Emergency Rescue Plan active — senior engineer replies within 12 hours See the plan →
Security · people search: “My WordPress site got hacked. Now what?”

My WordPress site got hacked. Now what?

The panic is normal. The response shouldn't be. Here's the calm, step-by-step playbook — and how to know if you need a professional.

Plain English · no jargon · 4-minute read

Part of Security & Emergencies — read first, then fix it in 48h.

Your WordPress site is showing pop-ups you didn't add, redirecting to strange pages, or your host has suspended it for 'malicious activity'. Take a breath. Hundreds of thousands of WordPress sites get hacked every year, and almost all of them can be put right. What matters is how you respond in the first hours — that decides whether you lose the site, the ranking, or customer data.

Check these first, yourself

  1. Change every password and key you can reach now: hosting — The service that runs your site on a server; the plan you pick decides your speed ceiling and your crash risk., admin users, FTP — File Transfer Protocol — the old way of moving files to a server; left open and unencrypted, attackers love it., payment accounts.

  2. Do NOT wipe and reinstall WordPress yet. You'll lose the evidence of how they got in, and you may destroy the data you need.

  3. Log into your host and look for the last-modified dates on your theme and upload folders. Recently modified files are the fingerprints.

  4. Enable two-factor — A second proof of identity (a code from your phone) on top of the password, so a stolen password isn't enough. on your admin account and every email account connected to the site.

Should you fix it yourself or call a rescue?

Have you tried the free fixes (images, caching, plugins)?If yes and it's still slow → the problem is deeper.
Is your hosting or server the bottleneck?Shared hosting, old PHP, no object cache → server-level problem.

Still have questions?

Should I pay the ransom they ask on the hack screen?

Almost never. Extortion screens on WP sites are usually automated malware looking for a quick payout — they rarely restore anything, and paying tells the attacker you're worth revisiting.

Can I just restore an old backup?

Only if the backup is clean — and the backdoor can live in files you restored. Once the site is restored, the hackers can stroll back in through the same door. The infection has to be removed at the source.

Skip the diagnosis

Get this fixed in 48 hours, flat rate

Same problem, less sleep lost. One of these rescues maps directly to what you're dealing with.

Don't want to become an expert in this?

Send the symptom — get a flat-rate ticket and a plain-English plan within 12 hours.

Start the Rescue