The instinct is to start removing suspicious files, but the evidence of how the attacker got in is usually inside those files. Delete it and you will be cleaned up and reinfected within a fortnight.
What follows is what to do in the first hour, in order, and where to stop and get help. If you are not sure whether you have actually been hacked, start with the warning signs instead.
Site down and out of your depth?
If your site is live and compromised, the fastest thing you can do is talk to a developer. Our team is in Manchester and works on WordPress every day. Get in touch, and we will tell you straight away whether this is something you can handle or something you need help with.
Most of the damage in a WordPress compromise happens in the response, not the attack.
Don't delete files you think look suspicious. Without knowing what the attacker changed, you are as likely to break the site as clean it, and you destroy the evidence trail.
Not every compromise is equal, and the response should scale to the severity. Broadly, there are three levels.
Spam links injected into pages or posts, usually invisible to you and visible to Google. Irritating, damaging to rankings, and generally the cheapest to resolve.
Redirects sending your visitors elsewhere, injected scripts, fake admin accounts, or your server being used to send spam. At this point, your domain reputation and your email deliverability are both at risk, and Google may already have flagged you.
Any evidence of database access where customer data, orders or personal information is held. This is no longer a website problem. It is a data breach, and the priority shifts from fixing the site to establishing what was taken.
If you can't confidently place your situation in one of those three, treat it as the level above your guess.
A proper remediation has five parts, and skipping any one of them is why sites get reinfected.
It's almost certainly not because WordPress is insecure.
Security researchers consistently find that the overwhelming majority of WordPress compromises come through plugins and themes rather than WordPress core, followed by weak and unpatched hosting.
Which is uncomfortable, because it means the cause is usually something that was known about and could have been prevented. We have written separately about where the real risk sits and about why so many businesses stop updating.
Once the site is clean, the work that matters is unglamorous: updates applied on a schedule rather than when someone remembers, a staging environment so updates can be tested before they go live, backups that are stored off the server and actually tested, restricted admin access with two-factor authentication, and monitoring that tells you about a problem rather than leaving you to notice it.
None of that is difficult. It just needs to be somebody's job. When it's nobody's job, this article becomes relevant again in about eighteen months.
Yes, like any website on any platform. WordPress is targeted more than most simply because it powers such a large share of the web, which makes automated attacks against it worthwhile at scale. The platform itself is well maintained; the risk almost always sits in what has been added to it.
Compare your installation against clean copies of WordPress core, your theme and your plugins, and look for files whose modification dates do not match a change you made. Malicious code is frequently obfuscated and placed in legitimate-looking files, so a visual scan is unreliable. This is the point at which a scanner or a developer is worth more than an afternoon of your time.
Possibly, temporarily, and it's recoverable. Rankings suffer when Google detects injected content or flags the site as unsafe. Once the site is clean and you have submitted a review request through Search Console, positions usually return, though it can take weeks. The longer a compromise stays live, the longer the recovery.
Sometimes, yet. If the site was already outdated, running abandoned plugins, or built in a way no one can maintain, a clean-up buys you months rather than years. We'll tell you honestly which situation you're in, because a remediation on a site that needs replacing is money spent twice.
We build and maintain WordPress sites for businesses across the UK from our HQ in Manchester, UK, with security handled at the code level rather than patched on afterwards. No juniors, no outsourcing.
If your site has been compromised, or you would rather it never was, we should talk.