IT or ops leader Security By Shashank and Partha Last updated on September 26, 2026 6 min read

How Do I Know If My WordPress Site Is Hacked?

Something about the site looks off: a warning in search, an email from the host, or a visitor who landed somewhere strange. Most hacks built for money stay invisible to the owner, so the dashboard looks normal while search engines and visitors see something else. So how do I know if my WordPress site is hacked, and how do I check without being a developer?

#Diagnosing
TL;DR

Five signs settle it: a Google or browser warning, unpublished pages in search, a redirect to another site, an admin account or file nobody created, or a host suspension. A site that looks fine while logged in hasn’t passed the test, since these hacks serve content to search engines and logged-out visitors, not the admin. The checks are external: the Security Issues report in Search Console, and a logged-out, incognito look at the site. If any one of the five is true, see how NoDrama handles WordPress security monitoring.

Contents

  1. 01
    Work out what you’re looking atWhat a hacked site looks like
  2. 02
    Check the five signs
    The five signsHack vs. broken
  3. 03
    Act, and stop it recurring
    What to do once you’re sureTroubleshootingStop it happening againWhat this doesn’t solveIs your site hacked?

What does a hacked WordPress site look like?

Google’s own definition: “This is any content placed on your site without your permission because of security vulnerabilities in your site.” Three common ways in: a vulnerable plugin, weak credentials, or an outdated core file with write access.

The usual motive is SEO spam or redirects, via cloaking: the real site loads for a logged-in admin, and a different, injected page loads for Googlebot or a search visitor. “It looks fine to me” is not a clean bill of health, since that’s exactly what this hack is built to show.

See whether WordPress itself is the weak point for that separate question.

How to confirm the site is compromised (the five signs of a compromised website)

Five signs checklistAny one of these holding is enough to act on
  1. 01 Google or browser warning
  2. 02 Pages you never published in search
  3. 03 Redirects to another site
  4. 04 Unknown admin users or files
  5. 05 Host suspension or abuse notice
Five signs a WordPress site has been hacked, shown as a checklist.

Each sign has its own cause and check; none needs developer skill.

1. Google or your browser warns people away

Google’s Search Console help: “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.” This shows as “This site may be hacked” in search, or a warning in Chrome, under Hacked Content, Malware and Unwanted Software, or Social Engineering.

Verify it

Open Security Issues in Search Console (site must be verified there). Green “no issues” clears this; anything listed does not. See Google’s Security Issues help.

Google’s Security Issues help

2. Search results show pages you never published

Injected spam: pharmacy, gambling or foreign-language pages, often served only to Googlebot.

Verify it

Search site:yourdomain.com in a logged-out incognito window and scan titles and snippets for anything that matches nothing in your CMS.

3. Visitors get sent to another site

Injected JavaScript, or a modified .htaccess or functions.php file, often triggers only on referrer or device, so a direct visit looks fine. Wordfence documented a 2019 campaign exploiting vulnerable plugins to inject this code.

Verify it

Visit the site logged out, in incognito, arriving from search rather than typed, and once more from a phone on a different network.

Wordfence’s 2019 write-up

4. Admin users or files appear that nobody created

This sign is the foothold: a new admin account, an extra file in wp-content or plugins, or an edited core file lets an attacker return after cleanup. wordpress.org’s checklist includes unauthorised new users.

Verify it

Open Users, filter by Administrator, and match every account to a named person. Ask a developer to check file-modification dates in wp-content and core.

wordpress.org’s FAQ on a hacked site

5. Your host suspends the site or reports abuse

Hosts run their own malware and abuse scanners, independent of Google. A suspension, or a report the site is sending spam or attacking others, can arrive before, or without, a Google flag.

Verify it

Check host email and the control panel for a suspension notice or an abuse report.

When it looks like a hack but isn’t

A broken plugin update, an expired SSL certificate, a stale cached page, or a host outage can look alarming and match none of the five signs above. If Security Issues is clean, admin accounts belong to the team, and the host hasn’t flagged anything, the read is broken, not hacked: roll back, renew, or contact the host. An SSL warning or outage doesn’t need a forensic audit.

What you see Points to a hack Points to broken
Search Console Security Issues An issue is listed Green “no issues”
Unknown admin users An account nobody can name Every account belongs to the team
Host abuse notice Suspension or abuse report received Host hasn’t flagged anything
SSL warning only — Expired certificate: renew it
Error after an update — Broken plugin update: roll back
Stale cached page — Cache serving an old version
Table comparing signs of a compromised website with ordinary WordPress failures.

See how tested updates and rollback are handled.

What to do once you’re sure

wordpress.org’s first steps: stay calm, document what you found, and scan.

Option 1Recommended

Easiest: tell your host and follow wordpress.org’s first steps

Your host runs its own scanners and may already know. Follow wordpress.org’s guidance from there.

Option 2

Done for you: hand it to whoever runs security for the site

A retainer with monitoring and backups already running means some of these signs can be caught before you notice them.

Option 3

Manual: restore from a clean backup and close the foothold

Restore to a known-clean point before the first sign appeared: the older the sign, the further back. Remove admin accounts nobody can name, and have a developer compare files against a clean copy. See how off-site backups and restores work.

Verify it

Re-run all five checks: Security Issues clean, site: search clean, incognito visit from search and mobile clean, Users list matches named people, no host notice.

Troubleshooting

“Google says this site may be hacked, but Search Console shows no security problems”

Cloaking can explain the mismatch: the spam goes to Googlebot and search visitors, not you. Run the site: search and incognito check rather than trusting either alone.

“My security plugin says everything is clean”

A scanner reports what it was configured to catch; silence isn’t proof of more. Cross-check against the signs above.

How to stop it happening again

Turn the causes above into a routine: tested updates, admin accounts reviewed, monitoring and scanning running, and off-site backups you could restore from tomorrow. The monthly check is the five-sign list. See the site’s state now with NoDrama’s free WordPress audit.

See what a security retainer covers.

NoDrama’s WordPress security retainer runs security monitoring and malware scanning on every plan, which can catch some of these signs before you do, and keeps off-site backups to restore from if one turns up.

See Security Work

What this guide does not solve

It doesn’t cover a full malware cleanup, a forensic investigation, or how a specific attacker got in. A site handling payments or client data also has obligations this guide doesn’t cover.

So, is your WordPress site hacked?

Five signs settle it: a Google or browser warning, unpublished pages in search, a redirect elsewhere, an unrecognised admin account or file, or a host suspension. None depend on how the dashboard looks while logged in; the checks happen outside it. If none hold, the read is broken, not hacked, or fine.

Let Us Watch The Site For You

Get Started
Cancel anytime
Yearly runs to the end of the paid year
Real team behind every plan