WordPress site hacked? What to do right now
, 6 min read
Steps to recover a hacked WordPress site, why it keeps happening, and the setups that remove the risk.
Spam pages in Google, redirects to strange sites, a warning in Chrome: if your WordPress site has been hacked, act quickly but carefully.
Right now
- Change all WordPress, hosting, FTP and database passwords
- Put the site in maintenance mode if visitors are being redirected
- Take a full backup of the infected site for investigation
- Check Google Search Console for security issues and manual actions
Clean up
- Restore a clean backup from before the hack, if you have one
- Reinstall WordPress core, themes and plugins from official sources
- Remove unknown admin users and unfamiliar files
- Request a review in Search Console once the site is clean
Why it happens again
Most WordPress hacks come through outdated or abandoned plugins and themes. As long as the site depends on many third-party plugins, it needs constant updates and monitoring.
Removing the risk
A Next.js site has no public login page and no plugins to exploit; content lives in a hosted CMS like Sanity. For many businesses that have been hacked once, migrating is cheaper than paying for cleanup and security services year after year.