Maybe Google flagged your site with a red warning screen. Maybe visitors are being redirected to a spam site, or strange pharma links have appeared in your pages. Your stomach drops - your WordPress site has been hacked.
Take a breath. Thousands of WordPress sites get compromised every day, almost always by automated bots exploiting outdated software, not by someone targeting you personally. Recovery is a known, repeatable process. Here is what to do, in order.
Speed matters more than perfection right now. The longer malware sits on your site, the more damage it does: Google blacklisting, blocked emails, stolen customer data, spam pages piling up in the search index.
If you can, put the site into maintenance mode or ask your host to temporarily suspend public access. Many hosts have a security team - contact them first, because they can often tell you exactly when and how the breach happened from server logs.
Do not delete anything yet. You need to know what happened before you start cleaning.
Assume every credential connected to the site is compromised. Change, in this order: your hosting control panel password, WordPress admin passwords for all users, FTP/SFTP passwords, and the database password (your host's support can help update wp-config.php to match).
While you are in the WordPress users screen, look for admin accounts you do not recognise - hackers routinely create their own. Delete them. Enable two-factor authentication on your hosting account and WordPress login if available.
Change these passwords from a computer you trust. If your own PC is infected with a keylogger, the attacker just gets the new passwords too, so run a local antivirus scan as well.
Install a reputable security scanner - Wordfence and Sucuri Scanner are the standard free options - and run a full scan. It will flag modified core files, known malware signatures, and suspicious code.
Common places malware hides: fake plugins with generic names, extra files in wp-content/uploads (a folder that should contain only media), modified wp-config.php or .htaccess files, and code injected into your theme's functions.php.
Also check Google Search Console under 'Security and Manual Actions' - if Google flagged your site, it often tells you which URLs are infected, which is a free roadmap for cleanup.
The fastest reliable fix is restoring a backup taken before the hack. Check the scanner's report for when files were modified, then restore a backup older than that date. Most hosts keep daily or weekly backups even if you never set one up - ask.
No clean backup? Then clean manually: re-download fresh copies of WordPress core, your theme and every plugin from official sources and replace the files wholesale, keeping only wp-content/uploads (scanned) and wp-config.php (inspected line by line). Let the scanner verify the result.
One warning: restoring a backup without fixing the vulnerability means you will be hacked again, often within days. Which brings us to the next step.
The overwhelming majority of WordPress hacks come through outdated plugins, themes, or core. Update all three - now, not next week.
Then remove what you do not need: deactivated plugins and unused themes are still attack surface even when switched off. Delete them entirely. If a plugin has not been updated by its developer in over a year, find a maintained alternative.
If your scan or host logs identified the specific vulnerable plugin, make sure the patched version is installed or the plugin is gone.
Once clean, spend thirty minutes on prevention. Keep a security plugin active with its firewall enabled. Turn on automatic updates for plugins and core, or diarise a monthly update session. Limit login attempts and rename the default admin username.
Set up off-site backups on a schedule - daily for busy sites, weekly minimum - with a plugin like UpdraftPlus storing copies somewhere outside your hosting account. A clean backup is the difference between a bad hour and a bad week.
Finally, if Google flagged your site, request a review in Search Console once you are confident it is clean, and the warning typically clears within a few days. If your site is central to how you win business, treat security as part of ongoing website maintenance, not a one-time scramble.
DIY cleanup makes sense for simple infections with a good backup on hand. It stops making sense when the site keeps getting reinfected, when malware has reached the database, when customer data may have been exposed, or when your business is losing money every hour the site stays flagged. Professional cleanup includes log analysis to find the entry point - the part most DIY efforts skip, and the reason reinfections happen.
If you have followed these steps and the infection keeps coming back, contact Kentaurx - we clean up and harden hacked WordPress sites for business owners every week.
Mostly through outdated plugins and themes with known vulnerabilities, weak or reused passwords, and nulled (pirated) themes that ship with malware built in. Automated bots scan thousands of sites a day for these openings - it is rarely personal.
Only if the backup predates the infection and you also patch the vulnerability that let the attacker in. Restore a clean backup, then immediately update all plugins, themes and core, and change every password - otherwise reinfection is likely.
After you clean the site, request a review in Google Search Console under Security Issues. Reviews are typically processed within a few days, and the warning clears once Google confirms the malware is gone.
Not necessarily. Free versions of Wordfence or Sucuri plus timely updates, strong passwords, two-factor authentication and scheduled off-site backups prevent the vast majority of attacks. Paid tiers add real-time firewall rules, which are worth it for e-commerce or high-traffic sites.
Whatsapp: +91 93618 97364
Email: We@kentaurx.com