The most reliable signs are a security warning in Google Search Console, visitors being redirected to sites you do not recognise, administrator accounts you did not create, and pages that look normal to you but show spam content to Google. Many WordPress compromises are deliberately hidden from logged-in administrators, so the site looking fine when you check it proves very little.
Below are nine signs, roughly in order of how conclusive they are, followed by how to check properly and what is usually a false alarm.
This is the closest thing to proof.
Google flags security issues under Security and Manual Actions, and if there is a notice there, something has been detected on your site. It is also the sign most businesses miss, because nobody has Search Console set up or nobody is monitoring the alerts.
Particularly when the redirect only happens for some visitors: on mobile but not desktop, or only for people arriving from a search result rather than typing your address directly.
That selectivity is a deliberate tactic to keep the site owner from noticing, and it is a strong indicator rather than a coincidence.
Check Users in your WordPress admin. Any administrator account you cannot account for is a serious sign.
Look at the registration dates too, because an attacker will often create an account that looks unremarkable in a list of thirty users.
Search your own domain in Google using site: followed by your address, and read the descriptions. If they mention pharmaceuticals, casinos, replica goods or anything else unrelated to your business, your pages are serving different content to search engines than to you.
This is the most common form of WordPress compromise and the easiest one to have for months without noticing.
Not sure what you are looking at?
If you have found something and cannot tell how serious it is, a second opinion takes minutes. Get in touch with our team and we will help you work out what you are dealing with.
Through your hosting file manager or SFTP, sort your WordPress files by date modified. If core files, theme files or anything in wp-includes changed on a date when nobody touched the site, that needs explaining.
Be aware that sophisticated attacks alter timestamps, so this test can produce false negatives.
Bounce messages for emails you never sent, a sudden spike in outbound mail, or your domain appearing on a spam blacklist.
Compromised sites are frequently used as mail relays, and this one costs you twice, because it damages your legitimate email deliverability at the same time.
Unexplained load usually means the server is doing work for somebody else, whether that is sending spam, mining, or being used to attack other sites.
On its own this is weak evidence, since plenty of things slow a site down, but combined with anything else on this list it is meaningful.
Hosts monitor for malicious activity and will often detect a compromise before you do.
If they have suspended the account, treat that as confirmed rather than as a possibility, and ask them for the logs. They frequently have server-side detail you cannot see yourself.
A plugin you do not remember installing, or one that has no entry in the WordPress plugin directory, is worth investigating.
So is a plugin that quietly fails to update, because attackers sometimes disable update mechanisms to protect the vulnerability they are using.
If you have seen one or more of the above, four checks will usually settle it.
It's always worth ruling out the ordinary before assuming the worst.
Stop reading and start acting, in the right order. We've written a blog on exactly what to do in the first hour, including the mistake most people make immediately.
Possibly. Many WordPress compromises are designed to stay hidden from logged-in administrators and only show malicious content to search engines or to visitors arriving from Google. Checking in a private browsing window, and checking Google Search Console, is more reliable than looking at the site while logged in.
Google Search Console will tell you if Google has detected a security issue, and it costs nothing. Combine it with a free malware scanner and a check of your WordPress user list for accounts you do not recognise. Between those three you will catch most common compromises.
Constantly, and automatically. Every public WordPress site receives ongoing automated login attempts and vulnerability probes regardless of its size or traffic. That is background noise rather than a cause for alarm. What matters is whether any of it succeeds, which comes down to how current your plugins are and how strong your credentials are.
Yes. Injected spam content, redirects and malware warnings all damage rankings, and Google may label the site as unsafe in search results, which affects click-through even where positions hold. Recovery is normal once the site is clean and you have requested a review, but it takes time, and the longer the compromise ran the longer it takes.
Most of the businesses that call us found out something was wrong from a customer, or from Google. Proper monitoring means you hear about a problem before your visitors do. We build and maintain WordPress sites for businesses across the UK, with security handled during the build rather than bolted on afterwards.
To find out more, visit our build page.