WordPress Site Hacked? Steps to Recover and Secure It Fast
If your WordPress site is hacked: confirm the compromise, contain damage, restore or clean, rotate access, close the entry point, and harden so it does not return.
If your WordPress site is hacked: confirm the compromise, contain damage, restore or clean, rotate access, close the entry point, and harden so it does not return.
If your WordPress site is hacked, act fast and in order. Stop visitor harm, regain clean access, remove or restore away the malware, close how they got in, then harden so the same door does not reopen.
Related: 7 signs of a hack, malware removal guide, hire cleanup.
Common signs (several together matter more than one alone):
Not every glitch is a hack. A failed plugin update can look scary too. If several signs show up together, treat it as a compromise.
If wp-admin is dead, use hosting panel, SFTP/SSH, or the host’s emergency recovery. You need file and database access to restore or remove malware.
If you restore a backup that already contained the malware, you relaunch the problem.
.htaccess, wp-config.php, and must-use pluginsThis is slower and easier to get wrong. If the site matters, hire cleanup help.
A restore without a fix is a rewind button for the attacker. Common causes:
Find it. Remove or patch it. Then harden login and scanning so you notice the next attempt earlier.
Treat credentials, FTP/SFTP, hosting panel, and database passwords as compromised (assume breach). Rotate them after cleanup, not only at the first panic moment.
Cleaning visible redirects without removing persistence is how the same infection returns within hours. If malware comes back on a schedule, audit hosting cron and WP-Cron: malware that kept coming back.
Should I restore from backup or clean files by hand?
Restore from a known-clean backup when you can. Manual cleanup is for when no clean restore exists, or when you need forensics first.
Do I need to take the site offline?
If visitors see redirects, phishing, or malware warnings, yes, at least maintenance mode. A short outage beats actively harming customers.
When should I hire help?
Stores with payment data, reinfection after DIY cleanup, locked hosting accounts, or infections you cannot locate. Start at consultation.
Is updating plugins enough after a hack?
No. Updates matter, but you still need clean files or a clean restore, rotated credentials, and the entry point closed.
What tool helps after I am back online?
Security Ninja covers firewall, malware scanning, vulnerability checks, security tests, events, and 2FA. Start with Free tests if you are rebuilding the baseline.
Going forward, assume another scan hits tomorrow. Keep updates current, keep the plugin list short, and keep backups you have actually restored. More: backup plan, security checklist, do I need a security plugin?.
Found this useful? Share it.