
Also on: https://bkdevops.lk/wordpress-site-hacked-signs-recovery/
If your WordPress site suddenly looks wrong, sends spam, or Google warns visitors away, you may be dealing with a compromise. For Sri Lankan service businesses, a hacked site can mean lost leads, damaged trust, and days of downtime.
This guide covers warning signs, a calm recovery sequence, and ways to reduce repeat attacks.
Common signs your WordPress site is hacked
1. Unexpected redirects or fake pages
Visitors may be sent to gambling, pharma, or unrelated sites. Sometimes only mobile users or Google visitors are redirected.
2. Strange admin users or locked-out access
New administrator accounts appear that nobody created, or the usual login fails while someone else has access. Check Users in wp-admin.
3. Spam content, SEO spam, or injected links
Hidden pages, odd posts, or footer links you never added are classic signs. Search Google for site:yourdomain.lk.
4. Browser or Google Safe Browsing warnings
Chrome or Search Console may flag the site as deceptive or containing malware.
5. Sudden resource use or email abuse
CPU/RAM jumps, timeouts, or domain spam can lead hosts to suspend the account.
6. Defacement, odd plugins, or changed core files
Unknown plugins/themes, changed core files, or a replaced homepage deserve urgent attention.
What to do first (containment)
Before reinstalling a theme, slow down and limit damage:
- Put the site in maintenance mode or temporarily take it offline.
- Change all passwords—WordPress, hosting, FTP/SFTP, database, and connected email. Use unique passwords and enable 2FA.
- Export a forensic copy of files and database, even if infected.
- Scan management devices so a stolen password cannot re-infect the site.
- Notify the host so the account can be isolated or quarantined.
Do not delete everything blindly. Logs, timestamps, and a known-good backup may be needed to restore bookings, orders, or forms.
A practical recovery checklist
Recovery is usually identify → clean or restore → harden → monitor.
Step 1: Confirm with more than one signal
- Google Search Console security issues / Safe Browsing status
- Hosting malware scanner
- A reputable WordPress security plugin scan
- Manual review of recent file changes and new users
Cross-check before wiping production data.
Step 2: Prefer a clean restore
If you have a verified clean backup, note the infection date, restore files and database, update WordPress, rotate credentials, and re-check admin users and plugins.
Step 3: Clean in place
When no clean backup exists, remove unknown admin users, delete unused themes/plugins, replace core files with a fresh copy, inspect wp-config.php, .htaccess, index.php, and uploads, clean injected database rows, and reinstall plugins from trusted sources.
Step 4: Clear caches and ask Google to review
- Clear site, CDN, and browser caches
- Resubmit key URLs in Search Console
- Request a security review if Safe Browsing flagged the site
- Watch analytics and server logs
Step 5: Harden the site
- Keep core, themes, and plugins updated
- Use strong unique passwords and 2FA
- Limit login attempts and prefer SFTP
- Use sensible file permissions
- Maintain tested offsite backups
- Avoid pirated themes and plugins
Security is maintenance plus good hosting hygiene.
Sri Lanka SME context
Local businesses use WordPress for bookings, hotel enquiries, menus, tuition leads, and shops. When Google flags the site, phones go quieter even if the shop is open.
- Keep hosting logins with more than one trusted person
- Store backups away from the server
- Document recovery when payments or customer data are involved
- Prefer help available in Sri Lanka time zones
When to call for help
DIY cleanup can work for a simple brochure site with a clean backup. Call a professional for persistent reinfection, WooCommerce or membership data, Google blacklisting, multiple infected sites, or no recent clean backup.
BK DevOps helps Sri Lankan businesses with WordPress malware cleanup, secure recovery, ongoing site care, web design, hosting, and SEO. Get in touch for an assessment.
Comments
Post a Comment