“Have you ever had your WordPress website hacked?” It is one of the most common questions I hear from business owners, usually asked the day after it happened to them. A hacked site is stressful, but it is not the mystery it feels like in the moment. The cleanup is a repeatable process, and if you work through it in order, you can get a site clean and keep it clean.
A hacked WordPress site can be cleaned by working in a specific order: limit the damage first, change every password from a clean device, back up the site as it is, scan and remove the malware, replace the core WordPress files and any infected plugins or themes, update everything, then clean the Google warning and lock the site down. Do not patch it piecemeal, and do not leave the backdoor the hacker used, or the hack comes back.
Key Takeaways
- The order matters. Change passwords and take the site offline before you start deleting things.
- A hack usually leaves a backdoor. If you only remove the visible damage, the site gets reinfected.
- Replacing the core WordPress files and reinstalling clean plugins is faster and safer than hunting for every infected file.
- After cleanup, submit a review in Google Search Console so the warning lifts and your rankings recover.
Stop the Bleeding First

When you first notice a hack, the instinct is to start deleting files. Resist it. Deleting the wrong thing makes recovery harder and can destroy the only copy of what happened.
Do these three things first, in this order.
- Take the site offline or put it in maintenance mode. This stops the infected site from spreading malware to visitors and stops the hacker from continuing to poke around. Most hosts have a one-click “suspend” option or a maintenance mode setting.
- Change every password from a clean device. Hosting control panel, WordPress admin, FTP or SFTP, database, and any email accounts tied to the site. Use a machine you know is clean. If you change passwords on an infected computer, the hacker may already have them.
- Back up the site as it is. Yes, back up the hacked version before you change anything else. You want a snapshot to restore from if a removal step goes wrong, and it gives you something to inspect for what the hacker actually did.
The Cleanup, Step by Step

Now you work through the actual removal. The goal is not to patch the visible damage. It is to remove the infection and the way the hacker got in.
Step 1. Scan and find the infection. Install a security plugin like Wordfence or run your host’s malware scanner if it has one. You want a list of infected or suspicious files. Note where they are. Plugins, themes, and the wp-config.php file are the usual hiding spots.
Step 2. Replace the WordPress core files. The cleanest way to remove infected core files is not to edit them. It is to replace them with a fresh copy of WordPress from wordpress.org. Delete the wp-admin and wp-includes folders and the root files, then upload a clean copy. Your wp-content folder holds your themes, plugins, and uploads, and it gets handled separately.
Step 3. Remove the backdoor. A backdoor is a small file the hacker left behind so they can get back in after you clean the site. Common spots are wp-config.php, .htaccess, functions.php, and any randomly named file that does not belong. Delete unknown admin users from the WordPress users list, and check for any users you did not create.
Step 4. Reinstall plugins and themes from official sources. Do not keep the existing copies. Delete every plugin and theme, then reinstall the ones you actually use from the WordPress repository or the developer’s site. This removes any infected plugin or theme files in one pass.
Step 5. Change the security keys. In wp-config.php, generate new authentication keys and salts from the WordPress secret-key generator and paste them in. This logs everyone out and invalidates old sessions.
Step 6. Update everything. Now that the files are clean, update WordPress core, plugins, and themes to the latest versions. Most hacks get in through outdated software, so this closes the door you just cleaned.
Step 7. Clear the Google warning. If Google flagged your site, it now shows a red warning in search results. After the site is clean, go to Google Search Console and request a review. Google re-scans the site and lifts the warning when it confirms the malware is gone.
How to Keep It Clean

Cleaning a hack is one job. Staying clean is a different one, and it is where most sites slip.
- Run automatic updates for WordPress core, plugins, and themes.
- Delete unused plugins and themes. Old, abandoned plugins are the most common entry point.
- Use strong passwords and two-factor authentication on every admin account.
- Take automatic backups that you can restore in one click.
- Add a firewall and a malware scanner that run on their own.
None of this is hard. It is consistent. A site that does these five things gets hacked far less than a site that relies on remembering to check.
When to Call Someone
You can clean a hacked site yourself if you are comfortable with files and have the time. Most business owners are not, and that is fine. The risk of doing it wrong is not just a lingering hack. It is the cost of downtime and the search rankings you lose while the warning sits up.
A single serious hack can easily cost more than a year of a maintenance plan, in cleanup fees, lost leads, and the SEO hit. That is the argument for preventing it before it happens. My web maintenance and hosting service covers updates, backups, security monitoring, and malware cleanup from PHP 6,000 a month. If your site is already hacked and you want it handled, I do that too, and I have walked more than a few Baguio City businesses through exactly this recovery.
If you want to know what it costs to prevent a hack versus clean one up, my breakdown of WordPress maintenance costs lays out the real numbers.
Table of Contents
About the Author
Jude Pudlao is a freelance web designer and SEO specialist based in Baguio City, Philippines. He builds WordPress websites for small businesses that need to get found on Google and convert visitors into customers.
His work combines design, development, and search optimization so his clients get websites that look professional and actually perform.
Let's work together.
Over 6 years of experience. Results you can measure. Websites that do the selling for you.
Frequently Asked Questions
How do I know if my WordPress site is hacked?
The common signs are a defaced homepage, the site redirecting somewhere else, strange new admin users, spam links appearing on your pages, a sudden drop in traffic, or a red “this site may be hacked” warning in Google. If you see any of these, scan the site right away.
Can I clean a hacked WordPress site myself?
Yes, if you are comfortable working with files and can follow the steps in order. The risk is leaving a backdoor behind. If you are not sure, or the site makes money, hiring someone to do it cleanly is usually cheaper than a botched job.
How long does it take to clean a hacked WordPress site?
A straightforward cleanup takes a few hours. The Google warning review can add a few days while Google re-scans the site. The faster you start, the less damage the hack and the downtime do.
Will Google remove the warning after I clean my site?
Yes, but not automatically. After the site is clean, request a review in Google Search Console. Google re-checks the site and lifts the warning once it confirms the malware is gone.
How much does it cost to fix a hacked WordPress site?
It depends on how deep the hack goes. A simple cleanup is quick. A serious infection with a lost backup can run into real money and lost rankings. That is why prevention, like a PHP 6,000 a month maintenance plan, usually costs less than a single emergency.
Ready to Redesign Your Website?
A website that is slow, outdated, or hard to update is not a marketing asset. It is a liability. I build WordPress websites with speed, SEO, and conversion built in from the start.




