WordPress Hacked?
What to Do Now

A step-by-step guide from the engineers behind our hacked website repair service: how to tell if your WordPress site has been hacked, what to do in the first hour, how to clean it up properly and how to stop it happening again.

Pixelbird client
Pixelbird client
Pixelbird client

Over a decade of website security expertise

Signs Your WordPress Site Has Been Hacked

Many WordPress hacks are built to stay hidden from the people who run the site. Spam and redirects are often only shown to visitors arriving from Google or on a phone, never to a logged-in administrator. Watch for:

  • A “This site may be hacked” or “Deceptive site ahead” warning in Google or Chrome
  • Visitors being redirected to scam, gambling or pharmacy sites
  • Japanese or spam pages appearing when you search Google for site:yourdomain.com.au
  • Administrator accounts, plugins or files you don’t recognise
  • Your host suspending the account or reporting malware or unusual load
  • Emails from your domain bouncing or landing in spam
  • Customers or members reporting card fraud after paying on your site
  • A security issue notice in Google Search Console

Check from a private browser window and a phone, not just from your usual logged-in computer.

Businessman Wearing Headset Talking To Caller In Busy Customer Services Centre

What to Do

in the

First

Hour

What to Do in the

First Hour

What to Do in the

First Hour

  1. Don’t delete anything or restore a backup yet. That destroys the evidence of how attackers got in and whether data was taken, and the backup may already contain the backdoor.
  2. Take a full copy of the site files and database. Your host can usually do this for you.
  3. Change passwords from a clean device: hosting control panel, every WordPress administrator, the database, SFTP and the email accounts tied to them. Turn on two-factor authentication wherever you can.
  4. Protect visitors. If the site is redirecting people or could be capturing card details, put it into maintenance mode or ask your host to take it offline.
  5. Work out what data the site could reach. Member records, form entries and orders all count. If personal information may have been accessed, the clock on your breach assessment has started.
  6. Get someone who can find the way in. Cleaning up without closing the hole usually means being hacked again within weeks.
Smiling mature confident professional executive manager at office.

How WordPress

Sites Get

Hacked

How WordPress Sites

Get Hacked

How WordPress Sites

Get Hacked

Outdated Plugins & Themes

Most known WordPress vulnerabilities are in plugins and themes, not WordPress itself. Abandoned, unsupported and “nulled” (pirated) plugins are the worst offenders.

Weak or Stolen Logins

Reused passwords, no two-factor authentication, and old staff or agency accounts that were never removed give attackers the front-door key.

Old Hosting & PHP

End-of-life PHP versions no longer get security fixes, and on shared hosting one compromised site can infect every other site on the same account.

0

Data Breaches Notified to the OAIC in 2025

0

Days to Assess a Suspected Eligible Breach

0

Association Breaches Notified in 2025

0 +

Years Shipping Production Software

How to Clean a Hacked WordPress Site Properly

Lock down access, rotate every password and key, and keep a copy of the hacked site as evidence before anything is cleaned.

Young African businessman looking at data on computer screen

Step 2: Clean

Everything

Replace WordPress, plugins and themes with fresh copies, then hunt down backdoors in the uploads folder, injected scripts in the database, hidden admin users and rogue scheduled tasks.

Group of young happy business people looking at laptop screen, communocating and discussing work

Step 3: Close the

Way In & Harden

Find and fix the vulnerability that let attackers in, remove unused plugins, then ask Google to review the site so the warning is lifted.

Brands We Have Helped

What People Say

Makes the Magic Happen

“Love the professional finishes . Dustin and the team know how to make the magic happen.”

Sam Hunter

Sam Hunter

Corporate Headshot Photographer

Always Shows Up

“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”

Kym Bolger

Kym Bolger

Social Media Marketing

Responsive Professionalism

“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”

Ivan Huang

Ivan Huang

CPA

Frequently Asked Questions

Only once you know how attackers got in, and only from a backup taken before the hack. Attackers often sit quietly for weeks, so recent backups can include the backdoor. Restoring without closing the hole usually ends with the site being hacked again.

Security plugins are good at spotting known malware, but they often miss custom backdoors, scripts injected into the database and rogue administrator accounts. They also can’t tell you how attackers got in or what data they could reach.

Clean the site completely first, then request a review under Security issues in Google Search Console. Google usually reviews hacked sites within a few days. If the site is still infected, the request is rejected and the next review takes longer.

If your organisation is covered by the Privacy Act and personal information was likely accessed in a way that could cause serious harm, it may be an eligible data breach under the Notifiable Data Breaches scheme. You must assess a suspected breach quickly, generally within 30 days. We provide the technical facts; get legal advice on your obligations.

It depends on the size of the site and how deep the attackers got. We contain the damage the same day and give you a fixed quote for the full clean-up. See hacked website repair.

Keep WordPress, plugins and themes updated, remove anything you don’t use, turn on two-factor authentication, give each person only the access they need, keep off-site backups and run a supported PHP version. A website security audit shows where you stand today, and our care plans keep it that way.

WordPress Hacked? Talk to an Engineer Today