Security advisorywp2shell: WordPress core vulnerability. Updated August 4, 2026.

Read the advisory

Possible signs your WordPress website is hacked - common malware traits

Common WordPress malware traits: stealth redirects, SEO spam, backdoors, Search Console warnings, and what to do next without panicking.

Topics Malware & cleanup

Lars Koudal

Updated Published

Most WordPress infections are not a villain picking your brand out of a hat. Bots scan for known plugin holes, weak logins, and abandoned software. Once they get in, the malware often tries to stay quiet.

Obvious vs stealthy attacks

Obvious

  • Homepage defacement
  • Full-site redirects to scam pages
  • Login completely broken

Stealthy

  • Redirects only for logged-out visitors (admins see a clean site)
  • Cloaked spam links shown mainly to Googlebot
  • Backdoors waiting for later use
  • Drive-by scripts aimed at visitors
  • Pharma / gambling SEO injections in posts, widgets, or theme files

If you only check the site while logged in, you can miss visitor-only redirects. Use a private window.

Why attackers want your site

They usually want one of these:

  • Spam or phishing pages on your domain
  • SEO link spam
  • A backdoor for later
  • Mail relay / spam sending
  • Crypto mining or malware delivery to visitors

Small sites are useful because they are plentiful and often poorly maintained. See why hackers still hit small sites.

SEO and trust damage

Infected sites often get:

  • Safe Browsing / browser warnings
  • Search Console security notices
  • Ranking drops after Google stops trusting the pages

"The site ahead contains malware" warning message

Google’s hacked site guidance and Search Console are useful after cleanup. You still need to clean the install first. A review request before the malware is gone wastes time.

How to confirm and clean

  1. Note when symptoms started (logs, file dates, first odd admin)
  2. Prefer restore from a clean backup from before that point
  3. If no clean backup: remove unknown admins/plugins, scan files, check wp-config.php, .htaccess, mu-plugins, and uploads
  4. Update core/plugins/themes, delete unused software
  5. Rotate all passwords and enable 2FA
  6. Scan again, then request Google review if needed

Security Ninja’s malware scanner helps find suspicious files. For locked-out or recurring infections, hire cleanup.

Prevention that actually matters

  • Keep plugins/themes updated; delete unused ones
  • Strong unique passwords + 2FA for admins
  • Firewall and login protection
  • Scheduled malware / vulnerability scans
  • Off-site backups you have restore-tested

Related: 7 signs of a hack, recovery steps, and backup plan.

Found this useful? Share it.