Quick answer
The most common signs your WordPress site has been hacked include: unfamiliar admin accounts, visitors being redirected to spam sites, a Google “this site may be hacked” warning in search results, your hosting provider sending spam abuse emails, unexplained slowdowns, files or code you didn’t create, and security alerts from Google Search Console. Most WordPress hacks go undetected for weeks because hackers deliberately hide their activity — they want to keep using your site, not shut it down.
Most small business owners don’t discover their WordPress site has been hacked until real damage is already done — customers see a browser warning, Google removes rankings, or the hosting company suspends the account without warning.
The bad news: over 90% of hacked WordPress sites were running at least one outdated plugin or theme at the time of the breach (Sucuri Website Threat Research Report). The good news: if you know what to look for, you can catch a hack early before it costs you customers, rankings, or your reputation.
Here are the 7 most common signs your WordPress website has been hacked — and what to do about each one.
Sign 1: Unfamiliar admin user accounts appear in your dashboard
Sign 01 — User accounts
New administrators you didn’t create
Go to Dashboard → Users → All Users. If you see admin accounts you don’t recognise — especially with random usernames or email addresses from free providers — your site has very likely been compromised.
Hackers use plugin vulnerabilities to inject backdoor administrator accounts. This gives them permanent access even after you change your password. It’s one of the first things attackers do after gaining entry.
Delete the unfamiliar accounts immediately. Change your password and the passwords of all legitimate admin accounts. Run a full security scan with Wordfence or Sucuri. Check your wp-config.php file for unfamiliar code.
Sign 2: Your website redirects visitors to spam or adult sites
Sign 02 — Redirects
Visitors land elsewhere — often without you knowing
Visitors arrive at your URL but get immediately sent to a spam site, adult content, or a fake pharmacy. You may not notice this yourself because many redirect hacks only activate for visitors arriving from Google, while leaving direct browser visits unaffected.
Hackers inject malicious code into your .htaccess file or wp-config.php that triggers conditional redirects. This is particularly common after a plugin vulnerability is exploited.
Open your .htaccess file via FTP or hosting file manager and look for unusual redirect rules (lines starting with “RewriteRule” pointing to external URLs). Also check wp-config.php for base64-encoded strings at the top of the file. Restore from a clean backup if found.
Sign 3: Google displays a “This site may be hacked” warning
Sign 03 — Google warning
The most damaging sign for your local business
Search your business name on Google. If you see red warning text beneath your listing — “This site may be hacked” or “Deceptive site ahead” — Google has detected malware or phishing content on your site. This warning alone will stop most customers from clicking.
Google’s Safe Browsing crawler continuously scans sites for malware, phishing pages, and deceptive content. Once flagged, your listing is suppressed in rankings and visitors who do click see a full-screen browser warning before reaching your site.
Go to Google Search Console → Security & Manual Actions → Security Issues. Follow Google’s remediation steps, clean the malware, then request a review. The warning typically clears within 1–3 days of a successful review. This is one case where having a recent clean backup is essential.
94%
of websites that receive a Google Safe Browsing warning lose more than half their organic traffic within 48 hours
Source: Sucuri Hacked Website Report
Sign 4: Your hosting provider sends spam abuse emails or suspends your account
Sign 04 — Hosting suspension
Your account becomes a spam bot
You receive an email from your host saying your account is sending large volumes of spam, has been flagged for abuse, or — worst case — your site has been suspended entirely. You may also notice email deliverability issues.
Hackers use compromised WordPress sites as spam distribution servers. Your server’s PHP mail() function gets hijacked to send thousands of phishing or spam emails per day using your hosting resources and your domain’s reputation.
Contact your hosting provider immediately to understand the scope. Run a malware scan. Look for unfamiliar PHP files in your uploads directory. Ask your host to temporarily disable PHP mail() while you clean the infection. Check your domain’s email reputation at MXToolbox.com.
Sign 5: Your site loads extremely slowly or goes down without explanation
Sign 05 — Unexplained slowness
Your server resources are being stolen
Your WordPress site suddenly takes 15–30 seconds to load, or goes down entirely during business hours even though you haven’t changed anything. Your host’s control panel shows unusually high CPU or memory usage.
Hackers use compromised sites to run cryptocurrency mining scripts, automated spam operations, or brute-force attacks on other sites — all of which consume your server’s CPU and memory. Your site slows because its resources are being stolen.
Log in to your hosting control panel and check resource usage graphs. If CPU or memory is spiking without obvious cause, contact your host. Run a malware scan. Check your wp-content/uploads folder for unusual .php files — legitimate image upload folders should only contain image and media files, not PHP scripts.
Sign 6: New files or code you didn’t create appear on your server
Sign 06 — Unknown files
Backdoor files hidden in plain sight
Using your hosting file manager or FTP, you find PHP files in your uploads directory (e.g. wp-content/uploads/2024/image.php), strange code at the very top or bottom of your wp-config.php or index.php, or recently modified core WordPress files.
These are “webshell” backdoors — PHP files that give hackers remote control over your server even after you’ve cleaned other malware. Hackers also modify core files to persist access.
Legitimate WordPress core files can be compared to the official WordPress repository. Use Wordfence’s file integrity scanner or run WP-CLI’s “wp core verify-checksums” command to identify modified core files. Any .php files in your uploads directory are almost certainly malicious and should be deleted. Reinstall WordPress core files from a clean download at wordpress.org.
Sign 7: Google Search Console or Bing Webmaster Tools sends a security alert
Sign 07 — Webmaster alerts
The search engines notice before you do
You receive an automated email from Google Search Console with subject lines like “Security issue detected on your site” or “Manual action taken on your site.” Bing Webmaster Tools may send similar notifications about malware or suspicious activity.
Search engine crawlers find malware, hidden spam pages, pharmaceutical content, or cloaked links that aren’t visible to human visitors. These are often injected specifically to manipulate search rankings for the hacker’s sites — a tactic called SEO spam or spamdexing.
Log in to Google Search Console immediately. Go to Security & Manual Actions → Security Issues for specific details of what was found and where. If it’s a manual action (meaning a human at Google reviewed and took action), you’ll need to clean the infection AND submit a reconsideration request after remediation. This can take 2–4 weeks to resolve.
What should you do if your WordPress site has been hacked?
Step-by-step recovery
If you believe your WordPress site has been hacked, the first step is not to panic — acting quickly and systematically gives you the best chance of a clean recovery. Start by taking the site offline if possible (most hosts have a “suspend site” option in cPanel), then run a malware scan, restore from your most recent clean backup, change all passwords across WordPress and hosting, remove any unfamiliar admin accounts, and update every plugin, theme, and WordPress core to the latest version. After cleanup, request a Google review if your site was flagged in Safe Browsing.
Here’s the most important thing a small business owner can take away from this article: the vast majority of WordPress hacks are preventable. Over 90% happen because of outdated plugins — and keeping plugins updated is the single most effective security measure you can take.
The challenge is that most florists, café owners, and salon operators don’t have time to log into their WordPress dashboard every week to check for updates, run security scans, and verify backups. That’s exactly why WPM’s WordPress maintenance service exists — we do all of this on a fixed monthly retainer so you never have to think about it.
Is your WordPress site at risk right now?
Get a free WordPress health check — we’ll scan your site for security vulnerabilities, outdated plugins, and active threats. Delivered to your inbox within 24 hours. No credit card required.
Get my free security audit →
WordPress Maintenance
Small Business
Security
US Local Business