Security

What to do when your WordPress site looks compromised.

Do not panic-click your way through the admin area. A compromised website needs calm handling, notes, backups, and a clear order of operations.

First, write down what you see: strange redirects, unknown users, spam pages, warnings from browsers, blocked login, or unexpected changes. Screenshots help.

Second, preserve evidence and backups before deleting things. A messy backup is still better than no backup when a recovery goes sideways.

Third, check users, plugins, themes, server files, database entries, redirects, and scheduled tasks. Update only when you understand the risk. Some hacked sites break during updates because the attacker changed core files or plugins.

Finally, close the hole, clean the site, rotate passwords, review hosting access, and submit rechecks where needed. Then maintain the site so the same mess does not return next month. If the infection is beyond what you have access or time to handle yourself, the WordPress Hack Recovery package covers the technical cleanup, hardening, and a plain-English explanation of what was found.

From the packages

Already dealt with a hack or worried you might be next?

WordPress hack recovery gets your site cleaned, hardened, and back online — with a clear record of what was done and why.

Work with me

Tell me about your project

Send the details and I will reply within one working day. No automated responses, no offshore handoffs.

Get in touch