GUIDE / WORDPRESS SECURITY

Your WordPress site was hacked. Here is what to do in the first hour.

A page you did not write, visitors redirected somewhere ugly, or a red Google warning across your domain. The next sixty minutes decide whether this is an afternoon of work or a week of lost business. This is the order of operations used on every WordPress rescue that lands on my desk in Louisville.

READ TIME

About 8 minutes

WHO IT IS FOR

Site owners, right now

WRITTEN BY

The Louisville developer who does the rescues

LAST UPDATED

September 2026

FIRST, IS IT REALLY A HACK?

Not every broken site is a break-in.

A white screen after a plugin update, a database that ran out of space, or an expired SSL certificate all look alarming, and none of them are attacks. Those are crashes, and they are usually a faster repair. A hack leaves fingerprints, and they tend to look like the six below.

If you see any of them, treat it as a hack and keep reading. If you only see a white screen or an error message, start with the crash and update-conflict repair instead.

SIX SIGNS

What a hacked WordPress site looks like.

01

Pages you never wrote

Posts about pharmaceuticals, gambling or knock-off goods, sometimes visible only in Google search results and not on the site itself.

02

Redirects

Visitors sent to another site, often only on phones or only when they arrive from a Google click, so you never see it yourself.

03

A red warning

Chrome shows “Deceptive site ahead”, or Google labels the result “This site may be hacked”.

04

Users you did not create

New administrator accounts, or your own password suddenly refused.

05

The host steps in

The hosting account suspended for sending spam or serving malware.

06

Files that do not belong

Strange names in the uploads folder, or a wp-config.php modified at an hour nobody was working.

THE ONE RULE

Do not delete anything. The evidence is the only thing that tells you how they got in.

Infected files, fake users and odd log entries are the trail. Erase them and the same door stays open.

THE FIRST HOUR

Six moves, in this order.

01

Do not delete anything

The infected files, the fake users and the log entries show how the attacker got in. That is the one question a cleanup has to answer, or you will be back here in a month.

02

Take screenshots

The defaced page, the redirect, the Google warning, the host email. Note the time. Thirty seconds now saves an hour of guesswork later.

03

Change the passwords you still control

WordPress admin, the hosting panel, FTP or SFTP, and the email tied to the admin account. New passwords, not variations, and two-factor wherever it is offered.

04

Check backups, but do not restore yet

A backup newer than the break-in puts the infection straight back. One older than the hole leaves the same door open. Know what you have first.

05

Tell your host, and your people

Good hosts pull logs, scan the account and can isolate the site. And if customers log in, order or pay through it, a short “we know and we are on it” beats a silent site.

06

Get a professional in before you start deleting

Cleaning a hacked WordPress site is not hard. Cleaning it completely, and proving it, is the part people skip.

Two monitors side by side showing an outdated gray website transforming into a modern elegant design
WHAT NOT TO DO

Four shortcuts that make it worse.

Do not run a one-click cleaner plugin and call it done. Scanners find signatures; they do not find the backdoor left in a file that looks perfectly normal.

Do not reinstall WordPress over the top and hope. Core files are rarely the problem. The infection lives in plugins, themes, uploads and the database.

Do not pay whoever emailed you first about the hack. A compromised site attracts a second wave of people selling cures.

Do not restore and move on without rotating every credential and closing the entry point. That is how a site gets hacked twice in one season.

HOW A REAL CLEANUP WORKS

The cleanup, stage by stage.

01

Triage and protect

A full copy of the site and database is taken before anything is touched, so nothing is lost and the evidence survives. A maintenance screen goes up if visitors are being harmed.

02

Diagnose the entry point

Server logs, file modification times and the database are read together. Usually it is an outdated plugin, a weak or reused password, or a second compromised site on the same account. Until that is answered, nothing is finished.

03

Clean and verify

Core, plugins and themes replaced with clean copies from the source, not patched in place. Uploads scanned file by file, because PHP should never live there. The database checked for injected content, fake users and hidden options. Then the whole site re-scanned and tested.

04

Close the door

Every password rotated, two-factor on, file permissions corrected, the vulnerable plugin removed or replaced, and Google asked to re-review the site so the warning comes down.

THE SITES BEHIND THE ADVICE

Live WordPress sites I host, update and answer the phone for.

Shop Peerless online store homepage designed by Shaun Wilson Designs
Shop Peerless: a WooCommerce store that has to survive release-day traffic.
Todd Lewis Law homepage designed by Shaun Wilson Designs
Todd Lewis Law: a solo practice that needs the phone to ring.
Aerial Photography Louisville homepage built by Shaun Wilson Designs
Aerial Photography Louisville: my own brand site, kept running the same way.

20+

Years of WordPress, zero drama

24h

Most single-site cleanups are back online within a day

4

Stages, always in the same order

1

Person: the developer you brief does the repair

WHAT IT COSTS TO WAIT

Two days of “we will look at it Monday” can undo months of search progress.

A hacked site does more than embarrass you. Google drops the pages it flags, browsers block the whole domain, email sent from the domain starts landing in spam, and the payment processor behind an online store can suspend the account.

The sites I keep running for Louisville businesses get looked at the same day for exactly that reason.

MAKE IT THE LAST TIME

Six habits that keep a WordPress site clean.

01

Update, and remove what you do not use

Most break-ins start with an outdated plugin nobody was watching. Fewer plugins, fewer doors.

02

Unique passwords and two-factor

On the admin login and the hosting panel. A password reused from another service is the most common key an attacker holds.

03

Backups that live somewhere else

Off the server, and restored once so you know they work. A backup you have never restored is a hope, not a plan.

04

Fewer administrators

Editors do not need to install plugins. Give admin rights to the people who genuinely need them.

05

A firewall in front

Cloudflare in front of a well-configured server blocks most automated attempts before they ever reach WordPress.

06

Someone whose job it is to notice

A care plan with monitoring catches a compromised file in hours, instead of the week it takes a customer to mention it.

WHILE THE SITE IS DOWN

Questions people ask first.

Can a hacked WordPress site be fixed without losing content?

Almost always. Content, images and orders live in the database and uploads, and the first step of every cleanup is protecting a copy of both. Content is lost when someone restores an old backup in a panic, not from the cleanup itself.

How long does it take?

A straightforward infection on a single site is usually cleaned, verified and back online the same day. Sites with many plugins, several domains on one hosting account, or an attacker who has been in for months take longer because there is more to trace.

Will Google remove the warning?

Yes, once the site is clean and you request a review in Google Search Console. The review typically clears within a day or two of a proper cleanup. Requesting it before the site is actually clean resets the clock.

Can you fix a site someone else built?

Yes. Most of the rescues I do are on sites I have never seen before, on every builder and host imaginable. You do not need to know who built it or how.

Heimerdinger Cutlery WordPress store running clean on a desktop monitor after repair work by Shaun Wilson Designs
Aerial Photography Louisville homepage built by Shaun Wilson Designs
IF THE SITE IS DOWN RIGHT NOW

Take the screenshots. Change the passwords you can. Then send me what you see.

You will hear back from the Louisville WordPress developer who does the work, with a plain-English picture of what happened, what it takes to fix, and what it costs, before anything is touched.

Similar Posts