Security

WordPress Site Hacked? Step-by-Step Malware Removal & Recovery Guide

Redirects, spam pages or a Google warning? The exact process I have used to recover 60+ hacked WordPress sites — and keep them clean.

WordPress Site Hacked? Step-by-Step Malware Removal & Recovery Guide

Discovering your website has been hacked is stressful — especially when Google shows a red warning or visitors get redirected to spam. I have recovered 60+ hacked websites, including a large batch in eight days of 20+ hour shifts. This is the same process, simplified so you know exactly what needs to happen.

Signs your WordPress site has been hacked

  • Visitors (often only on mobile or from Google) are redirected to spam or scam sites.
  • Google shows “This site may be hacked” or Chrome displays a red “Deceptive site” warning.
  • Strange pages in Google results — often pharma or Japanese keyword spam.
  • Unknown admin users, new files in /wp-content/uploads/, or changed .htaccess rules.
  • Your host suspends the account for sending spam or high resource usage.

Step 1: Contain the damage

  1. Take a full backup of the infected site (files + database). Yes, infected — you need it for investigation and as a fallback.
  2. Put the site into maintenance mode so visitors aren’t exposed.
  3. Change every password: hosting/cPanel, FTP/SFTP, database, every WordPress admin and your email account.

Step 2: Find out what was infected

Scan with a server-side scanner or a plugin such as Wordfence, and use an external check like Sucuri SiteCheck. Then check manually — automated scanners miss obfuscated code:

  • Recently modified files (sort by date in your file manager or via SSH).
  • PHP files inside /uploads/ — there should be none.
  • wp-config.php, .htaccess and index.php for injected code.
  • The database: unknown admin users, injected <script> tags in posts, and the siteurl/home values in wp_options.

Step 3: Clean the site properly

  1. Replace WordPress core with a fresh copy from wordpress.org (keep only wp-content and wp-config.php).
  2. Reinstall every plugin and theme from official sources. Delete anything nulled, abandoned or unused — nulled themes are one of the most common infection sources.
  3. Remove backdoors — hidden files that let the attacker back in. This is the step most DIY cleanups miss, and why sites get reinfected days later.
  4. Clean the database and remove rogue admin accounts.
  5. Regenerate security keys and salts in wp-config.php to log everyone out.

Step 4: Harden so it doesn’t happen again

  • Update WordPress, plugins, themes and PHP — and keep them updated.
  • Enable two-factor authentication and limit login attempts.
  • Add a web application firewall (Cloudflare or a security plugin).
  • Disable file editing in the dashboard with DISALLOW_FILE_EDIT.
  • Set correct file permissions (folders 755, files 644, a stricter setting for wp-config.php).
  • Schedule automatic off-site backups and uptime/integrity monitoring.

Step 5: Remove Google warnings and blacklists

Once the site is clean, open Google Search Console → Security issues, confirm the problems are fixed and request a review. Also check your domain on other blocklists if emails were affected. Reviews are usually processed within days.

How WordPress sites usually get hacked

In most of the 60+ recoveries I’ve handled, the entry point was one of these:

  • Outdated plugins or themes with known vulnerabilities — by far the most common cause.
  • Nulled (pirated) premium themes and plugins that ship with hidden backdoors.
  • Weak or reused passwords on admin, hosting or FTP accounts.
  • Shared hosting cross-contamination — one infected site on an account infecting the others.
  • Abandoned installs — old staging copies or test sites left on the server and never updated.

Cleaning many sites on one server

If you host several websites on one cPanel account or server, treat them as one incident. Cleaning one site while another infected site sits next to it leads to reinfection within hours. Isolate accounts where possible, clean every site, remove unused installs and then harden the server itself — firewall rules, PHP settings, malware scanning and monitoring.

A simple prevention routine

  1. Weekly: apply updates and review the security plugin’s alerts.
  2. Daily: automatic off-site backups, with at least 30 days of history.
  3. Monthly: review admin users, remove unused plugins and test a backup restore.
  4. Always: 2FA for admins, unique passwords and a web application firewall.

Prevention costs far less than recovery — and a fast, well-maintained site also ranks better. See how to speed up WordPress while you harden it.

Hacked right now? I offer malware removal & hardening with most cleanups done within 24–48 hours. Message me on WhatsApp and I’ll look at it straight away.

Frequently asked questions

How do I know if my WordPress site is hacked?

Common signs are redirects to spam sites, Google or Chrome security warnings, spam pages appearing in search results, unknown admin users and unexpected files in the uploads folder.

Can I just restore a backup to fix a hacked site?

Only if the backup is from before the infection — and you must still find and fix how the attacker got in, change all passwords and remove backdoors, or the site will be reinfected.

How long does WordPress malware removal take?

Most single-site cleanups take 24–48 hours including hardening. Google blacklist reviews are usually processed within a few days after the site is clean.

Hamza Umar, author and Head of Development
Written byHamza Umar

Head of Development at Bright Ideas Communications and founder of OPT Tech Solution. 6+ years, 1000+ websites and 250+ clients across 20+ countries — WordPress, Laravel, MERN, security and AI.

Need help with this?

Get a fixed quote, scope and timeline — usually within an hour.

Leave a Reply

Your email address will not be published. Required fields are marked *