32 chapters · 6 parts
How to Fix a Hacked WordPress Site: The Complete Step-by-Step Guide
Use this guide to confirm a WordPress hack, preserve evidence, clean files and the database, close the entry point, recover search visibility, and reduce reinfection risk.
A hacked WordPress site can show obvious damage, such as redirects, phishing pages or an unfamiliar administrator. It can also look normal while serving spam to search engines, sending email, loading malicious JavaScript or keeping a hidden route back into the server.
This guide is for site owners who need a clear recovery sequence and for developers who need the commands behind each step. Each chapter starts with the plain version of the job, then gives you the checks, files, database locations and commands needed to carry it out.
Where to start
If you have just discovered the hack, start with Part 1 and work forward. Confirm the signs, contain the incident, preserve a copy of the compromised site, scan it and use the available logs to work out what changed and how access was gained. Deleting suspicious files before that work can destroy evidence while leaving another persistence mechanism in place.
If you already know what infection you have, you can jump to its chapter. The redirect, Japanese keyword, pharma spam, backdoor, database, phishing, spam-email and checkout-skimmer chapters each focus on that symptom before bringing you back into the cleanup and recovery sequence.
What this guide covers
The guide covers self-hosted WordPress and WooCommerce recovery from confirmation through post-cleanup monitoring. It also covers Multisite and multiple WordPress installations sharing a hosting account.
It does not replace incident-response work for a wider server or company-network compromise. It also does not provide legal or payment-card compliance advice. If customer information or payment data may have been exposed, involve your payment provider, a qualified security investigator where required, and a lawyer who can assess notification duties for the affected jurisdictions.
The chapters
Is it hacked? The first hour
Confirm the hack, contain it, preserve evidence and find where the attacker entered.
Chapter 1
How to Tell If Your WordPress Site Is Hacked: Warning SignsA hacked WordPress site can hide behind redirects, spam pages, unknown admins or changed files. Check the strongest signals first and record what you find before cleanup.
Chapter 2
WordPress Site Hacked? What to Do in the First HourConfirmed a WordPress hack? Record what happened, restrict public harm, preserve the compromised state, protect access and collect the records you will need for cleanup.
Chapter 3
Locked Out of WordPress Admin After a Hack: How to Get Back In · coming 12 October 2026
Locked out of WordPress after a hack? Use the access path you still control to recover a trusted administrator account, verify its email and end old sessions.
Chapter 4
How to Back Up a Hacked WordPress Site Before You Clean It · coming 16 October 2026
Preserve the compromised WordPress files and database before malware removal starts. This chapter shows how to record the site state, create the backup set, store it safely and verify it.
Chapter 5
How to Scan WordPress for Malware, Online and on the Server · coming 19 October 2026
Check a suspected WordPress infection from the outside and the server. Verify core and plugin files, inventory loaded code, search the database, and save every finding before cleanup.
Chapter 6
How Was My WordPress Site Hacked? Finding the Entry Point in the Logs · coming 23 October 2026
Trace a WordPress compromise back to its likely entry point by building a timeline from file changes, logs, accounts and the software present at the time.
The common infections
Identify and remove redirects, spam, backdoors, skimmers, rogue users and other persistence.
Chapter 7
WordPress Redirect Hack: Remove Redirects to Spam Sites · coming 26 October 2026
A WordPress redirect hack can hide in files, database values, server rules or browser code. Trace the redirect, remove its source, close the entry point and test the conditions that triggered it.
Chapter 8
Japanese Keyword Hack in WordPress: Remove the Spam Pages · coming 30 October 2026
Japanese spam pages can appear in Google while your normal WordPress pages look unchanged. Find the affected URLs, remove their source, clean injected content and verify the response Google receives.
Chapter 9
WordPress Pharma Hack: Remove Spam Only Google Can See · coming 2 November 2026
Pharma spam can alter Google results while your normal pages look unchanged. Trace the injected source, clean files and database records, then retest the affected URLs.
Chapter 10
How to Find and Remove Hidden Admin Users in WordPress · coming 6 November 2026
Find every privileged WordPress account, preserve evidence, remove a confirmed rogue administrator without losing legitimate content, and check for persistence.
Chapter 11
How to Find a Backdoor in WordPress: Web Shells and Hidden PHP · coming 9 November 2026
Find a hidden WordPress backdoor without executing suspicious code. Check core, plugins, uploads, must-use plugins and drop-ins, then remove confirmed persistence safely.
Chapter 12
How to Remove Malware from the WordPress Database · coming 13 November 2026
WordPress database malware can hide in posts, options, metadata, users and plugin tables. Find confirmed indicators, inspect each match, back up first, then make targeted changes without damaging serialized data.
Chapter 13
WordPress Core Files Modified? Check and Restore Them · coming 16 November 2026
A checksum mismatch shows that an installed WordPress core file differs from the official release. Verify the right version and locale, save evidence, restore trusted core files, and check again.
Chapter 14
Nulled WordPress Plugins and Themes: Find and Remove Malware · coming 20 November 2026
Identify plugins and themes from untrusted sources, preserve suspicious packages, remove them without running their uninstall code, install trusted replacements and check for persistence elsewhere.
Chapter 15
Hacked Through a Vulnerable Plugin: Find It and Close the Hole · coming 23 November 2026
A vulnerable plugin may explain how an attacker got in, but the version alone is not proof. Preserve the evidence, check the files and logs, install the fix, then verify the path is closed.
Chapter 16
WooCommerce Credit Card Skimmer: Detect and Remove Checkout Malware · coming 27 November 2026
A WooCommerce checkout skimmer can steal payment or customer data from an altered checkout. Find the affected payment path, trace the code, remove it safely, and test checkout before reopening.
Chapter 17
WordPress Site Sending Spam Emails: Find the Script and Stop It · coming 30 November 2026
Trace unauthorized email to WordPress code, a scheduled task, a compromised mailbox or another server process. Preserve the evidence, remove the sender and verify normal mail still works.
Chapter 18
Phishing Pages on a WordPress Site: Find and Remove Them · coming 4 December 2026
A phishing page can be served from WordPress, a standalone folder or another application under the same hosting account. Trace the reported URL before deleting anything, then remove the malicious content and close the access path.
Chapter 19
WordPress Malware Keeps Coming Back: Find the Reinfection Source · coming 7 December 2026
Recurring WordPress malware means something still has a way to write it back. Trace the recreated files, scheduled tasks, configuration, accounts and neighboring sites before cleaning again.
The clean-up
Choose restore or cleanup, replace trusted code and rotate every affected credential.
Chapter 20
Clean a Hacked WordPress Site or Restore a Backup? · coming 11 December 2026
A clean pre-hack backup can shorten recovery, but only if it predates the compromise and the original entry path is fixed. This chapter shows how to choose, restore, preserve recent data, and verify the result.
Chapter 21
How to Reinstall WordPress Core, Plugins and Themes Safely · coming 14 December 2026
Replace compromised WordPress code with trusted copies while preserving your database, uploads and configuration. Record versions first, then verify the replacement files.
Chapter 22
What Passwords Should You Change After a WordPress Hack? · coming 18 December 2026
Rotate every credential the compromised WordPress environment may have exposed. This chapter covers the order, exact WordPress commands, sessions, salts, database access and integrations.
Recovery
Clear Google warnings, repair search damage, regain hosting access and watch for a return.
Chapter 23
How to Remove "This Site May Be Hacked" from Google · coming 21 December 2026
Google's "This site may be hacked" label can remain after WordPress looks clean. Check the affected scope, verify the cleanup and request Google's review when required.
Chapter 24
How to Remove Hacked Spam URLs from Google Search · coming 25 December 2026
Clean the hacked URLs from your server, return the right permanent status, use Search Console removals where useful, and check that Google is processing the changes.
Chapter 25
Deceptive Site Ahead on WordPress: Remove the Google Warning · coming 28 December 2026
A Deceptive Site Ahead warning can remain after a WordPress cleanup until Google reviews the security issue. Check what Google flagged, verify the fix, request review and confirm the warning is gone.
Chapter 26
Hosting Account Suspended for Malware: Get Your WordPress Site Back · coming 1 January 2027
A malware suspension can take WordPress, email or an entire hosting account offline. Use the host's evidence, preserve the site, clean every affected area and submit a clear reinstatement request.
Chapter 27
How to Secure WordPress After a Hack · coming 4 January 2027
A clean site can still be vulnerable to the same entry path. Turn the evidence from the incident into specific security changes, verify each one, then start monitoring.
Chapter 28
WordPress Security Monitoring: Catch the Next Hack Early · coming 8 January 2027
Build a post-hack monitoring baseline for WordPress files, privileged users, software versions, Search Console, uptime, logs and scheduled events.
By type of site
Handle the extra scope created by WooCommerce, Multisite and shared hosting.
Chapter 29
Hacked WooCommerce Store: Customer Data, Payments and Who to Tell · coming 11 January 2027
A WooCommerce compromise can involve customer records, checkout code, payment extensions and connected services. Preserve evidence, establish what was exposed and involve the right people before reopening payments.
Chapter 30
Hacked WordPress Multisite: Clean Every Site in the Network · coming 15 January 2027
A Multisite breach can cross site boundaries through shared code and privileged users. Inventory the network, clean shared and site-specific data, then verify every site.
Chapter 31
One Hacked Site Infected the Rest: Cross-Contamination on Shared Hosting · coming 18 January 2027
One infected WordPress site can expose other installations under the same hosting account. Inventory every reachable site, investigate each one, and remove shared persistence before recovery.
Scan with an AI agent
Run the full scan and recovery on copies with the wp-full-site-scan skill, then review the agent's findings before approving live changes.
Chapter 32
How to Scan a Hacked WordPress Site With an AI Agent · coming 22 January 2027
Run a hacked WordPress investigation with the wp-full-site-scan agent skill. It works from file and database copies, checks evidence, prepares cleanup and waits for approval before live changes.
Frequently asked questions
How long does it take to clean a hacked WordPress site?
There is no reliable fixed time. The work has separate stages: containment, evidence preservation, investigation, cleanup, closing the entry point, recovery and monitoring. A site with one modified plugin has a different investigation scope from a store with checkout malware or several infected sites under one hosting account.
Can a malware scanner say my WordPress site is clean when it is still hacked?
Yes. Google notes that scanning tools can miss some spam hacks, and a clean Safe Browsing result does not prove that a site has no hacked search spam. Use scanner results as evidence alongside file checks, database inspection, user review, logs and the symptoms that first exposed the incident.
Do I have to tell customers that my WordPress site was hacked?
A hack does not automatically mean every customer must be notified. The answer depends on what information was accessed, the people affected and the laws that apply to the business and those people. For a possible breach of personal information, have a lawyer assess the notification duties that apply rather than using this guide as legal advice.
What should I do if a hacked WordPress site may have exposed payment card data?
Stop treating it as a normal malware cleanup. Preserve evidence and contact the payment processor or acquiring bank so they can tell you what their incident process requires; use a qualified forensic investigator if that process calls for one. The technical cleanup in this guide can support the investigation, but it does not establish payment-card compliance.
Should I pay a ransom if a WordPress hacker demands money?
The FBI does not support paying ransomware demands and states that payment does not guarantee that data will be recovered. Preserve evidence, contact appropriate law enforcement or incident-response help, and get legal advice if the demand creates business, disclosure or sanctions questions.
When should I stop trying to clean a hacked WordPress site myself?
Bring in specialist help when you cannot establish the scope of the compromise, the infection returns after cleanup, the server itself may be compromised, several sites share the affected account, or sensitive customer or payment data may have been exposed. Google also recommends professional help for site owners who are not comfortable investigating server files and hacked-site behavior.
Will my Google traffic return after I clean the hacked site?
Cleaning the site removes the technical cause, but search recovery is a separate process. Google may need to recrawl affected URLs, reprocess security findings and remove old hacked URLs from its index. Search Console shows security findings and review paths, while its Removals tool provides temporary hiding rather than permanent URL removal.