Skip to main content

Incident Response

How to Fix a Hacked WordPress Site, Step by Step

Finding spam links, a defaced homepage, or a browser blacklist warning is stressful, but a clear sequence of steps gets a hacked WordPress site clean and back online without guesswork.

Daily

Backups to restore a clean version from

24/7

Human support during an active incident

Free

Managed migration if a rebuild is needed

30-Day

Money-back guarantee

In short

Fixing a hacked WordPress site means taking it offline or into maintenance mode first to stop further damage, scanning every file and database table for malicious code, then restoring from a clean backup taken before the compromise rather than trying to hand-edit infected files. Once the site is clean, reset every password and API key, update WordPress core, themes, and plugins, and add the hardening steps that likely let the attacker in to begin with.

Discovering a hacked WordPress site usually starts with one of a few unmistakable signs: a browser 'deceptive site ahead' warning, spam links injected into pages that weren't there yesterday, a defaced homepage, or a hosting alert about unusual outbound traffic. Whatever the trigger, the instinct to start clicking around and deleting suspicious files immediately is understandable but often makes things worse.

A methodical response, in the right order, gets the site clean faster and reduces the chance of missing a second piece of malicious code left behind as a backdoor. The sequence below moves from containment to cleanup to hardening, and skipping ahead, especially restoring a backup before confirming how the attacker got in, often means being hacked again within days through the same hole.

Step One: Take the Site Offline and Contain the Damage

Put the site into maintenance mode or take it fully offline first, before doing anything else, to stop the malicious code from serving more spam content, mining further data, or continuing to attack other sites from your server. Change the admin password immediately, even before investigating further, in case the attacker is actively logged in.

If the hosting environment flagged unusual outbound traffic or resource usage, that's often the first sign something is wrong, and 24/7 human support can confirm whether the flagged activity matches a known compromise pattern while the site is being taken offline.

Scan for Malware and Identify the Entry Point

Run a full malware scan across every file and the database, not just the areas that look obviously affected, since injected code often hides in a plugin file, the theme's functions.php, or a rarely viewed database table rather than somewhere visible on the homepage. Compare file timestamps against known-clean versions where possible to spot what was altered.

Identifying how the attacker got in, whether through an outdated plugin, a weak password, or a vulnerable theme, matters just as much as removing the code itself, because restoring a backup or cleaning files without closing that entry point usually just means a repeat compromise within days.

Remove Malicious Code and Restore a Clean Backup

Once the entry point is identified, the safest path is restoring from a daily backup taken before the compromise, rather than hand-editing infected files one by one, since malware often leaves multiple backdoors that are easy to miss when working file by file under pressure.

After restoring, immediately reinstall or update the plugin or theme that let the attacker in, so the clean backup isn't running the same vulnerable version. If backups only exist from after the compromise, a manual line-by-line cleanup of core files, themes, and plugins is the fallback, ideally with support from someone experienced in malware removal.

Reset Every Credential and Harden Against Round Two

Reset every password on the site: WordPress admin accounts, database credentials, FTP or SFTP logins, and any API keys stored in plugins, since a hack often exposes more than just the WordPress login itself. Also check for any new, unfamiliar admin accounts the attacker may have created and remove them.

Finally, apply the hardening steps that would have prevented this specific compromise, whether that's updating the plugin that was exploited, adding two-factor authentication, or limiting login attempts, and ask your host to check whether the site has been blacklisted by search engines or browsers so a delisting request can be submitted once it's confirmed clean.

How to Fix a Hacked WordPress Site: Recovery Guide

Recovery Starts With a Backup You Can Actually Trust

The single biggest factor in how fast a hacked site gets back online is whether a clean, recent backup exists to restore from. Daily backups mean the gap between the last clean copy and the compromise is measured in hours, not weeks.

24/7 human support means the containment and scanning steps don't have to be figured out alone under pressure, and if a full rebuild is the better option, free managed migration handles moving the cleaned site to a fresh environment.

  • Daily backups so a clean restore point always exists
  • 24/7 human support during an active incident
  • Free managed migration if a fresh environment is the better path
  • 30-day money-back guarantee while getting resettled

Why Hosting Cheap

What you get

Daily Backups

Restore to a clean point taken before the compromise instead of cleaning every file by hand.

24/7 Human Support

Get real-time help containing and scanning the site during an active incident, any time of day.

Free Managed Migration

Move the cleaned site to a fresh environment without handling the technical transfer alone.

Free Auto-Renewing SSL

Re-secure the connection automatically as part of getting the site back online.

NVMe SSD + LiteSpeed

A restored or rebuilt site loads fast again immediately, without a slow recovery period.

30-Day Money-Back Guarantee

Move to a hosting setup with stronger backups and support without financial risk.

How It Works

Get set up in a few steps

1

Take the site offline and change the admin password

Stop the malicious code from doing further damage before anything else.

2

Scan everything and find the entry point

Check files and the database fully, and identify what let the attacker in.

3

Restore a clean backup and reset all credentials

Recover from before the compromise, then change every password and key.

Included

Everything you need, on every plan

  • Take the site offline or into maintenance mode immediately
  • Change the admin password before investigating further
  • Run a full malware scan of files and the database
  • Identify the specific entry point the attacker used
  • Restore from a clean backup taken before the compromise
  • Reset all passwords, FTP logins, and API keys
  • Remove any unfamiliar admin accounts the attacker created
  • Check for a search engine or browser blacklist and request removal

FAQ

Frequently asked questions

What's the very first thing I should do when I discover a hacked WordPress site?

Take the site offline or into maintenance mode and change the admin password immediately, before investigating further. This stops the malicious code from causing more damage or the attacker from staying logged in while you work.

Should I restore a backup right away, or scan first?

Identify how the attacker got in before or while restoring, since restoring a clean backup without closing the entry point, such as an outdated plugin, usually leads to being hacked again within days through the same hole.

How do I know which backup is actually clean?

Check backup dates against when unusual activity first appeared in logs or analytics, and restore from a point clearly before that. If daily backups are available, the gap to check is small, which makes finding a genuinely clean point much easier.

Do I need to change my hosting password too, or just WordPress?

Reset everything: WordPress admin, database credentials, FTP or SFTP logins, and any API keys stored in plugins. A compromise can expose more than the WordPress login alone, so a partial credential reset can leave a way back in.

My site is now on a browser blacklist warning. How do I fix that?

Once the site is confirmed clean and the entry point is closed, submit a review request through the relevant search engine or browser's webmaster tools to have the blacklist warning removed, which typically takes a few days to process.

How can I make sure this doesn't happen again?

Apply the hardening step tied to the actual entry point first, such as updating the exploited plugin, then add broader protections like two-factor authentication, login attempt limits, and keeping daily backups running so recovery is faster if it ever happens again.

Recover Faster With Daily Backups and Real Support

Get a clean restore point every day and 24/7 human help the moment something looks wrong.

Get Started