and server: the first warning signs
Hosting notification about malicious code
Most hosts scan sites for viruses and phishing. An email with the subject "Malware detected" or "Suspicious activity": react immediately, the host has the right to quarantine the site.

The email usually specifies the path to the infected file, which gives you a ready starting point for cleanup.
Unknown users in the admin panel
Open Users → All Users. Every account with administrator, editor, or author rights should be familiar to you. Unknown accounts are a red flag, especially those with privileges above subscriber.
Delete strangers, but first check whether they created any content: WordPress will offer to reassign their posts to another author. After the cleanup, change all passwords: admin panel, FTP, database, and hosting control panel.
Locked out of the admin panel
Your password suddenly stopped working, and you didn't change it. An attacker may have changed the credentials or created a hidden administrator directly through the database.
Regain access via the Lost your password? link or phpMyAdmin by resetting the hash in the wp_users table. Immediately after logging in: a full audit of accounts and changing passwords everywhere: WP, FTP, hosting, database.
Suspicious files on the server
Look into the installation root, as well as the wp-admin, wp-includes, and wp-content directories. Files like wp-config.bak, class-mail.php, or db-cache.php are classic "intruders" used to load malicious code. A typical case is described on Stack Overflow: a foreign PHP file in the root, disguised as a system file.
If you find a suspicious file, the attacker has access to the file system. Change the FTP password, delete the foreign files, and start searching for the entry point.
5-8. Front end and content: what visitors see
Altered site content
The most noticeable and reputation-damaging sign. Three typical manifestations:
- Japanese, Chinese, or Arabic characters in page text;
- pop-up windows with porn ads or casino offers;
- hidden links to dubious sites, visible only in the source code.
Check the homepage and several inner pages in different browsers. Hidden links are inserted via display:none or position:absolute; left:-9999px; you won't spot them without viewing the source code.
Redirect to third-party sites
A user opens your URL and lands on a page with ads, phishing, or a counterfeit store. The redirect is set up through .htaccess, a JavaScript injection in header.php, or a hidden plugin.
Check .htaccess for unfamiliar RewriteRule and Redirect directives. Open the site from a mobile device: some redirects only trigger for mobile traffic.
Google warning about an unsafe site
When visiting, the user sees a red screen: "This site may contain harmful programs."

Check the status via Google Safe Browsing. If the site is flagged, do a full cleanup and request a review through Google Search Console. Without this, your rankings will drop to zero within a few days.
Spam mailings from your domain
Acquaintances complain that spam is pouring in from your address. A compromised site sends thousands of emails through hidden PHP scripts, using your domain. The host may block the mail function or the entire account.
Check the sending logs in your hosting panel and scan the site for hidden mail() calls in unfamiliar PHP files.
9-12. Traffic, search, and security
Sudden traffic drop
Organic traffic from Google has plummeted for no apparent reason: the search engine may have demoted or removed the site from its results.
Compare the graph in Google Search Console with the dates in the Security Issues and Manual Actions sections. A match in timing is a guarantee of a hack.
Distorted metadata in search results
You google your site and see Japanese characters, links to Viagra, or strange descriptions in the results. This is Japanese SEO spam: a hacker injects hidden links and rewrites meta tags to promote their own goods.

Check the source code via Ctrl+U: look for unfamiliar <title>, <meta name="description">, and hidden links. They are often inserted directly into header.php or through a malicious plugin.
Security scanner alert
Wordfence, Solid Security, and similar tools scan files for malicious code signatures. An email with the subject "Scan Results: 3 critical problems found" is not a false alarm. Treat it as seriously as a hosting notification.
The scanner will show the file and the threat type: backdoor, phishing, spam injection.
Blocked by antivirus or ad blocker
A visitor's antivirus or uBlock Origin suddenly blocks your site. This is a very early signal: blocker signatures update faster than Google indexes pages, and the warning appears several days before the red Safe Browsing screen.
Ask a friend with antivirus enabled to visit the site. The exact warning text will tell you which file or domain triggered the detection.
13-16. Indirect symptoms
Suspicious cron jobs
WP-Cron schedules posts, checks for updates, sends emails. Hackers add their own jobs: sending spam, contacting a command server, downloading malicious code.
Check cron jobs via the WP Crontrol plugin or in the wp_options table under the cron key. An unfamiliar job with a suspicious name and a 60-second interval is grounds for immediate investigation.
Site slowdown with no apparent cause
The site suddenly loads several times slower than usual. Malicious scripts mine cryptocurrency, send spam, or participate in DDoS attacks on other resources. Check the load in your hosting panel: a CPU running at almost full capacity under normal traffic points to unauthorized activity.
Server overload under low traffic
A similar scenario: traffic according to Google Analytics is normal, but the server is choking. Server logs will show numerous POST requests to a single file, a likely backdoor for sending spam or brute-forcing other sites.
Errors with no apparent cause
White screen of death, 500 Internal Server Error, database connection errors: malicious code may have damaged system files. If errors appear and disappear on their own, the attacker may be temporarily covering their tracks.
Enable WP_DEBUG in wp-config.php and check debug.log in wp-content. A specific error message often points to the compromised file.
What to do if your site is hacked: five steps

Step 1. Back up everything. Save the infected site as-is, for analysis and in case something goes wrong during cleanup. Full file copy via FTP and a database dump. Do not delete anything before the backup.
Step 2. Isolate the site. Enable maintenance mode via .maintenance or a plugin. Visitors must not land on infected pages.
Step 3. Find the entry point. Run a security scanner, Wordfence or Sucuri SiteCheck, and cross-check with server logs. The entry point, nine times out of ten, is an outdated plugin, a theme with a vulnerability, or a compromised password.
Step 4. Clean the site. Remove malicious files, replace WordPress core files with fresh ones from the official archive, change all passwords and secret keys in wp-config.php.
Step 5. Request a re-check. Submit the site for a re-check in Google Search Console to remove the red screen and notify your hoster that cleanup is complete.
How to protect WordPress from hacking: a layered approach

A single measure won't save you, but five layers together make the site an economically unattractive target for botnets.
- Update everything, right away. WordPress core, themes, plugins: every unpatched component is a potential hole. Enable auto-updates for minor versions.
- Security plugin. The free Wordfence covers the basics: firewall, scanner, brute-force login protection. That is enough for most sites.
- One site, one hosting account. A breach on one site in a shared account opens access to all of them. Isolate your projects.
- Regular backups. Daily, automatic, stored off-server. Ideally, one-click restore.
- Strong passwords and two-factor auth. A 16+ character password and 2FA via Wordfence or Solid Security eliminate virtually all brute-force attempts.
If the video didn't load, open it on YouTube. Author WPDev shows the full cycle: from detecting an infection to manual cleanup and setting up protection.
⁉️🤔 Frequent questions
Can I clean the site myself, without a developer?
Yes, if you are comfortable working with FTP and phpMyAdmin. The plan: backup, Wordfence scan, remove infected files, replace WordPress core files with fresh ones, change all passwords. If the scanner report shows more than a dozen files or there are backdoors in the database, contact a specialist. The Sucuri service offers turnkey cleanup; current pricing is on their site.
Wordfence or Solid Security: which one to choose for protection?
Wordfence wins on signature quality and free features: firewall, scanner, login protection are all in the free version. Solid Security (formerly iThemes Security, renamed in 2024) is strong at hardening, automatically closing typical holes without manual config edits. A small site will be fine with free Wordfence. For a project with online payments, Wordfence Premium with real-time signature updates.
How often should I scan the site for viruses?
Daily automatic scanning, at a minimum. Wordfence free does it every three days; premium, daily. A manual check with an external scanner like Sucuri SiteCheck once a week is a good practice: a minute of time, an independent view.
What to do if the hosting provider has already blocked the site?
Contact support and request temporary access for cleanup; many hosters provide FTP access even during a block. Follow the five-step plan, first removing the files the hoster flagged. After cleanup, send the hoster a scan result or a Sucuri report.
How long does site recovery after a hack take?
A typical infection, one to three files, a spam inject: one to three hours including backup and verification. A serious hack with backdoors in the database: one to three business days. Google rankings after the red screen is removed recover in anywhere from a few days to two or three weeks.
A hack doesn't shout, it whispers: what to remember
A hoster's email, an unknown user in the admin panel, a sharp traffic drop: each signal on its own can be dismissed as a coincidence. But two or three signs together mean an almost guaranteed infection.
Check three points right now: the user list in the admin panel, the site's root folder via FTP, and the status in Google's site check tool. Five minutes. If it's clean, set up daily backups and auto-updates.
If you find something suspicious, don't put it off. Every day an infected site loses search rankings and risks getting blocked by the hoster. Share in the comments: where did you start your cleanup, and which sign was the first red flag?



