WordPress Site Hacked: How to Contain, Clean and Recover

A hacked WordPress site is a horrible thing to find on a Monday morning, and it happens to small firms far more often than people assume. Most attacks aren't personal: they're automated scans hunting for an out-of-date plugin on any site, be it a law firm in Edinburgh or a joiner in Livingston. Here's the order to work through, and the mistake that gets sites reinfected within days.

The signs your site has been compromised

Sometimes it's blatant, like a defaced homepage. The attacks that pay best are the quiet ones: the longer they go unnoticed, the more they earn. Watch for:

  • Spam redirects. Visitors land on a pharmacy or betting site, often only from Google, only on mobile, or only on a first visit.
  • Unknown administrator accounts. A new admin user you didn't create, or an account whose role has quietly been raised.
  • Defaced search results. Your Google listings show pharmaceutical or foreign-language keywords even though the pages look normal.
  • Browser and host warnings. A red "deceptive site" interstitial, or your host suspending the account for spam or malware.
  • Odd behaviour. Unexplained load spikes, mail bouncing, or files with scrambled names in your uploads folder.

The first hour: contain it

Your priority is stopping harm to visitors, not diagnosing the cause. Take the site offline or into maintenance mode, or ask your host to; a site that's briefly down beats one serving malware to customers. Resist the urge to start deleting files: you'll destroy evidence you need later and rarely get it all anyway.

Change passwords from a device you're confident is clean: if malware on your laptop captured the original login, the new ones leak straight back out. The same applies to recovering a hacked email account, and the two often go together: whoever has your email can reset your website.

Tell your host, and keep the logs

Contact your hosting provider early, whether that's us or someone else. They can see server-level access logs you can't, may already have flagged the account, and can often tell you when the unusual activity started. Ask them to preserve those logs rather than rotate them away, and take your own copy of the files and database as they stand, labelled and kept away from anything you plan to restore. If the site held customer data, the compromise may also count as a personal data breach, which is worth proper advice, not guesswork.

Restore from a known-good backup, don't trust a clean-up

This is the part people get wrong. Removing the malicious code you can find leaves behind the code you can't. Attackers routinely plant several backdoors: a stray file in the uploads folder, lines appended to a theme function, a scheduled task, a hidden admin user, precisely so a tidy-up doesn't lock them out.

The more reliable route is to rebuild from a backup taken before the compromise, then reapply legitimate content added since. That means knowing roughly when it started, which is why the logs matter, and backups that go back far enough and sit somewhere the site itself can't reach. The 3-2-1 thinking behind a proper business backup strategy applies to websites too.

Rotate every credential, not just the admin password

Assume everything the site could reach has been seen: WordPress admin accounts, the database user, control panel and SFTP logins, any API or payment keys, and the email account tied to the site. Delete accounts you don't recognise rather than changing their passwords, and turn on two-factor authentication wherever it's offered, as our post on strong passwords and MFA sets out.

Find the entry point, or it just happens again

A cleaned site with the hole still open gets reinfected, often within days, and people assume the clean-up failed rather than that the door was never shut. The usual ways in are an unpatched plugin or theme, an abandoned plugin nobody maintains, a weak or reused administrator password, an outdated PHP version, or credentials stolen from a compromised computer. Work out which it was before you go live again; if you can't tell, close them all.

Staying clean afterwards

The habits that keep you clean are unglamorous: apply updates promptly, delete unused plugins and themes rather than deactivating them, keep administrator accounts to the few who need them, and check that backups actually restore.

We design, host and look after business websites

We're based in Wishaw and work with firms across Edinburgh and the Lothians. We design and host business websites, we run email hosting, and we take on WordPress sites someone else built: updates applied, backups kept out of the site's reach, admin accounts pared back. Where a compromise has spread to your computers or accounts, our cyber security and business IT support work covers that too. Tell us what's happened and you'll get a clear quote before any work.

Get a free quote

Broken device or a business IT headache?

From cracked screens to fully managed networks, our specialists can help. Tell us what you need and we'll get back to you fast.

WhatsApp Book Quote