Discovering that your website has been compromised is every webmaster’s worst nightmare. If your site is redirecting visitors to spam pages, showing Japanese keywords in Google search results, or throwing security warnings, learning how to recover hacked WordPress site immediately is critical to protect your brand reputation, search engine rankings, and customer trust.
In this comprehensive, battle-tested tutorial, the cybersecurity team at AMSIT breaks down the exact seven-step protocol we use to neutralize malware, clean infected files, flush rogue database users, and restore normal operations without losing crucial data.
Table of Contents
- Common Symptoms of a Compromised WordPress Site
- Why Fast WordPress Malware Removal Matters
- Step 1: Quarantine the Site and Enable Maintenance Mode
- Step 2: Create a Forensic Backup (Files and Database)
- Step 3: Replace Core WordPress Files with Fresh Copies
- Step 4: Audit wp-config.php and Regenerate Security Salt Keys
- Step 5: Clean Themes, Plugins, and uploads Directory
- Step 6: Audit MySQL Database and Remove Rogue Admins
- Step 7: Inspect DNS Records and Wildcard Subdomains
- Post-Recovery Hardening Checklist for 2026
- Frequently Asked Questions (FAQ)
Common Symptoms of a Compromised WordPress Site
Hackers rarely announce their presence. Modern website attacks are designed to stay stealthy, monetizing your traffic behind the scenes. Recognizing the early red flags is the first step when determining how to recover hacked WordPress site effectively.
- Google Search Console Alerts: Receiving notifications regarding “Deceptive pages ahead”, “Harmful downloads”, or “Japanese Keyword Hack” indexing spikes. For complete details on warning flags, review the Google Search Central Security Guidelines.
- Unexplained URL Redirects: Visitors coming from mobile devices or search engines get redirected to scam landing pages, gambling portals, or fake tech support sites.
- Rogue Administrator Accounts: Mysterious usernames appearing under Users > All Users with administrator privileges that nobody on your team created.
- High Server CPU & Memory Spikes: Background mining scripts, automated mail relay spammers, or brute-force bots overwhelming your hosting server resources.
- Blacklisted by Email Providers: Outgoing notifications landing in junk folders due to your server IP being flagged by Spamhaus or MXToolbox.
Why Fast WordPress Malware Removal Matters
Every hour your site remains infected costs you organic impressions and client confidence. Google aggressively de-indexes URLs that distribute malware or spam links. If an infection lingers, your domain authority can plunge by over 80% within days.
Beyond search rankings, compromised e-commerce sites violate compliance regulations. If you manage an online store, client credit card data or personal customer records could be exposed. Knowing how to recover hacked WordPress site cleanly prevents devastating financial penalties and permanent blacklisting.

Step 1: Quarantine the Site and Enable Maintenance Mode
Before modifying any code, stop active attacks and prevent visitors from landing on malicious scripts. Place your site in offline maintenance mode immediately.
You can achieve this by adding a temporary 503 Service Unavailable header in your root .htaccess file or activating a maintenance splash page. This tells search engine crawlers that your site is undergoing temporary maintenance so your SEO rankings are preserved while you investigate.
Change your cPanel, hosting control panel, SFTP, and MySQL database passwords immediately. If an attacker stole your FTP credentials, updating these passwords cuts off their real-time pipeline.
Step 2: Create a Forensic Backup (Files and Database)
It might seem counterintuitive to back up infected files, but having a full snapshot is crucial before executing how to recover hacked WordPress site procedures. If a cleanup script accidentally deletes a customized theme file or breaks an active WooCommerce table, you must have a restore point.
Connect to your server via SFTP or cPanel File Manager and compress your entire public_html directory into an archive. Next, export your complete database using phpMyAdmin. Store this archive locally in an isolated folder for forensic review.
Step 3: Replace Core WordPress Files with Fresh Copies
Malware injection scripts frequently alter core files such as index.php, wp-blog-header.php, and files within wp-includes/ and wp-admin/. Rather than trying to manually locate obfuscated PHP strings, replacing the core files entirely is the safest approach.
- Download a pristine, authentic copy of WordPress directly from the official repository at WordPress.org Documentation.
- Extract the zip archive on your local computer.
- Delete the
wp-contentfolder from your newly downloaded local copy (to prevent overwriting your real content). - Using SFTP, delete the remote
wp-adminandwp-includesdirectories on your server. - Upload the fresh
wp-admin,wp-includes, and root PHP files (excludingwp-config.php) to your server.
This single maneuver wipes out hundreds of backdoors that hide inside standard core WordPress directories.
Step 4: Audit wp-config.php and Regenerate Security Salt Keys
The wp-config.php file is the crown jewel of your WordPress installation. Inspect it line by line to verify there are no unauthorized PHP declarations or suspicious base64 strings prepended before <?php.
Next, invalidate all current user sessions, cookies, and active login tokens by regenerating your WordPress Security Keys (Salts). Visit the official WordPress salt generator API (https://api.wordpress.org/secret-key/1.1/salt/), copy the newly generated 8 unique keys, and overwrite the existing definitions in wp-config.php:
define('AUTH_KEY', 'put-your-unique-phrase-here');
define('SECURE_AUTH_KEY', 'put-your-unique-phrase-here');
define('LOGGED_IN_KEY', 'put-your-unique-phrase-here');
define('NONCE_KEY', 'put-your-unique-phrase-here');
define('AUTH_SALT', 'put-your-unique-phrase-here');
define('SECURE_AUTH_SALT', 'put-your-unique-phrase-here');
define('LOGGED_IN_SALT', 'put-your-unique-phrase-here');
define('NONCE_SALT', 'put-your-unique-phrase-here');
Replacing these keys immediately kicks out any logged-in malicious sessions, forcing everyone to re-authenticate with fresh credentials.
Step 5: Clean Themes, Plugins, and uploads Directory
Because the wp-content directory houses your unique media and styling, hackers frequently inject persistent PHP backdoors here. Follow this strict checklist to clean hacked WordPress site assets:
- Plugins Directory: Delete all existing plugin folders in
wp-content/plugins/and reinstall verified copies directly from the official WordPress directory. Never use nulled or pirated themes or plugins, as they almost always contain hardcoded backdoors. - Themes Directory: Inspect your active theme files. Check
functions.phpandheader.phpfor functions likeeval(),base64_decode(), orgzinflate(). If possible, re-download the original theme from the developer. - Uploads Directory: The
wp-content/uploads/folder should contain only images, PDFs, and media files. There should never be a.php,.icofile containing PHP code, or.htaccessfile inside uploads. Run a search for all*.phpfiles inside uploads and purge them instantly.
Step 6: Audit MySQL Database and Remove Rogue Admins
Attackers often inject backdoor administrator accounts directly into the database. To audit your database:
- Open phpMyAdmin and select your WordPress database.
- Open the
wp_userstable. Review every registered user. If you see unfamiliar emails or randomly generated strings, delete them. - Check the
wp_usermetatable forwp_user_level10 oradministratorcapabilities tied to illegitimate user IDs. - Search the
wp_postsandwp_optionstables for spam scripts using SQL queries likeSELECT * FROM wp_posts WHERE post_content LIKE '%<script%'.
If managing manual SQL queries feels overwhelming, our technical engineers at AMSIT WordPress Services provide rapid emergency malware cleanup and database sanitation.
Step 7: Inspect DNS Records and Wildcard Subdomains
A recent, highly pervasive attack vector is the Wildcard Subdomain Hijack. In this scenario, hackers gain access to your DNS records (via Cloudflare, cPanel, or your domain registrar) and create a wildcard record (*) pointing to an offshore rogue server.
This allows attackers to generate thousands of fake Japanese spam subdomains (such as notifier.yourdomain.com or m.yourdomain.com) without touching a single file on your hosting server! When understanding how to recover hacked WordPress site threats completely, you must check your DNS zone files:
- Log into Cloudflare or your DNS dashboard.
- Look for any wildcard
A,AAAA, orCNAMErecords pointing to unrecognized IP addresses. - Delete all rogue DNS records immediately and flush your DNS cache.
- Submit URL removal requests in Google Search Console to de-index the phantom spam pages.
Post-Recovery Hardening Checklist for 2026
Once you have neutralized the immediate threat, take proactive measures to guarantee that the vulnerability cannot be exploited again:
- Enforce Two-Factor Authentication (2FA): Require 2FA on all administrator and editor accounts.
- Implement an Enterprise Web Application Firewall (WAF): Use Cloudflare or Wordfence to filter malicious bots before they touch your server.
- Disable PHP Execution in Uploads: Add a security rule inside
wp-content/uploads/.htaccessto prevent any uploaded PHP scripts from executing. - Keep Core, Plugins, and Themes Updated: Enable automatic updates for security patches. Over 90% of WordPress vulnerabilities originate from outdated plugins.
- Schedule Automated Off-Site Backups: Maintain daily off-site snapshots stored on Amazon S3 or Google Cloud.
For custom web applications or specialized business websites, consider partnering with an experienced professional web development agency to construct secure architectures from the ground up.
Frequently Asked Questions (FAQ)
How long does it take to clean a hacked WordPress site?
A basic malware infection can usually be diagnosed and cleaned in 2 to 4 hours. However, complex infections involving database corruption, Japanese SEO spam, or wildcard DNS hijacking can take 24 to 48 hours to fully resolve and verify with Google Search Console.
Can a hacked WordPress site affect my search rankings permanently?
Not if you act quickly. If you quarantine the site, submit a clean review in Google Search Console, and verify removal of all malicious redirects, your organic rankings typically recover within 2 to 4 weeks. Delaying the cleanup, however, can lead to severe manual action penalties.
Why did my site get hacked even though I had strong passwords?
Most WordPress hacks do not happen through brute-force password guessing. Instead, vulnerabilities in outdated plugins, unpatched themes, insecure shared hosting environments, or server-level file permission exploits provide backdoor access to attackers.
Need emergency assistance to recover your website?
If you are struggling with recurring malware or unexpected redirects, contact the AMSIT security team today for an immediate security audit and forensic cleanup.