First: the honest truth about recovery
If your WordPress site is hacked, the fastest reliable fix is usually a clean restore, not a cleanup. Hand-deleting malware is a race against obfuscated backdoors you might not see — while the hacker still holds their access. The proven sequence below minimizes both downtime and recurrence. Prevention is the real cure — that's the security checklist.
Step 1: Assess the damage
Before touching anything, document:
- Signs — redirects to spam, weird pages, admin logins failing, Google "this site may be hacked" warnings
- Timeline — when did it start? What changed right before (a plugin update, a password reuse)?
- Scope — unknown admin users, files in
/uploadsthat aren't yours, modified theme files
Run a scanner (Wordfence, or your host's malware scanner) to map what it finds. Screenshot everything — you'll need it if you involve your host or a cleanup service.
Step 2: Restore or clean
If you have a clean backup (from before the hack):
- Wipe everything on the server
- Restore the files and database from the clean backup
- Update WordPress, themes, and plugins immediately
If you have no clean backup, clean in place:
- Reinstall WordPress core (Update → Reinstall)
- Delete unknown plugins/themes; reinstall clean copies of the ones you use
- Replace
wp-config.php(it's safe to regenerate) and check for injected code - Clean the database — unknown admin users and injected content — via phpMyAdmin or a cleanup plugin
A fresh restore is 30 minutes and definitive. Hand-cleaning can take a day and still miss a backdoor.
Step 3: Rotate every credential
The hacker's access survives a cleanup unless you kill it:
- [ ] WordPress admin passwords (every user, especially admins)
- [ ] Database user password (update
wp-config.phpafter) - [ ] Hosting panel password
- [ ] FTP/SFTP passwords
- [ ] Email passwords (a hacked mailbox re-hacks you)
- [ ] Any API keys the site uses
Then add 2FA to every admin account and the hosting panel. This is the step people skip — it's the one that stops round two.
Step 4: Harden and monitor
Apply the full security checklist:
- Strong unique passwords + 2FA
- Automatic updates for core, themes, and plugins
- A web application firewall (Cloudflare or Wordfence)
- Limit login attempts
- Daily backups — off-site, tested
Then set up monitoring so an injection triggers an alert instead of a silent infection. Consider telling your host — many will scan for you and confirm the site is clean.
When to call in help
If the hack is severe (spam redirects at scale, blacklisted IPs, ransom notes, or you lack a clean backup):
- Your host — many include malware cleanup (SiteGround's are famous; others charge)
- Sucuri / Wordfence cleanup services — professional malware removal for ~$100–200 one-time
- Google Search Console — request review after the site is verified clean, to clear the "hacked" flag
Frequently asked questions
How do I know if my WordPress site is hacked? Redirects, unknown admins, strange files in uploads, failing logins, or Google's hacked warning. Scanner tools (Wordfence, Sucuri SiteCheck) confirm it.
What is the fastest way to remove malware from WordPress? Restore from a clean pre-hack backup — it wipes the infection in one step. If no backup exists, reinstall core, replace plugins/themes, and clean the database. Backups guide.
Do I need to pay for malware removal? Often not — a clean restore plus credential rotation fixes most sites. Paid cleanup (Sucuri, host services) is for severe infections or when you lack a clean backup.
Why does my WordPress site keep getting hacked? Because something was left vulnerable — usually an old password, no 2FA, or an outdated plugin. The security checklist closes each one.
Will my host clean a hacked WordPress site? Some do — SiteGround offers malware removal; others scan but don't clean. Ask during the support conversation, and check what your plan includes.