Dealing with a Hacked WordPress Site: A Step-by-Step Guide
Oh no! Your security scans have come back positive, and it’s confirmed: your website has been successfully infiltrated.
Don’t panic! I’ve been in your shoes, and I’m here to walk you through the process of how to clean a hacked WordPress site and what next steps you should take to recover.

Why WordPress Sites Get Hacked
First, let’s talk about why WordPress sites are so vulnerable to hacking. With over 300 million websites using WordPress, it’s no surprise that it’s the most popular target for hackers. The sheer volume of WordPress sites out there makes it an attractive target for malicious activity.
🟢 WordPress powers 2/5 Websites in the world
🟢 59,000 Plugins (free)
🟢 500+ new WordPress websites every day
Additionally, with numerous plugins and themes available, there are multiple potential entry points for hackers to exploit.
Table of Contents
Step 1: Stay Calm and Assess the Situation
When you discover that your site has been hacked, it’s essential to stay calm and think clearly. Take a deep breath and go through this quick list of questions to assess the situation:
Hacked Checklist
- Are you able to log in to your WordPress Admin Panel?
- Is your website redirecting you to some other website?
- Does your WordPress website contain any illegal links?
- Has Google already marked your website as insecure?
- Do you have access to your Hosting?
- Do you know you built your WordPress Website?
- Do you have a backup?
Record your answers to each question and make sure that you’ve noted everything for the next step.
Step 2: Contact Your Hosting Company
Many good hosting companies have experienced staff who can help you deal with a hacked site. Get in touch with your hosting provider and follow their advice.
They may be able to tell you how the hack occurred, where the backdoor is, and how to prevent future attacks. If your website is hosted on a shared server, your hosting provider can also help you determine if the hack was caused by a vulnerability on another site on the same server.
Step 3: Hire a Professional (Optional)
If your website has been severely attacked or you’re not comfortable cleaning it up yourself, consider hiring a professional. A vulnerable website only gets worse as time goes on, so the faster you can get your issues fixed, the safer your website will be.
One excellent option is Malcare, a complete WordPress security solution that can protect your online identity, or you can hire WebCare to restore your hacked website.
What to Look for in a WordPress Security Solution
When choosing a WordPress security solution, look for the following features:
| Feature | Description |
|---|---|
| Powerful Scanner | A scanner that will never slow down your website and goes beyond just signature matching to find new and complex malware |
| One-Click Automatic Malware Removal | A feature that surgically cleans all traces of malware permanently from the website |
| Intelligent Plugin-Based Firewall | A firewall that protects your website from bad traffic by using the collective intelligence of its network of sites |
| Intuitive Site Management Module | A module that lets you manage your themes, plugins, users, and WordPress core for better security of your website |
Step 4: Restore a Previous Version
If you’ve made a habit of backing up your site, now is the time to restore a previous version. Keep in mind that this will revert your website back to the version you’re restoring from, so any changes you’ve made since then will be lost. However, this may be worth it to get a clean website back.
Step 5: Scanning and Removal of Malware
If you can’t restore a previous version or prefer to clean your site manually, you’ll need to scan for and remove malware. Use a WordPress security plugin like iThemes Security to regularly scan your website and find any backdoors or malicious code.
Make sure to keep all your plugins and themes up-to-date, as outdated files can provide an entry point for hackers.
Tips for Preventing Future Hacks
To prevent future hacks, make sure to:
- Keep all plugins and themes up-to-date
- Use strong, unique passwords and secret keys
- Limit user permissions and monitor user activity
- Regularly back up your website
- Install a WordPress security plugin and regularly scan for malware
Step 6: Check User Permissions
Check the user permissions of all your WordPress users to ensure that only authorized users have access to admin accounts. Remove any suspicious new users and make sure that user permissions haven’t been tampered with.
Step 7: Change Passwords and Secret Keys
Change all passwords related to your WordPress site, including the password to access your WP dashboard, cPanel, MySQL database, FTP, and any others that could help someone access your website. Use a password generator to ensure your password is strong, unique, and not easy for a hacker to guess. Also, change your secret keys and salts to ensure that your WordPress website is safe and secure.
Conclusion
Cleaning a hacked WordPress site can be a daunting task, but by following these steps, you can get your site back to normal. Remember to stay calm, assess the situation, and take the necessary steps to prevent future hacks.
Don’t be afraid to seek help from a professional if you’re not comfortable cleaning your site yourself. And always keep in mind that WordPress security is an ongoing effort – stay vigilant and keep your site safe!




