How to Clean a Hacked WordPress Site in 2026
A safe incident-response checklist for hacked WordPress sites: containment, evidence, cleanup, credential rotation, restoration and hardening.
A hacked WordPress site is an incident, not merely a plugin problem. The visible redirect or spam page may be one symptom while backdoors, rogue administrators and scheduled reinfection remain hidden. If the site processes payments or personal data, involve qualified incident-response and legal/privacy professionals.
Affiliate disclosure: This guide contains affiliate links. We may earn a commission at no additional cost to you.
1. Contain the Incident
Put the site behind maintenance controls, restrict administrator access and contact the host. Do not browse infected pages from a normal workstation. Preserve web, authentication and CDN logs plus a snapshot of the affected server before making broad changes.
2. Protect Users and Accounts
If credentials or personal data may have been exposed, follow applicable breach-notification requirements. From a known-clean device, rotate hosting, registrar, CDN, SFTP, SSH, database, email and WordPress credentials. Revoke sessions and API keys; do not reuse a password that passed through the compromised site.
3. Choose Restore or Cleanup
A verified clean backup from before the intrusion is usually safer than editing infected files one by one. Restore into an isolated environment, patch the vulnerable component, scan it and only then return it to production. If no trustworthy backup exists, compare WordPress core and extensions against clean vendor packages and inspect uploads, database options, scheduled tasks, must-use plugins and administrator accounts.
4. Use Professional Cleanup When Needed
Business-critical stores, memberships and repeatedly reinfected sites warrant specialist help. Sucuri's platform includes malware-removal requests alongside its WAF, which can reduce exposure while remediation is underway.
Request Sucuri malware cleanup →
5. Close the Entry Point
Common causes include vulnerable plugins, abandoned themes, stolen passwords, exposed hosting panels and infected administrator devices. Update or remove the vulnerable component, enforce two-factor authentication, reduce administrator privileges, block unnecessary PHP execution in upload directories and replace secret keys.
6. Validate the Clean Site
Scan from more than one layer, review recent file changes, check outbound requests, verify DNS and search-engine results, and monitor new administrator creation. Test forms, checkout and scheduled jobs. Keep enhanced logging during the observation period.
7. Request Search-Engine Review
After cleanup, confirm that malicious URLs return appropriate status codes and update the sitemap. In Google Search Console, review Security Issues and request reconsideration with the cause, files/accounts affected and corrective actions. Do not request review before the infection is actually removed.
Prevent Reinfection
- Enable automatic security updates where operationally safe.
- Remove unused plugins, themes and accounts.
- Add an edge firewall and login protection.
- Maintain encrypted, off-site, versioned backups.
- Restore a backup in a test environment every quarter.
- Monitor file changes, uptime, DNS and administrator events.
Compare protection layers in our best WordPress security plugins and read the full Sucuri review.
Frequently Asked Questions
Can a hacked WordPress site be recovered?▾
Should I delete the hacked site immediately?▾
How do I remove Google's hacked-site warning?▾
Marcus founded HostPro Reviews after spending 18 months testing web hosting providers across three continents. He has personally migrated over 60 websites between hosts, evaluated 30+ hosting providers across shared, cloud, VPS, managed, and reseller categories, and published 80+ independent reviews since 2022. His methodology uses automated uptime monitoring across 3 global server locations, standardized GTmetrix and Core Web Vitals benchmarks, and live support response-time tracking — never marketing claims. Marcus holds a degree in Computer Engineering and has worked as a full-stack developer for e-commerce, media, and SaaS companies. He has tested reseller hosting platforms, WHM/cPanel environments, and WHMCS billing setups extensively for agencies evaluating white-label hosting income streams. All pricing and feature data is re-verified monthly; articles carry a lastModified timestamp reflecting each verification date. Last methodology review: July 2026.
View all articles →Free Download
2026 Web Hosting Comparison Cheat Sheet
- ✓11 hosts ranked by speed, uptime & price
- ✓Renewal price traps to avoid
- ✓Best host for WordPress, WooCommerce & agencies
- ✓Exclusive discount codes for 2026
Free · Join 2,400+ readers · Unsubscribe anytime