How to Tell if Your WordPress Site Has Been Hacked: 7 Signs
Seven practical signs your WordPress site may be hacked: traffic drops, lockouts, odd admins, redirects, spam, Search Console warnings, and more. What to do next.
Topics Malware & cleanup
Security advisorywp2shell: WordPress core vulnerability. Confirm every site is on 6.8.6, 6.9.5, 7.0.2, or newer.
Read the advisorySeven practical signs your WordPress site may be hacked: traffic drops, lockouts, odd admins, redirects, spam, Search Console warnings, and more. What to do next.
Topics Malware & cleanup
Not every weird glitch means you were hacked. A broken plugin update can look scary too. When several of the signs below show up together, treat it as a compromise and act.
Full response path: what to do if your site is hacked.

A sharp analytics drop can mean redirects, Safe Browsing warnings, or SEO spam changing titles and content Google sees. Check Search Console security issues and open your site in a private window while logged out.
Password resets fail, the login loops, or your admin user is gone. Attackers often change credentials, add their own admin, or lock you out on purpose.
If wp-admin is dead, use hosting panel or SFTP.

Unexpected administrator accounts are a classic post-compromise leftover. So are odd “customer” or “subscriber” floods if open registration is on.
Review Users regularly. Remove what you did not create. Prefer least privilege for real teammates.
Malware, spam bots, crypto miners, and brute-force noise can hammer the server. Slow alone is not proof of a hack, but combined with other signs it is worth a malware scan and host check. Also rule out a heavy security scan or stacked plugins: do security plugins slow WordPress down?.

Some infections hide when you are logged in as admin and only hit regular visitors. Log out, try incognito, and ask someone else to open the homepage on mobile. Redirect malware often keys off referrer, device, or country so your own checks look clean.

Infected sites often start blasting spam email, injecting spam links, or serving cloaked content to Googlebot. Check comments, mail logs, and random posts for injected HTML. Search site:yourdomain.com for pages you never published.
Chrome/Google warnings and Search Console security emails are late signals, but they are clear. Clean the site, then request a review so rankings can recover. Phishing kits on your domain can trigger the same alarms even when the homepage looks fine to you.
Logged-in admins often see a clean site while customers get redirects or spam. Always check as a logged-out visitor, on mobile, and via Search Console. Also check for backdoors and scheduled reinjection if symptoms return after a “cleanup”: malware that kept coming back.
Step-by-step: WordPress site hacked recovery. Deeper cleanup: WordPress malware removal.
Can my site be hacked if the homepage looks fine?
Yes. Cloaked redirects, SEO spam, and backdoors often hide from logged-in admins.
Is a slow site always malware?
No. Hosting limits, bad caching, and heavy plugins can slow a site. Combine slowness with other signs before assuming compromise.
What is the fastest first check?
Open the site logged out in a private window, check Users for unknown admins, and look at Search Console for security issues.
Do I need a security plugin to detect this?
A plugin helps with scans and logs, but you can start with the checks above. After recovery, a clear stack helps you notice the next incident earlier: do I need a security plugin?.
Security Ninja helps with malware scanning, vulnerability checks, events, and login hardening after you are back online. If you are locked out or the infection keeps returning, hire cleanup.
More detail: common malware traits and SEO impact and backup/recovery plan.
Found this useful? Share it.