Most WordPress compromises stay hidden for weeks. No defaced homepage, no ransom note.
Technical support and fixing a compromised WordPress site
Often here's no dramatic defacement, no ransom note, no angry emails from customers. Instead, the compromise sits quietly in the background, harvesting credit card details, sending spam, or quietly redirecting your visitors somewhere you really don't want them to go. By the time most site owners notice, the malware has been there for weeks or months.
The good news is that compromises leave fingerprints. If you know where to look, you can catch an infection early, before it trashes your search rankings or gets your domain blacklisted. Here's what I look for when auditing a WordPress site, plus the quick checks you can run yourself today.
The warning signs
1. Unexplained traffic drops or ranking changes
A sudden dip in organic traffic is often the first visible symptom. Malicious scripts injected into your pages can trip Google's Safe Browsing warnings, trigger "this site may be hacked" notices in search results, or cloak content so that search engines see something different from your visitors. Check Google Search Console for security issues and manual actions; it's free and it tells you what Google actually sees.
2. Strange files in your installation
Attackers love to drop files with innocent-looking names into directories nobody watches. Classic hiding spots include:
wp-content/uploads/, which should only ever contain media files, never PHP- Your theme's root directory and child directories
wp-includes/andwp-admin/, where files masquerading aswp-class.phporwp-tmp.phpsit alongside genuine core files
A file modified recently in wp-includes/ almost always means trouble. Legitimate core files only change when you update WordPress.
3. Suspicious cron jobs and scheduled tasks
Few things are as overlooked as WordPress's own scheduler. Compromised sites often gain malicious entries in the wp_options table under cron, silently re-downloading malware even after you've cleaned the files. While you're there, check for phantom admin users. Attackers frequently create accounts with usernames like wp_support or admin_2024 and give them administrator rights.
4. Injected scripts and iframes
Base64-encoded strings, long minified blobs appended to your functions.php, or <script> tags referencing unfamiliar external domains are all red flags. Cloaking scripts are particularly sneaky: they check whether the visitor came from Google or is using a mobile device, then show the malware only to those users. That's why the site owner often browses their own site and sees nothing wrong, while customers are being hit.
5. Your site is slower than it should be
Malware isn't written for performance. Crypto-mining scripts, spam-generation routines, and outbound connections to command-and-control servers all eat resources. If your hosting provider suddenly starts nagging you about CPU limits, and nothing on the site has changed, investigate.
6. Search results you didn't write
Query Google with site:yourdomain.com and look for Japanese pharmaceutical spam, poker pages, or anything in a language you don't recognise. The "Japanese keyword hack" is notorious for injecting thousands of gibberish pages that only appear in search results, invisible when browsing the site normally.
Quick checks you can run today
Diff your core files. Download a fresh copy of WordPress from wordpress.org and compare it against your installation. Any difference outside wp-config.php and wp-content/ deserves scrutiny.
Check file modification times. From SSH, find . -mtime -3 -type f lists everything changed in the last three days. Legitimate updates are obvious; unexpected changes are not.
Inspect the database. Look at the wp_users table for unfamiliar accounts, and search your posts and pages for <script> and base64_decode.
Scan your site externally. Tools like Sucuri's SiteCheck and UpGuard surface injected content, blacklisting status and exposed version information. Nothing beats a proper server-side scan, but external checks are fast and catch a lot.
Review your access logs. Look for POST requests to files that shouldn't accept POST requests, or repeated hits to xmlrpc.php. Which brings us to the biggest single win most WordPress sites can make.
Close the door behind you
Spotting an infection is only half the battle. The same audit should cover your exposure:
- Disable XML-RPC entirely unless you have a specific dependency on it; it's a brute-force magnet and most sites never use it
- Remove version leakage from your page head, feeds and readme files so attackers can't trivially match your site against known plugin vulnerabilities
- Keep plugins updated religiously, and delete the ones you've stopped using; abandoned plugins are the number one infection vector I see
- Set security headers properly, but test them carefully; a misconfigured
Header setdirective in.htaccesscan take a whole site down with a 500 error - Back up regularly, store backups off-site, and actually test restoring one
Ten minutes of systematic checks weekly catches most compromises before they cascade. Set a reminder, run the file diffs, review new users, glance at Search Console. Automation helps but nothing replaces periodic hands-on inspection.
Technical support and fixing a compromised WordPress site
If you're managing multiple WordPress installations or simply don't want to think about this at all, I can audit your sites and harden the configuration. Get in touch and we'll sort it.
Ready to elevate your WordPress site?
Whether you're launching a new site, strengthening security, or integrating WooCommerce, I can help transform your vision into a high-performing online presence.
More WordPress posts
—
Tech Support: Fixing a compromised WordPress site
Most WordPress compromises stay hidden for weeks. No defaced homepage, no ransom note. More on how to spot a compromised WordPress site Technical support for suspected WordPress hacks Any malicious…
Continue reading "Tech Support: Fixing a compromised WordPress site"
—
How to spot a compromised WordPress site before it's too late
Most WordPress compromises stay hidden for weeks. No defaced homepage, no ransom note. Technical support and fixing a compromised WordPress site Often here's no dramatic defacement, no ransom note, no…
Continue reading "How to spot a compromised WordPress site before it's too late"
—
Modern WordPress security: why management beats manual hardening
Discover why the latest WordPress updates and tools like Wordfence make active management more effective than old-school hardening techniques. A few years ago, I wrote about Hardening WordPress against hacking.…
Continue reading "Modern WordPress security: why management beats manual hardening "
—
Enhancing WordPress Search: The Best Plugins and Tools for 2026
Visitors come expecting to find what they need quickly; when search fails, bounce rates climb and conversions slip. The default WordPress search leaves much to be desired, which means you…
Continue reading "Enhancing WordPress Search: The Best Plugins and Tools for 2026 "
More Security posts
—
Content security policy implementation from generator to production
Why content security policy matters more than you think Content Security Policy (CSP) is one of those security headers that sounds straightforward until you try implementing it on a live…
Continue reading "Content security policy implementation from generator to production"
—
Tech Support: Fixing a compromised WordPress site
Most WordPress compromises stay hidden for weeks. No defaced homepage, no ransom note. More on how to spot a compromised WordPress site Technical support for suspected WordPress hacks Any malicious…
Continue reading "Tech Support: Fixing a compromised WordPress site"
—
How to spot a compromised WordPress site before it's too late
Most WordPress compromises stay hidden for weeks. No defaced homepage, no ransom note. Technical support and fixing a compromised WordPress site Often here's no dramatic defacement, no ransom note, no…
Continue reading "How to spot a compromised WordPress site before it's too late"
—
Modern WordPress security: why management beats manual hardening
Discover why the latest WordPress updates and tools like Wordfence make active management more effective than old-school hardening techniques. A few years ago, I wrote about Hardening WordPress against hacking.…
Continue reading "Modern WordPress security: why management beats manual hardening "