WordPress Site Hacked? Here’s the Recovery Checklist We Actually Use

WordPress Site Hacked? Here’s the Recovery Checklist We Actually Use — HD Web Mobile

If your WordPress site is hacked, the next hour matters more than the next week. Spam redirects, defaced pages, a Google “This site may be hacked” warning, or a hosting suspension notice all mean the same thing: something got in, and every minute it stays live is more damage to your rankings, your reputation, and your visitors. A WordPress site hacked today can be flagged by Google and indexed with spam within hours, so speed matters as much as thoroughness. This is the exact checklist we run through when a client’s site is compromised, in the order we run it.

WordPress Site Hacked? The First 15 Minutes

Before touching a single file, take the site offline or put it in maintenance mode so the malware can’t keep serving spam pages, redirecting visitors, or infecting other sites through your server. If you have hosting-level access, isolate the account from shared resources if your host allows it.

Next, change your hosting account password immediately, even before you know how the breach happened. Attackers who compromised WordPress often also grabbed FTP or hosting credentials, and leaving those open lets them back in the moment you think you’ve cleaned up.

Confirm What Actually Happened

Don’t guess — check. Before you can fix a WordPress site hacked by malware, you need to know exactly what changed: compare your current file list against a known-clean backup or a fresh WordPress install to spot files that shouldn’t exist, especially in wp-content/uploads and inside theme folders, where malware loves to hide PHP files disguised as images. Look at recently modified file timestamps; malware injections almost always touch files right around the breach window.

Check the Users screen for any admin account you didn’t create, and review recent posts and pages for spam content or hidden links, which is one of the most common signs a WordPress site is hacked for SEO spam rather than defacement.

Clean the Malware or Restore From a Clean Backup

If you have a backup from before the infection, restoring it is almost always faster and safer than manually hunting down every injected file. This is exactly why we push every client toward a real backup routine before anything goes wrong — see our backup plugin recommendations if you’re not already covered.

No clean backup? Reinstall WordPress core files fresh from wordpress.org, replace every plugin and theme with a fresh copy from the original source, and manually inspect any custom code or uploads that can’t simply be replaced. Don’t just delete the obvious malware and call it done — attackers frequently leave backdoors elsewhere so they can walk right back in.

Reset Every Credential, Not Just WordPress

Once the site is clean, reset every password that touches it: WordPress admin accounts, hosting/cPanel, FTP/SFTP, database, and any connected services like your CDN or SMTP provider. Rotate API keys and secret keys in wp-config.php too, since a leaked AUTH_KEY or SECRET_KEY can let an attacker forge valid login sessions even after passwords change.

Harden the Site So It Doesn’t Happen Twice

A cleaned site with the same weak setup that let the attacker in the first time will get hit again, often within days. Update WordPress core, every plugin, and your theme to the latest version, since outdated software is still the single biggest entry point. Add two-factor authentication on all admin accounts, limit login attempts, and remove any plugin or theme you’re not actively using.

We’ve written a full walkthrough of the settings and plugins worth prioritizing in our WordPress security hardening checklist, and WordPress.org maintains an excellent technical reference in its own hardening documentation if you want to go deeper on server-level protections.

When to Bring In Help

If the site handles customer data, payments, or you can’t confidently confirm every backdoor is gone, it’s worth having someone experienced verify the cleanup rather than relaunching and hoping. A WordPress site hacked once and cleaned poorly tends to get reinfected, and each round costs more in downtime and lost trust than doing it right the first time.

We handle hacked-site cleanup and hardening for clients regularly, and we’d rather help you fix it properly than watch it happen again next month. If you’re dealing with a compromised site right now, or want a security audit before it becomes a problem, get in touch and we’ll walk through it with you.


Ready to start your project?

Share your brief and we’ll propose the right approach — a full site, a landing page, or a custom plugin.