WordPress

7 signs your WordPress site has been hacked

A hacked site rarely shouts. It whispers. Here are the seven signs you can't ignore — from Google warnings to admin accounts you never created — and how to confirm them.

Most people don’t discover their WordPress site is hacked until someone else tells them — a customer, Google or the hosting provider. But the signs are there earlier, if you know what to look for. Here are the seven most common, how to confirm them, and why you shouldn’t wait.

1. Google shows a security warning

”This site may be hacked” under your link in search results, or a red warning screen in the browser, means Google Safe Browsing found harmful content. Check Security Issues in Google Search Console — it’s the fastest confirmation, and you’ll often see examples of the affected pages there.

2. Strange redirects

Visitors are sent to spam or ad sites — often only on mobile, or only the first time they arrive from Google. That’s exactly why you rarely notice it yourself while logged in. Test your site in an incognito window on mobile, or ask a colleague to visit it via a Google search.

3. Unknown admin accounts

A user with administrator rights you didn’t create is a strong sign. Worse: skilled attackers hide the account so it doesn’t show in the user list. Count the number of administrators directly in the database, not just in wp-admin, since the list can be tampered with.

4. Files you didn’t upload

Especially PHP files in wp-content/uploads (where there should never be code) or files with random names. Core files with a changed timestamp or size are also a red flag — they should be identical to the original.

5. The site sends spam

If your domain suddenly lands on email blocklists, or customers receive junk that appears to come from you, your server is likely being used to send spam. It hurts both your deliverability and your reputation.

6. Sudden slowness or crashes

Malicious code consumes resources — a cryptominer can bring a whole server to its knees. If the site has become slow or crashes without you changing anything, check resource usage and look for processes that don’t belong.

7. Your host has warned or suspended the site

When a hosting provider detects malicious code, they sometimes suspend the site to protect others on the server. It’s the clearest sign of all — and means the cleanup can’t wait.

What NOT to do

Don’t delete files in a panic — you can take content with you or crash the site. Don’t blindly restore from an old backup either; if it’s from after the infection, it’s infected too. And don’t request a Google re-review before the site is actually clean — it just gets flagged again.

How to act correctly

Change admin passwords immediately, take the site offline if you can, and let someone who knows WordPress security dig in. Every sign above means malicious code is already running — and the longer it stays, the deeper it digs. We run a full WordPress cleanup — a scan of files, database and core files, backdoor removal and a clear report — and can then keep the site clean going forward with Managed WordPress hosting.

Bygg på ett moln du faktiskt äger.

Ingen bindningstid. En körande VM innan du betalar en krona.