Security advisorywp2shell: WordPress core vulnerability. Confirm every site is on 6.8.6, 6.9.5, 7.0.2, or newer.

Read the advisory

How to Tell if Your WordPress Site Has Been Hacked: 7 Signs

Seven practical signs your WordPress site may be hacked: traffic drops, lockouts, odd admins, redirects, spam, Search Console warnings, and more. What to do next.

Topics Malware & cleanup

Lars Koudal

Updated Published

Not every weird glitch means you were hacked. A broken plugin update can look scary too. When several of the signs below show up together, treat it as a compromise and act.

Full response path: what to do if your site is hacked.

1. Sudden traffic drop or weird search listings

Google Analytics

A sharp analytics drop can mean redirects, Safe Browsing warnings, or SEO spam changing titles and content Google sees. Check Search Console security issues and open your site in a private window while logged out.

2. You cannot log in to wp-admin

Password resets fail, the login loops, or your admin user is gone. Attackers often change credentials, add their own admin, or lock you out on purpose.

If wp-admin is dead, use hosting panel or SFTP.

WP Login

3. Strange users, especially new admins

Unexpected administrator accounts are a classic post-compromise leftover. So are odd “customer” or “subscriber” floods if open registration is on.

Review Users regularly. Remove what you did not create. Prefer least privilege for real teammates.

4. Site is suddenly slow or unstable

Malware, spam bots, crypto miners, and brute-force noise can hammer the server. Slow alone is not proof of a hack, but combined with other signs it is worth a malware scan and host check. Also rule out a heavy security scan or stacked plugins: do security plugins slow WordPress down?.

5. Pop-ups, ads, or redirects you did not add

Website Speed

Some infections hide when you are logged in as admin and only hit regular visitors. Log out, try incognito, and ask someone else to open the homepage on mobile. Redirect malware often keys off referrer, device, or country so your own checks look clean.

6. Spam comments, outbound spam, or pharma SEO junk

Spam Comments in WordPress

Infected sites often start blasting spam email, injecting spam links, or serving cloaked content to Googlebot. Check comments, mail logs, and random posts for injected HTML. Search site:yourdomain.com for pages you never published.

7. Browser or Search Console malware warnings

Chrome/Google warnings and Search Console security emails are late signals, but they are clear. Clean the site, then request a review so rankings can recover. Phishing kits on your domain can trigger the same alarms even when the homepage looks fine to you.

What people miss

Logged-in admins often see a clean site while customers get redirects or spam. Always check as a logged-out visitor, on mobile, and via Search Console. Also check for backdoors and scheduled reinjection if symptoms return after a “cleanup”: malware that kept coming back.

What to do when you see these signs

  1. Take it seriously: maintenance mode if visitors are at risk
  2. Preserve access via hosting/SFTP if wp-admin is gone
  3. Restore from a clean backup if you have one, or clean carefully
  4. Rotate passwords, enable 2FA, update everything, delete unused plugins
  5. Scan again before calling it done
  6. Close the entry point (vulnerable plugin, weak login, nulled software)

Step-by-step: WordPress site hacked recovery. Deeper cleanup: WordPress malware removal.

Short FAQ

Can my site be hacked if the homepage looks fine?
Yes. Cloaked redirects, SEO spam, and backdoors often hide from logged-in admins.

Is a slow site always malware?
No. Hosting limits, bad caching, and heavy plugins can slow a site. Combine slowness with other signs before assuming compromise.

What is the fastest first check?
Open the site logged out in a private window, check Users for unknown admins, and look at Search Console for security issues.

Do I need a security plugin to detect this?
A plugin helps with scans and logs, but you can start with the checks above. After recovery, a clear stack helps you notice the next incident earlier: do I need a security plugin?.

Security Ninja helps with malware scanning, vulnerability checks, events, and login hardening after you are back online. If you are locked out or the infection keeps returning, hire cleanup.

More detail: common malware traits and SEO impact and backup/recovery plan.

Found this useful? Share it.