Security

My WordPress Site Was Hacked — What to Do First

The order of operations matters. Here's exactly what to do, and in what sequence.

Quick Answer: First, take the site offline or into maintenance mode to stop the damage from spreading. Second, change every password tied to the site — WordPress admin, hosting account, database, and FTP — since all should be treated as compromised. Third, identify the entry point (usually an outdated plugin or theme) before restoring, so the same vulnerability doesn't let the attacker back in immediately. Then clean the malicious code, either from a confirmed-clean backup or through manual removal, and update everything before bringing the site back online.

Site Hacked or Showing Malware Right Now?

Tell us what's happening and we'll help you contain and clean it — or take security off your plate entirely going forward.

Why the Order of Steps Matters

A hacked site is a situation where doing things in the wrong order actively makes it worse — restoring from a backup before finding the entry point just gets the site reinfected, and leaving the site live while investigating lets malicious code keep affecting visitors, search rankings, and potentially spreading further into the server. The sequence below is built specifically to avoid those mistakes.

Step 1: Contain It — Take the Site Offline

Put the site into maintenance mode, or if the compromise is serious (malware actively serving to visitors, defaced content, spam injection), take it fully offline at the hosting level. This stops the immediate damage — to visitors, to your search rankings, and to your reputation — while you work through the rest of the process without the pressure of live traffic hitting a compromised site.

Step 2: Change Every Password, Everywhere

Treat every credential associated with the site as compromised: WordPress admin accounts, the database user, the hosting account login, and FTP/SFTP credentials. Change all of them before doing anything else, from a device you trust. If an attacker had access to any of these, leaving even one unchanged gives them a way back in during cleanup.

Step 3: Identify the Entry Point

Before restoring or cleaning anything, figure out how the attacker got in — otherwise you're cleaning up the same door they'll walk through again. Check your hosting account's access and error logs around the time the compromise likely started, and audit every plugin and theme for outdated versions with known vulnerabilities, which is the single most common entry point for WordPress compromises. A security scanner like Sucuri or Wordfence can identify known malware signatures and often point directly to the affected file.

Step 4: Clean the Site — Backup or Manual Removal

If you have a backup from before the compromise, and you've confirmed the entry point is now understood and will be closed, restoring that backup is the fastest and most reliable path back to a clean site. If no clean backup exists, or you need to preserve legitimate content created after the infection, manual removal is necessary: this means going through theme and plugin files for injected code, checking for unfamiliar admin users, and scanning the database for injected spam content or redirect scripts.

Step 5: Close the Entry Point and Harden

Update every plugin, theme, and WordPress core to their latest versions — if the entry point was an outdated plugin, updating it (or removing it if it's abandoned/unmaintained) is what actually prevents reinfection. Remove any plugins or themes you're not actively using; unused, outdated software is attack surface with no offsetting benefit. Add server-level hardening — a web application firewall, login attempt limiting, and file integrity monitoring — so a similar attempt is caught before it succeeds next time.

Step 6: Address Google Safe Browsing Flags

If the site was serving malware or spam to visitors, Google Safe Browsing or Search Console may have flagged it, which can show visitors a warning page even after cleanup. Once you've confirmed the malicious code is fully removed, submit a reconsideration request through Google Search Console — this typically clears within a few days.

Related Reading

Martin Van Den Boogerd
Martin Van Den Boogerd
Founder & Owner, CriticalWP — background in cybersecurity and municipal government infrastructure
More about Martin →

Common Questions

Take the site offline or into maintenance mode first, to stop the damage from spreading or continuing to affect visitors and search rankings. Then change every password associated with the site — WordPress admin accounts, database, hosting account, and FTP — since a hacked site means those credentials should be treated as compromised.
Check the hosting account's access and error logs around the time the compromise started, and audit every plugin and theme for outdated versions, since an unpatched vulnerability in one of them is the most common entry point. A security scanner (such as Sucuri or Wordfence) can also identify known malware signatures and flag the likely entry file.
A clean backup from before the compromise is the fastest and most reliable fix, provided you confirm the backup predates the breach and you close the entry point before restoring — otherwise the same vulnerability lets the site get reinfected immediately. Manual cleanup is necessary when no clean backup exists, or when you need to preserve content created after the infection date.
Update every plugin, theme, and WordPress core to the latest version, remove any plugins or themes you don't actively use, change all passwords again after cleanup, and add server-level security hardening (firewall rules, login attempt limiting, file integrity monitoring). Cleaning the malware without closing the entry point that let it in is why so many sites get hacked repeatedly.
It's common for Google Safe Browsing or Search Console to flag a compromised site, which can show visitors a warning page. After cleanup, submit a reconsideration request through Google Search Console to have the flag removed — this typically takes a few days once the malicious code is confirmed gone.

A hacked site needs an expert response, fast.

CriticalWP handles containment, cleanup, and hardening for compromised WordPress sites — and prevents it from happening again with managed security monitoring.