WordPress Site Hacked or Redirecting Visitors? What to Do First
If your WordPress site is sending visitors to another website, showing spam pages, or has administrator accounts you did not create, treat it as compromised. Start by writing down what you see and when, reading any notice from your hosting company, and changing your passwords from a computer you trust. Do not delete files or restore an old backup yet, because both can destroy the evidence needed to find how the attacker got in.
The steps below are limited to things an owner can do safely without touching code. The cleanup itself is a job for whoever handles your WordPress development, and this article explains what to hand them so they can start quickly.
What does it mean when a WordPress site redirects visitors to another site?
It usually means someone has changed files or settings on your site without permission. WordPress.org's own guide, FAQ My site was hacked (last updated July 26, 2026; checked October 6, 2026), names the .htaccess file as one of the files most often altered in an infection, along with theme files such as index.php, header.php and footer.php, because a change there can affect every page request.
You may not see the redirect yourself. Google's hacked site guidance notes that hacks are often invisible to users while still being harmful to anyone viewing the page. If a customer reports a redirect and the site looks normal to you, believe the customer and check from another device.
How do I know if my WordPress site has been hacked?
You know by the symptoms, which WordPress.org calls indicators of compromise. The ones its guide lists as clear signs are:
- Google, Bing or another service has flagged or blocklisted the site.
- Your host has disabled or suspended the website.
- Visitors say their antivirus software or browser warns them about your site.
- You are told your site is distributing malware or being used to attack other sites.
- Something happened that nobody authorized, such as new user accounts appearing.
- The damage is visible when you open the site: redirects, spam pages or defaced content.
One of these is enough to act on.
What can I safely check in about 10 minutes?
You can gather the facts and read the notices without changing anything on the site. Work through these in order; the password changes in step 6 take a little longer.
- Write it down. Note what you are seeing, the time and time zone you noticed it, and anything changed recently, such as a new plugin. WordPress.org calls this the first actionable step.
- Look from another device. Open the site on a phone using mobile data and in a private browser window. Take screenshots that show the address you end up on. Do not type anything into the site you are redirected to.
- Read your host's messages. Check your email, including spam, and the hosting control panel for a suspension or malware notice. WordPress.org notes the host may be able to confirm whether this is an actual hack or a loss of service.
- Open Google Search Console. If your site is registered, the Security issues report shows whether Google has detected hacked content, malware and unwanted software, or social engineering, with sample affected pages.
- Look at the Users screen. If you can still log in to WordPress, open Users and note the username and email address of any administrator you do not recognize. Leave removal to your developer.
- Change passwords from a clean computer. Run a full antivirus scan on the computer you normally use first; WordPress.org warns that many infections begin on the owner's own machine. Then set long, unique passwords for WordPress, the hosting control panel, FTP or SFTP, and the email account linked to them.
- Ask your host three questions. Can they put up a temporary maintenance notice? What backups do they hold and for which dates? How long do they keep access logs?
What should I not do when my WordPress site is hacked?
Do not delete, restore or reinstall anything yourself, and do not ask Google for a review until the problem is fixed.
Why is deleting suspicious files risky?
Deleting files removes the evidence that shows how the attacker got in, and it rarely removes the whole infection. WordPress.org notes that hacks often add new files as well as changing existing ones, so removing the one file you spotted usually leaves others behind. It also recommends taking one more snapshot of the site before cleaning, even though it is infected, so there is a copy to refer to.
Why not just restore an old backup?
An old backup brings back the same weakness the attacker used, and it may already contain the infection if the break-in happened before the symptoms appeared. Restoring also overwrites everything added since that backup, which can include orders, form entries and new content. A developer may well use a backup, but only after saving the current state first.
What else should I avoid?
Avoid the reinstall button in the WordPress dashboard; WordPress.org says those installers often only overwrite existing files and miss the files a hack added. Avoid installing cleanup tools from unfamiliar websites, since the WordPress hardening guide says to get plugins and themes only from the WordPress.org repository or well known companies. And do not treat a password change as the fix. WordPress.org describes it as one small piece of a larger problem and says to change passwords again once the site is clean.
When should I call a developer, and what should I have ready?
Call a developer as soon as you have confirmed any one sign, because finding and removing the hack means working with files, the database and server logs. That includes removing rogue users, replacing WordPress core files, resetting the secret keys that log everyone out, changing the database password, and deciding whether to restore a backup. Have this ready:
- Your written notes and screenshots, with times.
- The host's notice, and the name of your hosting plan.
- Logins for WordPress, the hosting control panel and Search Console (send them through a password manager, not plain email).
- The dates of available backups and how long the host keeps logs.
- A list of who has admin access, and whether the site takes payments or stores customer details.
If personal data may have been exposed, whether you must notify customers or a regulator depends on where you operate and what was accessed. Ask a qualified adviser; this is not legal advice.
How long do Google and browser warnings last after cleanup?
They last until Google reviews the site and confirms the problem is gone. Google's Security issues report page says affected sites can show a warning label in search results or a full-page browser warning, and that after you select Request Review a review can take from a few days to a few weeks (as of October 6, 2026). The same page warns that requesting a review before the issue is actually fixed can lengthen the turnaround, so leave that button to the person doing the cleanup.
For technical readers
If the site is taken offline during cleanup, serve a 503 Service Unavailable response, which MDN describes as the status for temporary conditions, ideally with a Retry-After header.
How do I stop my WordPress site being hacked again?
You reduce the risk by keeping the software current, tightening access and making sure someone is responsible for the site. The WordPress hardening guide recommends always running the latest version of WordPress, using strong passwords with two-step authentication, taking regular backups that include the database and are kept in a trusted location, and avoiding plugins or themes from untrusted sources. Remove administrator accounts nobody uses, and register the site in Google Search Console so security alerts reach you by email.
Ask your developer for a written explanation of how the attacker got in. Our web application security checklist for business covers the wider set of controls.
Quick answers
Why is my WordPress site redirecting to another website?
A WordPress site that redirects visitors to an unrelated website has usually been compromised, with files such as .htaccess or theme files changed without permission. Check your hosting company's notices and Google Search Console's Security issues report to confirm.
Should I restore a backup if my WordPress site is hacked?
Not on your own. An old backup can contain the same weakness or the infection itself, and restoring it overwrites recent orders and content and the evidence of how the attacker got in. Let a developer save the current state and choose the backup.
Is changing my WordPress password enough after a hack?
No. WordPress.org describes password changes as one small piece of the response. Change passwords for WordPress, hosting, FTP or SFTP and email from a clean computer, then change them again after the site has been cleaned.
How long does Google take to remove a hacked site warning?
Google says a security review can take from a few days to a few weeks after you request it in Search Console, as of October 6, 2026. Requesting a review before the problem is fixed can make it take longer.
Conclusion
A hacked or redirecting WordPress site is recoverable. Record the symptoms, read the host's notice, check Search Console, change passwords from a clean computer, and leave files and backups alone until someone qualified has looked.
Entrant Technologies builds websites, web applications, mobile apps and custom software. If you have no developer available, contact us and we will take a look.