How to Tell If Your WordPress Site Has Been Hacked (7 Warning Signs)

By Catcher24

Aug 03, 2026

How to Tell If Your WordPress Site Has Been Hacked (7 Warning Signs)

Most WordPress site hacks don't announce themselves. There's no ransom note, just quiet changes that bleed away your traffic, your trust, and sometimes your Google ranking before you ever notice. The good news: the signs are recognizable once you know what to look for.

Here are seven of the most common, and how to confirm what's actually going on.

1. Your site redirects somewhere you don't recognize

You (or your visitors) type your address and land on a different site, often spammy or sketchy. Redirect hacks frequently target visitors from search engines or mobile devices specifically, so you might not see it when you visit directly. If readers mention being "sent somewhere weird," take it seriously.

2. There are admin accounts you didn't create

Go to Users → All Users and look for administrators you don't recognize. Attackers often create a hidden admin account to keep access even after you patch the original hole. An unfamiliar admin is one of the clearest signs something is wrong.

3. Browsers or Google show a warning

A red "Deceptive site ahead" screen, or a "This site may be hacked" label under your result in Google, means a security system has already flagged you. By this point the damage to trust, and traffic, is underway, so treat it as urgent.

4. Strange content or "pharma" spam appears

New posts or pages you didn't write, gibberish text, or links to pharmaceuticals, counterfeit goods, or gambling, often invisible on the page but visible to Google. This "pharma hack" hijacks your site's reputation to rank someone else's spam.

5. Unfamiliar files, plugins, or scheduled tasks

A plugin you never installed, oddly named files in your directories, or unexpected scheduled tasks (cron jobs) are red flags. Attackers hide backdoors in places that look almost legitimate.

6. Your site is suddenly slow or behaving oddly

Compromised sites are often quietly put to work sending spam, mining, or attacking other sites, which drains resources. Unexplained slowdowns, spikes in server load, or your host emailing you about "unusual activity" are worth investigating.

7. Your traffic drops, or you've been blocklisted

A sudden, unexplained fall in organic traffic can mean Google has flagged or de-indexed you, or that your domain landed on a blocklist. Check Google Search Console for security notices.

How to confirm it

Warning signs aren't proof, and panicking helps no one. The fastest way to understand your exposure is to scan your site from the outside, the way an attacker sees it. A scan shows you which known weaknesses are present and how someone could have gotten in.

One honest note: a vulnerability scan tells you how you could be (or were) compromised. If you suspect active malware, you'll also want a malware or integrity check to find code that's already on the site.

What to do if you've been hacked

Don't delete everything in a panic. In short: take a backup of the current state for evidence, change all passwords (WordPress, hosting, database, FTP), update everything, remove unknown users and files, and restore from a known-clean backup if you have one.

How to stop it from happening again

Look back at almost any WordPress hack, and you'll find the same root cause: a known vulnerability that was left unpatched. The fix isn't more anxiety; it's visibility. Scan your site regularly so a new exposure reaches you before it reaches an attacker.

vector

Secure WordPress For Free

Catch known CVEs before they are exploited. Install our plugin to run automated vulnerability checks on your themes, plugins, and core directly from your admin panel.

Free for new sign-ups · No credit card · Setup in minutes

logo

Similar posts