Skip to content
Emergency response

Hacked WordPress site? We clean it up and lock it down

Redirects to shady sites, Japanese pages in Google, a “This site may be hacked” warning, your host suspending your account: your WordPress site is compromised. Every hour counts (search rankings, blocked emails, customer data). Here is what to do right now, and how V-Shield gets you back on track.

Tell-tale signs

  • Visitors (often on mobile) are redirected to gambling, pharmacy or scam sites.
  • Google shows “This site may be hacked”, or Japanese/Chinese pages appear in search results.
  • An administrator account you do not know has appeared in WordPress.
  • Your host reports malware, sends a warning or suspends your site.
  • Your domain sends spam: your emails land in junk folders or are rejected.
  • Unknown PHP files sit in wp-content/uploads or at the site root.
  • The site is suddenly slow, crashes, or the home page has been replaced.

Do this now

  1. 1.

    Do not delete files at random

    Blind deletions often break the site while leaving the backdoor that lets the attacker come back.

  2. 2.

    Change your passwords

    Hosting, FTP/SFTP, database and every WordPress administrator account, from a clean computer.

  3. 3.

    Keep a copy of the current state

    It helps understand how the attacker got in, and ensures none of your content is lost.

  4. 4.

    Tell your host

    Especially if the site is suspended: they usually expect a cleanup commitment before reactivating it.

How V-Shield cleans your site

  1. 1

    Full analysis

    A copy of the site is scanned with ClamAV, WordPress-specific YARA rules and integrity checks of core, plugins and themes.

  2. 2

    Database

    We look for scripts injected into content and options, and for rogue administrator accounts.

  3. 3

    Cleanup and quarantine

    Backdoors and malicious files are removed. Anything removed goes into a reversible quarantine: nothing is lost for good.

  4. 4

    Closing the holes

    Core, plugin and theme updates, application firewall, configuration and back-office hardening.

  5. 5

    Continuous monitoring

    Automatic scans, alerts on drift (new admin, modified file) and 24/7 monitoring to stop reinfection.

Why WordPress sites get hacked

Most of the time the way in is an outdated plugin or theme, a “nulled” theme downloaded for free, a weak or reused password, or another compromised site on the same hosting account. Cleaning without fixing the cause just means waiting for the next infection: V-Shield fixes the cause, then keeps watching.

After the cleanup: never again

Once your site is clean, the V-Shield agent stays in place: daily scan (every 6 h on Pro), firewall, backups and alerts. You are warned at the first anomaly, before your visitors and before Google.

See plans

Frequently asked questions

How long does a cleanup take?

It depends on the extent of the infection and the size of the site. Analysis starts as soon as we have access (V-Shield plugin or FTP/SFTP), and we keep you posted at every step.

Will I lose my content?

No. A copy of the current state is kept and removed files go into a reversible quarantine. Your pages, posts and orders stay in place.

Google flagged my site as dangerous. What now?

The site must first be truly cleaned, then a review requested in Search Console. A request sent before a complete cleanup is rejected and delays the warning removal.

My host suspended my site.

That is common. We can work on a copy, then give you what your host needs to reactivate the account.

My site is not on WordPress.

V-Shield also has an agent for custom PHP and HTML sites. Describe your situation in the form.

Site hacked? You do not have to handle it alone.

Tell us what is happening: we get back to you quickly with a diagnosis and an action plan.

Request emergency help