
What actually happens when your WordPress site gets hacked
Here is the part nobody tells you: when a WordPress site gets hacked, it usually keeps working. The homepage loads, the contact form sends, and the owner has no idea anything is wrong. That is by design. Modern hacks make money by staying invisible, and the longer they hide, the more damage they do to your search rankings, your email deliverability, and your customers’ trust.
This post is for small business owners running WordPress who want the real sequence of events: how a hacked WordPress site got that way, what the hack is doing right now, how owners actually find out, and what cleanup involves. No scare tactics, just what we see when a hacked site lands on our bench.
TL;DR
- Almost every WordPress hack comes in through an outdated plugin or theme, not WordPress core, and it is done by a bot, not a person targeting you.
- Hacked sites are built to look normal to their owner. Most people find out from Google, their host, or a customer.
- Real cleanup means finding the entry point and every backdoor, not just deleting the obvious bad files. We do it for a flat $299.
- Updates applied within days, off-site backups, and monitoring turn a hack from a crisis into a non-event.
- How WordPress sites actually get hacked
- What the hack does with your site
- How you find out (it is usually not from your site)
- What real cleanup involves
- What a hack costs beyond the cleanup
- How to make a hack a non-event
- Frequently asked questions
How WordPress sites actually get hacked
WordPress powers over 40% of all websites, according to W3Techs. That market share makes it the biggest target on the internet, but not in the way most people picture. Nobody sat down and chose your site. Automated bots scan millions of sites a day looking for one thing: known vulnerabilities in outdated software.
And the outdated software is almost never WordPress itself. Patchstack’s security research shows year after year that the overwhelming majority of newly disclosed WordPress vulnerabilities are in plugins and themes, not core. A contact form plugin that has not been updated in eight months is a far more likely entry point than WordPress itself.
The other common doors are weak or reused admin passwords, and crowded hosting accounts where several sites share one login, so one infected site spreads to the rest of the account. In every case the pattern is the same: the attack is automated, opportunistic, and preventable with boring maintenance.
What the hack does with your site
Once a bot is in, it installs a backdoor (a small file that lets the attacker return whenever they want) and then puts your site to work. That work usually looks like one of these:
- SEO spam. Thousands of hidden pages for pharmaceuticals, knockoff goods, or gambling get injected into your site to hijack your domain’s reputation in Google.
- Malicious redirects. Your visitors get bounced to scam sites. Often only some visitors, some of the time, which makes it maddening to reproduce.
- Phishing pages. A fake bank or parcel-delivery login page gets hosted in a hidden folder on your domain, and your domain takes the blame.
- Spam email. Your server starts sending thousands of junk messages, which lands your domain on email blocklists.
- Card skimming. On WooCommerce stores, injected code quietly copies payment details at checkout.
Key insight: a hacked site is engineered to look normal to its owner. Many infections show the spam only to search engine crawlers, or redirect only visitors arriving from Google, so the person who checks the site every day sees nothing wrong.
How you find out (it is usually not from your site)
Because the infection hides from you, discovery almost always comes from outside. In our experience the first signal is one of these four:
- Google flags it. A “this site may be hacked” note appears under your search listing, or Search Console sends a security issue alert. Google’s Safe Browsing system also powers the full-screen red warning in Chrome that stops visitors cold.
- Your rankings slide. The injected spam drags down your whole domain, and traffic drops week after week with no obvious cause.
- Your host suspends you. Hosts detect outbound spam or malware and take the site offline, sometimes with one vague email as notice.
- A customer tells you. Usually some variation of “your website sent me somewhere weird.” By then it has been happening for a while.
The gap between infection and discovery is commonly weeks, sometimes months. Every one of those days, the site is quietly damaging your domain’s reputation with Google and with email providers.
What real cleanup involves
The instinct is to delete the weird files and move on. That fails, because the visible spam is not the infection. The backdoor is, and there is almost never just one. Real cleanup is a process:
- Take a full copy of the site first. Evidence matters, especially if payments or customer data are involved.
- Find the entry point. Server logs show which plugin or account let the attacker in. Skip this step and the site gets re-hacked within days.
- Remove every backdoor. Compare core, plugin, and theme files against known-clean copies, and inspect the database too, not just the file system.
- Update and rotate everything. WordPress, plugins, themes, PHP, admin passwords, database credentials, hosting and FTP logins.
- Audit user accounts. Attackers add their own admin users so they can walk back in through the front door later.
- Request review. Once clean, ask Google to re-check the site through Search Console so the warnings and blocklist entries are lifted.
This is exactly what our hack cleanup service does, for a flat $299. If you are not hacked and just want to know whether your site is clean and patched, a security audit is $149.
What a hack costs beyond the cleanup
The cleanup fee is the small part. The larger cost is everything that happens while the site is infected and while trust is rebuilt afterwards:
- Lost rankings. Spam pages and browser warnings push your legitimate pages down, and recovery after cleanup takes time even when everything is done right.
- Lost visitors. A red browser warning turns away nearly everyone who sees it, and you rarely get a second visit from them.
- Email trouble. If your domain lands on spam blocklists, your normal business email starts silently going to junk folders.
- Your time. Owners who go it alone routinely lose days to a cleanup we finish in one, and the site stays compromised the whole time.
None of that shows up on an invoice, which is why the cheapest moment to deal with a hack is before it happens.
How to make a hack a non-event
Prevention is not a product, it is a routine. The sites that never end up on our cleanup bench share the same four habits:
- Updates within days, not months. In nearly every cleanup we do, the vulnerability that let the attacker in already had a fix available. The site just had not applied it.
- Off-site backups, tested. A nightly backup stored away from the server turns “we are down” into “we restored, now let’s close the entry point.”
- Fewer, better plugins. Every plugin is a door. Delete deactivated ones entirely, since they can be exploited even while switched off.
- Least privilege. One admin account per human who needs it, strong unique passwords, and two-factor authentication on all of them.
If you would rather not own that routine, that is what managed care is for. Our managed hosting starts at $40/mo and includes updates, off-site backups, and monitoring, so the patching is our job instead of yours. Sites on our $299/mo website subscription get all of that included as part of the plan.
Frequently asked questions
How do WordPress sites get hacked in the first place?
Almost always through a known vulnerability in an outdated plugin or theme, found by an automated bot scanning millions of sites. Weak admin passwords and crowded shared hosting accounts are the other common doors. Attacks are opportunistic, so a small local site is just as likely a target as a big one.
My site looks fine. How can I tell if it is hacked?
Search Google for site:yourdomain.com and look for pages you did not create. Check Search Console for security alerts, and open your site from a Google search on your phone, since some infections only redirect those visitors. A $149 security audit settles the question properly.
Should I just delete everything and rebuild?
Usually no. A rebuild that skips finding the entry point often gets re-hacked, because the vulnerable plugin or stolen password comes back with it. Cleaning the existing site, closing the entry point, and updating everything is faster and preserves your content and SEO. Rebuild only if the site was already due for it.
How much does hack cleanup cost?
Our hack cleanup is a flat $299. That covers finding the entry point, removing the infection and its backdoors, updating and hardening the site, and submitting the Google review that clears the warnings. A preventive security audit, if you are not currently hacked, is $149.
Will Google hold the hack against my site forever?
No. Once the site is clean and Google’s review passes, the warnings come down and rankings can recover. The timeline depends on how long the infection sat there: days for a fast catch, months for a long-neglected one. Nobody can honestly promise you a specific position back.
Is WordPress itself insecure?
No. WordPress core is actively maintained and patched quickly. The risk lives in the ecosystem around it: thousands of third-party plugins and themes of varying quality. A WordPress site with a few well-chosen, updated plugins on decent hosting is a hard target. An unmaintained one is an easy one.
The bottom line
A hacked WordPress site is rarely a lightning strike. It is the predictable result of software that stopped getting updates. The hack hides, an outsider finds it, and the real cost lands on your rankings and your reputation before the cleanup bill is even written.
If your site is showing any of the signs above, our security and hack recovery service will clean it for a flat $299. If you would just like to know where you stand, start with a free website review and we will tell you plainly what we find.