Incident Response
How to Fix a Hacked WordPress Site, Step by Step
Finding spam links, a defaced homepage, or a browser blacklist warning is stressful, but a clear sequence of steps gets a hacked WordPress site clean and back online without guesswork.
Daily
Backups to restore a clean version from
24/7
Human support during an active incident
Free
Managed migration if a rebuild is needed
30-Day
Money-back guarantee
In short
Fixing a hacked WordPress site means taking it offline or into maintenance mode first to stop further damage, scanning every file and database table for malicious code, then restoring from a clean backup taken before the compromise rather than trying to hand-edit infected files. Once the site is clean, reset every password and API key, update WordPress core, themes, and plugins, and add the hardening steps that likely let the attacker in to begin with.
Discovering a hacked WordPress site usually starts with one of a few unmistakable signs: a browser 'deceptive site ahead' warning, spam links injected into pages that weren't there yesterday, a defaced homepage, or a hosting alert about unusual outbound traffic. Whatever the trigger, the instinct to start clicking around and deleting suspicious files immediately is understandable but often makes things worse.
A methodical response, in the right order, gets the site clean faster and reduces the chance of missing a second piece of malicious code left behind as a backdoor. The sequence below moves from containment to cleanup to hardening, and skipping ahead, especially restoring a backup before confirming how the attacker got in, often means being hacked again within days through the same hole.
Step One: Take the Site Offline and Contain the Damage
Put the site into maintenance mode or take it fully offline first, before doing anything else, to stop the malicious code from serving more spam content, mining further data, or continuing to attack other sites from your server. Change the admin password immediately, even before investigating further, in case the attacker is actively logged in.
If the hosting environment flagged unusual outbound traffic or resource usage, that's often the first sign something is wrong, and 24/7 human support can confirm whether the flagged activity matches a known compromise pattern while the site is being taken offline.
Scan for Malware and Identify the Entry Point
Run a full malware scan across every file and the database, not just the areas that look obviously affected, since injected code often hides in a plugin file, the theme's functions.php, or a rarely viewed database table rather than somewhere visible on the homepage. Compare file timestamps against known-clean versions where possible to spot what was altered.
Identifying how the attacker got in, whether through an outdated plugin, a weak password, or a vulnerable theme, matters just as much as removing the code itself, because restoring a backup or cleaning files without closing that entry point usually just means a repeat compromise within days.
Remove Malicious Code and Restore a Clean Backup
Once the entry point is identified, the safest path is restoring from a daily backup taken before the compromise, rather than hand-editing infected files one by one, since malware often leaves multiple backdoors that are easy to miss when working file by file under pressure.
After restoring, immediately reinstall or update the plugin or theme that let the attacker in, so the clean backup isn't running the same vulnerable version. If backups only exist from after the compromise, a manual line-by-line cleanup of core files, themes, and plugins is the fallback, ideally with support from someone experienced in malware removal.
Reset Every Credential and Harden Against Round Two
Reset every password on the site: WordPress admin accounts, database credentials, FTP or SFTP logins, and any API keys stored in plugins, since a hack often exposes more than just the WordPress login itself. Also check for any new, unfamiliar admin accounts the attacker may have created and remove them.
Finally, apply the hardening steps that would have prevented this specific compromise, whether that's updating the plugin that was exploited, adding two-factor authentication, or limiting login attempts, and ask your host to check whether the site has been blacklisted by search engines or browsers so a delisting request can be submitted once it's confirmed clean.

Recovery Starts With a Backup You Can Actually Trust
The single biggest factor in how fast a hacked site gets back online is whether a clean, recent backup exists to restore from. Daily backups mean the gap between the last clean copy and the compromise is measured in hours, not weeks.
24/7 human support means the containment and scanning steps don't have to be figured out alone under pressure, and if a full rebuild is the better option, free managed migration handles moving the cleaned site to a fresh environment.
- Daily backups so a clean restore point always exists
- 24/7 human support during an active incident
- Free managed migration if a fresh environment is the better path
- 30-day money-back guarantee while getting resettled
Why Hosting Cheap
What you get
Daily Backups
Restore to a clean point taken before the compromise instead of cleaning every file by hand.
24/7 Human Support
Get real-time help containing and scanning the site during an active incident, any time of day.
Free Managed Migration
Move the cleaned site to a fresh environment without handling the technical transfer alone.
Free Auto-Renewing SSL
Re-secure the connection automatically as part of getting the site back online.
NVMe SSD + LiteSpeed
A restored or rebuilt site loads fast again immediately, without a slow recovery period.
30-Day Money-Back Guarantee
Move to a hosting setup with stronger backups and support without financial risk.
How It Works
Get set up in a few steps
Take the site offline and change the admin password
Stop the malicious code from doing further damage before anything else.
Scan everything and find the entry point
Check files and the database fully, and identify what let the attacker in.
Restore a clean backup and reset all credentials
Recover from before the compromise, then change every password and key.
Included
Everything you need, on every plan
- Take the site offline or into maintenance mode immediately
- Change the admin password before investigating further
- Run a full malware scan of files and the database
- Identify the specific entry point the attacker used
- Restore from a clean backup taken before the compromise
- Reset all passwords, FTP logins, and API keys
- Remove any unfamiliar admin accounts the attacker created
- Check for a search engine or browser blacklist and request removal
FAQ
Frequently asked questions
What's the very first thing I should do when I discover a hacked WordPress site?
Take the site offline or into maintenance mode and change the admin password immediately, before investigating further. This stops the malicious code from causing more damage or the attacker from staying logged in while you work.
Should I restore a backup right away, or scan first?
Identify how the attacker got in before or while restoring, since restoring a clean backup without closing the entry point, such as an outdated plugin, usually leads to being hacked again within days through the same hole.
How do I know which backup is actually clean?
Check backup dates against when unusual activity first appeared in logs or analytics, and restore from a point clearly before that. If daily backups are available, the gap to check is small, which makes finding a genuinely clean point much easier.
Do I need to change my hosting password too, or just WordPress?
Reset everything: WordPress admin, database credentials, FTP or SFTP logins, and any API keys stored in plugins. A compromise can expose more than the WordPress login alone, so a partial credential reset can leave a way back in.
My site is now on a browser blacklist warning. How do I fix that?
Once the site is confirmed clean and the entry point is closed, submit a review request through the relevant search engine or browser's webmaster tools to have the blacklist warning removed, which typically takes a few days to process.
How can I make sure this doesn't happen again?
Apply the hardening step tied to the actual entry point first, such as updating the exploited plugin, then add broader protections like two-factor authentication, login attempt limits, and keeping daily backups running so recovery is faster if it ever happens again.
Related hosting
WordPress Hosting
Hosting with daily backups and 24/7 support to recover from a compromise quickly.
SSL Certificates
Re-secure the site's connection with free auto-renewing SSL as part of recovery.
Web Hosting
NVMe-backed hosting to get a restored or rebuilt site back to full speed immediately.
Business Hosting
Reliable hosting with support on hand for businesses that can't afford extended downtime.
Recover Faster With Daily Backups and Real Support
Get a clean restore point every day and 24/7 human help the moment something looks wrong.
Get Started