WordPress · September 17, 2026

WordPress site hacked? What to do in the first hour.

If your WordPress site just got hacked, you are in very large company. WordPress runs a huge share of the web, which makes it the most attacked website software there is. That also means the way these hacks happen is well understood, and so is the way to fix them.

Why WordPress sites get hit so often

It usually is not WordPress itself. The large majority of WordPress security holes turn up in plugins and themes, the add-ons that give a site its features. A typical small business site is carrying a dozen or more of them, and it only takes one that nobody updated.

Nobody picked your site out on purpose, either. Automated programs crawl the web all day looking for any WordPress site running a plugin with a known hole, and they break in without a person ever looking at your site. That is why a small local business with nothing worth stealing still gets hacked.

WordPress code on a computer screen, a hacked WordPress site being repaired

The first hour, in order

1. Change the passwords that matter. Your hosting account first, then every WordPress administrator, then the email address tied to them. Use a computer you trust.

2. Look for users you do not recognize. In WordPress, open Users and check for administrators you did not add. Attackers love to create one so they can walk back in later. Write down their names, then remove them.

3. Take it offline if it is hurting visitors. If your site is sending people to scams or triggering warnings, ask your host to put up a maintenance page. It is better for customers to see "back soon" than something that hurts them or your name.

4. Make a full copy before you touch anything. That means the files and the database, as they are right now. Whoever repairs it will need that copy to work out how the attacker got in.

Things that feel helpful but make it worse

Deleting files that look strange tends to break the site while leaving the real problem behind, since backdoors are built to look like normal WordPress files. Installing four security plugins at once mostly adds more code to go wrong.

The big one is restoring last month's backup and calling it done. If the plugin they came through is still outdated, the same bots will find it again, usually within days. We see this constantly.

What proper WordPress repair includes

Every WordPress core file gets checked against a fresh official copy, so anything that was quietly changed shows up. The uploads folder gets checked for program files, which should never be there and are one of the most common hiding spots. The database gets searched for injected code and extra administrators.

Then the hole gets closed. Outdated plugins are updated, abandoned ones are removed, and the site's security keys are reset so every existing login is kicked out. Finally, if Google flagged the site, a review is requested so the warning comes down. That is the work behind our hacked website repair service.

Or stop being a target at all

If this is not your first hack, it is worth asking whether the site needs to be on WordPress at all. Many small business sites are a handful of pages that barely change, and they are carrying all the upkeep and risk of WordPress for no reason.

We can rebuild a site like that so it looks the same, loads faster, and has no plugins or login page sitting there for bots to attack. It is not right for everyone, and online stores and very busy sites often need WordPress. But when it fits, it ends the hacking for good. See our WordPress replacement service.

Frequently asked questions

Do security plugins stop WordPress hacks?

They help, but they are not a replacement for keeping plugins updated. Most hacks come through an add-on with a known hole, and a security plugin cannot fix a hole in somebody else's code. Updates can.

Should I just reinstall WordPress?

Reinstalling WordPress replaces its own files, but backdoors usually hide in plugins, themes, the uploads folder, or the database, and a reinstall does not touch those. It can make the site look fixed while the attacker still has a way back in.

How do I know if my WordPress site is safe now?

Check that you recognize every administrator, that every plugin is up to date, and that Google shows no warnings for your site. For a proper look, our $149 website checkup includes a basic security scan.

Let's build

Ready to out-rank, out-design, and out-sell your competition?

Tell us what you're trying to grow. You'll get a straight answer, a clear plan, and a free quote — usually within one business day.