Skip to content
Nexta Web Solution

Urgent help · Mon–Sat 10 am–7 pm IST

WordPress site hacked? Here is what to do now

Redirects to casino or pharma sites, Japanese pages in Google, a red “deceptive site” warning, or an admin you did not create. It is fixable. What you do in the next hour decides how much you lose.

Do these first, right now

  1. 1Do not delete the site or restore a random backup yet. You may restore the same infection, or lose the evidence of how they got in.
  2. 2Change passwords from a clean device: hosting/cPanel, WordPress admins, FTP and database. Turn on two-factor login.
  3. 3Tell your host. They may already have suspended the account or have scan results and logs.
  4. 4Note what you see: screenshots of the redirect, the Google warning or the spam pages, with times.
Free first check

Get your hacked site checked

A developer looks at your site and tells you what is wrong, free.

  • 5+ years experience
  • 10,000+ clients
  • MSME registered
  • ISO certified
  • PCI DSS certified
  • NIXI accredited

A Nexta project advisor replies within 15 minutes, Mon–Sat 10 am–7 pm IST. Outside these hours, by 10:30 am the next working day.

We use your name and number only to reply about your enquiry. See our Privacy Policy to withdraw consent or raise a complaint.

Four quick taps help us send the right price.

  • 5+ years experience · 10,000+ clients

    Businesses in India, the UK, the Gulf and beyond

  • MSME · ISO · PCI DSS · NIXI

    Registered, certified and accredited. See details

  • Registered Pvt Ltd company

    CIN U62099WB2024PTC267968 · 2 offices in Hooghly

  • A real person on WhatsApp

    Reply within 15 minutes in office hours

How hacked WordPress sites are fixed properly

A real cleanup has four parts: find every infected file and database entry (not just the obvious one), close the hole they used, usually an outdated plugin, a nulled theme or a stolen password, restore clean core files and harden the site, then ask Google to review it so warnings and spam pages drop out of search. Skipping the second part is why many “cleaned” sites are hacked again within days.

Signs you may be seeing

  • Visitors on mobile are redirected to spam, casino or adult sites
  • Google shows Japanese or pharma pages under your domain (the “Japanese keyword hack”)
  • Chrome shows “Deceptive site ahead” or Search Console reports a security issue
  • New admin users or unknown plugins appear
  • Your host suspended the account for malware or sending spam
  • The site is slow and CPU usage is high for no reason

The usual causes

Outdated plugins and themes

Most WordPress infections come through a plugin with a known vulnerability that was never updated.

Nulled (pirated) themes or plugins

Free downloads of paid themes often contain backdoors from day one.

Weak or reused passwords

Admin, FTP or hosting passwords leaked elsewhere and tried automatically.

Fix it yourself: step by step

If you have access and some confidence, you can try these. Stop if anything looks unfamiliar; a wrong step can make it worse.

  1. 1

    Take a full backup of the infected site

    Files and database, as they are now. You need it for analysis and in case something goes wrong.

  2. 2

    Check Search Console

    Open Security & Manual Actions → Security issues to see what Google found and sample URLs.

  3. 3

    Remove unknown admins and plugins

    In WordPress Users, delete administrators you do not recognise. Deactivate plugins you did not install.

  4. 4

    Reinstall WordPress core

    Dashboard → Updates → Re-install. This replaces core files but not themes, plugins or uploads, where most malware hides.

  5. 5

    Scan with a security plugin

    Run a malware scan and review flagged files in wp-content, especially PHP files inside uploads, which should not exist there.

  6. 6

    Request a review

    Once clean, request a review in Search Console. Google usually processes it within a few days.

What we do

  1. Free first check same day

    We look at the symptoms, Google’s report and the host’s scan and tell you how bad it is.

  2. Full cleanup usually within 24 hours

    Files and database, including hidden backdoors, fake admins, spam pages and injected redirects.

  3. Close the entry point

    Update or replace vulnerable plugins, remove nulled code, reset all credentials and keys.

  4. Harden and monitor

    Firewall rules, file-change monitoring, login protection and daily off-site backups.

  5. Clear Google

    Remove spam URLs (they should return 404 or 410), resubmit the sitemap and request a security review.

Price

The first check is free. You get a fixed quote before any paid work starts. On our Priority maintenance plan (₹4,999/month + GST) site-down issues are fixed the same day; plans start at ₹999/month.

How to stop it happening again

  • Update WordPress, plugins and themes every week, or put it on a maintenance plan that does.
  • Never install nulled themes or plugins.
  • Use unique passwords and two-factor login for every admin and the hosting account.
  • Keep daily off-site backups for at least 30 days.
  • Remove plugins and admin accounts you no longer use.
  • Use hosting with malware scanning and a web application firewall.

See maintenance plans : updates, daily backups, uptime monitoring and change hours every month.

Questions people ask in a panic

Call +91 7500-4300-91 or WhatsApp us now.

Most sites are cleaned within 24 hours of access. Removing the spam pages from Google takes longer: usually days to a few weeks after the site is clean.

Normally no. We clean the existing site rather than rebuild it. If the database is badly damaged, we restore content from the cleanest backup.

Usually because the hole was not closed: a vulnerable plugin, a backdoor that was missed, or an unchanged password.

Google removes it after a successful review. We clean the site, then request the review from your Search Console.

Yes. Hosts usually allow access for cleanup, or give a copy of the files. We work with them to get the account restored.

Yes, including Joomla, PHP and custom sites. WordPress is simply the most common.

Get a developer on it today

Send your website address on WhatsApp. A developer replies within 15 minutes in office hours with what is wrong and what it takes to fix.