Insights

How to tell if your WordPress site has been hacked

Written by Alison | Aug 18, 2026, 4:29:08 PM

The most reliable signs are a security warning in Google Search Console, visitors being redirected to sites you do not recognise, administrator accounts you did not create, and pages that look normal to you but show spam content to Google. Many WordPress compromises are deliberately hidden from logged-in administrators, so the site looking fine when you check it proves very little.

Below are nine signs, roughly in order of how conclusive they are, followed by how to check properly and what is usually a false alarm.

 

1. A security warning in Google Search Console.

This is the closest thing to proof.

Google flags security issues under Security and Manual Actions, and if there is a notice there, something has been detected on your site. It is also the sign most businesses miss, because nobody has Search Console set up or nobody is monitoring the alerts.

 

2. Visitors are redirected somewhere else

Particularly when the redirect only happens for some visitors: on mobile but not desktop, or only for people arriving from a search result rather than typing your address directly.

That selectivity is a deliberate tactic to keep the site owner from noticing, and it is a strong indicator rather than a coincidence.

 

3. Administrator accounts you do not recognise

Check Users in your WordPress admin. Any administrator account you cannot account for is a serious sign.

Look at the registration dates too, because an attacker will often create an account that looks unremarkable in a list of thirty users.

 

4. Your pages show different content to Google than to you

Search your own domain in Google using site: followed by your address, and read the descriptions. If they mention pharmaceuticals, casinos, replica goods or anything else unrelated to your business, your pages are serving different content to search engines than to you.

This is the most common form of WordPress compromise and the easiest one to have for months without noticing.

 

Not sure what you are looking at?

If you have found something and cannot tell how serious it is, a second opinion takes minutes. Get in touch with our team and we will help you work out what you are dealing with.

5. Files with modification dates that do not match anything you did

Through your hosting file manager or SFTP, sort your WordPress files by date modified. If core files, theme files or anything in wp-includes changed on a date when nobody touched the site, that needs explaining.

Be aware that sophisticated attacks alter timestamps, so this test can produce false negatives.

 

6. Your server is sending email you did not send

Bounce messages for emails you never sent, a sudden spike in outbound mail, or your domain appearing on a spam blacklist.

Compromised sites are frequently used as mail relays, and this one costs you twice, because it damages your legitimate email deliverability at the same time.

 

7. The site has slowed down or your hosting resource use has jumped

Unexplained load usually means the server is doing work for somebody else, whether that is sending spam, mining, or being used to attack other sites.

On its own this is weak evidence, since plenty of things slow a site down, but combined with anything else on this list it is meaningful.

 

8. Your host has contacted you, or suspended the account

Hosts monitor for malicious activity and will often detect a compromise before you do.

If they have suspended the account, treat that as confirmed rather than as a possibility, and ask them for the logs. They frequently have server-side detail you cannot see yourself.

 

9. Unfamiliar plugins, or plugins that will not update

A plugin you do not remember installing, or one that has no entry in the WordPress plugin directory, is worth investigating.

So is a plugin that quietly fails to update, because attackers sometimes disable update mechanisms to protect the vulnerability they are using.

 

How to check your website properly.

If you have seen one or more of the above, four checks will usually settle it.

  1. Open Google Search Console and read the Security Issues report. If you don't have Search Console, set it up. It's free and is a useful monitoring tool to have on your website.

  2. Run a reputable malware scanner against the site. A scanner won'talways find everything, but it will find most common infections quickly.
  3. View your site in a private browsing window, and again from a mobile device arriving via a Google Search result. Compromises that hide from administrators frequently reveal themselves this way.

  4. Ask your host to check their service logs for the period you are suspicious about, then tell them what you've seen.

 

What is probably not a compromise.

It's always worth ruling out the ordinary before assuming the worst.

  • A sudden traffic drop on its own is far more often an algorithm update, a tracking problem, or seasonality than a hack.

  • A single strange comment is spam, not a compromise. Comment spam is constant and largely harmless.

  • A plugin conflict after an update will break layouts and functionality, and looks alarming, but is a different problem entirely.

  • An expired SSL certificate produces a browser warning that looks like a security alert and is simply an administrative lapse.

  • Failed login attempts in a security log are normal background noise. Automated attempts run against every WordPress site continuously. Successful ones are the concern.

 

If it is confirmed.

Stop reading and start acting, in the right order. We've written a blog on exactly what to do in the first hour, including the mistake most people make immediately.


 

Common questions, answered.

Has my WordPress site been hacked if it looks normal?

Possibly. Many WordPress compromises are designed to stay hidden from logged-in administrators and only show malicious content to search engines or to visitors arriving from Google. Checking in a private browsing window, and checking Google Search Console, is more reliable than looking at the site while logged in.

 

How can I check if my WordPress site is hacked for free?

Google Search Console will tell you if Google has detected a security issue, and it costs nothing. Combine it with a free malware scanner and a check of your WordPress user list for accounts you do not recognise. Between those three you will catch most common compromises.

 

How often are WordPress sites attacked?

Constantly, and automatically. Every public WordPress site receives ongoing automated login attempts and vulnerability probes regardless of its size or traffic. That is background noise rather than a cause for alarm. What matters is whether any of it succeeds, which comes down to how current your plugins are and how strong your credentials are.

 

Does a hacked site affect SEO?

Yes. Injected spam content, redirects and malware warnings all damage rankings, and Google may label the site as unsafe in search results, which affects click-through even where positions hold. Recovery is normal once the site is clean and you have requested a review, but it takes time, and the longer the compromise ran the longer it takes.

 

Would you rather find out automatically than by accident?

Most of the businesses that call us found out something was wrong from a customer, or from Google. Proper monitoring means you hear about a problem before your visitors do. We build and maintain WordPress sites for businesses across the UK, with security handled during the build rather than bolted on afterwards.

To find out more, visit our build page.