WordPress website got hacked? Get it fixed fast!

Help! My WordPress Website Got Hacked!

A Step-by-Step Guide to Fix Your Hacked Site Fast

Realizing your website got hacked is NOT a fun experience. It feels like a complete violation and can cause a bit of panic – understandably so! But after that initial freak-out, it’s time to answer the question: My website got hacked! What should I do??!

Because WordPress powers over 40% of all websites (really!), it’s become a pretty big target for hackers, so breaches can be common. But if you’re able to take quick action to clean things up and lock down your website security, it doesn’t need to be a panic situation for very long.

How do you know if your website was hacked?

The first indications that you’ve got a hacked website might be a weird popup that shows up on your site, or a page gets redirected to a different website. Maybe it’s an admin user that was added and you have no idea how it got there. Sometimes the content on a page has changed or been defaced.

Maybe you got a notification from Google or see this page when you visit your website:

Google's warning when your website gets hacked

You also might get a notification from your webhost that they’ve disabled your site until things get cleaned up.

If you’re not entirely sure if your website has been compromised, you can use a few different tools to verify a hacked website:

  • Check Google’s Safe Browsing tool to see if your website has been marked as unsafe.
  • Wordfence is a WordPress security plugin that has a built-in site scanner to check for compromised files, malicious code, and anything else that might be suspicious.
  • Sucuri Site Check – if you suspect your website has been hacked, you can do a free scan for malware, viruses, blacklisting status, website errors, out-of-date software, and malicious code.

Step 1: Take your hacked website offline & lock down access

Once you’ve verified that yep, your website was hacked, here are the next steps:

  1. To protect your website visitors & avoid further damage, you’ll want to put your website into maintenance mode so that anyone visiting will see a temporary ‘coming soon’ page.
  2. Remove any admin users that don’t look familiar or that no longer need access, and change passwords to any existing admin users. Be sure to use a secure password that you don’t use anywhere else.
  3. Change all of your other website passwords – FTP users, database users, and your main website hosting account or cPanel login.
  4. If you can, update WordPress. Make sure all of your plugins and themes are up to date, and update WordPress core files. Delete any plugins or themes you don’t need anymore.

All of the above steps are good website hygiene and ongoing habits for your WordPress website to keep it from getting hacked in the future.


Step 2: Clean Your Hacked Website

Remove malware or malicious code & restore your site

I recommend doing a deep security scan to find exactly which files have been compromised. WordFence has a built-in site scanner that will search through all of your WordPress files and compare them to a clean WordPress installation. Anything that looks different, isn’t part of a normal WordPress website, or matches any known code from other hacks will be flagged.

This scan will help you figure out how extensive the hack is, and if you’ll be able to clean up your hacked website yourself or if you’ll need to hire security experts to take care of it for you.

Do-it-yourself Hacked Website Cleanup

Option 1: Restore from a site backup

If you find after a security scan that it’s just a file or two that need to be removed, that’s pretty simple to clean up. But sometimes the hack is extensive and in that case, restoring from a clean backup is the best option. 

You can determine when the website hack happened by looking at timestamps on the offending files. Then you’ll know how far back you’ll need to go in your backups and restore from a clean version before that date.

Option 2: Manual File Removal & Restoration

Sometimes restoring from a backup isn’t an option if the hack happened too far in the past and you don’t have a backup from before that point, or you’ve made other website changes you can’t risk losing with a backup restoration.

Using the WordFence scan helps you find the offending files and you can remove them manually. An automated scan isn’t foolproof – you’ll also want to examine the files on the server and make sure nothing has been missed. Reviewing timestamps on the files is the best way I’ve found to notice things that are out of place. You’ll want to pay special attention to files like wp-config.php, index.php, and plugin files.

Hiring Professional Site Cleaning after a Hack

If the clean up is more than you’re able to handle, hiring a cleanup service is a great option:

  • WordFence Site Cleaning – you can hire WordFence directly to scan and clean up your site after it’s been hacked.
  • Sucuri Emergency Site Cleanup  – Sucuri can provide immediate help and support getting your hacked website cleaned and back online quickly.
  • Your web hosting company may be able to help too! If your website gets hacked, check your webhost for scanning tools and other malware detection software that you can use to clean things up. They may also have an add-on service that you can purchase to assist you.

Step 3: Initiate a site review with Google and your website host

If you got a notice from your webhost or from Google that your website was hacked, or you’re seeing a big red warning screen when you visit your site, you’ll need to submit a review once you have the site sufficiently cleaned up.

If you’ve been blacklisted by Google:

It may take a few days but if your website has been cleaned up and all of the issues were resolved, your site will be restored in search results.


Final Steps: Caring for your website after repairing a hack

WordPress websites can be fully recovered after a website hack if you follow the correct steps. And once you’ve got everything back online, you’ll want to make sure that doesn’t happen again! Here’s everything I recommend doing on a monthly basis to protect your website from getting hacked and to avoid future downtime:

  • Monthly installation & testing of WordPress updates to core files, plugins, & themes
  • Continuous security scans & monitoring
  • Full website backups – weekly, saved off-site if possible
  • Reviewing any Google Search Console alerts that need attention
  • Routine database optimization, spam, & revisions cleanup

I offer monthly WordPress maintenance packages that include all of this and more. Hiring me to care for your website each month means you’re taking the most important step towards a safe and secure website. Because NOBODY has time for website hacking nonsense!

WordPress website got hacked? Get it fixed fast!

Hi there! I'm Jen.

Jen Lyker, Website Designer

For over 20 years, I’ve simplified the website strategy process for hundreds of clients. I’ve mastered blending creative and techie with sensible and systematic to become a recognized & reliable website expert among Pittsburgh web design companies.

Affiliate Disclaimer

Sometimes my posts contain affiliate links, meaning at no additional cost to you, I will receive a commission if you click through and make a purchase. But! I sincerely recommend and love everything I share!

Back to top