Check if Your WordPress Site Is Hacked
A practical way to check if a WordPress site is hacked: run free security and vulnerability scans, review common compromise signals, then clean or harden.
Topics Malware & cleanup
Security advisorywp2shell still active nearly a month later. Confirm 6.8.6, 6.9.5, 7.0.2, or newer.
Read the advisoryA practical way to check if a WordPress site is hacked: run free security and vulnerability scans, review common compromise signals, then clean or harden.
Topics Malware & cleanup
To check if a WordPress site is hacked, run real scans from inside the install, then look for compromise signals you can verify. Start with free vulnerability checks, security tests, and core integrity. Add a malware scan when files look wrong or the site already shows redirects, spam, or lockouts.
This page is the short tool path. For the longer signs walkthrough, use how to tell if your WordPress site is hacked.
You do not need a fake “paste your URL” checker on a marketing page. You need tools that see installed versions and files from wp-admin.
Install WP Security Ninja (free on WordPress.org, or start from pricing if you already know you want Pro). Then run these in order:
Vulnerability scanner
Compares plugins, themes, and core against known vulnerabilities. Outdated software with a public advisory is how many hacks start.
Security tests
Flags configuration gaps (file permissions, exposed bits, weak defaults). Failed tests are not always “you are hacked,” but they show what attackers look for next.
Core Scanner
Checks WordPress core files against known-good copies. Modified, missing, or unexpected core files deserve a close look.
Events
Review recent security-related activity in the free Events view so you notice odd logins or changes after the scans.
Free covers security tests, vulnerability scanning, core integrity, and events. Pro adds the malware scanner when you need on-disk suspicious-file review and schedules.
Run the free scans even if the homepage “looks fine” while you are logged in. Cloaked redirects and SEO spam often hide from admins. Scanner output plus a logged-out check beats guessing from the homepage alone.
Scans answer “does software or core look wrong?” Pair them with a fast human check:
site:yourdomain.com for pages or titles you never publishedSeveral signals together matter more than one odd glitch. Full detail, false positives, and the seven common signs live on signs your WordPress site is hacked.
Do not keep clicking random plugins while visitors hit malware. Work a recovery path:
Close the entry point before you celebrate. Updating a vulnerable plugin after a restore matters as much as deleting odd PHP. Leaving the same hole open is why malware “keeps coming back.”
Guides:
A restore without hardening is a rewind button for the attacker. Clean first, then lock doors.
Bottom line: check with scans you control inside WordPress, confirm with the signs checklist, then clean and harden. Start free with Security Ninja, then add Pro malware scanning when file-level review is the job at hand.
Found this useful? Share it.
Install a security plugin with admin access, run vulnerability and security-test scans, check WordPress core file integrity, then review Users for unknown admins and open the site logged out in a private window. Pair scanner output with the common signs checklist. One green badge alone is not proof the site is clean.
A free scan is a strong first pass for known vulnerabilities, configuration gaps, and core file changes. It will not replace a full malware file scan when you already see redirects, spam, or lockouts. Free Security Ninja covers tests, vulnerability checks, core integrity, and events. Pro adds the malware scanner when you need deeper file review.
Treat findings by type. Update or remove vulnerable plugins and themes first. Investigate core integrity mismatches and unknown admins. If malware or a backdoor is likely, follow the cleanup path or hire help, then harden so the same entry point does not reopen.