You log into your site and something feels off.
Maybe the homepage looks fine, but your contact form stopped sending emails. Maybe Google throws up a scary warning. Maybe customers say they got redirected to a sketchy casino page and you’re sitting there thinking, wait, what? I’ve seen this happen to small business owners who thought their little 6-page brochure site was too boring to target. Nope. Hackers love boring sites, because boring sites often get ignored for months.
The annoying part is that hacked WordPress sites don’t always look obviously broken. Sometimes the damage hides in the background for weeks while spam pages get indexed, malware spreads, or your hosting account starts sending rubbish emails to half the internet.
So let’s get practical. Here are the signs to watch for, and what you should actually do if you spot them.
Your site suddenly redirects people somewhere weird
This is a big red flag. A visitor clicks your normal website link, and instead of landing on your bakery, plumbing business, or 47-product WooCommerce store, they end up on a fake pharmacy page, a gambling site, or some random “you’ve won an iPhone” nonsense.
Sometimes it only happens on mobile. Sometimes only first-time visitors get hit. That’s what makes it sneaky. You check the site yourself, everything seems normal, and meanwhile real customers are being sent off into the weeds.
If this happens, stop fiddling with design settings and treat it like a security issue right away. Redirect hacks usually mean malicious code has been added somewhere – your theme files, a plugin, your .htaccess file, or even the database.
- Test your site on your phone, desktop, and in an incognito browser
- Ask someone else to check from a different location
- Pause any ads you’re running until it’s cleaned up
- Contact your host and ask if they detected malware or file changes
If you’re already in that mess, proper WordPress security help is a lot faster than guessing your way through file folders you barely recognize.
Google starts showing security warnings
This one’s hard to miss. You click your own website in search results and see “This site may be hacked” or a big red browser warning. That’s bad for traffic, obviously. But it’s also a trust killer. Most people won’t click through just to give you the benefit of the doubt.
And yes, even a small local service business can get flagged.
Usually this means Google’s found malware, spam content, suspicious scripts, or deceptive pages on your site. Cleaning it up can take a few hours if the infection is light. It can also turn into a full-day headache if spam pages have multiplied across dozens or hundreds of URLs.
After cleanup, you’ll need to request a review in Google Search Console. That’s the bit people forget. They remove the infection, then wonder why the warning is still hanging around two days later.
If you want to understand how neglected sites drift into this kind of mess, this article on what happens if you never update WordPress lays it out pretty clearly.
You notice new pages, posts, or admin users you didn’t create
Honestly, this is one of the clearest signs.
If your WordPress dashboard suddenly shows weird blog posts, hidden product pages, draft pages full of spammy links, or a new admin account called something like “wpsupport123”, you’ve probably been compromised. No legit plugin just casually creates mystery administrators for fun.
Check these places first:
- Users – look for admin accounts you don’t recognize
- Pages and Posts – especially drafts, trashed items, and scheduled posts
- Media Library – odd PHP files or filenames stuffed with random characters
- WooCommerce products – surprise listings, price changes, or weird descriptions
Delete the fake users only after you’ve reset passwords and checked how they got in. Otherwise they may just come back. And change every password tied to the site – WordPress admin, hosting, database, FTP, email accounts. Yes, all of them. A bit tedious. Still cheaper than losing customer trust.
Your site gets slow for no clear reason
Now, slow websites happen for all sorts of boring reasons. Heavy images. Cheap hosting. Too many plugins. A homepage video nobody asked for. But if your site suddenly goes from loading in 1.8 seconds to 9 seconds, and you haven’t changed much, malware could be chewing through server resources.
I’ve seen infected sites quietly run spam scripts, create hidden pages, and hammer the database in the background while the business owner just thinks, huh, maybe WordPress is acting up again.
Look for patterns:
- CPU or memory usage spikes in your hosting panel
- Your site goes down at random times
- Pages load slowly even after caching is cleared
- Your host sends “resource usage” or “suspicious activity” emails
Not every slowdown means a hack. But unexplained performance drops deserve a proper check, especially if they come out of nowhere.
Customers say your emails are landing in spam – or you stop receiving forms
This one gets missed alot.
If a hacked site starts sending spam through your domain, your email reputation can tank. Then your quote requests, order confirmations, and password reset emails start disappearing into spam folders. Or your contact form stops reaching you entirely.
That doesn’t always mean the form plugin is broken. Sometimes your domain has been abused.
For a small business, this hurts fast. A plumber missing three leads in a week notices. A small online shop losing order emails notices even faster.
Check your hosting mail logs if you have access. If not, ask your host whether unusual outbound email activity has been detected. Also test every major form on your website manually. Contact form, quote form, checkout emails, account registration. Click the buttons yourself. Don’t assume.
Your files or plugin settings keep changing on their own
If you fix something and it breaks again the next day, that’s suspicious.
Maybe a plugin gets reinstalled after you removed it. Maybe your homepage title changes. Maybe a line of code appears in the header file again and again. That usually means the real backdoor is still there somewhere, tucked into a plugin file, theme folder, uploads directory, or database entry.
This is where DIY cleanup often goes sideways. You remove the visible mess, but not the hidden entry point. Then the infection reappears and you have to do the whole miserable dance again.
A decent cleanup should include:
– scanning files and the database
– removing malicious code and backdoors
– updating WordPress, themes, and plugins
– replacing compromised passwords
– checking user accounts and file permissions
And after that, ongoing protection matters. Regular updates, backups, malware scans, and basic monitoring are the boring parts that stop this from happening again. That’s exactly why some businesses hand it off through website maintenance and management instead of trying to remember plugin updates between client calls.
Your hosting company suspends the site
Not subtle. Not fun.
If your host suspends your account for malware, phishing files, or abusive scripts, take it seriously. They usually don’t pull the plug because of one harmless glitch. In shared hosting especially, infected sites can affect other accounts on the same server, so hosts move pretty fast.
The first step is getting the exact reason for suspension. Ask for the file paths, malware names, timestamps, anything they can share. That saves time. Then work through cleanup before asking them to restore public access.
If you’re rebuilding after a hack, don’t just put the same old vulnerable setup back online. That’s how people get hacked twice in the same month. And yes, I’ve seen this kill a launch.
What to do in the first hour
If you think your site’s been hacked, don’t panic. But don’t ignore it either.
Here’s a good first-hour plan:
- Take the site offline or put up a maintenance page if the hack is visible
- Change passwords for WordPress, hosting, FTP, database, and email
- Make a backup copy before deleting anything, even infected files
- Scan the site and ask your host what they can see server-side
- Check admin users, recent file changes, and suspicious plugins
- Update everything after cleanup, not before random file deletions
If your store is running WooCommerce, move fast. Every extra hour can mean failed payments, customer confusion, and lost trust. For store owners, this gets expensive quick. A small shop doing even €200 to €500 a day in sales feels the hit immediately.
And while you’re tightening things up, it helps to read about why backups save your business. Boring topic. Absolutely. But a clean backup can turn a disaster into a mildly annoying afternoon.
The part people skip: preventing the next hack
Cleaning a hacked site is one job. Stopping the next one is another.
Most small business WordPress sites get compromised through very ordinary stuff: outdated plugins, weak passwords, nulled themes, abandoned contact form plugins, or admin accounts that belonged to a freelancer from 2022 who still has access. Nothing glamorous.
A sensible setup doesn’t need to be expensive either. Basic paid security tools might cost €5 to €20 a month. Maintenance plans often start around the price of a couple of takeaway pizzas and save you hours of stress. Worth it, if you ask me.
At minimum, you want automatic backups, plugin and core updates, strong passwords, limited admin users, and malware scanning. Fancy custom hardening is nice for bigger stores, but honestly most small sites just need the basics done consistently. That’s the bit people miss.
Because the real warning sign isn’t always the weird redirect or the Google message. Sometimes it’s simpler than that. A site that’s been ignored for 11 months. A plugin update you’ve postponed six times. An old admin account nobody uses. That’s where the trouble starts.
Small things. Until they aren’t.