WordPress

How to Fix a Hacked WordPress Site: The Complete Cleanup Guide

Published on August 5, 2026 • 10 min read
#Security #WordPress
How to Fix a Hacked WordPress Site: The Complete Cleanup Guide

Few messages alarm a site owner more than "Warning: this site may be hacked" from Google, or the sight of visitors redirected to spam pages. The good news is that almost every WordPress infection is fixable — the bad news is that how you react determines how much damage is done. Panic leads to bad decisions: deleting files you cannot restore, reinstalling over an infected database, or paying a "cleaner" who removes the symptom and leaves the backdoor.

This guide is the complete, calm sequence we follow: confirm the compromise, contain it, clean it fully, recover your search presence, and harden the site so it stays clean. Work through it in order.

The First Hour: Do These Before Anything Else

Speed matters in the first hour — but so does not destroying evidence or making things worse:

• Take a full backup of the site AS IT IS, infected files included. This is your evidence and your safety net if cleanup goes sideways

• Change every password: WordPress admins, hosting panel, FTP/SFTP, database. Attackers with working credentials will simply undo whatever you clean

• Put the site into maintenance mode if visitors are being served malware or redirects

• Do not delete anything yet — deleted files cannot tell you how attackers got in

• Note what you are seeing: warning types, strange URLs, new admin users. Screenshots help later, especially if you end up needing Google review support

Only after those five things should actual cleaning begin.

Confirm It Really Is a Compromise

Some "hacks" turn out to be plugin conflicts or expired SSL certificates. Legitimate signs include:

• Browser or search-result warnings (Safe Browsing flags)

• Visitors reporting redirects to unrelated sites

• Unknown administrator accounts

• Pages in Google's index that you never created — especially foreign-language or pharmaceutical content

• Sudden, unexplained traffic collapse

• Files in uploads or theme folders with recent modification dates you cannot explain

• Your host contacting you about outbound spam or resource abuse

Check Google Search Console's Security Issues report and the public Safe Browsing status page for your domain — both show what Google sees from its side.

Choose Your Route: Three Ways Out

Route A: Restore a known-good backup

Fastest option IF you have a backup from before infection began, verified clean, covering both files and database. The trap: backups taken after the compromise started restore the malware along with everything else. If you cannot establish when the infection began, assume every recent backup is contaminated.

Route B: Manual cleanup

The do-it-yourself path below. Reasonable for smaller sites, early-stage infections, and owners comfortable with file managers and database tools.

Route C: Professional cleanup

Right answer when the infection is severe, the site generates revenue by the hour, previous cleanup attempts failed, or you simply cannot afford a mistake. Our WordPress malware removal service follows exactly the sequence in this guide, with a fixed quote agreed after assessment — and if you want a sense of market pricing before talking to anyone, see what WordPress malware removal typically costs.

Manual Cleanup: The Complete Sequence

Step 1: Contain

Put the site in maintenance mode, revoke unknown sessions, enable maintenance via your host if admin access is lost. Containment stops active damage during cleanup.

Step 2: Scan everything

Run reputable scanners (Wordfence, MalCare, Sucuri's tools) — then go beyond them. Signature scanners miss custom and obfuscated code, so also review files by modification date, focusing on anything changed recently in themes, plugins, uploads, and the root directory.

Step 3: Replace core files

Download fresh WordPress from wordpress.org and replace the wp-admin and wp-includes directories wholesale, plus root core files — never wp-content, and preserve wp-config.php and .htaccess for individual inspection. Core replacement eliminates any tampering hiding in core.

Step 4: Inspect wp-config.php and .htaccess

Compare both against clean defaults. Look for unfamiliar includes, base64 blobs, eval() calls, redirects, and rule injections. Regenerate your security keys and salts from the official WordPress secret-key API while you are in there — this invalidates cookies attackers may have forged.

Step 5: Clean plugins and themes

Delete (do not just deactivate) every plugin and theme you do not actively need, then reinstall the survivors fresh from their official sources. Custom-coded themes deserve manual inspection of template files and functions.php for injected code.

Step 6: Clean the database

Injected content hides in posts (spam pages), the options table (autoloaded malware loaders), and user tables (rogue administrators). Search the database for suspicious script tags, base64 patterns, and unfamiliar admin accounts — including ones inserted directly into the users table, bypassing the dashboard entirely.

Step 7: Hunt the backdoors

This is the step that decides whether the infection returns:

• Check the mu-plugins folder — code there loads automatically and appears nowhere in the plugin list

• Inspect scheduled tasks: WP-Cron entries and server-level crons that quietly reinstall malware

• Look for PHP files inside wp-content/uploads, where nothing PHP should live

• Search the codebase for the usual obfuscation markers: eval, base64_decode, gzinflate, str_rot13, assert — in places they have no business being

Step 8: Rotate everything, again

By now you have touched the database and files; rotate every credential one final time — WordPress, hosting, FTP/SFTP, database user, API keys, and email accounts tied to recovery flows.

Step 9: Update, harden, verify

Update core/themes/plugins to current versions, apply baseline hardening (file permissions, login rate limiting, two-factor authentication, disabled file editing), then rescan until clean. Only now bring the site out of maintenance.

Common Infection Patterns Worth Knowing

Recognizing the pattern often shortens diagnosis dramatically:

• Pharma hack — hidden pharmaceutical pages or links injected into your site, usually invisible to normal visitors but fully visible to Google

• Japanese keyword hack — thousands of spam pages targeting Japanese search terms appear in Google's index while your site looks normal logged-in

• Redirect malware — visitors intermittently sent to gambling, phishing, or scam domains; often conditional (mobile-only, referrer-based) so it evades casual testing

• SEO spam injection — product pages for counterfeit goods added to your domain to harvest your rankings

• Defacement — the attacker replaces your homepage outright; loud, reputationally painful, but usually among the easier infections to confirm

Each pattern has preferred hiding spots and cleanup nuances, which is why experienced cleaners check pattern-specific locations rather than relying on scanner output alone.

After Cleanup: Recovering Your Search Presence

If Google flagged the site, cleanup alone lifts nothing — you must verify and then formally request review through Search Console. The full procedure, including what to write and realistic timelines, is in our guide to removing the Google hacked-warning.

Tools of the Trade

The toolkit is mostly free; the value is in knowing what to run when:

• Scanners: Wordfence, MalCare, Sucuri SiteCheck — useful first passes, never the final word

• Diff tools: comparing current files against pristine downloads from wordpress.org and vendor repos

• Database access: Adminer or phpMyAdmin for options-table, users-table, and post-content sweeps

• Search Console: Security Issues examples and the eventual review request

• File manager/SFTP: modification-date sorting is your fastest triage instrument

No single tool catches everything. The sequence — scan, compare, inspect manually — is what produces verified-clean rather than apparently-clean.

Working With Your Host During an Incident

Your hosting provider is either an ally in cleanup or an obstacle, depending on how you engage them:

• Report the compromise early — hosts monitor outbound spam and resource abuse, and a heads-up prevents account suspension mid-cleanup

• Ask what they can see: server-side malware scanners, access logs, and mail logs frequently reveal things WordPress-level tools cannot

• Request log retention — access logs covering the infection window are the single best source for finding the original entry point

• Understand restore policies before you need them; some hosts keep daily snapshots for only a few days

A suspension during cleanup is disruptive but recoverable; hosts typically reinstate quickly once you report a confirmed-clean scan.

Special Cases That Change the Playbook

WooCommerce stores

Stores carry customer data and payment flows, which raises both stakes and caution level. Cleanup must preserve orders and customer records exactly — database work happens with export backups first, and checkout gets tested deliberately before relaunch. If any indication exists that customer data was exposed, disclosure obligations may apply depending on your jurisdiction.

Multisite networks

One compromised site in a multisite network means every site is suspect until proven otherwise: shared plugins and themes propagate infections network-wide, and super-admin credentials override everything. Clean the network as one incident, not several small ones.

Managed WordPress platforms

Some managed hosts restrict file access by design. Where SFTP or database tools are limited, cleanup runs through their support channels — slower, but their tooling also handles some hardening automatically.

Budgeting the Work

Whether you clean it yourself or hire it out, know the market: real-world cleanup pricing currently spans roughly $80 for trivial cases to four figures for severe infections, with most business sites landing between $150 and $500. Our cost breakdown explains what drives the number up and how to judge any quote — including ours.

When the Infection Keeps Coming Back

Reinfection after cleanup is so common it has its own playbook. It almost always means persistence survived: a backdoor in a location the cleanup never checked, a rogue account created directly in the database, or compromised hosting credentials operating outside WordPress entirely. Work through where attacker access survives cleanup before spending money on another surface-level scan.

Prevention: The Short Version

Every hour spent on prevention beats an incident:

• Updates applied on a tested schedule — the single biggest factor

• Two-factor authentication and login rate limiting

• Integrity monitoring with alerts a human actually receives

• Offsite backups tested for restore, not just taken

• Plugin hygiene: fewer plugins, reputable sources, abandoned ones removed

That discipline is exactly what our WordPress security service runs for clients daily — hardening plans start at $99, and incident response is quoted fixed after assessment.

Frequently Asked Questions

Can I clean a hacked WordPress site myself?

Yes — smaller, early infections respond well to careful manual work following the sequence above. The risks are missed backdoors and accidental breakage. Revenue-generating sites and repeat infections are better served professionally.

How long does cleanup take?

Simple infections: a few focused hours. Severe cases with database involvement, blacklisting, or prior failed cleanups: days. Anyone promising instant results without diagnosing is guessing.

Will my SEO recover after a hack?

Generally yes, provided the site is genuinely cleaned, warnings are cleared through Google's review process, and reinfection does not occur. Traffic lost to warnings typically returns once they lift; prolonged neglect is what causes lasting damage.

Should I just restore a backup instead?

Only when the backup provably predates the compromise and covers files AND database. Otherwise you restore the infection with the site — one of the most common self-inflicted setbacks we see.

What do professionals do differently from a careful DIY cleanup?

How do I know a cleanup actually worked?

Three signals, checked in order: an independent rescan comes back clean — not just the tool that flagged the infection originally — no new unauthorized file changes appear over the following one to two weeks of monitoring, and, where relevant, the Google review clears without rejection. Anything less is optimism.

Mostly pattern recognition built from hundreds of incidents: knowing which plugin historically carried which exploit, where this particular malware family persists, and when a database finding changes the whole scope. The technical steps overlap heavily with this guide — the difference is speed and the reduced chance of a missed persistence point.

Removing the visible malware without closing the entry point is not cleaning, it is decorating.

The Five Stages

Contain, Identify, Clean, Harden, Request review. In that order, every time.

Enjoyed This Article?

Let's turn these insights into real growth for your business. Get a free consultation today.

Get Started Today