How to Tell If Your WordPress Site Is Hacked: 9 Warning Signs

A hacked WordPress site rarely puts up a flashing alert. It leaks small, easy-to-miss clues first. Here are the nine warning signs that matter, what each one actually means, and the calm first steps to take before you touch a single file.

By Nathan Cross, Co-Founder, Network & Security Engineering·

The clues are usually small before they are obvious

Most owners imagine a hack as a defaced homepage with a hacker's logo plastered across it. That happens, but it is the loud, rare version. Far more often a compromised WordPress site keeps running and looking normal to you while quietly doing something else for someone else: redirecting your visitors, hiding spam pages from search engines, or sending junk email under your domain's name.

That is by design. An attacker who wants to keep using your site has every reason to stay invisible to you, the one person who could shut it down. So the early signs are small and easy to explain away: a slightly slower page, an odd search result, a security warning you assume is a fluke. Learning to read those clues is the difference between catching a problem in week one and discovering it after your domain has been blocklisted.

None of the signs below is absolute proof on its own. A white screen can be a plugin conflict; a slow site can be a cheap host. But when you see two or three of these together, treat it as a real compromise and act.

The nine warning signs of a hacked WordPress site

Run through this list the way an attacker hopes you never will. Each sign points at a different kind of compromise, and several of them are things your visitors or Google will notice before you do.

If several of these ring true at once, stop diagnosing and move to the first-response steps further down. Speed matters more than certainty once the pattern is clear.

  • Unexpected redirects. You (or a customer) click your link and land on a pharmacy, casino, or sketchy product page. Classic malware often redirects only visitors arriving from Google, or only on mobile, so it stays invisible when you visit directly.
  • Spam or pharma pages you never made. Your site suddenly has pages selling pills, replica goods, or loans. These are usually hidden from your dashboard and built purely to rank in search and pass traffic to the attacker.
  • A Google 'this site may be hacked' or blocklist warning. A red interstitial in Chrome, a 'deceptive site ahead' page, or a flagged search result means Google's Safe Browsing has detected something. This is one of the loudest, most reliable signs.
  • Unknown admin users. An account in Users you did not create, or finding yourself suddenly locked out of wp-admin, strongly suggests someone else has a key to the site.
  • Defacement. The obvious one: your homepage is replaced with the attacker's message or imagery. Rare, but unambiguous.
  • Sudden, unexplained slowness. Your site crawls or your host flags high CPU. Compromised sites are often quietly put to work sending spam, mining, or attacking other sites, and that load shows up as sluggishness.
  • Junk in your search results. Searching site:yourdomain.com on Google returns pages in other languages, garbled titles, or spam keywords you never wrote. This is search-engine spam injection, and it can quietly tank your rankings.
  • Your host suspends the account or emails you about malware. Hosts run their own scans. A suspension or a malware notice from them is a strong signal, not a false alarm, and worth treating seriously.
  • Spam sent from your domain. Customers report spam 'from you', or your domain lands on an email blocklist and legitimate mail stops being delivered. Attackers love a trusted domain to send from.

What each sign tells you about the way in

The pattern of symptoms hints at what was compromised. Redirects and spam pages usually point to injected code in your files or database, often through a vulnerable plugin or theme. Unknown admin users and lockouts point to a stolen or brute-forced login, which is why two-factor authentication matters so much. Spam sent from your domain can mean the site itself was turned into a mailer, but it can also mean your email authentication is weak enough that anyone can forge mail as you, which is a separate problem worth checking with an SPF, DKIM, and DMARC test.

Whatever the symptom, the entry point is usually the same family of weakness. Plugins account for roughly 96% of WordPress vulnerabilities, with only a handful ever found in WordPress core itself (Patchstack). An out-of-date or abandoned plugin is the single most common doorway, because attackers run automated scans for known-vulnerable versions and walk straight in.

This is not personal targeting. It is volume. In Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR). Small WordPress sites are exactly the kind of soft, plentiful target these automated sweeps are built to find.

Confirm it without making things worse

Before you start deleting files in a panic, confirm the compromise is real, and try to confirm it from the outside first. A passive external scan reads what your site is actually serving to the public, the same view an attacker or Google has, without you having to log in or touch anything. That can tell you whether your pages are redirecting, serving injected spam, or running software with known flaws, all without the risk of you breaking a working site while stressed.

You can run a free external scan of your site in seconds, with no login. It checks your DNS, email authentication, TLS certificate, HTTP security headers, exposed files, and known CVEs for versions detectable from outside. If something is being served to visitors that should not be, this is often where it shows up first. For the malware-and-blocklist angle specifically, a remote malware scanner such as Sucuri SiteCheck is also a fast, free second opinion (Sucuri SiteCheck).

One honest limit: an outside scan sees the outside. It cannot read your exact installed plugin versions, spot a hidden back door in your files, or list the admin accounts in your database, because it has no login to your server. That inside view is a separate check, which is why a complete picture pairs the two. We cover that split in the inside and outside of a website security scan.

What to do first if the signs add up

If two or three signs line up, treat it as real and shift from diagnosing to containing. The goal of the first hour is not to clean the site, it is to stop the attacker from doing more harm and to protect your visitors while you figure out what happened.

Work calmly and in order. If you are not comfortable with these steps, this is a good moment to call for help rather than risk making it worse under pressure.

  • Put the site into maintenance mode or take it temporarily offline so visitors are not exposed to malicious code or redirects
  • Change every password: WordPress admin, hosting and cPanel, the database, FTP and SFTP, and the email tied to your logins
  • Force a logout of all active sessions so any stolen logins stop working immediately
  • Disable or remove admin accounts you do not recognise, and rotate any API keys or secrets stored in the site
  • Tell your web host: many can isolate the account, take a snapshot, and point you to their own cleanup tools
  • Do not start deleting files at random yet, because that destroys evidence of how deep the problem goes

From confirmed to clean

Confirming a hack is the start, not the finish. Once you know it is real and you have contained it, the work is to assess how deep it goes, clean or restore from a known-good backup, and then harden the site so the same hole does not let an attacker straight back in within days. Rushing the cleanup and skipping the hardening is the most common reason a site gets reinfected within weeks.

We have written the full step-by-step for that next stage. If the signs above have confirmed your fears, work through the WordPress hacked recovery checklist next, and lean on the WordPress security guide for the underlying hardening. And if the site handles customer or payment data, or you simply cannot find the source, getting a professional in is the safe call rather than guessing.

Not sure if your site is compromised? Check from the outside first

Run a free BadgerScan external scan to see what your WordPress site is actually serving the public: redirects, injected spam, weak email authentication, and known vulnerabilities, all with no login. If the signs add up, our Hamilton and Burlington team can confirm what happened, clean it properly, and harden it so it stays fixed. Reach us at (289) 796-8900.

Run a free security scan

Frequently asked questions

How do I tell if my WordPress site is hacked?

Look for the common warning signs together: unexpected redirects to pharmacy or casino pages, spam pages you never made, a Google 'this site may be hacked' warning, admin users you did not create, sudden slowness, junk in your search results, a host suspension or malware notice, or spam sent from your domain. Any one can have an innocent explanation, but two or three at once point to a real compromise. A passive external scan can confirm whether your site is serving anything malicious to visitors without you logging in.

Can a WordPress site be hacked without any visible signs?

Yes, and that is common. Attackers who want to keep using your site, to send spam or host hidden spam pages, have every reason to stay invisible to you. Some malware only redirects visitors arriving from Google or only triggers on mobile, so the site looks normal when you check it directly. That is why an outside scan, which reads what the public actually sees, is useful for catching what your own browser does not show you.

Why is my WordPress site redirecting to spam sites?

A redirect to pharmacy, casino, or scam pages is a classic sign of injected malware, usually introduced through a vulnerable or abandoned plugin or theme. Plugins account for roughly 96% of WordPress vulnerabilities (Patchstack), so an out-of-date plugin is the most likely entry point. Confirm it with an external scan, then contain the site and work through a recovery process rather than just deleting the redirect, because a hidden back door will usually put it back.

My WordPress site shows the warning signs. What should I do first?

Stay calm and contain it before cleaning. Put the site into maintenance mode or take it temporarily offline, change every password, force a logout of all sessions, remove admin accounts you do not recognise, and tell your web host. Avoid deleting files at random, because that destroys the evidence you need to understand how deep the problem goes. Then follow a full recovery checklist.

Keep reading

Sources

  1. Patchstack, State of WordPress Security
  2. Verizon 2025 Data Breach Investigations Report
  3. Sucuri SiteCheck (remote website scanner)

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.