Contents
- 01
Work out what you’re looking atWhat a hacked site looks like
- 02
Check the five signs
- 03
Act, and stop it recurring
What does a hacked WordPress site look like?
Google’s own definition: “This is any content placed on your site without your permission because of security vulnerabilities in your site.” Three common ways in: a vulnerable plugin, weak credentials, or an outdated core file with write access.
The usual motive is SEO spam or redirects, via cloaking: the real site loads for a logged-in admin, and a different, injected page loads for Googlebot or a search visitor. “It looks fine to me” is not a clean bill of health, since that’s exactly what this hack is built to show.
See whether WordPress itself is the weak point for that separate question.
How to confirm the site is compromised (the five signs of a compromised website)
- 01Google or browser warning
- 02Pages you never published in search
- 03Redirects to another site
- 04Unknown admin users or files
- 05Host suspension or abuse notice
Each sign has its own cause and check; none needs developer skill.
1. Google or your browser warns people away
Google’s Search Console help: “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.” This shows as “This site may be hacked” in search, or a warning in Chrome, under Hacked Content, Malware and Unwanted Software, or Social Engineering.
Open Security Issues in Search Console (site must be verified there). Green “no issues” clears this; anything listed does not. See Google’s Security Issues help.
2. Search results show pages you never published
Injected spam: pharmacy, gambling or foreign-language pages, often served only to Googlebot.
Search site:yourdomain.com in a logged-out incognito window and scan titles and snippets for anything that matches nothing in your CMS.
3. Visitors get sent to another site
Injected JavaScript, or a modified .htaccess or functions.php file, often triggers only on referrer or device, so a direct visit looks fine. Wordfence documented a 2019 campaign exploiting vulnerable plugins to inject this code.
Visit the site logged out, in incognito, arriving from search rather than typed, and once more from a phone on a different network.
4. Admin users or files appear that nobody created
This sign is the foothold: a new admin account, an extra file in wp-content or plugins, or an edited core file lets an attacker return after cleanup. wordpress.org’s checklist includes unauthorised new users.
Open Users, filter by Administrator, and match every account to a named person. Ask a developer to check file-modification dates in wp-content and core.
5. Your host suspends the site or reports abuse
Hosts run their own malware and abuse scanners, independent of Google. A suspension, or a report the site is sending spam or attacking others, can arrive before, or without, a Google flag.
Check host email and the control panel for a suspension notice or an abuse report.
When it looks like a hack but isn’t
A broken plugin update, an expired SSL certificate, a stale cached page, or a host outage can look alarming and match none of the five signs above. If Security Issues is clean, admin accounts belong to the team, and the host hasn’t flagged anything, the read is broken, not hacked: roll back, renew, or contact the host. An SSL warning or outage doesn’t need a forensic audit.
| What you see | Points to a hack | Points to broken |
|---|---|---|
| Search Console Security Issues | An issue is listed | Green “no issues” |
| Unknown admin users | An account nobody can name | Every account belongs to the team |
| Host abuse notice | Suspension or abuse report received | Host hasn’t flagged anything |
| SSL warning only | — | Expired certificate: renew it |
| Error after an update | — | Broken plugin update: roll back |
| Stale cached page | — | Cache serving an old version |
What to do once you’re sure
wordpress.org’s first steps: stay calm, document what you found, and scan.
Easiest: tell your host and follow wordpress.org’s first steps
Your host runs its own scanners and may already know. Follow wordpress.org’s guidance from there.
Done for you: hand it to whoever runs security for the site
A retainer with monitoring and backups already running means some of these signs can be caught before you notice them.
Manual: restore from a clean backup and close the foothold
Restore to a known-clean point before the first sign appeared: the older the sign, the further back. Remove admin accounts nobody can name, and have a developer compare files against a clean copy. See how off-site backups and restores work.
Re-run all five checks: Security Issues clean, site: search clean, incognito visit from search and mobile clean, Users list matches named people, no host notice.
Troubleshooting
“Google says this site may be hacked, but Search Console shows no security problems”
Cloaking can explain the mismatch: the spam goes to Googlebot and search visitors, not you. Run the site: search and incognito check rather than trusting either alone.
“My security plugin says everything is clean”
A scanner reports what it was configured to catch; silence isn’t proof of more. Cross-check against the signs above.
How to stop it happening again
Turn the causes above into a routine: tested updates, admin accounts reviewed, monitoring and scanning running, and off-site backups you could restore from tomorrow. The monthly check is the five-sign list. See the site’s state now with NoDrama’s free WordPress audit.
See what a security retainer covers.
NoDrama’s WordPress security retainer runs security monitoring and malware scanning on every plan, which can catch some of these signs before you do, and keeps off-site backups to restore from if one turns up.
What this guide does not solve
It doesn’t cover a full malware cleanup, a forensic investigation, or how a specific attacker got in. A site handling payments or client data also has obligations this guide doesn’t cover.
So, is your WordPress site hacked?
Five signs settle it: a Google or browser warning, unpublished pages in search, a redirect elsewhere, an unrecognised admin account or file, or a host suspension. None depend on how the dashboard looks while logged in; the checks happen outside it. If none hold, the read is broken, not hacked, or fine.