Web design · Security
Work in this order: contain it, find how they got in, clean everything, close the hole, then ask Google to review the site.
Contain first, clean second
Find the entry point
Stop the reinfection loop
Tell us what you need and we’ll get back to you. Or book a free 30-minute call. Or call 954-539-5678.
If your WordPress site has been hacked, fix it in this order. First, take a full backup of the infected site so you have evidence and a fallback. Second, change every password: WordPress admins, hosting, FTP or SFTP, the database and your email. Third, find how the attacker got in, which is usually an outdated plugin or theme, or a stolen admin password. Fourth, clean or replace the files and database, and remove any admin accounts you did not create. Fifth, update everything and close the hole. Finally, if Google has flagged the site, request a review in Search Console.
The order matters. Most sites that get reinfected a week later were cleaned without anyone finding the original entry point. The rest of this guide walks through each step, the signs that tell you how bad it is, and when to hand it to someone else.
Some hacks are loud and some are quiet. The quiet ones do more damage because they run for months.
Before you change anything, protect what you have and stop the harm spreading.
The WordPress.org guidance on hacked sites lists forensics, working out how the attackers got in, as a core step, so they cannot use the same route again. Patchstack’s State of WordPress Security in 2026 report found 91% of new WordPress vulnerabilities disclosed in 2025 were in plugins and 9% in themes, with only six in WordPress core. So start there.
Cleaning means replacing what you can and inspecting what you cannot replace.
Restoring a backup can be faster, but only if you know the backup was taken before the infection and you close the entry point straight after. Otherwise you restore the same hole.
Dealing with a hacked site right now and would rather not do this alone? Book a free 30-minute call. We look at what happened and tell you what we’d fix first. No obligation.
Once it is clean, make the same attack fail next time. The official WordPress hardening guide covers the full list. The essentials:
If Google flagged the site, check the Security Issues report in Search Console. It lists the problem type and sample URLs. Once you have fixed every listed issue, request a review from that report. Google’s Security Issues report help says to request a review only once every listed issue is fixed on all pages, because requesting too early can slow down your next review and can get the site marked as a repeat offender. For spam pages that were injected, return a 404 or 410 for those URLs so they drop out of the index.
Also check whether your domain landed on email blocklists, and tell customers if you have reason to think their data or payment details were exposed. If you take payments or store personal data, speak to your insurer and counsel about notification duties. That part is general information, not legal advice.
A small, clearly understood infection on a simple brochure site is often a DIY job for someone comfortable with SFTP and a database tool. Bring in help when:
When you hire help, ask them to report what the entry point was and what they changed. A cleanup without that report leaves you guessing.
Our website hosting and support includes constant automated monitoring and malware cleanup, plus the updates that close most of the holes attackers use. If your site needs rebuilding rather than patching, we build custom WordPress websites that you can edit yourself and keep if you ever leave. For ongoing care costs, see our guide to website maintenance costs.
Book it now · Free
Pick a time. We look at what you have now with you and tell you what we would change first. No obligation.
Prefer to talk now? Call 954-539-5678, or send the form and we’ll contact you.
Often, yes, if the site is simple and you are comfortable with SFTP and a database tool. The hard part is finding how the attacker got in. If you cannot find the entry point, or the site takes payments or personal data, get help.
Only if the backup predates the infection and you close the entry point immediately afterwards. Otherwise the same vulnerable plugin or stolen password lets the attacker straight back in.
After you fix the issues and request a review in Search Console, Google reviews the site. Google says most reviews take several days to a few weeks, depending on the issue. Make sure every listed URL is clean before you request the review.
Most often through outdated or vulnerable plugins and themes, followed by weak or reused admin passwords. Patchstack’s 2026 report found 91% of new WordPress vulnerabilities in 2025 were in plugins.
If there is any chance customer data, logins or payment details were exposed, talk to your insurer and counsel about notification duties. This is general information, not legal advice.