WordPress security
Your WordPress site is hacked: how to react
Redirects to shady pages, spam pages, unknown content, a warning from your host or from Google. A hacked WordPress site can usually be repaired, but every hour counts to limit the damage and avoid blacklisting.
The symptoms
- The site redirects visitors to unknown or shady pages.
- Pages or posts you never created appear (often spam: pharma, counterfeits, betting).
- Google shows "This site may be hacked" in the results.
- Your host reports mass e-mail sending or abnormal activity.
- Administrator accounts you do not recognise.
- The site is slower, or displays a hacker page (defacement).
The likely causes
- A plugin or theme left outdated with a known vulnerability.
- A weak administrator password, or one reused elsewhere.
- A nulled plugin (pirated version) carrying malicious code.
- Shared hosting where another compromised site infected yours.
- Injected PHP files (backdoors) that reinfect after a surface cleanup.
What you can try yourself
Put the site into maintenance mode
Cut public access if you can, to protect your visitors and your SEO during the intervention.
Change every password
WordPress admin accounts, FTP/SFTP, database and hosting panel, from a clean device.
Back up the current state
Even infected, it helps analyse the attack and recover your content. Do not overwrite a clean backup with it.
Check accounts and plugins
Remove unknown administrator accounts and plugins you did not install.
Do not rely on a cleanup plugin alone
Backdoors often hide outside WordPress. A surface scan lets the site reinfect within days.
When to call a professional
If the site reinfects after cleanup, if Google has blacklisted the domain, if you run a shop or hold customer data, or if you have no access to analyse the files in depth: it is time to call a professional. A serious cleanup means analysing the files and the database offline, removing the backdoors, patching the entry point, then requesting a review from Google.
Frequently asked questions
Can a hacked WordPress site be recovered?
In the vast majority of cases, yes, provided every backdoor is removed and the original vulnerability is patched. Some very old or heavily compromised sites are faster to rebuild than to clean. We tell you plainly after testing.
How long does it take to clean a hacked site?
A simple showcase site is often cleaned in a few hours. An e-commerce site or a compromised server takes longer. The price is set case by case, from around 250 EUR.
How do I stop it happening again?
Regular, tested updates, strong passwords, removal of nulled plugins, and maintenance that watches and patches continuously. That is the purpose of the Relax by Yumea plans.
We look at your site.
If we can recover it, we send you a clear price and a payment link. If we cannot, we tell you plainly, we charge nothing for that, and we can offer you a brand new site. Either way, you are never stuck.
The first look is free.
Describe my problemOther common problems
WordPress outage
White screen (blank page)
WordPress error
Critical error
WordPress error
Database connection
WordPress outage
Broken after an update
WordPress display
Broken layout
WordPress maintenance
Updates stuck
WordPress outage
Site down / 500 error
WordPress performance
Very slow site
WordPress security