Most hacked WordPress sites don’t look hacked. No skull on the homepage, no ransom note — just a site that quietly starts serving spam links to Google while showing you, the logged-in owner, a perfectly normal page. We’ve found injections like this during routine audits of sites whose owners had no idea anything was wrong. Here’s how to check yours, and what to do if you find something.
The signs owners actually notice (usually late)
- Google results for your site show pharmacy spam, casino text, or Japanese characters under your brand name
- Search Console warnings about “security issues” or a sudden flood of indexed pages you never created
- Traffic drops off a cliff without an algorithm update to blame
- Your emails start landing in spam — blacklisted server IP
- Hosting account CPU usage spikes while your traffic stays flat
Check right now, in five minutes
Search Google for site:yourdomain.com and read every result title — spam injections show up here before anywhere else, because attackers cloak the spam from normal visitors but serve it to Googlebot. Then view your homepage source (Ctrl+U) and search for terms like “viagra,” “casino,” or unfamiliar URLs. Finally, check your WordPress user list for administrator accounts you don’t recognize.
If you found something: the cleanup order
First, take a full backup — yes, of the infected site. You’ll want evidence and a fallback if cleanup goes wrong. Then, in order: change every password (WordPress admins, hosting, database, SFTP), scan with a server-side tool (Wordfence or a host-level scanner — browser-based checkers miss server files), remove unfamiliar admin users, delete plugins you don’t recognize including anything in the mu-plugins folder — a favorite hiding spot because those load automatically and don’t appear in the normal plugin list — then update everything, reinstall WordPress core files fresh, and request a review in Search Console once clean.
The step most people skip: finding out how they got in. If you clean the symptoms but the vulnerable plugin or stolen password is still there, reinfection within weeks is the norm, not the exception.
Preventing round two
The unglamorous basics prevent the vast majority of compromises: updates applied within days (not months), unique passwords with two-factor on admin accounts, one reputable security plugin, off-server backups, and removing plugins you stopped using. We covered the full routine in our WordPress maintenance checklist — unsexy, effective.
If your site is compromised and the DIY cleanup feels over your head — or you cleaned it and it came back — get in touch. We do fixed-price cleanup with a written report of what we found, how they got in, and what we closed. No scare tactics: if it’s a false alarm, we’ll tell you that too.

