Hacked WordPress Site? What to Do in the First 24 Hours

What should you do first when you have a hacked WordPress site?
A hacked WordPress site needs three immediate moves: take a full backup to preserve evidence, put the site into maintenance mode, and change every password from a clean device. Then tell your hosting provider. Start cleaning only after these steps, so you do not destroy clues or miss the entry point.
Searching for a fix when you say "hacked WordPress site" feels urgent, and that is normal. Even so, a hacked WordPress site rewards patience and order more than speed.
Panic makes people delete things in a hurry. However, that often wipes out the traces that show how the attacker got in. As a result, the site gets hacked again a few days later through the same hole.
We are Talha Aslan and team, and we are not a hosting company. We do not run servers. Still, we see the search impact of hacked sites in web design and SEO work, so this guide combines that field experience with official documentation.
How do you know your WordPress site was hacked?
Not every hack shows a defaced page. In fact, many attackers stay quiet because they want to borrow your search reputation for their own spam pages. So you need to watch for signs regularly.
- Visitors land on an unknown site or ad page, sometimes only on mobile or when they arrive from Google.
- Search results show unrelated product titles or foreign language spam under your domain.
- Google shows a warning that the site may be compromised.
- An administrator account appears that you do not recognize.
- Your browser flags the site, or your host sends a malware notice.
- The site slows down suddenly, and your emails start landing in spam.
Any hacked WordPress site shows at least one of these signs sooner or later. Even one of them deserves attention. Also check your Search Console notifications, because Google reports security issues there.
Listen to your visitors as well. Often the first warning comes from a customer who says your site sent them somewhere strange. Moreover, open your site in a private window, on mobile data, by clicking through from Google. Some hacks only show bad content to people who are not logged in.
What does the Search Console security issues report show?
Google shows verified site owners the security problems it detects, right inside Search Console. The report lists the type of issue, sample URLs when available, and the date of the last detection. After you fix the problem, you can ask Google to review all issues in one request.
Menu names can change over time. Therefore, look for the security related section in your account and follow the official Google Search Central article. If you track traffic losses after a hack, our guide on diagnosing traffic drops in Search Console helps you find the affected pages.
An empty report does not prove a clean site. For example, an attacker may show malicious content only to certain visitors. Hence you should also review your own search results manually.
Which steps do you take in the first hour?
Order matters. The list below is an emergency flow drawn from our field experience. It does not guarantee a result, but it limits unnecessary damage.
- Stay calm and write down when you noticed the problem and what you saw.
- Download a full backup of files and database to your own computer, even if it is infected.
- Switch the site to maintenance mode, or restrict access in your hosting panel.
- Contact your hosting provider immediately, because only they can reach server level logs.
- Change all passwords from a clean device.
- Plan the cleanup and record every action you take.
None of these steps tells you to open a new site and abandon the old one. That move loses your content and address history. Besides, the hole stays open, so the new site gets hit the same way.
The goal of the first hour is to freeze the situation. First stop the bleeding, then start treatment. If one step feels too hard, do at least the backup and the password change.
Why is cleaning without a backup risky?
One wrong deletion can break the entire site. Without a backup, you cannot go back. Moreover, you can only see which files changed by comparing against a copy.
A hacked WordPress site can look fine on the surface while the database hides spam. Hence the backup must include both files and database. Think in terms of two backups. The first keeps the site exactly as the hack left it, for investigation only. The second is a clean version from before the attack, if you have one. To build a proper routine afterward, read our website backup strategy guide, which we do not repeat here.
Restoring an old backup does not always solve the problem. If the hole is still open, the restored site gets hacked again. Therefore, apply the update and password steps right after any restore.
Store the backup on your own computer or separate storage. A backup that sits on the same server can be deleted by the attacker. Add the date and a note like "post hack" to the file name, so you never mix up versions.
What should you tell your hosting provider?
Be specific when you write to support. Give a short list of facts, so their team can check the right records quickly.
- Date and time you first noticed the problem.
- Signs you saw, such as redirects, spam pages or warnings.
- The date of your backup and where it is stored.
- A request to review server access logs for suspicious logins.
- A request to scan other sites on the same account.
On shared hosting, other sites in the same account can be the way in. Thus cleaning a single site may not be enough. Ask support directly and get the answer in writing.
Which passwords and keys do you need to change?
Attackers often get in with a stolen password. Therefore, changing only the WordPress admin password is not enough. Keep the scope wide.
- Passwords of all WordPress administrator and editor accounts.
- Hosting control panel, FTP or SFTP and SSH access.
- The database user password, plus the matching value in your site configuration.
- Your domain registrar account password and two step verification.
- WordPress security keys and salts, because renewing them logs out every active session.
- Connected email, payment and marketing accounts.
Do not invent strong passwords in your head. Instead, use our password generator to create long random ones and store them in a password manager. The official WordPress documentation also recommends strong passwords and two step authentication.
End all open sessions after the change. An old session cookie can keep an attacker inside without any password. Furthermore, if you reused a password anywhere else, change it everywhere on the same day.
How do you check unknown admin users and plugins?
Attackers often create a hidden administrator account. Open the user list, note every administrator you do not know, and then remove it. Before deleting, check when the account was created, because that helps you build a timeline.
Review plugins and themes with the same care. Outdated plugins, abandoned plugins and files from outside the official directory are the most common entry doors. Delete inactive plugins and themes too, since their files stay exposed even when switched off.
Pirated "nulled" plugins are a special danger. In other words, a cracked copy of a paid plugin may contain a backdoor. Never keep such files.
Keep the number of administrators minimal. Create a separate account for each person, avoid shared logins, and close agency or freelancer access when the job ends. That way you can see who did what next time.
How do you clean the WordPress core files?
The most reliable way is to reinstall the core files from the official WordPress package. In other words, you overwrite the suspicious files with a clean copy instead of hunting them one by one. Review your content folder separately, because your uploads and custom settings live there.
The concept works like this. First keep your backup safe. Next, download a clean copy of the same version from the official source. Then replace the core folders with it. Finally, inspect the content folder for files you do not recognize, especially executable files where only images should be.
If you use a customized theme, ask your developer for a clean source copy. A theme can hide harmful lines too. We do not give command or code examples here. If you get stuck on technical details, ask your hosting support or a security specialist.
How do you find injected content in the database?
Sometimes attackers leave the files alone and add hidden links, spam posts or redirect snippets straight into the database. Cleaning files alone may therefore fail. Post content, the options table and widget areas are the first places to check.
The method is conceptual. Look at recently added or changed posts in the admin area and remove posts with links you do not know. In your database tool, search for foreign domains that do not belong to you. Deleting the wrong row can break the site, so keep a fresh database backup ready.
Spam posts often sit in draft or hidden status. Hence you should scan all post statuses, custom fields and menus, and also look at your sitemap for addresses you do not recognize.
If you feel unsure at this step, call a WordPress security specialist. We are not a hosting company. We can, however, help with search visibility after the cleanup.
How do you confirm the hacked WordPress site is truly clean?
Thinking the cleanup is done differs from verifying it. First open the homepage, a few posts and the mobile view from different devices. Then search Google for your own pages and note any leftover spam titles.
- Only accounts you recognize remain in the user list.
- Your host malware scan returns a clean result.
- No redirects or new spam URLs appear; our redirect checker helps with that.
- Your certificate is valid; check it with the SSL checker.
- Search Console shows no new security warning.
Repeat these checks for several days. Hidden backdoors sometimes come back hours after a cleanup. Ask a colleague to open the site on a different network as well, because cache and sessions on your own machine can hide the problem.
How do you request a review from Google?
After you clean the site and close the hole, you can ask Google for a review through Search Console. Google expects an explanation that shows you fixed the problem. Write a short, honest note that lists what you did.
- Open the security issues report and see which problems are listed.
- Prepare a brief note for each issue: files cleaned, accounts removed, components updated.
- Use the review request option that the report offers.
- Wait for the result, and check the official Google help page for timing, because it can change.
If Google rejects the request, clean again and resubmit. No review process carries a guarantee. Besides, never write a false explanation, because it makes things worse.
Make the note concrete. "Removed an unauthorized admin account, restored core files from the official package, changed all passwords" builds more trust than "we cleaned it". Write only what you actually did.
Do you have to report a personal data breach?
If your hacked site holds personal data, such as member records, contact forms or order details, the incident may count as a data breach. In that case, laws like GDPR or the Turkish KVKK can require notice to the supervisory authority and to affected people.
We do not quote deadlines or procedures, because they change and depend on your case. Check the current legal text on the official site of your authority. This article is not legal advice, so talk to a lawyer or a data protection specialist.
In practice, write down which data was affected, when the incident started and what you did. For broader compliance basics, read our guide to a GDPR compliant website.
Even if you think you hold no personal data, check your forms and plugins. Customer emails, form entries and order details sit on most sites. So check what your plugins store before you say there is nothing.
What should you do for each type of hack?
Every attack leaves different traces. The table below sums up common types and the first priority. It is a general starting point based on field experience, not a firm diagnosis.
| Hack type | Typical sign | First priority |
|---|---|---|
| Redirect hack | Visitors are sent to another site | Replace core and configuration files with clean copies |
| Spam page injection | Foreign language product titles in search | Review database and uploads, check the sitemap |
| Malware distribution | Browser and Google warnings | Take the site offline, clean all files, request a review |
| Hidden admin account | A user you do not know | Delete the account, renew passwords and keys |
| Phishing page | A fake login form on your site | Remove the page, report it to the brand and your host |
Several types can appear together. For example, a hidden admin account is often the real door behind a redirect or spam injection. Therefore, look for the root cause, not only the symptom.
If your case does not match the table, do not panic. Keep the order: backup, access control, cleanup.
What happens to your Google rankings after a hack?
A hack hits your visibility in two ways. First, Google may show a warning or remove affected pages. Second, injected spam pages can damage the quality signals of your site.
Recovery time varies from site to site, so we promise no number of days. Keeping the site clean, removing spam URLs and submitting a fresh sitemap speed things up. Our article on Google spam updates explains how quality signals work.
Old spam URLs can take time to drop out of search. After removing them, make sure the server returns a proper error code, then send the updated sitemap in Search Console. For help with search recovery, see our SEO consulting page.
How do you prevent a hacked WordPress site from happening again?
Most prevention is boring but effective. The official WordPress documentation recommends current versions, strong passwords, two step authentication, limited file permissions and regular backups. You can read the details on the WordPress hardening page.
- Update core, themes and plugins regularly.
- Delete plugins and themes you do not use.
- Give each administrator a separate account with two step authentication.
- Keep backups away from your site and test a restore.
- Consider a server side web application firewall; our ModSecurity and WAF article explains it.
We cover general vulnerability classes in our OWASP Top 10 guide, so we do not repeat them here.
Treat security as a routine, not a one time job. Set a monthly update day, test a restore and review the user list. This small habit prevents big incidents.
Does WordPress versus custom code matter for security?
Security depends more on maintenance discipline than on the platform. WordPress is common, so attackers pay attention to it. Yet a lean, regularly updated install can stay safe. Custom code carries the same risk when nobody maintains it.
Do not let security alone decide. Budget, flexibility and maintenance capacity matter too. Our WordPress versus custom website article compares both options in detail. If you plan a fresh build, look at our web design service.
Whichever you pick, define who is responsible. Who updates the site, who checks the backups, and who do you call during an incident? Write down the answers before you need them.
How are domain and SSL problems linked to a hack?
Sometimes the attacker also reaches your domain account or DNS records. If so, visitors go to another server even after you clean the files. Check the records at your registrar as well. Our DNS lookup tool shows the public records.
If your browser shows a "your connection is not private" warning after a hack, the certificate or configuration may be broken. See our guide on the not private error. If your domain expired, the expired domain guide shows the way.
Turn on two step verification at your registrar and use a registrar lock if one exists. The exact setting name differs by provider, so check your provider help page. You can also verify ownership with the WHOIS lookup.
What do you tell visitors and customers after a hack?
If your site holds customer data or an order flow, silence hurts trust. A short, honest note is usually the best path. Still, avoid firm statements before you know which data was affected.
Describe the incident, the steps you took and what you expect from users, for example a password change. Skip technical detail, because it can help an attacker. If a legal duty applies, have a lawyer review the text.
Inform your team and partners as well. Email accounts or shared panel access may be affected, so everyone should renew passwords at the same time.
What do you monitor during the first 30 days?
The first weeks after a hack are critical, because attackers often try to return through a hidden backdoor. A regular checklist helps you spot reinfection early.
- Check weekly whether new user accounts appeared.
- Track changed files in the records of your hosting panel.
- Look for new security warnings or crawl errors in Search Console.
- Measure uptime and speed; the is it down checker gives a fast first check.
- Watch login attempts and failed logins.
Do not wait if something looks odd. A small sign can be the first hint of a second attack.
Why should you keep a written incident log?
An incident log has technical and legal value. If you write down what you did each day, you respond faster next time. Furthermore, you hold a concrete timeline when talking to your host, insurer or lawyer.
Include the moment you noticed it, the signs, the backups taken, the passwords changed, the files and accounts removed, and the note sent to Google. Add screenshots. If personal data is involved, share the log only with authorized people.
Who should help you, and who should you avoid?
Work with your hosting provider first, because the server records are theirs. For a complex case, hire a well known security specialist. On the SEO and web design side, we can help you recover visibility with our SEO consulting, but we do not touch your server.
Stay away from strangers who message you offering to clean any hack for a fee with a sure result. Giving admin access to such people can lead to a second attack. Likewise, opening a new domain to dodge a Google review, or submitting fake documents, counts as circumventing the system and makes the problem bigger.
Choose accountable and traceable channels. Also ask any expert for the method first. A trustworthy specialist explains what they will do, what access they need, documents the backup and reports every change. No expert can guarantee recovery.
When someone helps you, use the least privilege rule. Create a temporary account, delete it when the work ends and change the passwords again.



