Most WordPress compromises stay hidden for weeks. No defaced homepage, no ransom note.

Technical support and fixing a compromised WordPress site

Often here's no dramatic defacement, no ransom note, no angry emails from customers. Instead, the compromise sits quietly in the background, harvesting credit card details, sending spam, or quietly redirecting your visitors somewhere you really don't want them to go. By the time most site owners notice, the malware has been there for weeks or months.

The good news is that compromises leave fingerprints. If you know where to look, you can catch an infection early, before it trashes your search rankings or gets your domain blacklisted. Here's what I look for when auditing a WordPress site, plus the quick checks you can run yourself today.

The warning signs

1. Unexplained traffic drops or ranking changes

A sudden dip in organic traffic is often the first visible symptom. Malicious scripts injected into your pages can trip Google's Safe Browsing warnings, trigger "this site may be hacked" notices in search results, or cloak content so that search engines see something different from your visitors. Check Google Search Console for security issues and manual actions; it's free and it tells you what Google actually sees.

2. Strange files in your installation

Attackers love to drop files with innocent-looking names into directories nobody watches. Classic hiding spots include:

  • wp-content/uploads/, which should only ever contain media files, never PHP
  • Your theme's root directory and child directories
  • wp-includes/ and wp-admin/, where files masquerading as wp-class.php or wp-tmp.php sit alongside genuine core files

A file modified recently in wp-includes/ almost always means trouble. Legitimate core files only change when you update WordPress.

3. Suspicious cron jobs and scheduled tasks

Few things are as overlooked as WordPress's own scheduler. Compromised sites often gain malicious entries in the wp_options table under cron, silently re-downloading malware even after you've cleaned the files. While you're there, check for phantom admin users. Attackers frequently create accounts with usernames like wp_support or admin_2024 and give them administrator rights.

4. Injected scripts and iframes

Base64-encoded strings, long minified blobs appended to your functions.php, or <script> tags referencing unfamiliar external domains are all red flags. Cloaking scripts are particularly sneaky: they check whether the visitor came from Google or is using a mobile device, then show the malware only to those users. That's why the site owner often browses their own site and sees nothing wrong, while customers are being hit.

5. Your site is slower than it should be

Malware isn't written for performance. Crypto-mining scripts, spam-generation routines, and outbound connections to command-and-control servers all eat resources. If your hosting provider suddenly starts nagging you about CPU limits, and nothing on the site has changed, investigate.

6. Search results you didn't write

Query Google with site:yourdomain.com and look for Japanese pharmaceutical spam, poker pages, or anything in a language you don't recognise. The "Japanese keyword hack" is notorious for injecting thousands of gibberish pages that only appear in search results, invisible when browsing the site normally.

Quick checks you can run today

Diff your core files. Download a fresh copy of WordPress from wordpress.org and compare it against your installation. Any difference outside wp-config.php and wp-content/ deserves scrutiny.

Check file modification times. From SSH, find . -mtime -3 -type f lists everything changed in the last three days. Legitimate updates are obvious; unexpected changes are not.

Inspect the database. Look at the wp_users table for unfamiliar accounts, and search your posts and pages for <script> and base64_decode.

Scan your site externally. Tools like Sucuri's SiteCheck and UpGuard surface injected content, blacklisting status and exposed version information. Nothing beats a proper server-side scan, but external checks are fast and catch a lot.

Review your access logs. Look for POST requests to files that shouldn't accept POST requests, or repeated hits to xmlrpc.php. Which brings us to the biggest single win most WordPress sites can make.

Close the door behind you

Spotting an infection is only half the battle. The same audit should cover your exposure:

  • Disable XML-RPC entirely unless you have a specific dependency on it; it's a brute-force magnet and most sites never use it
  • Remove version leakage from your page head, feeds and readme files so attackers can't trivially match your site against known plugin vulnerabilities
  • Keep plugins updated religiously, and delete the ones you've stopped using; abandoned plugins are the number one infection vector I see
  • Set security headers properly, but test them carefully; a misconfigured Header set directive in .htaccess can take a whole site down with a 500 error
  • Back up regularly, store backups off-site, and actually test restoring one

Ten minutes of systematic checks weekly catches most compromises before they cascade. Set a reminder, run the file diffs, review new users, glance at Search Console. Automation helps but nothing replaces periodic hands-on inspection.

Technical support and fixing a compromised WordPress site

If you're managing multiple WordPress installations or simply don't want to think about this at all, I can audit your sites and harden the configuration. Get in touch and we'll sort it.