If your WordPress site has been hacked, the first steps are to take the site offline or into maintenance mode, change all passwords immediately, scan for malware, remove any unauthorised files or admin accounts, restore from a clean backup if one exists, and then patch the vulnerability that let the attacker in. Acting quickly limits the damage — to your data, your search rankings, and your customers’ trust. This guide walks Australian business owners through exactly what to do, in the right order, and how to make sure it doesn’t happen again.
WordPress powers over 40% of websites worldwide, which makes it a constant target for automated attacks. Most hacks aren’t personal — they’re bots scanning the internet for outdated plugins, weak passwords, and unpatched vulnerabilities. The good news: most hacked WordPress sites can be fully recovered, usually without needing to pay a ransom or rebuild from scratch.
How Do I Know If My WordPress Site Has Been Hacked?
Common warning signs include:
- Your site redirects visitors to a different (often spammy or offshore) website
- Google Search Console shows a “Security Issues” warning
- Your browser or hosting provider flags the site as containing malware
- Strange new admin users appear in your WordPress dashboard
- Unfamiliar files or folders in your site’s directory
- A sudden spike in outbound traffic, spam emails, or server resource usage
- Your homepage is defaced, or unfamiliar pages/posts appear that you didn’t create
- Antivirus tools (like Wordfence, Sucuri, or even browser-level tools such as F-Secure or Norton) block visitors from reaching your site
If you’re seeing any of these, assume the site is compromised and act immediately — delaying gives the attacker more time to spread malicious code deeper into your files and database.
Step-by-Step: What to Do When Your WordPress Site Is Hacked
1. Put the Site in Maintenance Mode or Take It Offline
This limits further damage to visitors and stops search engines from indexing malicious content. Most hosting providers allow you to quickly suspend public access, or you can enable a maintenance-mode plugin if you can still log in.
2. Change All Passwords Immediately
This includes:
- WordPress admin accounts
- Hosting account / cPanel login
- FTP/SFTP credentials
- Database password
- Any connected email accounts used for site notifications
Use strong, unique passwords for each — password reuse is one of the most common reasons attackers regain access after a “clean-up.”
3. Scan for Malware and Identify the Entry Point
Use a reputable WordPress security scanner such as Wordfence, Sucuri SiteCheck, or MalCare to identify infected files, injected scripts, and backdoors. Most hacks trace back to one of three causes:
- An outdated plugin or theme with a known vulnerability
- A weak or leaked admin password
- Compromised hosting account credentials (sometimes via a different, unrelated hacked site on shared hosting)
4. Remove Malicious Code and Unauthorised Users
Go through your WordPress users list and delete any admin accounts you don’t recognise. Then review your files for:
- Unfamiliar PHP files in your wp-content/uploads folder (uploads should never contain executable PHP)
- Injected code in theme functions.php, .htaccess, or wp-config.php
- Suspicious scheduled tasks (cron jobs) that weren’t set up by your team
If you’re not confident identifying malicious code manually, this is the point where bringing in a WordPress security specialist is worth the cost — misidentifying or missing a backdoor is the single biggest reason sites get reinfected within days of being “cleaned.”
5. Restore From a Clean Backup (If Available)
If you have a backup from before the infection, restoring it is often faster and safer than manual clean-up — provided you also close the vulnerability first, or the same backup will simply get reinfected. Check backup dates carefully; some malware sits dormant for weeks before activating.
6. Update Everything
Once the site is clean, update:
- WordPress core to the latest version
- All plugins and themes
- PHP version (outdated PHP versions are a common attack vector)
Remove any plugins or themes you no longer use entirely, rather than just deactivating them — inactive code can still be exploited.
7. Request a Google Security Review (If Flagged)
If Google Search Console shows a security warning, you’ll need to submit a review request once the site is confirmed clean. This typically takes 24–72 hours and is necessary to remove “This site may be hacked” warnings from search results.
How Much Does It Cost to Fix a Hacked WordPress Site in Australia?
| Situation | Typical Cost Range (AUD) |
|---|---|
| Simple malware removal, one entry point | $200 – $600 |
| Moderate infection, multiple files affected | $600 – $1,500 |
| Severe compromise (database corrupted, backdoors, blacklisted) | $1,500 – $4,000+ |
| Ongoing managed security/monitoring (monthly) | $50 – $250/month |
Costs vary depending on how long the infection went undetected and whether a clean backup is available — the earlier it’s caught, the cheaper and faster the fix.
How to Prevent Your WordPress Site From Being Hacked Again
- Keep everything updated — WordPress core, plugins, and themes, on a regular schedule
- Use a Web Application Firewall (WAF) — such as Wordfence, Sucuri, or Cloudflare
- Enforce strong passwords and two-factor authentication for all admin accounts
- Limit login attempts to block brute-force attacks
- Remove unused plugins and themes rather than leaving them dormant
- Take automated daily backups, stored off-site (not just on your hosting server)
- Use managed WordPress hosting with built-in malware scanning and server-level security
- Restrict admin access to only the people who genuinely need it
Frequently Asked Questions
Can a hacked WordPress site be fully recovered? Yes, in almost all cases. Full recovery typically involves malware removal, closing the vulnerability that allowed access, and restoring content from a clean backup if needed. Data loss is rare if backups are in place.
How long does it take to fix a hacked WordPress site? A straightforward infection can be cleaned within a few hours to a day. More severe cases — especially where the database is compromised or the site has been blacklisted by Google — can take several days, particularly while waiting on a Google security review.
Will my WordPress site get hacked again after cleaning it? It can, if the original vulnerability isn’t identified and closed. This is why professional clean-ups focus on finding the entry point, not just deleting visible malicious files.
Should I pay a ransom if attackers demand payment? No. Paying does not guarantee the attacker will restore access or remove malware, and it can mark your site as a target for repeat attacks. Focus on clean-up and prevention instead.
Is shared hosting more vulnerable to hacks? Yes, generally. On shared hosting, a vulnerability in one website on the server can sometimes be used to access others. Managed WordPress hosting with isolated environments significantly reduces this risk.
Final Thoughts
A hacked WordPress site is stressful, but it’s rarely fatal to a business if handled properly and quickly. The priority order matters: contain the damage first, remove the malicious code and its entry point second, and restore/update third. Skipping steps — especially closing the actual vulnerability — is why so many businesses find themselves hacked again within weeks of a DIY clean-up.
If your site has been compromised and you’re not confident handling the technical clean-up yourself, getting a WordPress security specialist involved early is almost always cheaper than the cost of prolonged downtime, lost customer trust, or a Google blacklist affecting your search rankings.
