A customer tells you your website is sending them somewhere unfamiliar. Your contact form starts producing spam. Or worse, your online store is still accepting orders while malicious code quietly collects customer information. Knowing how to recover hacked WordPress quickly matters, but speed should not mean guessing.
For a small business, a hacked website is not just an IT problem. It can interrupt calls, bookings, online sales, Google visibility, and the trust you have worked hard to build. The right response is to contain the issue, identify what changed, restore from a safe point, and close the gap that allowed access in the first place.
First, contain the damage
Before changing files or deleting plugins, reduce the hacker’s ability to keep using the site. If you can access WordPress, put the site into maintenance mode or ask your hosting provider to temporarily restrict public access. This is especially urgent if you sell products, take payments, collect form submissions, or provide member logins.
Do not assume the visible problem is the only problem. A defaced homepage is obvious, but many compromises are quieter. Attackers may add hidden administrator accounts, inject spam pages for search engines, redirect mobile visitors, alter payment scripts, or use your hosting account to send email.
Start by recording what you see. Take screenshots of warnings, redirects, unfamiliar users, strange files, or messages from your host. Note when the issue was first noticed and whether staff members recently installed a plugin, changed a password, or shared login access. This information helps establish a timeline and can make cleanup more accurate.
Next, change passwords from a clean device. Update the passwords for WordPress administrators, hosting, domain registration, database access, SFTP or FTP accounts, and every email inbox that can reset those accounts. Use unique, long passwords rather than a variation of the old one. If multiple people have access, reset everyone’s credentials, not just the primary site owner’s.
Confirm whether WordPress was actually compromised
A broken website is not always a hacked website. A failed update, expired SSL certificate, overloaded server, or plugin conflict can all cause errors that look alarming. The distinction matters because restoring a backup over a technical error can create unnecessary downtime or remove recent customer data.
Common signs of a real compromise include unfamiliar WordPress administrator accounts, files with recent modification dates you cannot explain, unexpected redirects, browser security warnings, spam pages appearing in Google, or notices from your host about malware or suspicious activity. Sudden traffic spikes to odd URLs and emails sent from your domain without your knowledge are also warning signs.
Check your WordPress user list for accounts you do not recognize. Review recently modified themes, plugins, and core files through your host’s file manager or SFTP. Look at server logs if they are available. A security scan can identify known malware patterns, but do not treat a clean scan as proof that everything is safe. Some infections are designed to avoid basic detection.
If the website processes payments or stores sensitive customer information, contact your payment provider and host promptly. You may need to take additional steps based on the services you use and the information involved. It is better to pause transactions briefly than to continue operating with an unknown security risk.
How to recover hacked WordPress safely
The most dependable recovery method is usually to restore a verified clean backup, then update and secure the installation before returning it to normal service. The key word is verified. A backup from after the compromise began can simply reinstall the infection.
Start by choosing a backup from before the first known sign of trouble. If you are unsure when the attack started, compare several backup dates and inspect the restored version in a staging environment if your host provides one. For a service business, restoring an older site may be reasonable. For an active e-commerce store, you also need a plan for orders, customer accounts, inventory changes, and form submissions created after that backup was made.
A clean recovery generally involves these actions:
- Back up the current compromised files and database separately for evidence and reference.
- Remove the infected WordPress files rather than attempting to overwrite only the suspicious ones.
- Install a fresh copy of the current WordPress core software.
- Restore only a known-clean database, uploads folder, theme files, and necessary plugins.
- Update WordPress, themes, and plugins before the site goes live.
- Scan the finished site and test its main functions on desktop and mobile.
Be careful with premium themes and plugins. Download fresh copies from the original developer or marketplace using a legitimate account. Do not reinstall an old ZIP file from a desktop folder if you cannot confirm where it came from or whether it has been altered.
The uploads directory deserves special attention. It contains valuable images, PDFs, and media, but it can also contain malicious scripts. A proper cleanup checks that directory for files that do not belong, especially executable files in locations intended only for images or documents.
Manual cleanup can work when the scope is known and the person doing the work understands WordPress file structure, database entries, and server permissions. But it is easy to miss a hidden backdoor. For most business owners, the practical choice is to have an experienced WordPress professional or hosting security team handle the cleanup, particularly after a repeat infection or a payment-related incident.
Check the parts customers and Google can see
A website can appear normal on the homepage while still being compromised elsewhere. After recovery, test the paths that matter to your business: contact forms, booking requests, checkout, account logins, email notifications, search functions, and key pages on a mobile phone.
Search your brand name and a few important services in Google. Look for unfamiliar page titles, spam results, or warnings. Review your Google Search Console account for security messages, indexing problems, and suspicious URLs. If malicious pages were indexed, they may need time to disappear after the site is cleaned, but ignoring them can prolong the damage to search visibility.
Also check outgoing email. A hacked site may have been used to send spam, which can harm the reputation of your domain and interfere with legitimate customer messages. Ask your hosting provider whether they detected unusual mail volume or account activity during the incident.
Close the door that was left open
Recovery is incomplete if the original weakness remains. WordPress itself is widely used and can be secure when it is properly maintained. Most incidents come down to outdated software, weak or reused passwords, abandoned plugins, excessive user access, or a hosting account that was compromised through another service.
Remove plugins and themes you no longer use, including inactive ones. Every extra component is another item that needs updating and evaluating. Keep only software that is actively supported, necessary for the business, and compatible with your current WordPress version.
Limit administrator access to people who genuinely need it. Give staff the lowest access level that allows them to do their work, and remove former employees or contractors as soon as their access is no longer needed. Turn on two-factor authentication for administrator accounts where possible.
Reliable backups are equally important. Keep automatic backups on a schedule that reflects how often your site changes. A brochure-style site may be fine with daily backups. A busy online store may need more frequent backups and a process for protecting recent order data. Store backups separately from the main hosting account so they remain available if the server itself is affected.
Ongoing maintenance is not glamorous, but it prevents expensive surprises. Regular updates, backup checks, security monitoring, plugin compatibility reviews, and performance checks are far less disruptive than emergency recovery work on a Friday afternoon.
When to bring in professional help
Call for help if you cannot identify the infection, the hack returns after cleanup, the site has been blacklisted, or customer data or payments may be involved. You should also get support when you do not have a confirmed clean backup. Guesswork can turn a recoverable website problem into lost orders and a longer search recovery.
At Coastal Webmasters, we help Vancouver Island businesses restore, secure, and maintain WordPress websites with clear communication and practical next steps. You do not need to become a security specialist to make a good decision about your site.
A hacked website creates pressure, but it does not have to define your business. Protect your customers first, restore only what you can verify, and put a maintenance plan in place that gives you fewer emergencies and more time to run the business. If something on your site does not look right, reach out today before a small warning becomes a costly outage.
