October 10, 2026
Is My WordPress Site Hacked? 9 Signs of Malware and What to Do First
2026–10–11 · Oscar Villegas

By Oscar Villegas
2 min read
A WordPress site is probably hacked if visitors get redirected to spam, Google shows "This site may be hacked", you find administrator users you did not create, or new PHP files appear in the uploads folder. If you see any of these, do not delete things at random: take a full backup first, change every password and then clean the files and the database, because a partial cleanup usually leaves a backdoor that reinfects the site.
The 9 most common signs
- Visitors, or only mobile visitors coming from Google, are redirected to casino, pharmacy or adult sites, while the site looks normal when you type the address yourself.
- Searching site:yourdomain.com on Google shows pages you never wrote, often in Japanese or full of pharmacy keywords.
- Google shows "This site may be hacked" under your result, or Chrome shows a red "Deceptive site ahead" page.
- Google Ads disapproves your ads with the policy "Compromised site".
- There are administrator users you did not create in Users, or your password suddenly stopped working.
- New PHP files appear in wp-content/uploads, a folder that should only hold images and documents.
- Plugins you never installed, or plugins that reappear after you delete them.
- Your hosting suspends the account, warns you about malware or says the site is sending spam email.
- The site became very slow or the server CPU is at 100% with no extra traffic.
What to do first, in this order
- Take a full backup of files and database as they are now. It keeps your content safe and shows later how they got in.
- Change every password: WordPress admins, hosting panel, FTP and the database user. Remove any admin user you do not recognize.
- Check Google Search Console under Security issues to see what Google found and on which URLs.
- Do not just install a security plugin and call it done. Scanners find known patterns, but backdoors are often hidden in files that look normal.
- Clean the site completely: replace WordPress core with a fresh copy, reinstall plugins and themes from official sources, and check the uploads folder and the database for injected code.
How they usually get in
In our experience the most common entry point is an outdated plugin or theme with a known security hole. Next come pirated themes that already include a backdoor, passwords reused from another service, and other infected sites in the same hosting account. Closing that hole is what keeps the site clean after the cleanup.
When to ask for help
If the redirects come back after you clean them, if you cannot log in, or if your Google Ads are stopped, the infection usually has more than one backdoor. That is the point where a full cleanup by someone who reads the server logs saves time and ad spend.
Frequently asked questions
Can a security plugin remove the malware by itself?
Sometimes, for simple infections. Many hacks leave backdoors in files that look normal, so a plugin can report the site as clean while the attacker can still get in.
Will I lose my posts or orders if I clean the site?
No. A proper cleanup keeps posts, pages, products and orders. It removes infected files and injected code, after a full backup.
How long until Google removes the hacked warning?
After the site is clean you request a review in Search Console. Google usually answers within a few days.
Need it fixed?
I'm Oscar Villegas and I clean hacked WordPress sites for a fixed price, keeping your posts, products and orders: https://oscarvillegas.online/wordpress-fix/hacked-site
Originally published at https://oscarvillegas.online.