The short answer
Don’t delete anything yet. Take a backup, change every password, tell your host, then clean the site: reinstall WordPress, themes and plugins from fresh copies, remove unknown users and files, and close the gap the hacker got in through. If Google is warning visitors, ask it to review the site once it’s clean.
How do you know your site has been hacked?
The usual signs are Google showing “This site may be hacked” or a red warning screen, visitors being redirected to spam or scam sites, strange pages or links appearing in Google results, admin users you don’t recognise, your host suspending the site, or the site suddenly becoming slow or crashing.
1. Take a backup before you change anything
It sounds odd to back up a hacked site, but you need a copy of the files and database as they are now. It keeps your content safe if the clean-up goes wrong, and it shows how the hacker got in. Download it from your hosting control panel and keep it off the server.
2. Change every password
Change the passwords for your hosting account, every WordPress admin user, FTP or SFTP, the database and the email address linked to the site. Use long, unique passwords and turn on two-factor login where you can. If the hacker still has a working password, they will simply come back.
3. Tell your hosting company
Your host can often see which files changed and when, and may already have spotted the problem. If they have suspended the site, ask what they need from you to switch it back on once it’s clean.
4. Clean the site
- Reinstall WordPress core files from a fresh download.
- Delete and reinstall every plugin and theme from the official source. Remove any you don’t use.
- Delete admin users you don’t recognise.
- Look for PHP files in the uploads folder. There shouldn’t be any.
- Check the database for spam links and scripts injected into posts and pages.
- Scan the site with a security plugin to catch anything left behind.
Hackers usually leave a backdoor, a hidden file that lets them back in. If you only remove what you can see, the site is often reinfected within days.
5. Close the way they got in
Most WordPress hacks come through an outdated plugin or theme, a pirated (“nulled”) premium theme, or a weak password. Update everything, replace anything that’s no longer supported, and keep automatic backups running so you can recover quickly next time.
6. Get Google warnings removed
If Google is warning visitors, check the Security issues report in Google Search Console. Once the site is clean, request a review there. Warnings are usually removed within a few days.
When should you get help?
If you’re not comfortable working with website files and databases, or the site keeps getting reinfected, get a professional to do it. A half-cleaned site is worse than it looks, because the backdoor stays in place.
I clean hacked WordPress websites, remove backdoors and close the entry point. See WordPress malware removal, or call 07751 851666.
Checklist
- Backup taken and stored off the server
- All passwords changed and two-factor login switched on
- Hosting company told
- WordPress, plugins and themes reinstalled from fresh copies
- Unknown users and files removed
- Everything updated and unused plugins deleted
- Google review requested if warnings were showing