Many hacked WordPress sites look completely normal to the owner. Attackers often hide their changes from logged-in admins and only show spam or redirects to visitors or to Google. By the time someone notices, the damage to traffic and reputation is already done.

Here are the warning signs to watch for, and what to do if you spot them.

1. Visitors Are Redirected to Spam Sites

A very common infection redirects visitors to gambling, pharmacy, scam or adult sites. These redirects are often conditional. They might only trigger on mobile, only for visitors coming from Google, or only on the first visit. If a customer tells you your site “went somewhere weird,” take it seriously even if you can’t reproduce it.

2. Strange Pages Show Up in Google

Search Google for site:yourdomain.com and scroll through the results. Watch for:

  • Pages in Japanese or other languages you don’t use
  • Pharmaceutical, casino or counterfeit product pages
  • Titles and descriptions that don’t match your content

This is often called a spam injection or Japanese keyword hack. Thousands of spam pages can be created under your domain without appearing in your WordPress dashboard.

3. Google Search Console Shows Security Issues

Check the Security Issues report in Search Console. Google may flag hacked content, malware or deceptive pages. You might also see a sudden spike in indexed pages you didn’t create.

4. Browser or Google Warnings Appear

Chrome may show a red warning screen, or Google may add “This site may be hacked” under your listing. These warnings cut traffic sharply because most people won’t click past them.

5. Admin Users You Didn’t Create

Go to Users in WordPress and check every administrator account. Attackers often add their own admin users. Some infections even include code that recreates the rogue admin account after you delete it, which means the real problem is elsewhere in the files or database.

6. Your Host Suspends the Account or Flags Files

Hosting companies scan for malware. If they suspend your account or send you a list of infected files, act quickly. On shared hosting, one infected site can spread to every other site on the same account.

7. The Site Is Suddenly Slow or Behaving Strangely

Unexpected slowdowns, high server resource usage, unfamiliar files in your WordPress folders, or changes to files you didn’t edit can all point to malicious code running on the server.

What to Do First

If you suspect your site is hacked, work through these steps in order:

  1. Don’t panic-delete things. Deleting random files can break the site and destroy evidence of how the attacker got in.
  2. Take a full backup of the current files and database, even though it’s infected. You may need it for investigation or recovery.
  3. Change all passwords: WordPress admins, hosting account, FTP or SFTP, database and email.
  4. Check other sites on the same hosting account. Cross-contamination is common.
  5. Scan the site with a security plugin such as Wordfence, but don’t assume a clean scan means a clean site. Scanners often miss obfuscated code and database injections.
  6. Find the entry point. Outdated plugins, nulled themes, weak passwords and abandoned plugins are the usual causes. If you only remove the malware and don’t close the entry point, it will come back.
  7. Request a review in Search Console once the site is clean, to remove Google’s warnings.

Why Infections Keep Coming Back

The most frustrating hacks are the ones that return after cleanup. That usually means a persistence mechanism was left behind, such as a hidden backdoor file, a malicious cron job, modified core files or database code that rebuilds itself.

In one cleanup I handled, eight WordPress sites on a single hosting plan had been serving malware for thirteen days, with two separate payloads and an admin account that kept recreating itself. You can read the full case study here.

How to Prevent It

  • Keep WordPress core, plugins and themes updated
  • Remove plugins and themes you don’t use
  • Never use nulled or pirated premium plugins
  • Use strong, unique passwords and two-factor authentication
  • Keep regular off-site backups
  • Use a firewall and monitor for changes

If your site has been hacked, my WordPress malware removal service covers full cleanup, backdoor removal, SEO damage repair and hardening. For ongoing protection, see my website care plans.

Frequently Asked Questions

Can a hacked site hurt my Google rankings?

Yes. Spam pages, malicious redirects and security warnings can all reduce rankings and traffic. Cleaning the site and requesting a review in Search Console is the fastest route to recovery.

Is a security plugin enough to clean a hacked site?

Sometimes, for simple infections. More advanced infections hide from scanners, so manual inspection of files and the database is often needed.

How did my site get hacked?

The most common causes are outdated or vulnerable plugins, weak passwords, nulled themes and plugins, and infections spreading from other sites on the same hosting account.