Urgent help · Mon–Sat 10 am–7 pm IST
WordPress site hacked? Here is what to do now
Redirects to casino or pharma sites, Japanese pages in Google, a red “deceptive site” warning, or an admin you did not create. It is fixable. What you do in the next hour decides how much you lose.
Do these first, right now
- 1Do not delete the site or restore a random backup yet. You may restore the same infection, or lose the evidence of how they got in.
- 2Change passwords from a clean device: hosting/cPanel, WordPress admins, FTP and database. Turn on two-factor login.
- 3Tell your host. They may already have suspended the account or have scan results and logs.
- 4Note what you see: screenshots of the redirect, the Google warning or the spam pages, with times.
-
5+ years experience · 10,000+ clients
Businesses in India, the UK, the Gulf and beyond
-
MSME · ISO · PCI DSS · NIXI
Registered, certified and accredited. See details
-
Registered Pvt Ltd company
CIN U62099WB2024PTC267968 · 2 offices in Hooghly
-
A real person on WhatsApp
Reply within 15 minutes in office hours
How hacked WordPress sites are fixed properly
A real cleanup has four parts: find every infected file and database entry (not just the obvious one), close the hole they used, usually an outdated plugin, a nulled theme or a stolen password, restore clean core files and harden the site, then ask Google to review it so warnings and spam pages drop out of search. Skipping the second part is why many “cleaned” sites are hacked again within days.
Signs you may be seeing
- Visitors on mobile are redirected to spam, casino or adult sites
- Google shows Japanese or pharma pages under your domain (the “Japanese keyword hack”)
- Chrome shows “Deceptive site ahead” or Search Console reports a security issue
- New admin users or unknown plugins appear
- Your host suspended the account for malware or sending spam
- The site is slow and CPU usage is high for no reason
The usual causes
Outdated plugins and themes
Most WordPress infections come through a plugin with a known vulnerability that was never updated.
Nulled (pirated) themes or plugins
Free downloads of paid themes often contain backdoors from day one.
Weak or reused passwords
Admin, FTP or hosting passwords leaked elsewhere and tried automatically.
Fix it yourself: step by step
If you have access and some confidence, you can try these. Stop if anything looks unfamiliar; a wrong step can make it worse.
- 1
Take a full backup of the infected site
Files and database, as they are now. You need it for analysis and in case something goes wrong.
- 2
Check Search Console
Open Security & Manual Actions → Security issues to see what Google found and sample URLs.
- 3
Remove unknown admins and plugins
In WordPress Users, delete administrators you do not recognise. Deactivate plugins you did not install.
- 4
Reinstall WordPress core
Dashboard → Updates → Re-install. This replaces core files but not themes, plugins or uploads, where most malware hides.
- 5
Scan with a security plugin
Run a malware scan and review flagged files in
wp-content, especially PHP files insideuploads, which should not exist there. - 6
Request a review
Once clean, request a review in Search Console. Google usually processes it within a few days.
What we do
Free first check same day
We look at the symptoms, Google’s report and the host’s scan and tell you how bad it is.
Full cleanup usually within 24 hours
Files and database, including hidden backdoors, fake admins, spam pages and injected redirects.
Close the entry point
Update or replace vulnerable plugins, remove nulled code, reset all credentials and keys.
Harden and monitor
Firewall rules, file-change monitoring, login protection and daily off-site backups.
Clear Google
Remove spam URLs (they should return 404 or 410), resubmit the sitemap and request a security review.
Price
The first check is free. You get a fixed quote before any paid work starts. On our Priority maintenance plan (₹4,999/month + GST) site-down issues are fixed the same day; plans start at ₹999/month.
How to stop it happening again
- Update WordPress, plugins and themes every week, or put it on a maintenance plan that does.
- Never install nulled themes or plugins.
- Use unique passwords and two-factor login for every admin and the hosting account.
- Keep daily off-site backups for at least 30 days.
- Remove plugins and admin accounts you no longer use.
- Use hosting with malware scanning and a web application firewall.
See maintenance plans : updates, daily backups, uptime monitoring and change hours every month.
Questions people ask in a panic
Call +91 7500-4300-91 or WhatsApp us now.
Related
- Website maintenance (AMC)Updates, daily backups, uptime monitoring and change hours every month.
- Malware protection & endpoint securityEndpoint security services protect office computers and servers from malware, ransomware and account takeover.
- Server security hardeningServer hardening services reduce the ways a server can be attacked by tightening its configuration.
Get a developer on it today
Send your website address on WhatsApp. A developer replies within 15 minutes in office hours with what is wrong and what it takes to fix.