WordPress security and hacked sites
How to tell whether a WordPress site has been broken into, what to do in the first hour, how to clean it, and how to close the ways in so that it does not happen again.
- By
- WP Ministry
- Published
There are two kinds of security work, and which one you need depends on what you are looking at.
Something looks wrong now. Do not delete anything yet. Check whether the site has been hacked, or run the check from outside, which reads the site as a stranger is served it. If a check comes back positive, follow the first-hour runbook, then the full cleanup.
If you already know what you are looking at, go straight to it: visitors sent to another site, a red warning in the browser, spam pages under your name in Google, an administrator nobody created, a hosting account suspended for malware, or malware that comes back after every cleanup.
Nothing is wrong and you want to keep it that way. The security guide puts the work in order of what it prevents. The measures that stop the most for the least effort are two-factor sign-in, limits on password guessing, correct file permissions, and updates applied safely and on time. An audit tells you where a particular site stands.
If you are getting quotes for a cleanup, what malware removal costs says how cleanup is sold and what a complete one includes.
If you would rather hand it over, malware removal is a cleanup with the way in closed and a written report, and the security service is the upkeep that follows.
Guides
- "Deceptive site ahead" on a WordPress site: what the red warning means and how to get it liftedThe red full-page warning comes from Google Safe Browsing, which most browsers consult. Google found phishing, malware or unwanted software on your site or loaded by it. The warning goes only after the cause is removed and Google has reviewed the site.
- GDPR and WordPress: what the site collects and what to set upA WordPress site collects personal data through comments, forms, accounts, orders, tags from other companies and its server logs. WordPress has a privacy policy page, an export tool and an erase tool. The rest is an inventory, a reason for each thing kept, consent and retention.
- Hosting account suspended for malware: how to get your WordPress site backA host suspends an account to stop a hacked site harming others, and restores it when you show the cause is gone. Ask the host for three things. They are the list of what it found, access to the files and the database, and the steps of its review.
- How to add security headers to a WordPress siteSecurity headers are lines a server sends with each page that tell the browser how to treat it. Add X-Content-Type-Options, Referrer-Policy and a frame rule first, then HSTS with a short max-age, and Content-Security-Policy last, in report-only mode.
- How to audit a WordPress site for security weaknessesA security audit is a written inventory of a working site. It covers what is installed, who can log in, how the site is configured, what it shows from outside, whether a backup restores, and who holds the hosting and domain logins. Each finding gets a date to fix it or a reason to accept it.
- How to change the WordPress login URL, and what it does and does not protectWordPress has no setting for its login address, so a plugin moves it. That cuts down automated requests to wp-login.php. It does not make a password harder to guess, and xmlrpc.php stays where it is. Save the new address before you log out.
- How to check whether your WordPress site has been hackedCheck from outside first, with Google's Security issues report, its Safe Browsing page, a site search and the page as Google is served it. Then check inside, from administrators and checksums to uploads and the access log. Clean results lower the odds and do not prove the site is clean.
- How to disable XML-RPC in WordPress, and when to leave it onxmlrpc.php lets outside programs reach WordPress, and Jetpack and the mobile apps still use it. If nothing on your site does, switch off its login methods with a filter, remove its pingback methods, or refuse the file at the web server. Check the access log first.
- How to install a free SSL certificate on WordPress and move the site to HTTPSGet a free certificate from your host's control panel, or with Certbot on a server you run yourself. Check that the https address works, change WordPress's two addresses to https, redirect http with a 301, then clear what is left over.
- How to protect WordPress from brute force attacksA brute force attack is a program trying one password after another on your login page or on xmlrpc.php. Strong unique passwords and two-factor login make the guessing fail. Login limits, a firewall and server rules cut down how much of it reaches the site.
- How to remove malware from a hacked WordPress siteTake the site offline, keep a copy of it as it is, and change every password and the secret keys. Then restore a backup from before the break-in, or replace WordPress and every plugin with clean copies and check what is left. Finish by finding and closing the way in.
- How to set up two-factor authentication in WordPressInstall the Two Factor plugin, turn on an authenticator app and backup codes in your profile, and test the login before you close the window you are in. Keep the backup codes away from your phone. They are how you get back in when the phone is lost.
- The EU Cyber Resilience Act and WordPress: who it applies to and whenThe Cyber Resilience Act puts its duties on those who supply software on the EU market in the course of a commercial activity, not on a site owner who only uses WordPress. Reporting duties for manufacturers began on 11 September 2026. The rest applies from 11 December 2027.
- The Japanese keyword hack on WordPress: spam pages in Google and how to get them outSomeone has added pages to your site, or made it answer Google differently than it answers people, to sell links and traffic. Clean the site until every spam address answers 404. Then clear Google's index with the Removals tool, a clean sitemap and a review. They are two separate jobs.
- Unknown admin user in WordPress: what it means and how to remove it properlyAn administrator nobody created means someone had the power to make one. Deleting it removes the symptom and leaves the way in. Rule out the innocent explanations, list every account from the database, record what you find, then remove it while you close the hole.
- Why your WordPress site keeps getting hacked, and what finally stops itA WordPress site that is reinfected was either never fully cleaned or is still open the way it was first entered. There are eight reasons, and each one can be checked. A rebuild from clean sources, then new credentials, then updates, deals with them in order.
- WordPress file permissions: what the numbers mean and what to setWordPress's own guidance is 755 for folders, 644 for files and 440 or 400 for wp-config.php, with every file owned by your hosting account. Nothing should be 777. Who owns the files matters as much as the numbers.
- WordPress firewalls compared: plugin, DNS-level or host, and how to chooseA WordPress firewall is a plugin on your server, a service that sits in front of your site, or a filter your host runs. Where it sits decides what it can stop and what it costs to set up. Choose the place first, then the product.
- WordPress search results pages (/?s=) in Google and Search Console: what they are and what to doAn address with ?s= or /search/ in it is your site's own search page, asked for with someone else's words. WordPress puts noindex on every search page, so Google reads it and leaves it out. Check that your site prints the tag. Nothing was added to the site.
- WordPress security plugins compared: what each one does and how to chooseA security plugin scans for malware, guards the login page, switches on hardening settings, filters requests and keeps a log. It does not replace updates, backups or good passwords. Choose by where it does its work and by what its free version leaves out, and run only one.
- WordPress security: what to do, in order of what matters mostKeep WordPress, plugins and themes updated, give every account a strong unique password and two-factor login, and keep a backup you have restored at least once. Those three do most of the work. Roles, HTTPS, file hardening and a firewall come after them.
- WordPress site redirecting to another site: how to tell a hack from a setting, and what to do firstA redirect to a site you did not choose is a sign of a hacked WordPress, but a redirect rule, the site address settings, an expired domain or the visitor's own device can look the same. Check what a visitor is served, look where redirects are planted, and delete nothing until you have a copy.
What it costs
Runbooks and checklists
Tools
- WordPress site health checkGive your site's address and see what one page shows a visitor: whether it answers, how it is secured, what search engines are told, and which WordPress, theme and plugins it shows.
- Is my WordPress site hacked? A check from outsideGive your site's address and see the signs of a break-in that show from outside: visitors from search sent somewhere else, links hidden in the page, code written to hide what it does.
- WordPress salt and security key generatorEight fresh keys and salts for wp-config.php, made in your browser. They are never sent anywhere.
- .htaccess generator for WordPressChoose what you want the server to do and get a complete .htaccess: WordPress's own block, with redirects, closed files, headers and compression above it. Built in your browser.
- WordPress and PHP end-of-life checkerSee whether your PHP and WordPress versions still get security fixes, and until when, from php.net's and WordPress.org's own records.

