Is your WordPress hacked? Here is how to take back control.
Clear guides to spot the infection, clean the hack and close the doors behind you, written by the team that cleans hacked WordPress sites every day.
WordPress hack symptoms and types
Casino redirects, indexed spam, Google warnings, rogue admin accounts: pin down exactly what is affecting your site.
Symptoms & hack types Japanese keyword hack: cleaning the Japanese hack on WordPress
Japanese pages indexed under your name, titles full of Asian characters in Google? That's the Japanese keyword hack. Here's how to identify and clean it.
Read
Symptoms & hack types Pharma hack WordPress: remove pills and pharmacy spam
Viagra, Cialis and pharmacies indexed under your name in Google but nowhere in your admin? Here's where the pharma hack hides and how to remove it.
Read
Symptoms & hack types Remove indexed casino spam posts on WordPress (SEO spam)
Hundreds of casino or betting pages indexed under your name in Google, but invisible from your dashboard? Here's how to remove them and stop their return.
Read
Symptoms & hack types Remove the "This site may be hacked" warning from Google
Google flags your site as hacked or shows a red warning? Here's how to clean up, request a review, and how long it takes to clear.
Read
Symptoms & hack types An unknown admin account on WordPress: what to do
An admin you never created shows up in WordPress? That's a clear sign of a hack. Here's how to remove it without locking yourself out.
Read
Symptoms & hack types Is your WordPress redirecting to a casino or betting site? Here's how to stop it
Your WordPress site sends visitors to a casino or betting site, mostly from Google? That's a redirect hack. Here's where it hides and how to remove it.
Read
Symptoms & hack types Your WordPress is sending spam: how to stop it
Your domain is sending spam without your knowledge, your host is warning you, or your mail is blacklisted? Here's the cause and how to stop it.
Read
Symptoms & hack types WordPress slow or server overloaded: could it be a hack?
Site suddenly slow, CPU pinned, your host warning about resource usage? It may not be a performance issue but a cryptominer or a hidden botnet.
ReadClean and repair a hacked WordPress
Recognise an infection, find the backdoors, remove the malware and get your WordPress site back on its feet, step by step.
Clean & repair Guide Hacked WordPress: what to do? The guide to cleaning and securing your site
Is your WordPress site hacked? Here's the complete playbook to keep your cool, clean the infection without breaking anything, and close the hole for good.
Read
Clean & repair Clean a hacked .htaccess file on WordPress
The .htaccess is the favorite hiding spot for malicious redirects and access blocks. Here's how to spot injected rules, remove them, and restore a clean file.
Read
Clean & repair How to know if your WordPress site is hacked: 10 telltale signs
Not sure your site is clean? Here are 10 concrete signs of a hacked WordPress and how to check each one before you clean up.
Read
Clean & repair Cleanly reinstall WordPress core (without losing your site)
Replacing WordPress core files with a clean version clears out a good chunk of an infection. Here's how to do it without touching your content or your settings.
Read
Clean & repair Finding and removing a backdoor on WordPress
A backdoor is the door the attacker keeps open to come back after every cleanup. Here's where they hide in WordPress and how to track them down for good.
Read
Clean & repair Restoring WordPress after a hack: getting your content back
Content erased or hidden by the attacker? Here's how to recover your posts and pages: backups, Google cache, Wayback Machine, and what to do with no backup.
Read
Clean & repair Scanning a WordPress site for malware: the methods that actually work
Online tools, plugins, manual inspection: here's how to scan an infected WordPress, which to choose for your situation, and what no scanner can see.
ReadSecure WordPress and prevent reinfection
Harden WordPress, close the security holes an attacker exploited and build the habits that prevent reinfection: strong logins, updates and backups.
Secure & prevent Guide Securing WordPress after a hack: the hardening checklist
A cleaned but un-hardened site often gets reinfected through the same hole. Here's the security checklist to run right after cleanup.
Read
Secure & prevent Backing up WordPress: how to never lose everything
A good backup turns a hack into a minor setback. Here's what to back up, how often, where to store it, and how to confirm it actually works.
Read
Secure & prevent Protect the WordPress login page against brute-force attacks
The wp-login.php page is the number one target for bots. Here's how to hide it, limit login attempts, and block brute-force attacks.
Read
Secure & prevent Why WordPress sites get hacked (and how to prevent it)
WordPress doesn't get hacked because it's insecure, but because of a few concrete weak spots. Here are the real causes and how to shut them down.
ReadWordPress malware library: identify and remove
wp-vcd, lock360.php, webshells, cloaked injectors: each entry describes a real-world malware — files, symptoms, persistence and removal — straight from our cleanups.
lock360.php: what this file is and how to remove it
Found a lock360.php file on your site? It's a backdoor. Here's what it does, where it hides and how to remove it without leaving a door open.
Read Malware librarysc_, wp_custom_, home_links_custom_ options: spam hidden in wp_options
Spotted sc_, wp_custom_ or home_links_custom_ options in your wp_options table? That's database spam persistence. Here's how to identify and clean it.
Read Malware librarySky Login / redirect hijack: removing this fake plugin from WordPress
A 'Sky Login' plugin you never installed, and your site redirecting visitors? That's a redirect injection. Here's how to identify and remove it.
Read Malware libraryVitrina Site Connector / SEO Client: the cloaked mu-plugins injector
A 'Vitrina Site Connector' or 'SEO Client' mu-plugin you never installed? It's an injector cloaking a casino redirect. Here's how to recognise and remove it.
Read Malware librarywp-vcd: the nulled-theme malware and how to get rid of it
wp-vcd is one of the most widespread WordPress malwares, spread through nulled themes and plugins. Here's how to recognise it, remove it and stop it coming back.
Read Malware libraryWSO, FilesMan, c99: recognising and removing a WordPress web shell
A PHP file that shows a file manager in the browser? That's a web shell. Here's how to recognise WSO, FilesMan or c99 and remove them properly.
ReadWant us to handle it for you?
Run a free scan: we show you what is detected, then clean everything in ~30 minutes. €149 excl. VAT, refunded if we can't fix it.
Scan my site