How to Clean a Hacked WordPress Site (2026 Step-by-Step Guide)
Malware warning, defaced homepage, or Google flagging your site as dangerous — here's exactly what to do in the first hour, and how to fully clean and secure a hacked WordPress site.
First: Don't Panic, But Move Fast
A hacked WordPress site rarely stays "just a little hacked." Attackers use compromised sites to send spam, mine backlinks, host phishing pages, or pivot to other sites on the same server. Every hour it stays live makes cleanup harder and increases the chance your host suspends the account outright.
Here's the order of operations.
Step 1: Confirm It's Actually a Hack
Before doing anything drastic, verify with a scanner rather than guessing:
- Run your URL through Sucuri SiteCheck (free, no login required) — it flags known malware signatures, blacklist status, and defacements
- Check Google Search Console for a "Security Issues" warning
- Look for unfamiliar admin or editor users under Users → All Users
Step 2: Take the Site Offline (or Into Maintenance Mode)
If malware is confirmed, stop it from spreading or serving malicious content to visitors:
- Enable maintenance mode, or password-protect the site at the server level if your host allows it
- Change all passwords immediately — WordPress admin, hosting account, FTP/SFTP, and database — from a different, clean device
- Revoke and reissue any API keys or application passwords
Step 3: Back Up the Infected Site (Yes, Really)
Take a full backup even though it's compromised — you may need it for forensics, and some cleanup attempts make things worse before they make them better. Store this backup separately; don't restore it until it's been cleaned.
Step 4: Remove the Malware
This is where most DIY cleanups go wrong: removing the visible symptom (a defaced page, a spam redirect) without finding the backdoor that let the attacker back in. A proper cleanup means:
- Replacing WordPress core, theme, and plugin files with known-clean copies from the official source
- Diffing your uploads folder and custom code against backups for injected PHP
- Checking your config file, redirect rules, and any must-use plugins for injected backdoors
- Scanning the database for injected script tags or spam links in posts and options tables
- Removing any admin users, scheduled tasks, or files you didn't create
If that list feels like more than a weekend project — it usually is. This is exactly the scenario managed cleanup services exist for: they've seen the same backdoor patterns thousands of times and know where attackers hide persistence.
Get Your Site Cleaned by Sucuri →
Step 5: Close the Entry Point
Cleaning the malware without fixing how it got in guarantees reinfection. Common entry points:
- Outdated plugins or themes with known vulnerabilities (check every installed plugin's version against the latest)
- Weak or reused admin passwords
- Vulnerable or abandoned plugins with no recent updates
- Compromised FTP credentials stored insecurely
Step 6: Prevent It From Happening Again
- Put a firewall in front of the site so malicious requests never reach WordPress — a cloud WAF like Sucuri blocks common attack patterns before they hit your server
- Turn on two-factor authentication for all admin accounts
- Keep WordPress core, themes, and plugins updated — set a weekly reminder if you don't use auto-updates
- Remove any plugins or themes you're not actively using
Verdict: DIY vs Managed Cleanup
If you're technical, have clean recent backups, and can dedicate a few focused hours, manual cleanup is doable. If the site generates revenue, handles customer data, or you simply can't afford the downtime and risk of missing a backdoor, a managed service that includes a cleanup guarantee is the faster and safer call.
Related Reviews
Guide reviewed July 2026.
Frequently Asked Questions
How do I know if my WordPress site was hacked?▾
Can I remove WordPress malware myself?▾
How long does it take to clean a hacked WordPress site?▾
Will my host suspend my account if I get hacked?▾
Marcus founded HostPro Reviews after spending 18 months testing web hosting providers across three continents. He has personally migrated over 60 websites between hosts, evaluated 30+ hosting providers across shared, cloud, VPS, managed, and reseller categories, and published 80+ independent reviews since 2022. His methodology uses automated uptime monitoring across 3 global server locations, standardized GTmetrix and Core Web Vitals benchmarks, and live support response-time tracking — never marketing claims. Marcus holds a degree in Computer Engineering and has worked as a full-stack developer for e-commerce, media, and SaaS companies. He has tested reseller hosting platforms, WHM/cPanel environments, and WHMCS billing setups extensively for agencies evaluating white-label hosting income streams. All pricing and feature data is re-verified monthly; articles carry a lastModified timestamp reflecting each verification date. Last methodology review: July 2026.
View all articles →Free Download
2026 Web Hosting Comparison Cheat Sheet
- ✓11 hosts ranked by speed, uptime & price
- ✓Renewal price traps to avoid
- ✓Best host for WordPress, WooCommerce & agencies
- ✓Exclusive discount codes for 2026
Free · Join 2,400+ readers · Unsubscribe anytime