>_
Delvok
← Back to Blog
Security Guide

10 Signs Your WordPress Site Has Been Hacked (And What Each One Means)

June 20, 2026·Delvok Security Team·9 min read

Is Your WordPress Site Hacked? Here's How to Tell

Most hacked WordPress sites don't display a skull-and-crossbones on the homepage. Modern attacks are subtle - designed to go unnoticed for as long as possible while attackers extract value from your server, your traffic, and your reputation.

Here are ten signs that something is wrong, what each one means, and what you should do about it.

1. Your Site Redirects Visitors to Suspicious Websites

What you'll see: Visitors land on your site and get immediately redirected to a pharmacy, gambling, or fake tech-support page. Sometimes it only happens on mobile devices or when arriving from Google search results.

What's happening: Attackers have injected redirect code into your .htaccess file, theme files, or database. Many use conditional redirects - only triggering for search engine traffic or mobile users - so you might never see it yourself when checking your site directly.

Why it's sneaky: If you always visit your site by typing the URL directly, you'll never trigger a redirect that only activates for Google referral traffic. Your site looks fine to you while every visitor from search is being hijacked.

2. Unknown Admin Accounts Appeared

What you'll see: Check Users → All Users in your WordPress dashboard. There are administrator accounts you didn't create - often with generic email addresses or names that look semi-legitimate.

What's happening: Attackers create backdoor admin accounts to maintain access even after you change your password or patch the vulnerability they used to break in. Some are obvious (random strings for usernames), while others mimic legitimate names like "support" or "backup_admin."

Why it matters: Even if you clean every infected file, a rogue admin account gives attackers full access to reinstall their malware through the WordPress admin panel.

3. Files Have Been Modified Without Your Knowledge

What you'll see: Core WordPress files have recent modification dates that don't match your last update. Files exist in directories where they shouldn't - like .php files in wp-content/uploads/.

What's happening: Attackers have uploaded web shells or modified existing PHP files to include malicious code. Web shells give them a browser-based terminal to your server - they can upload files, execute commands, read your database credentials, and pivot to other sites on the same server.

4. Google Has Blacklisted Your Site

What you'll see: Google search results show "This site may be hacked" or "This site may harm your computer" beneath your listing. Visitors see a full-page Chrome warning before they can access your site.

What's happening: Google's Safe Browsing system has detected malware, phishing pages, or unwanted software on your site. This typically happens days or weeks after the initial infection - Google needs time to crawl and identify the threat.

The real damage: Being blacklisted by Google can tank your traffic overnight. Even after you clean the malware, it takes time for Google to re-crawl, verify the fix, and remove the warning. Every day counts.

5. Your Site Has Become Extremely Slow

What you'll see: Pages that loaded in 2 seconds now take 10 or more. Your hosting dashboard shows high CPU or memory usage even with normal traffic levels.

What's happening: Malware consumes server resources. Common culprits include cryptocurrency miners running in your PHP processes, spam email scripts sending thousands of messages through your server, or brute-force scripts attacking other websites from your hosting account.

Don't assume it's a hosting problem. If your site suddenly slows down without a traffic spike, malware is a more likely explanation than a server issue.

6. Your Server Is Sending Spam Emails

What you'll see: Your hosting provider contacts you about excessive email volume. You're receiving bounce-back notifications for emails you never sent. Your domain ends up on email blacklists.

What's happening: Attackers have injected a PHP mailer script into your site. Your server is being used as a spam relay - sending thousands of phishing or spam emails per hour. This is one of the most common reasons attackers compromise WordPress sites.

Long-term damage: Getting your domain off email blacklists can take weeks. During that time, legitimate emails from your domain (like customer receipts or contact form submissions) won't be delivered.

7. Your Homepage or Pages Have Been Defaced

What you'll see: Your homepage has been replaced with a message from the attacker - often political, ideological, or just showing off. Sometimes it's subtle: a hidden iframe or a small change to your footer.

What's happening: Defacement is usually the least sophisticated type of attack. Many are automated scripts exploiting known vulnerabilities for bragging rights. However, visible defacement can mask a deeper compromise - while you're focused on the defaced page, backdoors are being installed quietly.

8. Strange Entries in Your Database

What you'll see: Your wp_options table contains entries you don't recognize. Post content includes encoded strings, hidden <div> elements with display:none, or <script> tags pointing to external domains.

What's happening: Database injection is harder to detect than file-based malware because it doesn't trigger file integrity scans. Attackers store their payloads in wp_options under innocuous-sounding names, or inject spam links directly into your post content that only display for search engine crawlers.

9. Your .htaccess File Has Been Modified

What you'll see: Your .htaccess file contains rewrite rules you didn't add - typically conditional redirects based on user agent or referrer. The file may also be set to read-only permissions to prevent you from changing it.

What's happening: .htaccess modification is the fastest way for attackers to redirect your traffic. Because .htaccess is processed before WordPress even loads, these redirects can't be stopped by security plugins.

Pro tip: If your .htaccess file keeps getting re-modified after you fix it, the attacker still has a backdoor somewhere on your site that's regenerating the malicious rules.

10. Pharma or SEO Spam Pages Have Appeared

What you'll see: Searching site:yourdomain.com on Google reveals hundreds or thousands of pages you didn't create - usually targeting pharmaceutical keywords, gambling terms, or counterfeit products. These pages are invisible from your WordPress dashboard.

What's happening: SEO spam (also called "parasite SEO") hijacks your domain's authority to rank spam content. Attackers create these pages through database injections or by adding PHP files that generate content dynamically. They use your domain's existing search authority to rank their spam - then redirect visitors to affiliate sites.

Why it's devastating: Google may penalize your entire domain for hosting spam content, destroying the search rankings you've built over years.

What to Do If You Recognize Any of These Signs

If even one of these signs applies to your site, treat it as a confirmed compromise. Don't wait to see if it gets worse - it will.

  1. Document what you see - Take screenshots and note exactly what's happening
  2. Don't change passwords yet - If a keylogger is active, you'll compromise your new credentials too
  3. Contact a professional - Delvok offers same-day WordPress rescue for hacked sites
  4. Consider your hosting - If you're on shared hosting, your neighbor's infection might be the source. Isolated hosting eliminates this attack vector entirely

The longer malware stays on your site, the more damage it does to your search rankings, your reputation, and potentially your customers' data. Acting quickly is the single most important thing you can do.

What Delvok Does Differently

Every site we rescue is migrated to isolated container infrastructure — your own web root, database, and server process. 24/7 monitoring catches threats before they become problems. Forensic-grade remediation ensures nothing is left behind.

Get Protected