My WordPress site has been hacked - what to do now

If your site is defaced, redirecting elsewhere, sending spam or flagged with a warning by a browser, act quickly. The longer a compromised site stays online, the more damage is done to your search rankings and email reputation.

What to do first:

  1. Do not just delete the defacement. The way in is still open and the site will be reinfected.
  2. Change your WordPress admin, cPanel and database passwords
  3. Open a support ticket and tell us what you are seeing

We clean up compromised WordPress sites as a service. That means removing the malicious code, finding and closing the hole that allowed it in - usually an outdated plugin, theme or a weak password - and getting the site back online.

Cleaning without closing the entry point is why sites get hacked repeatedly, so we always do both.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

What is included in WordPress Maintenance

Our WordPress Maintenance plans cover the routine work that keeps a site healthy and is easy to...

How to keep WordPress secure

Most compromised sites we see share the same handful of causes. Avoiding them prevents the...