A Step-by-Step Guide to Fix Your Hacked Site Fast
Realizing your website got hacked is NOT a fun experience. It feels like a complete violation and can cause a bit of panic – understandably so! But after that initial freak-out, it’s time to answer the question: My website got hacked! What should I do??!
Because WordPress powers over 40% of all websites (really!), it’s become a pretty big target for hackers, so breaches can be common. But if you’re able to take quick action to clean things up and lock down your website security, it doesn’t need to be a panic situation for very long.
How do you know if your website was hacked?
The first indications that you’ve got a hacked website might be a weird popup that shows up on your site, or a page gets redirected to a different website. Maybe it’s an admin user that was added and you have no idea how it got there. Sometimes the content on a page has changed or been defaced.
Maybe you got a notification from Google or see this page when you visit your website:

You also might get a notification from your webhost that they’ve disabled your site until things get cleaned up.
If you’re not entirely sure if your website has been compromised, you can use a few different tools to verify a hacked website:
- Check Google’s Safe Browsing tool to see if your website has been marked as unsafe.
- Wordfence is a WordPress security plugin that has a built-in site scanner to check for compromised files, malicious code, and anything else that might be suspicious.
- Sucuri Site Check – if you suspect your website has been hacked, you can do a free scan for malware, viruses, blacklisting status, website errors, out-of-date software, and malicious code.
Step 1: Take your hacked website offline & lock down access
Once you’ve verified that yep, your website was hacked, here are the next steps:
- To protect your website visitors & avoid further damage, you’ll want to put your website into maintenance mode so that anyone visiting will see a temporary ‘coming soon’ page.
- Remove any admin users that don’t look familiar or that no longer need access, and change passwords to any existing admin users. Be sure to use a secure password that you don’t use anywhere else.
- Change all of your other website passwords – FTP users, database users, and your main website hosting account or cPanel login.
- If you can, update WordPress. Make sure all of your plugins and themes are up to date, and update WordPress core files. Delete any plugins or themes you don’t need anymore.
All of the above steps are good website hygiene and ongoing habits for your WordPress website to keep it from getting hacked in the future.
Step 2: Clean Your Hacked Website
Remove malware or malicious code & restore your site
I recommend doing a deep security scan to find exactly which files have been compromised. WordFence has a built-in site scanner that will search through all of your WordPress files and compare them to a clean WordPress installation. Anything that looks different, isn’t part of a normal WordPress website, or matches any known code from other hacks will be flagged.
This scan will help you figure out how extensive the hack is, and if you’ll be able to clean up your hacked website yourself or if you’ll need to hire security experts to take care of it for you.
Do-it-yourself Hacked Website Cleanup
Option 1: Restore from a site backup
If you find after a security scan that it’s just a file or two that need to be removed, that’s pretty simple to clean up. But sometimes the hack is extensive and in that case, restoring from a clean backup is the best option.
You can determine when the website hack happened by looking at timestamps on the offending files. Then you’ll know how far back you’ll need to go in your backups and restore from a clean version before that date.
Option 2: Manual File Removal & Restoration
Sometimes restoring from a backup isn’t an option if the hack happened too far in the past and you don’t have a backup from before that point, or you’ve made other website changes you can’t risk losing with a backup restoration.
Using the WordFence scan helps you find the offending files and you can remove them manually. An automated scan isn’t foolproof – you’ll also want to examine the files on the server and make sure nothing has been missed. Reviewing timestamps on the files is the best way I’ve found to notice things that are out of place. You’ll want to pay special attention to files like wp-config.php, index.php, and plugin files.
Hiring Professional Site Cleaning after a Hack
If the clean up is more than you’re able to handle, hiring a cleanup service is a great option:
- WordFence Site Cleaning – you can hire WordFence directly to scan and clean up your site after it’s been hacked.
- Sucuri Emergency Site Cleanup – Sucuri can provide immediate help and support getting your hacked website cleaned and back online quickly.
- Your web hosting company may be able to help too! If your website gets hacked, check your webhost for scanning tools and other malware detection software that you can use to clean things up. They may also have an add-on service that you can purchase to assist you.
Step 3: Initiate a site review with Google and your website host
If you got a notice from your webhost or from Google that your website was hacked, or you’re seeing a big red warning screen when you visit your site, you’ll need to submit a review once you have the site sufficiently cleaned up.
If you’ve been blacklisted by Google:
- Verify your site & domain ownership in Google Search Console if you don’t already have a profile for your site there.
- After your domain has been verified, go to Security Issues in your Google Search Console profile.
- Review anything listed there, and submit a request for review.
It may take a few days but if your website has been cleaned up and all of the issues were resolved, your site will be restored in search results.
Final Steps: Caring for your website after repairing a hack
WordPress websites can be fully recovered after a website hack if you follow the correct steps. And once you’ve got everything back online, you’ll want to make sure that doesn’t happen again! Here’s everything I recommend doing on a monthly basis to protect your website from getting hacked and to avoid future downtime:
- Monthly installation & testing of WordPress updates to core files, plugins, & themes
- Continuous security scans & monitoring
- Full website backups – weekly, saved off-site if possible
- Reviewing any Google Search Console alerts that need attention
- Routine database optimization, spam, & revisions cleanup
I offer monthly WordPress maintenance packages that include all of this and more. Hiring me to care for your website each month means you’re taking the most important step towards a safe and secure website. Because NOBODY has time for website hacking nonsense!

