How to Tell If Your WordPress Site Has Been Hacked (7 Warning Signs)
By Catcher24
•Aug 03, 2026
Most WordPress site hacks don't announce themselves. There's no ransom note, just quiet changes that bleed away your traffic, your trust, and sometimes your Google ranking before you ever notice. The good news: the signs are recognizable once you know what to look for.
Here are seven of the most common, and how to confirm what's actually going on.
1. Your site redirects somewhere you don't recognize
You (or your visitors) type your address and land on a different site, often spammy or sketchy. Redirect hacks frequently target visitors from search engines or mobile devices specifically, so you might not see it when you visit directly. If readers mention being "sent somewhere weird," take it seriously.
2. There are admin accounts you didn't create
Go to Users → All Users and look for administrators you don't recognize. Attackers often create a hidden admin account to keep access even after you patch the original hole. An unfamiliar admin is one of the clearest signs something is wrong.
3. Browsers or Google show a warning
A red "Deceptive site ahead" screen, or a "This site may be hacked" label under your result in Google, means a security system has already flagged you. By this point the damage to trust, and traffic, is underway, so treat it as urgent.
4. Strange content or "pharma" spam appears
New posts or pages you didn't write, gibberish text, or links to pharmaceuticals, counterfeit goods, or gambling, often invisible on the page but visible to Google. This "pharma hack" hijacks your site's reputation to rank someone else's spam.
5. Unfamiliar files, plugins, or scheduled tasks
A plugin you never installed, oddly named files in your directories, or unexpected scheduled tasks (cron jobs) are red flags. Attackers hide backdoors in places that look almost legitimate.
6. Your site is suddenly slow or behaving oddly
Compromised sites are often quietly put to work sending spam, mining, or attacking other sites, which drains resources. Unexplained slowdowns, spikes in server load, or your host emailing you about "unusual activity" are worth investigating.
7. Your traffic drops, or you've been blocklisted
A sudden, unexplained fall in organic traffic can mean Google has flagged or de-indexed you, or that your domain landed on a blocklist. Check Google Search Console for security notices.
How to confirm it
Warning signs aren't proof, and panicking helps no one. The fastest way to understand your exposure is to scan your site from the outside, the way an attacker sees it. A scan shows you which known weaknesses are present and how someone could have gotten in.
One honest note: a vulnerability scan tells you how you could be (or were) compromised. If you suspect active malware, you'll also want a malware or integrity check to find code that's already on the site.
What to do if you've been hacked
Don't delete everything in a panic. In short: take a backup of the current state for evidence, change all passwords (WordPress, hosting, database, FTP), update everything, remove unknown users and files, and restore from a known-clean backup if you have one.
How to stop it from happening again
Look back at almost any WordPress hack, and you'll find the same root cause: a known vulnerability that was left unpatched. The fix isn't more anxiety; it's visibility. Scan your site regularly so a new exposure reaches you before it reaches an attacker.
Secure WordPress For Free
Catch known CVEs before they are exploited. Install our plugin to run automated vulnerability checks on your themes, plugins, and core directly from your admin panel.
Free for new sign-ups · No credit card · Setup in minutes
Similar posts
Catcher24
•Jul 08, 2026