If your WordPress site has been hacked, act in this order: put the site in maintenance mode or take it offline, change every password (hosting, WordPress admin, database, FTP), take a full backup of the site in its hacked state for forensics, then scan and remove the malware or restore from a clean backup and patch the hole that let attackers in.
A professional cleanup takes anywhere from a few hours to two days and typically costs $150 to $500 for standard infections, more for badly compromised or e-commerce sites. Don’t just delete weird files and hope: hacks nearly always include hidden backdoors, and a cleanup that misses them means reinfection within days.
Do you have a wordpress hacked website ? We do repair websites that are in this situation, that require migration, that are infested with bad malware plugins or something. Just get in touch with our team and lets solve this for you.
First, confirm it’s actually a hack
Common signs: your site redirects visitors to pharma or gambling pages, Google shows “This site may be hacked” under your listing, search results for your brand show spammy Japanese or pharma keywords, unknown admin users appear, or your host emails you about malware. Sometimes there’s no visible symptom at all and the site is quietly hosting phishing pages in a subfolder.
Check Google Search Console’s Security Issues tab: it’s free, definitive, and tells you what Google found.
The emergency sequence
- Limit the damage. Put the site in maintenance mode. If it’s actively serving malware to visitors or stealing card data on a store, take it fully offline. Lost traffic for a day costs less than infected customers.
- Lock the doors. Rotate all credentials: WordPress admins, hosting panel, database, SFTP, and your salt keys in wp-config. Hacks persist because attackers keep a working password while you clean.
- Preserve the evidence. Back up the hacked site before touching anything. It sounds backwards, but you’ll need it to find the entry point, and if cleanup goes wrong you can’t investigate what no longer exists.
- Clean or restore. If you have a backup that predates the infection, restoring it is faster and more reliable than cleaning, provided you then patch the vulnerability. No clean backup means manual removal: scanning files, comparing core files against fresh WordPress copies, checking the database for injected scripts, and hunting the backdoors in themes, plugins, and uploads.
- Close the entry point. Update everything: core, themes, plugins, PHP. Delete anything unused. Most WordPress hacks come through one outdated plugin, and skipping this step is how sites get reinfected the same week.
- Repair your reputation. Request a review in Search Console if Google flagged you, resubmit your sitemap, and monitor for a couple of weeks. Blacklist warnings usually clear within a few days of a verified clean.
DIY or professional?
A technically comfortable owner can handle a simple infection with a scanner plugin and patience. Call a professional when any of these is true: it’s an e-commerce site (card data means legal exposure, not just downtime), the infection came back after a cleanup, Google has blacklisted the site, or you can’t find the entry point. Reinfection is the tell: it means a backdoor survived, and finding those is exactly the kind of work to hand to a WordPress developer rather than repeat-guessing.
Be wary of cleanup services quoting suspiciously fast one-hour fixes. Removing visible malware is quick; verifying a site is actually clean isn’t.
The part nobody wants to hear
Cleanup without prevention is a subscription to getting hacked. The same neglected site gets compromised again because the conditions (old plugins, no monitoring, weak hosting) are still there. The boring fix is ongoing WordPress maintenance: updates, malware monitoring, and offsite backups, which costs a fraction of a single emergency cleanup. Pair it with hosting that includes server-level security and the next vulnerability becomes a patched update instead of a crisis weekend.