Security

WordPress Malicious Redirect — How to Find and Remove It

Visitors land somewhere else entirely. Here's where the injected code is usually hiding.

Quick Answer: A malicious redirect means the site has been compromised and code has been injected into .htaccess, theme files (often functions.php), a plugin, or directly into the wp_options database table, sending visitors elsewhere instead of your real content. Check .htaccess for unfamiliar RewriteRule lines first, then scan theme/plugin files and the siteurl/home database values. Removing the code isn't enough on its own — you also need to close the entry point (usually an outdated plugin) or the redirect will return.

Site Redirecting Visitors Somewhere It Shouldn't?

Tell us what's happening and we'll help you find and remove it — or take security off your plate entirely going forward.

Why This Is a Hack, Not a Bug

A malicious redirect doesn't happen from a misconfiguration — it means an attacker has already placed code somewhere in the site that intentionally sends visitors to a different destination, usually a spam page, ad-fraud site, or scam page monetizing the traffic. It's worth treating this the same way as any other compromise: find the injected code, remove it, and close whatever let the attacker in — not just delete the visible symptom.

Step 1: Check for Device- or Referrer-Specific Behavior First

Many injected redirect scripts are deliberately conditional — they only trigger for mobile visitors, or only for visitors arriving from a Google search result, specifically so the site owner checking the site directly in a desktop browser sees nothing wrong. Before concluding you don't have this problem, test from an incognito mobile browser, or use a free site-checker tool that simulates a search-engine referrer.

Step 2: Check .htaccess for Injected Rewrite Rules

Via FTP or your host's file manager, open .htaccess in the site's root and look for any RewriteRule or RewriteCond lines you don't recognize, especially ones referencing an unfamiliar external domain. These are a common and relatively easy place for attackers to inject a redirect, since .htaccess executes before WordPress even loads.

Step 3: Check Theme and Plugin Files

Review your active theme's functions.php file for unfamiliar code, particularly anything referencing header('Location: or wp_redirect( that you didn't add. Also check for plugin files with names that look legitimate but aren't part of any plugin you actually installed — a common technique is dropping a file like wp-cache.php or similarly named file directly into /wp-content/ to blend in. A security scanner like Sucuri or Wordfence will often flag these automatically by comparing files against known-clean versions.

Step 4: Check the Database

Via phpMyAdmin, check the wp_options table for the siteurl and home rows — if either has been altered to point somewhere unexpected, that's a direct cause of site-wide redirects. Also check widget and theme option rows for injected <script> tags, which is another common place to hide redirect logic where it won't be noticed in a normal file review.

Step 5: Close the Entry Point

Removing the redirect code fixes the symptom but not the cause. Update every plugin, theme, and WordPress core to their latest versions, remove anything you're not actively using, and change every password associated with the site. If the entry point isn't identified and closed, the same vulnerability typically lets the redirect script get reinjected within days.

Related Reading

Martin Van Den Boogerd
Martin Van Den Boogerd
Founder & Owner, CriticalWP — background in cybersecurity and municipal government infrastructure
More about Martin →

Common Questions

A malicious redirect means the site has been compromised and malicious code has been injected — usually into theme files, a plugin, the .htaccess file, or directly into the database — that sends visitors to a spam, ad-fraud, or scam page instead of your actual content. It's a symptom of a broader hack, not a standalone bug.
The most common locations are the theme's functions.php file, the .htaccess file (often as RewriteRule injections), the wp_options table in the database (particularly siteurl, home, or widget/theme option fields), and sometimes a rogue plugin file disguised with a legitimate-looking name.
Yes, and this makes it harder to spot. Many injected redirect scripts only trigger for mobile visitors, or only for visitors coming from Google search results, specifically so the site owner checking it directly in a desktop browser doesn't see anything wrong. Testing from an incognito mobile browser or a site-checking tool is necessary to actually see it.
Check .htaccess for unfamiliar RewriteRule or RewriteCond lines and remove them, review functions.php and any recently modified theme/plugin files for injected redirect code, and check the wp_options table for altered siteurl or home values. A security scanner like Sucuri or Wordfence can also locate injected code automatically.
Only if you also close the entry point the attacker used — usually an outdated, vulnerable plugin or theme. Removing the redirect script without updating the vulnerable software and changing all passwords typically results in reinfection within days.

Malicious code shouldn't be a DIY project.

CriticalWP handles containment, cleanup, and hardening for compromised WordPress sites — and prevents it from happening again with managed security monitoring.