The message usually arrives at the worst possible time: “Something’s wrong with our website.” Strange redirects, a browser warning, or Google suddenly flagging “This site may be hacked.” Before panic sets in: most hacked WordPress sites can be cleaned up within a few hours — if you follow a structured process. That’s exactly what this guide walks you through.
1. Stay calm and take the site offline (don’t delete anything)
The first instinct is often to start changing things immediately. A better approach: put the site into maintenance mode or block access through your hosting panel, instead of deleting files at random. This stops visitors from encountering harmful content while preserving evidence for the investigation that follows.
2. Get a rough sense of the damage
Before fixing anything, take stock: Are there unknown admin accounts? Have files changed that hadn’t been touched in months? Is the site redirecting to unfamiliar domains? Is Google Search Console showing a security warning? This initial assessment determines whether restoring the last clean backup is enough, or whether a deeper cleanup is needed.
3. Restore a clean backup — if you have one
The fastest way back to normal is almost always a backup from before the attack. Important: check the creation date carefully so you don’t accidentally restore a version that was already compromised. Afterwards, still work through the remaining steps — a backup fixes the symptom, not necessarily the underlying cause.
4. Reset every set of credentials
WordPress login, FTP/SFTP, database, hosting panel, and any connected services (e.g. email marketing tools) should all get new, strong passwords. After a hack, it’s rarely clear exactly which credentials were exposed — so reset everything rather than just the most obvious one.
5. No backup? Clean up manually instead of starting from scratch
Without a clean backup, manual cleanup is the way forward: compare WordPress core, theme, and plugin files against their originals, remove unknown files and admin accounts, and check the database for injected scripts. It’s the more time-consuming route, but it’s doable — and getting professional help here can prevent something being missed.
6. Find the root cause, not just the symptoms
A common mistake: the site gets cleaned up, but the entry point stays open — and the hack repeats within days. Check specifically: was a plugin or theme outdated? Was a password too weak? Was a known vulnerability quietly being exploited? The cleanup is only really finished once the cause is known.
7. Check Google Search Console and request a review
If Google flagged a security warning, it won’t disappear automatically after cleanup. Under “Security Issues” in Search Console, you can request a review once the site is verifiably clean. Depending on the case, that can take a few days.
8. Lock things down for the future
After the immediate cleanup, the most important part follows: making sure it doesn’t happen again. Up-to-date software, a malware scanner, two-factor authentication, and regular, tested backups all belong on the list — I’ve laid out the concrete steps in 10 Steps to Stronger WordPress Security.
Conclusion
A hack is unpleasant, but rarely the end of the world — as long as you follow a structured process: secure, assess, clean up, find the cause, lock it down. If this feels like too much to handle right now: I take care of the cleanup and set up ongoing maintenance afterward so it doesn’t happen again. Just reach out via the contact form.


