Security & VPN
How to Clean a Hacked WordPress Site (Step by Step)
The verdict
A hacked WordPress site is fixable if you work through it methodically — here's the exact step-by-step process, and where a managed service like Sucuri saves you from the riskiest parts.
Nothing kills a website’s day faster than a hacked-site warning. Maybe Google Search Console flagged “This site may harm your computer,” maybe your host emailed you about malware, or maybe you just noticed strange redirects sending your visitors to spammy pharma or gambling sites. Whatever tipped you off, a hacked WordPress site is fixable — but only if you work through it methodically. Panicking and deleting random files usually makes things worse.
Here’s the step-by-step process we’d actually follow, plus where a managed service like Sucuri saves you from doing the riskiest parts yourself.
Step 1: Confirm You’re Actually Hacked
Before you touch anything, confirm the compromise. Common signs include:
- Unexpected admin users in Users > All Users
- New or modified files with recent timestamps you didn’t create
- Your site redirecting to another domain, especially on mobile
- A browser or Google Safe Browsing warning before the page loads
- Spam content, cloaked pages, or gibberish text appearing in search results for your domain
- Your host suspending the account or emailing you about abuse complaints
If you’re not sure, a free scanner (Sucuri’s own SiteCheck is a reasonable first pass) can confirm whether known malware signatures or blacklist flags are present, though free scanners only see what’s publicly visible — they can miss backdoors hidden deeper in your files or database.
Step 2: Take the Site Offline (or at Least Isolate It)
Put the site in maintenance mode if you can, and change every password that touches it: WordPress admin accounts, hosting/cPanel, FTP/SFTP, and the database user. Hackers frequently plant backdoors that let them back in even after you “clean” the visible malware, so a full password reset closes one of the easiest re-entry points.
Step 3: Back Up the Infected Site As-Is
Counterintuitive, but before you delete anything, take a full backup — files and database. If your cleanup goes wrong, you want a fallback, and if you ever need to investigate how the breach happened, you’ll want the original evidence rather than a half-cleaned version.
Step 4: Identify and Remove the Malware
This is where most DIY cleanups go sideways. Malware on WordPress sites usually isn’t one obvious file — it’s often scattered across theme files, plugin files, uploads directories, and sometimes injected directly into the database (in post content, options, or widget settings). Manually diffing every core file against a clean WordPress copy is possible but slow and easy to get wrong; miss one backdoor script and the site gets reinfected within days.
This is the step where a dedicated malware removal service earns its keep. Sucuri’s website security platform is built around exactly this: their team (backed by automated scanning) finds and removes malware, backdoors, and blacklist injections, and — importantly — includes cleanup as part of ongoing plans rather than charging per incident every time you get hit again. They also offer a one-time cleanup option if you just need the fire put out without committing to a subscription.
Sucuri Affiliates (Standard Terms) (CJ 5331920)
Approved CJ advertiser (ACTIVE). Destination: https://sucuri.net/.
Visit SiteStep 5: Update Everything
Most WordPress hacks exploit a known vulnerability in an outdated plugin, theme, or WordPress core itself — not some exotic zero-day. Once the site is clean, update:
- WordPress core to the latest version
- Every plugin and theme, or remove the ones you don’t actually use
- Your PHP version, if your host still has you on an old one
Delete any plugin or theme you don’t recognize installing — attackers sometimes leave a disguised “plugin” behind purely as a backdoor.
Step 6: Request Blacklist Removal
Even after the malware is gone, Google Safe Browsing, Norton, McAfee, and other blacklists may still be flagging your domain — they don’t automatically re-scan the moment you fix things. You’ll need to submit removal requests to each one that flagged you, which can take anywhere from a few hours to a few days per service. This is another area where a security platform helps, since blacklist monitoring and removal requests are typically bundled into their plans instead of being something you chase down individually across half a dozen dashboards.
Step 7: Put a Firewall in Front of the Site
Cleaning up after a hack is reactive. The better long-term move is a web application firewall (WAF) that filters malicious traffic before it ever reaches your server — blocking common attack patterns like SQL injection attempts, brute-force login attacks, and known bot signatures. Sucuri’s WAF sits in front of your site via DNS, which has the side benefit of also improving load times through caching, since it’s acting as a lightweight CDN layer at the same time.
Step 8: Set Up Real Monitoring and Backups
The single best predictor of how much a hack costs you — in downtime, reputation, and your own time — is how fast you catch it. Ongoing file integrity monitoring alerts you the moment something changes unexpectedly, rather than you finding out weeks later from an angry customer or a Google penalty. Pair that with automated off-site backups so that even in a worst case, you can roll back to a known-good version in minutes instead of rebuilding from scratch.
Do You Need a DIY Fix or a Managed Service?
If you’re comfortable in the WordPress file system and database, and the compromise looks minor (a single injected script, say), a careful manual cleanup is doable. But for anything involving multiple infected files, unknown backdoors, or a blacklist flag hurting your traffic right now, the time you’d spend safely diagnosing everything yourself usually costs more than just handing it to a service that does this daily. That’s the case for something like Sucuri: it turns “learn website forensics under pressure” into “submit a ticket and get back to running your business.”
Get Sucuri's Malware CleanupPreventing the Next One
Once you’re clean, a short checklist keeps you that way: strong unique passwords everywhere, two-factor authentication on admin accounts, prompt updates, a firewall in front of the site, and monitoring that actually notifies you instead of sitting unread in a dashboard. Getting hacked once is bad luck or an old plugin. Getting hacked twice usually means the underlying gaps never got closed.