Security

WordPress Site Hacked? What to Do in the First Hour

Your WordPress site was hacked. Here is what to do in the first hour: contain the damage, save evidence, lock every account, then clean up and recover safely.

If your WordPress site was hacked, the first hour is about control, not cleanup. Stay calm, write down what you see, take a full copy of the site, and lock every account an attacker could use. Only then should you start removing malware.

This guide walks through those first steps in order. It is written for business owners and marketing managers, with a few technical notes for the developer on your team. We clean hacked WordPress sites often, and the sites that recover fastest are the ones where nobody panicked and deleted the evidence.

Signs your WordPress site was hacked

Not every problem is a hack. A broken plugin update or an expired hosting plan can also take a site down. These signs, listed in the WordPress.org guide FAQ: My site was hacked, point to a real compromise:

  • Google or your browser shows a red “Dangerous site” or “Deceptive site ahead” warning.
  • Your host suspended the account or emailed you about malware or spam.
  • Search results for your site show pages you never wrote, such as pharmacy, casino or Japanese-language spam.
  • Visitors on phones get redirected to other sites, while you see nothing odd on your desktop.
  • New administrator users appear that nobody on your team created.
  • Customers or antivirus software report that your site is unsafe.

Attackers often hide their work from logged-in users and from the site owner’s own visits. So “it looks fine to me” does not mean the site is clean. Try loading the site from a phone on mobile data, in a private window, and from a Google search result.

Minute 0–10: stay calm and document

The WordPress.org guide puts it plainly: stay calm, then document. Before you touch anything, write down:

  • What you noticed, and the date, time and time zone.
  • Any recent changes: new plugins, theme edits, new users, hosting changes.
  • Who has access to the site, the hosting account, the domain and the email accounts tied to them.
  • Screenshots of warnings, strange pages, or emails from your host or Google.

This becomes your incident report. If you bring in help later, it saves hours. It also helps you answer questions from your insurer, your payment processor or your clients if they ask.

Minute 10–20: take a full copy before you change anything

It feels wrong to back up an infected site, but do it. A copy of the hacked site is evidence. It shows how the attacker got in, which files changed and whether customer data was touched. If a cleanup step breaks something, it also gives you a way back.

Take a copy of:

  1. All files, including hidden files such as .htaccess, and everything outside the WordPress folder that your hosting account can reach.
  2. The full database, exported as a SQL file.
  3. Server logs: web server access and error logs, and any FTP or control panel logs your host keeps. Logs are often kept for a short time only, so download them now.

Store the copy somewhere off the server and label it clearly as infected. Never restore it to a live site.

If you or your developer use WP-CLI, the WordPress command-line tool, a database export is one command:

wp db export hacked-site-$(date +%F).sql

Minute 20–40: lock every door

Assume the attacker has every password that was stored on the site or on the computers used to manage it. Change them all, from a computer you trust. The WordPress.org guide also recommends scanning your own computers, because stolen logins often come from malware on a laptop, not from the website itself.

Change these passwords

Access pointWhy it matters
WordPress administrator accountsDirect control of content, users and plugins
Hosting control panelFull access to files, databases and email
SFTP, FTP and SSH accountsDirect file access that bypasses WordPress
Database userUsed by WordPress itself; update wp-config.php after changing it
Domain registrar and DNS providerAttackers who control DNS can redirect your whole domain
Email accounts used for password resetsWhoever controls these can reset everything else
API keys stored in the sitePayment, email and marketing services connected to WordPress

Use long, unique passwords from a password manager, and turn on two-factor authentication wherever it is offered.

Log everyone out

Changing a password does not always end a session that is already open. Replace the secret keys and salts in wp-config.php to force every user to log in again. WordPress.org provides a secret key generator, or with WP-CLI:

wp config shuffle-salts

Check who has admin access

List every administrator and compare it with the people who should have access:

wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Do not delete unknown admins yet. Note their usernames and registration dates first, because those dates help pin down when the attack started. Then remove their access. Our guide to finding WordPress backdoors explains why a rogue admin is rarely the only thing an attacker leaves behind.

Minute 40–50: contain the damage

If the site is sending visitors to scam pages or serving malware, every minute it stays up affects real people. You have two reasonable options:

  • Put the site in maintenance mode at the server level, so visitors see a simple notice instead of the infected pages. Have it return an HTTP 503 status, which tells search engines the outage is temporary.
  • Ask your host to isolate the account if you are on shared hosting. A hack can spread to other sites in the same account, and your host may already be taking action.

If the site runs an online store or collects personal data, check whether payment pages or forms were changed. Card-skimming code is usually added to checkout pages. If you think customer data was exposed, talk to your payment processor and a lawyer about your notification duties. That part is outside what this guide can cover.

Minute 50–60: talk to your host and check Google

Call or open a ticket with your hosting provider. Ask them:

  • Whether other accounts on the server were affected.
  • Whether they have clean backups, and from which dates.
  • Whether they can share logs from the time of the attack.
  • Whether your server’s IP address was added to email blocklists, which can stop your business email from being delivered.

Next, open Google Search Console and check the Security Issues report. It lists what Google detected, with sample URLs. Do not request a review yet. Google warns that asking for a review before the problem is fully fixed can slow down your next request. Our guide to removing the Google dangerous site warning covers that process step by step.

After the first hour: clean, fix the cause, verify

With the site contained and the accounts locked, the real cleanup starts. This takes hours or days, not minutes, depending on how deep the infection goes.

Replace what you can, inspect what you cannot

WordPress core, and plugins and themes from WordPress.org, can be replaced with fresh, known-good copies. Your own content, uploads, custom theme and database cannot. Those need careful inspection.

WP-CLI can compare your files against the official checksums from WordPress.org:

wp core verify-checksums
wp plugin verify-checksums --all

These commands only cover software published on WordPress.org. Premium plugins and custom code have to be checked against a clean copy from the vendor or your version control.

When you replace core files, use the same WordPress version the site is running. The WordPress.org guide also advises replacing whole folders rather than using an installer that only overwrites existing files, because attackers often add new files.

Look where malware hides

Common places include PHP files in the uploads folder, must-use plugins, extra code at the top of wp-config.php or theme files, .htaccess rules that redirect mobile visitors, scheduled tasks, and spam scripts stored in the database. We explain each of these in where malware hides in WordPress.

Find out how they got in

Cleaning without finding the cause is the most common reason sites get reinfected. Typical entry points are:

  • A plugin or theme with a known vulnerability that was not updated.
  • An abandoned plugin that no longer gets security fixes.
  • A reused password found in an old data breach.
  • An infected computer belonging to someone with access.
  • Another hacked site in the same hosting account.

Your access logs, the file dates you saved, and the registration dates of rogue users usually point to the answer.

Update and change passwords again

Once the site is clean, update WordPress, all plugins and themes, and your PHP version if it is past support. Then change every password a second time. The first change happened while the site was still infected, so those new passwords may have been captured too. The WordPress.org guide makes the same point.

Mistakes that make a hack worse

These are the patterns we see most when a cleanup goes wrong:

  • Deleting files before taking a copy. You lose the evidence that shows how the attacker got in.
  • Restoring a backup and calling it done. If the hole is still open, the attacker comes back. Sometimes the backup is also infected, because the attacker was inside for weeks before anyone noticed.
  • Running one scanner and trusting a clean result. Scanners miss things, especially new or custom code. Use them as one input, not the final answer.
  • Requesting a Google review too early. A failed review can delay the next one.
  • Fixing only the visible symptom. Removing spam pages without finding the script that creates them means they return the next day.

How to make the next hack less likely

Most WordPress hacks we clean up trace back to software nobody was looking after. Prevention is mostly routine work:

  • Keep a short, well-maintained list of plugins, and remove anything abandoned.
  • Apply updates on a schedule, tested on staging first. Our guide to safe WordPress updates with staging and tests explains how.
  • Use two-factor authentication for every administrator.
  • Keep off-site backups and test that they actually restore.
  • Monitor file changes and new admin users, so you hear about problems in hours, not weeks.

Our WordPress security hardening checklist goes through each item, and our article on what WordPress maintenance includes shows how this fits into ongoing care.

Get help with a hacked WordPress site

If you would rather not do this alone, our WordPress malware removal service covers the full process: evidence copy, cleanup, root-cause analysis, hardening and the Google review request. We give a fixed quote after a quick assessment. Contact us with what you are seeing, and we will tell you what we would do first.

Frequently asked questions

What is the first thing to do when my WordPress site is hacked?
Write down what you see and when, then take a full copy of the files and database before you change anything. After that, change every password and contact your host. Do not start deleting files until you have a copy.
Should I just restore a backup of my hacked WordPress site?
A clean backup can help, but only if you know it was made before the attack and you also close the hole the attacker used. If you restore without fixing the cause, the site is often reinfected within days.
Will Google penalize my site because it was hacked?
Google may show a warning or drop hacked pages from results while the problem lasts. Once the site is clean and you request a review in Google Search Console, warnings are usually removed after the review succeeds.
How did my WordPress site get hacked?
The most common causes are outdated or abandoned plugins and themes, reused or stolen passwords, and infected computers used to log in. Finding the exact cause is part of a proper cleanup, so the same attack does not work twice.

Is your WordPress site hacked, slow or at legal risk?

Tell us what you're dealing with. We'll reply within one business day.