Possible signs your WordPress website is hacked - common malware traits
Common WordPress malware traits: stealth redirects, SEO spam, backdoors, Search Console warnings, and what to do next without panicking.
Topics Malware & cleanup
Security advisorywp2shell: WordPress core vulnerability. Updated August 4, 2026.
Read the advisoryCommon WordPress malware traits: stealth redirects, SEO spam, backdoors, Search Console warnings, and what to do next without panicking.
Topics Malware & cleanup
Most WordPress infections are not a villain picking your brand out of a hat. Bots scan for known plugin holes, weak logins, and abandoned software. Once they get in, the malware often tries to stay quiet.
Obvious
Stealthy
If you only check the site while logged in, you can miss visitor-only redirects. Use a private window.
They usually want one of these:
Small sites are useful because they are plentiful and often poorly maintained. See why hackers still hit small sites.
Infected sites often get:

Google’s hacked site guidance and Search Console are useful after cleanup. You still need to clean the install first. A review request before the malware is gone wastes time.
wp-config.php, .htaccess, mu-plugins, and uploadsSecurity Ninja’s malware scanner helps find suspicious files. For locked-out or recurring infections, hire cleanup.
Related: 7 signs of a hack, recovery steps, and backup plan.
Found this useful? Share it.