Skip to content
Back to the blog
Security WordPress Guide

How to tell if your WordPress is hacked (and what to do in the first 2 hours)

Seven signs you can check yourself in ten minutes, without being technical, and what to do —and above all what not to do— in the first two hours if any of them comes back yes.

7 min read

Most people don’t find out someone got into their website because they see something broken. They find out weeks later, when a customer mentions “hey, your site takes me somewhere odd on my phone”, or when the host emails to say the account has been suspended.

That happens because whoever got in doesn’t want you to notice. Visible damage gets fixed in a day; a quietly compromised site serves spam to Google, redirects visitors and keeps a back door open for months. The later you spot it, the more room it’s had to hide.

Here are the seven signs you can check yourself, without being technical and without installing anything. And at the end, what to do — and above all what not to do — in the first two hours.

1. Your phone goes somewhere else, your computer doesn’t

This is the most common sign and the most treacherous: you open your site on your own computer, it looks perfect, and you relax. But malicious redirects are usually set to fire only on mobile, only on a first visit, or only if you arrive from Google. The owner, who always visits the same way from the same place, never sees it.

How to check it yourself: open your site on your phone using mobile data, not your home wifi, in a private window. Then search for it on Google and click through from the result rather than typing the address. If any of those paths lands you somewhere else, that’s your answer.

2. Google is showing pages of yours that you never wrote

This is the one that costs the most money and the one fewest people check. The typical case is hundreds of injected spam pages — pharmaceuticals, casinos, replicas — served only to the search engine. You can’t see them anywhere on your site, but they’re indexed under your name.

How to check it yourself: search Google for site:yourdomain.com (like that, no space after the colon). You’ll see the list of your pages Google knows about. If addresses you don’t recognise show up, or titles in another language, there’s nothing left to debate.

3. The browser or your host is already telling you

If a red “deceptive site” screen appears, or your host has written to you about unusual resource use or spam being sent, this is no longer a suspicion. And the clock is running: getting off Google’s blacklists is slower than getting on them, and many hosts suspend an account without warning once they detect a site sending junk mail from their servers.

How to check it yourself: if you have Search Console, look under Security and manual actions. Google warns explicitly there if it has detected malicious content, and it usually tells you which pages.

4. There are administrator users you never created

When someone gets in, the first thing they usually do is guarantee a way back: they create an account with administrator rights, under a name that looks harmless (admin2, wpuser, support) so it doesn’t stand out in a list.

How to check it yourself: in your WordPress dashboard, go to Users and sort by registration date. Go through the administrators one by one: if there’s one you don’t recognise, or one with an email that belongs to nobody on your team, that’s the door.

5. The site suddenly got slow, and you changed nothing

This is the one almost nobody associates with an attack, and yet it’s among the most common. A compromised site is working for somebody else: serving spam, sending email or taking part in attacks on third parties. All of that eats your hosting resources, and what you notice is a site that crawls or drops out intermittently.

How to check it yourself: if your site used to be fast and now isn’t, and you haven’t installed anything new or seen a jump in traffic, don’t write it off as normal. Run it through our checker and compare against what you remember: if performance has collapsed with no cause, it’s worth looking inside.

6. Emails go out in your name that you never sent

If your customers tell you they’re getting odd messages from your domain, or if your normal emails suddenly start landing in spam, your server may be sending junk without your permission. The damage goes beyond the website: your domain’s reputation burns, and when that happens your invoices and quotes stop reaching your customers’ inboxes.

How to check it yourself: search Google for “domain blacklist check”, put your domain into any of those tools and see whether it appears on any list. If you show up on several, you have an active problem.

7. Files were modified on dates when nobody touched anything

This is the most technical of the seven, but also the hardest to argue with. If the last change you made to your site was in March, and there are system files modified in July at four in the morning, somebody was there.

How to check it yourself: open your host’s file manager, go to your site’s folder and sort by modification date. You don’t need to understand what each file does: just look at the dates. The ones that don’t match your calendar are already telling you something.

The first two hours

If any of the seven came back yes, this is what matters. And I’ll start with what not to do, because that’s where nearly everyone goes wrong:

Don’t delete files at random. The instinct is to go in and remove anything that looks odd. That’s exactly the worst move: you destroy the evidence of how they got in. And if you don’t know how they got in, the cleanup achieves nothing, because they’ll come back the same way within days.

Don’t reinstall WordPress over the top. It doesn’t clean the database, it doesn’t remove the users you never created, and it doesn’t close the vulnerability. All it does is make it harder to work out what happened.

Don’t just restore an old backup. If the backup is from after the infection, you restore the infection. And if it’s from before, you lose everything you’ve done since and the door they came through is still wide open.

And now what you should do:

Take a backup of the current state, infection included. Keeping something infected sounds odd, but it’s your safety net and your evidence of exactly what was there. Everything else happens on top of that copy.

Change the passwords, but in the right order. Hosting and database first, then the WordPress users. If you start with WordPress while the attacker still has server access, they’ll simply change them back.

Log every user out. Changing a password doesn’t kick out someone who’s already inside with an open session.

Tell your host. They usually have access logs that say exactly when and how the break-in happened. That information saves you hours.

Can you do it yourself?

Honestly: sometimes, yes. If the infection is two days old, it’s contained in a plugin you’ve already identified, and you have a verified clean backup from before, you can get through it yourself by following these steps calmly.

When not: if you’ve been infected for weeks, if several sites share the same hosting — the infection jumps between them and cleaning just one achieves nothing — if there’s a shop and customer data involved, or if you’ve already cleaned it once and it came back. That “it came back” almost always means the symptom was cleaned and the entry point wasn’t closed.

If that’s your situation, here’s how we do it: backup first, fixed quote before we touch anything, and the way in closed, not just the symptom.

What prevents the second time

Almost none of the sites we clean had been singled out by anyone. They had simply gone months without updates, and an automated bot found them. It isn’t bad luck: it’s statistics.

Which is why the conversation that matters isn’t how to clean a hacked site, but how not to be there again. Updating in time, with a backup first and a check afterwards, is boring and it works — and it’s exactly what a maintenance plan does.

If you’d rather start by seeing what’s visible from outside, check your site: two minutes, free, no sign-up.

Want us to look at your site?

A first no-strings review: we tell you how it stands and what we'd do to make it fast, secure and up to date.

Let's talk