Signs your WordPress site is already compromised

Up Speed

Up Speed

Security
Signs your WordPress site is already compromised

A hacked site rarely announces itself. There is no skull on the homepage and no ransom note. Modern attacks are quiet on purpose, because the longer they go unnoticed, the more they earn.

Which means the owner is usually the last to know. Someone else spots it first: a customer, Google, or an email provider that starts rejecting your mail.

Here is what to actually look for.

Your site behaves differently for visitors than it does for you

This is the classic one, and it is deliberate. A lot of malware checks who is asking before it decides what to serve. If you are logged in, or arriving directly by typing the address, you get the real site. If you arrive from a Google search result, or on a phone, you get redirected to a scam page or a fake pharmacy.

So your site looks perfect every time you check it, while a chunk of your traffic is being sent somewhere else entirely.

The fix: test the way a stranger would. Log out, open a private browsing window, search for your business name on Google and click the result. Then do the same on your phone, on mobile data rather than your office wifi. If any of those go somewhere unexpected, you have your answer.

Search results show pages you never wrote

Search your own domain on Google using site:yourdomain.com and read the list. If you find pages about products you do not sell, in languages you do not speak, or with titles full of pharmaceutical and gambling terms, your site is hosting spam content for someone else.

This is called SEO spam or pharma hacking, and it is one of the most common WordPress infections. The attacker uses your domain's reputation to rank their junk. You get the search penalty.

New admin users you did not create

Open Users in your dashboard and read every single account with an Administrator role. Anything you cannot personally account for is a serious problem, especially accounts with odd usernames or email addresses on domains you do not recognise.

Be careful here. Attackers sometimes hide their account so it does not appear in the user list at all, which means an empty-looking list is reassuring but not proof.

Files with recent modification dates you cannot explain

If nobody has touched the site in three months but core files were modified last Tuesday, something changed them. Common targets are wp-config.php, .htaccess, index.php, and the theme's functions.php file.

Injected code is usually easy to spot once you see it: a long unreadable block of encoded characters that looks nothing like the rest of the file, often wedged at the very top or bottom.

Your email suddenly stops arriving

If contact form notifications, receipts or password resets stop landing, and you start getting bounce messages for emails you never sent, your server may be being used to send spam.

The consequence outlives the infection. Once your domain or server IP ends up on an email blacklist, legitimate mail from your business keeps getting rejected long after the malware is gone. Getting delisted is slow and manual.

Warnings from browsers or a drop in traffic

A red interstitial warning in Chrome, a "deceptive site ahead" message, or a security notice inside Google Search Console are all late-stage signals. So is a traffic graph that fell off a cliff with no other explanation.

By the time these appear, the infection has typically been there for a while and real visitors have already been affected. Do not wait for this stage to take the earlier signs seriously.

Odd server behaviour

Watch for a site that got slow for no reason, hosting resource warnings, unexplained traffic spikes at strange hours, or files appearing in your uploads folder that are not images. Compromised sites are made to work: mining, spamming, hosting phishing pages. That work costs CPU, and the bill shows up as sluggishness.

What to do if two or more of these ring true

Do not start deleting things. You will destroy evidence and probably miss the backdoor, which means the infection comes straight back.

  • Take a full backup of the current state, infected and all, before you change anything.
  • Change every password: WordPress admins, hosting, FTP, database.
  • Run a proper malware scan rather than trusting a visual check.
  • Find and remove the entry point, not just the visible symptom.
  • Then, and only then, restore or clean, and request review with Google if you were flagged.

The version where you never have to do any of this

Every item on this checklist is something you have to remember to look for, on a schedule, forever. That is the real problem. Nobody runs a mobile redirect test on a Tuesday when the business is busy.

Up Speed runs malware scanning and 24/7 uptime monitoring on every plan, so the checking is not on your list. The Professional plan adds the Wordfence firewall, iThemes hardening, two-factor login and blacklist monitoring through Google Safe Browsing, which is the piece that tells us if Google has flagged you before your traffic disappears. And the important part of our SLA: when a scan finds something, we deal with it. You get a plain-English explanation of what happened, not a notification and a link to a support article.

Share this post

Start with a free WordPress site audit.

Send us your site and we will check its speed, security, backups, and update status, then write up what we found. A real person does the review.

  • No credit card required

  • No contracts, cancel anytime