5 Signs Your WordPress Site Has Been Hacked

B
Brad Leiphart
September 2, 2026 · 3 min read
Quick answer: Watch for unexpected redirects, unfamiliar admin users, sudden server-resource spikes, Google Search Console security warnings, and spam content injected into your pages. Any one of these is worth investigating immediately.
In This Article
  1. 1. Unexpected redirects or pop-ups
  2. 2. Unfamiliar admin users or plugins
  3. 3. A sudden spike in server resource usage
  4. 4. A “This site may be hacked” warning
  5. 5. Strange content in your pages that you didn’t write
  6. What to do if you spot any of these

Most hacked WordPress sites don’t announce themselves with a defaced homepage. The far more common pattern is quieter: the site still looks fine to you, while it’s doing something very different for search engines, ad networks, or a specific slice of your visitors. Here’s what to actually watch for.

1. Unexpected redirects or pop-ups

Visitors land on your homepage but get bounced to an unrelated site, or see pop-ups you never installed — especially on mobile, or only when arriving from Google. This is one of the most common symptoms of a compromised site, and it’s often invisible if you only check the site while logged into WordPress, since some malware specifically targets logged-out visitors to stay hidden from the site owner.

2. Unfamiliar admin users or plugins

Check Users › All Users periodically. An administrator account you don’t recognize, created on a date you don’t remember making changes, is one of the clearest signs of compromise there is. Same goes for a plugin in your list that nobody on your team installed — attackers often install a plugin themselves specifically to maintain access even after the original entry point gets patched.

3. A sudden spike in server resource usage

If your hosting dashboard shows CPU or bandwidth usage climbing with no matching increase in real traffic, something on the server may be running that shouldn’t be — sending spam email, mining cryptocurrency, or participating in attacks on other sites. This is often the first sign hosts notice before the site owner does, sometimes resulting in an account suspension notice before you’d otherwise have known anything was wrong.

4. A “This site may be hacked” warning

If Google Search Console flags your site, or Chrome shows visitors a red warning page before they can even load it, take it seriously and act immediately — both of these mean Google’s own systems already detected malicious code or content, and every hour that warning stays up costs you real traffic and trust.

5. Strange content in your pages that you didn’t write

Spam links, pharmaceutical or gambling content, or foreign-language text injected into pages, posts, or even your site’s footer are classic signs of an SEO spam injection — a common attack where compromised sites get used to boost the search rankings of other, unrelated pages. View your page source (not just the rendered page) since injected content is sometimes hidden with CSS specifically so it’s invisible to you while still being crawled by search engines.

What to do if you spot any of these

  1. Change all admin passwords immediately, from a different, clean device if possible
  2. Take the site offline or put it in maintenance mode while you investigate, so the problem doesn’t keep spreading or getting re-indexed by Google in its compromised state
  3. Check Users › All Users and your active plugins list for anything unfamiliar
  4. Restore from a clean backup taken before the compromise, if you have one — this is usually faster and more reliable than trying to manually find and remove every piece of injected code
  5. Once clean, request a security review in Google Search Console if your site was flagged

If it does happen, you’re covered: every NetConnect Digital WordPress Care Plan includes a hack cleanup guarantee — if your site is compromised while you’re on an active plan, we clean and restore it at no additional charge.

Keep Your WordPress Site Protected

Daily backups, security monitoring, and updates — handled for you, starting at $59/mo.

See Our Care Plans
B
Brad Leiphart
Founder, NetConnect Digital

Brad leads NetConnect Digital's WordPress support and maintenance practice, helping small businesses keep their sites secure, fast, and online.

Get Started Today Call Us Now