WordPress Site Hacked? What to Do: A Recovery Checklist That Saves Your Rankings
Your WordPress website has been compromised. Perhaps your visitors are encountering a red alert page, your hosting provider has suspended your account, or you may see Google listing spammy pages under your domain that you haven’t created. Regardless of how you discovered the issue, the actions you take in the next few hours will greatly influence the traffic and rankings you lose.
The silver lining: it’s possible to recover a hacked site, and typically, your rankings can be restored as well. The key, however, is to follow the correct sequence of actions. If you clean up first and don’t contain the damage, the malware could install itself again while you’re working. Change your passwords before eliminating the backdoor, and the attacker might log back in immediately.
This checklist outlines the recovery steps in the appropriate order: verify the hack, limit the damage, clean the files and database, change all credentials, remove Google’s blacklist warning, and finally manage the SEO implications—a crucial aspect often omitted in most recovery articles.
Follow each step in order, even those that seem unnecessary.


Step 1: Verify that it’s actually a hack
Not every alarming symptom signifies malware. Before taking any action, verify the situation. Common indicators of a compromise include:
- A red “Deceptive site ahead” or “This site may be hacked” warning appearing in browsers or search results
- Your host has suspended your account or notified you about malware
- Unknown admin users or posts and pages that you did not publish
- Visitors being redirected to spam websites
- Sudden traffic spikes to unfamiliar URLs
You can conduct three quick checks to assess your situation. First, run your domain through Google’s Safe Browsing site status tool to determine if Google has flagged it. Next, access Google Search Console and examine the Security Issues report (under Security & Manual Actions) to see what Google has detected. Finally, perform a thorough scan using a security plugin such as Wordfence, Sucuri, or MalCare.
It’s worth noting that a red browser warning could also stem from a misconfigured SSL setup rather than malware. If scans yield clean results and the only symptom is the browser warning, ensure your SSL certificate is properly configured and check for mixed content before leaping to conclusions.
Step 2: Limit the damage
A compromised website can affect its visitors, distribute spam emails, or be used to attack other sites, which could result in both your server’s IP address and your domain being blacklisted. Containing the issue reduces the potential fallout as you work:
- Take the site offline or engage maintenance mode. Most security and maintenance plugins have this feature; many hosting providers can assist you as well.
- Reach out to your hosting provider. If you’re on shared hosting, the infection might have originated from a neighbouring account. Reputable hosts can confirm the hack, isolate the site, or direct you to check the server logs.
- Scan your personal computer. Attackers often gain access through compromised credentials from an infected local device, so it’s essential to perform a complete antivirus scan on every device you use for site management.
PRO TIP: Keep a record of what you noticed and when, along with any changes made recently (new plugin, theme modification, or new user added). The official WordPress.org hacked-site guide refers to these as indicators of compromise, and maintaining this information can save you hours later on, especially if you end up needing to bring in outside assistance.
Step 3: Back up the infected site (yes, truly)
This is the step that most people want to bypass, but skipping it can lead to significant troubles down the line. Before you start deleting or replacing anything, take a full snapshot of the site’s files and database, even if they are infected.
There are two crucial reasons for this. If the cleanup process goes awry and breaks the site, you will still have a backup to revert to. Additionally, the snapshot serves as evidence: comparing infected files with clean originals later is often the only way to determine how the attackers gained access. Understanding their method is essential if you wish to move forward effectively.
WARNING: Clearly label this backup as infected (perhaps as
pre-cleanup-INFECTED) and store it separately from your routine backups. This is evidence and should only be used as a last resort, not as a rollback point, as restoring it will return the malware as well.
Step 4: Clean the files and the database
Now it’s time for the actual cleanup. You have two feasible paths, and realistically, most website owners should opt for the first:
Path A: use a tool or hire your host. Security plugins such as Wordfence, Sucuri, and MalCare can scan for known malware signatures and remove them, though the actual cleanup tools may be locked behind a paid tier for some. Many managed WordPress hosting providers offer complimentary cleanup services as part of your plan, so it’s advisable to ask for assistance before paying anyone.
Path B: perform a manual cleanup. If you choose the DIY approach, the essential tasks include: replacing the wp-admin and wp-includes folders with fresh copies of your specific WordPress version, reviewing the wp-content directory for files that do not belong, and scrutinising files that attackers commonly target: .htaccess, index.php, header.php, footer.php, and functions.php. Additionally, remove any unknown plugins and themes, check Users → All Users for accounts you did not create, and search the database for any injected spam posts and links. Manual cleanup can be effective, but it can be slow and error-prone, which is why many choose Path A.
Are visitors being redirected to spam sites? That indicates a specific infection with a distinct resolution process. Consult the dedicated guide for fixing the WordPress redirect hack rather than attempting to handle it without guidance.
When restoring a backup outweighs cleaning
If you possess a backup predating the infection and there haven’t been significant changes since then (like new orders, posts, or user accounts), restoring it is often quicker and more reliable than painstakingly extracting malware from files. There are two caveats, however. Ensure the backup genuinely predates the infection, as attackers can linger on a site for weeks before making their move. Additionally, you must still identify how they breached your site, as restoring can also reinstate the vulnerability that allowed them access initially.
For optimal results, restore the backup to a WordPress staging environment first, test everything there, and then push it live once you’re confident.
Step 5: Change every credential
After the site has been cleaned, assume all passwords that have ever touched it may be compromised. Update them all in the following order, as each is crucial:
- WordPress passwords for all users, starting with admins
- Your hosting control panel login details
- FTP and SFTP account passwords
- The database password (remember to adjust
wp-config.phpaccordingly) - Any API keys for connected services (payment gateways, email services, CDNs)
Following that, regenerate the security keys in wp-config.php. This single modification will invalidate every active login session, including those belonging to any infiltrator still logged in. WordPress.org offers a key generator specifically for this purpose, and their hacked-site guide endorses its use.
A couple of crucial details often overlooked: If you previously changed passwords upon discovering the hack, change them again. Passwords altered while malware still resided on the server might already be compromised. Additionally, enable two-factor authentication for every admin account, as a leaked password alone should never suffice for access again.
Step 6: Request Google’s review to lift the warning
Cleaning the site does not automatically remove the blacklist warning. Google keeps the red alert posted until it re-crawls your pages and confirms that the malware has been eliminated, and waiting for that to occur organically can take some time.
To expedite the process: in Search Console, navigate to Security & Manual Actions → Security Issues, then click Request Review. Detail what you found and the steps you took to rectify it, being specific about what was infected, what you removed, and what changes were made to prevent a recurrence. Google typically responds within a few days, but the warning will remain until the review is passed.
Only submit the review request once you are certain the site is completely clean. If Google re-crawls and still detects malware, the subsequent rejection will cost you more time than simply waiting for the initial review would have. For a comprehensive guide related to the warning itself, and specifics regarding false SSL alarms, refer to the article on removing the “Deceptive site ahead” warning. Google also provides security documentation for site owners that outlines how these issues are classified.
Step 7: Execute the SEO damage control that most guides overlook
This is the crucial element that will determine whether your rankings truly recover. Hackers often don’t just deface a site; a common tactic involves injecting numerous spam URLs (pharmaceutical pages, counterfeit product listings, foreign-language keyword pages) that Google subsequently indexes under your domain. Even after the malware is removed, those URLs continue to tarnish your site’s reputation until you address them.
Follow this concise checklist:
- Identify the injected URLs. Conduct a
site:yourdomain.comsearch on Google and scroll well past the first page, and review the Pages report in Search Console for any unfamiliar URLs. - Remove them properly. Eliminate the spam content so these URLs return a 404 or 410 status. Should legitimate pages contain spam links or keywords, ensure you clean the content accordingly.
- Get genuine pages re-crawled. Use the URL Inspection tool found in Search Console to request indexing for your homepage and key pages (this is the modern evolution of the old “Fetch as Google”). There is a daily quota per property, so for larger sites, update the last modified dates in your sitemap and resubmit it instead.
- Monitor the situation for weeks, not days. Keep an eye on the Security Issues report and repeat the
site:search weekly for a month or two. Rankings typically rebuild gradually after Google confirms the site is clean, rather than returning suddenly.
When to seek professional help
While many sites can be recovered DIY-style, there are clear indicators when it is time to hire a professional: if the infection keeps recurring post-cleanup, if you cannot identify the entry point, if the site handles sensitive customer data or payments, or if you are uncomfortable navigating the database. Hiring a professional cleanup service (or leveraging your host’s security team) entails a cost, but a poorly executed DIY cleanup on a website containing customer data can prove even more expensive. There’s no shame in making that call.
Conclusion
A hacked site can feel like a catastrophe, but the recovery process is straightforward if you adhere to the correct order:
- Confirm the hack before taking any action
- Limit the damage by going into maintenance mode, contacting your host, and performing local scans
- Make a backup of the infected site to serve as evidence and insurance
- Clean the files and database, or restore a verified clean backup
- Change every credential and regenerate security keys
- Request Google’s review to lift the warning
- Identify and remove injected spam URLs, monitoring the situation until rankings return
Once you’re back up and running, take steps to maintain that status: update everything promptly, use strong, unique passwords along with two-factor authentication, keep regular backups (and periodically test restoring them), and utilise a security plugin equipped with a firewall. Boring habits can yield excellent results.
Have you encountered a hacked WordPress site in the past? What strategies did you utilise, and what advice would you offer to others? Share your insights in the comments section below.
FREE GUIDE
4 Fundamental Steps to Accelerate Your WordPress Website
Implement these straightforward steps in our 4-part mini series to cut your loading times dramatically by 50-80%.
Well done! You’ve reached the end of the article!
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.

