WordPress Hacked?
What to Do Now
A step-by-step guide from the engineers behind our hacked website repair service: how to tell if your WordPress site has been hacked, what to do in the first hour, how to clean it up properly and how to stop it happening again.
- Signs to Check
- First-Hour Steps
- Proper Clean-Up
Over a decade of website security expertise
Signs Your WordPress Site Has Been Hacked
Many WordPress hacks are built to stay hidden from the people who run the site. Spam and redirects are often only shown to visitors arriving from Google or on a phone, never to a logged-in administrator. Watch for:
- A “This site may be hacked” or “Deceptive site ahead” warning in Google or Chrome
- Visitors being redirected to scam, gambling or pharmacy sites
- Japanese or spam pages appearing when you search Google for site:yourdomain.com.au
- Administrator accounts, plugins or files you don’t recognise
- Your host suspending the account or reporting malware or unusual load
- Emails from your domain bouncing or landing in spam
- Customers or members reporting card fraud after paying on your site
- A security issue notice in Google Search Console
Check from a private browser window and a phone, not just from your usual logged-in computer.
What to Do
in the
First
Hour
What to Do in the
First Hour
What to Do in the
First Hour
- Don’t delete anything or restore a backup yet. That destroys the evidence of how attackers got in and whether data was taken, and the backup may already contain the backdoor.
- Take a full copy of the site files and database. Your host can usually do this for you.
- Change passwords from a clean device: hosting control panel, every WordPress administrator, the database, SFTP and the email accounts tied to them. Turn on two-factor authentication wherever you can.
- Protect visitors. If the site is redirecting people or could be capturing card details, put it into maintenance mode or ask your host to take it offline.
- Work out what data the site could reach. Member records, form entries and orders all count. If personal information may have been accessed, the clock on your breach assessment has started.
- Get someone who can find the way in. Cleaning up without closing the hole usually means being hacked again within weeks.
Related Services
How WordPress
Sites Get
Hacked
How WordPress Sites
Get Hacked
How WordPress Sites
Get Hacked
Outdated Plugins & Themes
Most known WordPress vulnerabilities are in plugins and themes, not WordPress itself. Abandoned, unsupported and “nulled” (pirated) plugins are the worst offenders.
Weak or Stolen Logins
Reused passwords, no two-factor authentication, and old staff or agency accounts that were never removed give attackers the front-door key.
Old Hosting & PHP
End-of-life PHP versions no longer get security fixes, and on shared hosting one compromised site can infect every other site on the same account.
Data Breaches Notified to the OAIC in 2025
Days to Assess a Suspected Eligible Breach
Association Breaches Notified in 2025
Years Shipping Production Software
How to Clean a Hacked WordPress Site Properly
Lock down access, rotate every password and key, and keep a copy of the hacked site as evidence before anything is cleaned.
Step 2: Clean
Everything
Replace WordPress, plugins and themes with fresh copies, then hunt down backdoors in the uploads folder, injected scripts in the database, hidden admin users and rogue scheduled tasks.
Step 3: Close the
Way In & Harden
Find and fix the vulnerability that let attackers in, remove unused plugins, then ask Google to review the site so the warning is lifted.
Brands We Have Helped
















What People Say
Makes the Magic Happen
“Love the professional finishes . Dustin and the team know how to make the magic happen.”
Sam Hunter
Corporate Headshot Photographer
Always Shows Up
“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”
Kym Bolger
Social Media Marketing
Responsive Professionalism
“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”
Ivan Huang
CPA
Frequently Asked Questions
Can I just restore a backup?
Only once you know how attackers got in, and only from a backup taken before the hack. Attackers often sit quietly for weeks, so recent backups can include the backdoor. Restoring without closing the hole usually ends with the site being hacked again.
Will a security plugin fix a hacked WordPress site?
Security plugins are good at spotting known malware, but they often miss custom backdoors, scripts injected into the database and rogue administrator accounts. They also can’t tell you how attackers got in or what data they could reach.
How do I get the Google “This site may be hacked” warning removed?
Clean the site completely first, then request a review under Security issues in Google Search Console. Google usually reviews hacked sites within a few days. If the site is still infected, the request is rejected and the next review takes longer.
Do we have to report a hacked website?
If your organisation is covered by the Privacy Act and personal information was likely accessed in a way that could cause serious harm, it may be an eligible data breach under the Notifiable Data Breaches scheme. You must assess a suspected breach quickly, generally within 30 days. We provide the technical facts; get legal advice on your obligations.
How long does a WordPress clean-up take?
It depends on the size of the site and how deep the attackers got. We contain the damage the same day and give you a fixed quote for the full clean-up. See hacked website repair.
How do we stop it happening again?
Keep WordPress, plugins and themes updated, remove anything you don’t use, turn on two-factor authentication, give each person only the access they need, keep off-site backups and run a supported PHP version. A website security audit shows where you stand today, and our care plans keep it that way.