If you’re like most business owners, you probably have a low-level, background worry that your website might get hacked someday. Then one day you get the email from Google saying “your site has been compromised,” and that low-level worry turns into full-blown panic.

Take a breath. You’re going to be okay. I’ve spent 15 years cleaning up hacked WordPress sites for small businesses, nonprofits, and manufacturers who all thought “this won’t happen to me.” It happens. It’s recoverable. Here’s exactly what to do.

First, a reality check on what actually happened. When people picture a hack, they imagine a hoodie-wearing villain specifically targeting their business. In 99% of cases, that’s not what happened. Bad actors run automated scripts that scan millions of sites looking for known exploits: usually an outdated plugin, a weak admin password, or a file permission gap. When the script finds one, it injects code. Spammy links, redirect rules, hidden pages, or backdoors for sending bulk email. It’s not personal. Just a vulnerable door that got left unlocked.

The worst consequence isn’t the hack itself. It’s Google. Once Google detects compromised content, they’ll either delist the site entirely, flag it in search results with a “this site may be hacked” warning, or quietly drop it 20+ spots in rankings. For companies that rely on search traffic (read: most successful companies), this is devastating. A site that ranked #2 last week can vanish overnight.

The First 5 Minutes: Emergency Checklist

Before you start cleaning anything, do these five things in this order:

  1. Change your WordPress admin password. Use a password manager, generate something 20+ characters long. If your password was “CompanyName2024,” that’s probably how they got in.
  2. Change your hosting account password and your FTP/SFTP credentials. The attacker may have those too.
  3. Log into WordPress, go to Users, then All Users. Look for admin accounts you don’t recognize. Delete them. This is the #1 thing a compromised site will have: a new admin user with a name like “admin2,” “wp_user,” or something random.
  4. Run a free scan at Sucuri SiteCheck. Just drop your URL in. It won’t clean anything, but it’ll tell you what’s infected and where.
  5. Check Google Search Console under Security Issues. If Google has flagged anything, it’ll be listed there with specific URLs.

Already better off than you were five minutes ago. Now let’s get into the real cleanup.

Set Up Google Search Console (If You Haven’t Already)

Google Search Console is free and non-negotiable for any business website. Google continuously monitors nearly every site on the internet, and if they detect a hack on yours, GSC will email you immediately. Without it, you’re flying blind. Many companies go months before noticing a hack, usually when a client or prospect mentions it. That’s a terrible way to find out, because by then you’ve lost trust and traffic you’ll never recover.

Set it up today, even if your site isn’t hacked right now. Five-minute job. Huge payoff.

Contact Your Host (or Work in the Hosting Environment if You’re Technical)

Call your web host first. Their response will tell you a lot.

If you’re on a big box host like GoDaddy, Bluehost, HostGator, or Network Solutions, don’t expect much. Support queues are long, the first-tier tech probably isn’t a WordPress expert, and frankly, your site isn’t a priority to them. They’ll often tell you to pay for a malware cleanup add-on and send you on your way.

If you’re on a quality managed host like SiteGround, WP Engine, Kinsta, or Flywheel, you’re in much better shape. These hosts typically keep automatic daily backups for 30+ days, so you can often revert to a pre-hack snapshot in a few clicks. They also tend to have actual WordPress specialists on support. This is one of the unsung reasons premium hosting is worth the extra $10 to $30 per month.

Either way, ask these questions:

  • Do you have a clean backup from before the hack? If so, when?
  • Are there server-level indicators of compromise (unusual file changes, outgoing mail queue spikes)?
  • Can you scan the server for malware?

If You’re Not Technical, Get an Expert Involved Immediately

Cleaning a hacked WordPress site is deceptively hard. Even after 15 years of doing this, I still spend hours on some cleanups, because the malware scatters files across hundreds of folders. If you miss one single file, the infection comes back as soon as you think you’ve cleaned it.

This kind of server-side malware is much harder to deal with than a virus on your laptop. Your laptop you can unplug from the internet and scan locally. A website is always online, always exposed, and scanners have to run in the cloud using server resources, so they can’t run continuously. That’s the asymmetry that makes professional help valuable.

Good options:

  • Sucuri. The gold standard. Around $500/year, which covers unlimited cleanups for 12 months. If the hack comes back, they keep working until it’s gone. Not cheap, but worth every dollar if your site matters to revenue.
  • Wordfence Premium. Strong free tier, paid tier around $150/year. Better for ongoing prevention than emergency cleanup, but their team will assist if you’re paying.
  • MalCare. Cheaper than Sucuri (around $100 to $300/year depending on sites), automated cleanup-focused.
  • A WordPress agency that actually understands security. Not every agency does. Ask specifically about their hack-cleanup experience before handing over admin access.

After the Cleanup: Tell Google You’re Clean

This is the step most people miss. Even after you’ve cleaned every infected file, Google still has you flagged, and they won’t figure it out on their own for days or weeks.

Inside Google Search Console, go to Security Issues, review the flagged items, and click Request Review. You’ll describe what happened and what you did to fix it. Google typically responds within 24 to 72 hours. Once they confirm the site is clean, the “hacked site” warning disappears from search results and your rankings start recovering.

Skip this step and your site can stay penalized for weeks longer than necessary.

Harden the Site So It Doesn’t Happen Again

The best cleanup in the world is wasted if the same exploit gets you again in three months. Minimum hardening checklist:

  • Keep WordPress core, themes, and plugins updated. At least monthly. Most hacks exploit known vulnerabilities with patches already available.
  • Delete plugins and themes you’re not actively using. Every inactive plugin is still a potential attack surface.
  • Enable two-factor authentication on all admin accounts. Wordfence and iThemes Security both do this free.
  • Rotate admin passwords every 6 months and never reuse them from other services.
  • Limit login attempts. Brute-force attacks against /wp-login.php are constant. A simple plugin blocks most of them.
  • Disable XML-RPC if you don’t actively use it (most sites don’t).
  • Change your admin URL from /wp-admin to something custom. Security through obscurity isn’t everything, but it cuts automated attack volume enormously.
  • Daily offsite backups using UpdraftPlus, BlogVault, or your host’s built-in tool. Test the restore at least once.

If you don’t have someone on your team who can keep up with this, an ongoing WordPress maintenance agreement (with us or any reputable agency) handles it for you. We also run Sucuri on all of our managed sites, which catches problems before they turn into Google penalties. More on that in our breakdown of securing high-traffic WordPress sites.

The Bottom Line

A WordPress hack is scary but survivable. The order of operations matters: confirm, isolate, clean, request review, harden. Skip any step and you either reinfect, lose rankings longer than necessary, or both.

If you’re staring at a hacked site right now and you’re overwhelmed, reach out. We’ll give you a straight read on what you’re dealing with and what it’ll take to fix. No 47-slide deck. No pressure. Just an honest conversation. And if you don’t need us, we’ll tell you that too.

Subscribe to Read More Blogs Like This

  • This field is for validation purposes and should be left unchanged.

Contact Us Today!

Want to talk about your website? We’re a quick email or phone call away. No pressure, no 47-slide sales presentation. Just a straightforward conversation about what you need and whether we’re the right fit. And if we’re not, we’ll tell you that too.