Back to Blog

What to Do If Your WordPress Site Gets Hacked


The call always sounds the same. Somebody Googles their own business, sees their site listed with words that have nothing to do with them, and phones me in a panic on a Saturday.

If that is where you are, take a breath. Almost every hacked WordPress site I have cleaned up was recoverable, and the first hour matters more than the rest. Here is the order I work in.

First, check it is actually hacked

A surprising number of emergencies are not. A plugin update that broke a page looks alarming but is not an attack. Neither is a white screen, usually. What genuinely suggests a compromise:

  • Pages you did not create, often about pharmaceuticals, loans or gambling.

  • Your site redirecting somewhere else, sometimes only on phones or only from Google.

  • Google warning people before they visit, or your pages vanishing from search.

  • Admin users in WordPress that nobody recognises.

  • Your host emailing about spam sent from your account.

One quick check: log in and look at Users. An administrator nobody recognises is your answer.

Do not start deleting things

The instinct is to find the bad file and bin it. Resist for ten minutes. Delete before you have a copy and you destroy the evidence of how they got in, then miss something and get reinfected within a fortnight.

So the first real step is the boring one. Take a full backup of the site as it is, mess and all, files and database, and download it off the server. It feels wrong to back up a hacked site. Do it anyway. If the clean-up goes sideways you will want a way back.

If you already have a backup routine, this is when it pays for itself. I have written about backups and staging separately, and if this is the week you find out you have not got one, that is the real lesson.

Lock the doors

Change every password that touches the site, properly, rather than adding a number on the end. WordPress admin accounts, the hosting control panel, FTP or SFTP, the database user, and the email address the admin account uses. That last one matters more than people think, because with your email they can reset it all back.

Then force everyone out. Most security plugins end all active sessions in a click, and an attacker sitting on a valid session does not care that you changed the password.

Delete any admin account you do not recognise, but screenshot it first. The created date is often your best clue about when this started.

Get the site out of harm's way

If the site is serving something nasty, put it into maintenance mode or take it offline while you work. Customers seeing a "back shortly" page for a day is a far smaller problem than customers catching something from you, or Google flagging your domain.

Tell your host too. Most UK hosts have dealt with this hundreds of times, they see things in the server logs that you cannot, and some will run a malware scan as part of what you already pay for.

Free 30-min surgery Stuck on something like this? Let's talk it through. Book a free surgery. Straight to me, the developer, no agency, no sales pitch. Book a surgery

Work out how they got in

This is the step people skip, and it is why sites get hacked twice. It is nearly always one of four things: an out of date plugin with a publicly known hole, a weak or reused admin password, an abandoned theme or plugin that stopped getting updates years ago, or hosting on a version of PHP nobody has touched in years.

Look at the modified dates on your files. A cluster changed on a date when nobody was working on the site tells you roughly when it happened, and you can line that up against your plugin list. If a plugin had a security release just before, you have probably found it.

Have a proper look at what is installed while you are in there. Most sites I inherit carry plugins nobody has opened in three years. I have gone on about how many plugins is too many, and security is the strongest argument in it.

Clean it, or rebuild it

Two honest routes. Clean the existing install: replace core and every plugin and theme with fresh copies from source, hunt through the uploads folder for files that should not be there, check the database for injected content. Or rebuild: fresh WordPress, fresh plugins, content brought across.

Against most advice you will read, I think rebuilding a small business site is often quicker and always safer. Cleaning leaves a nagging doubt for months about what you missed. A rebuild takes a day or two and you know exactly what is on the server.

The exception is a site with a lot of custom theme work, or a shop with live orders. Then careful cleaning is the better call, and that is the point where it is worth paying somebody rather than guessing.

Sort out Google, and think about who else needs telling

Once the site is clean, get into Google Search Console and request a review if there is a security warning on your listing. Left alone that warning stays, and it does more damage to a small business than the hack did. Check the indexed pages while you are there, because spam pages that got indexed need removing.

The other question is data. If your site holds customer details and there is a real chance they were taken, that is a legal matter rather than a technical one. Under UK GDPR a personal data breach that meets the threshold has to be reported to the ICO within 72 hours, and the ICO publishes plain guidance for small organisations on exactly that. Not every incident meets the threshold, but the clock starts once you have reasonable certainty something happened, so decide quickly. I am a developer and not a lawyer, so take proper advice if you are unsure.

Then close the gaps

The fixes are dull and they work. Keep WordPress, themes and plugins updated, with automatic updates on for anything that will tolerate it. Delete plugins and themes you are not using rather than deactivating them, because a deactivated plugin is still a file on your server. Long unique passwords, two factor on admin accounts, backups running automatically with a restore you have tested, and hosting on a current PHP version.

None of it is clever. It is the stuff that never gets done because there is always something more urgent. The longer version is the checklist I go through on every site I take on, plus what I do each month on the sites I look after.

If you are in the middle of it right now

I am in Hull and I work direct with small businesses across East Yorkshire. If your site has been hit and you are not sure what you are looking at, the free half hour is genuinely free and you can book one here. Bring your hosting login and we will work out how bad it is. If you can fix it yourself in an afternoon, I will tell you so.

Here is what that half hour looks like if you want to know before you book.

Free 30-min surgery

Working on something similar?

Book a surgery

Forged in Hull. Not by an agency.

Let’s talk about what you’re building.

· ADAM JACKSON · FORGED IN HULL · EST. 2009
pwadeveloper.uk

Senior freelance web developer in Hull, East Yorkshire. 15+ years building fast, custom websites and web apps in WordPress, Magento, Vue and Nuxt. Work directly with the developer.

Where

Hull
East Yorkshire, United Kingdom

53.7676° N, 0.3274° W

© 2026 Pwa Developer. All rights reserved.

Forged by hand with Nuxt & a headless CMS