WordPress Site Redirecting to Another Website? How to Clean a Hack and Lock It Down
2 free files — jump to downloads
On this page
- Step 1: Confirm the redirect
- Step 2: Contain the damage
- Step 3: Clean the site
- Best option: restore a clean backup
- No clean backup? Clean in this order
- Step 4: Close the hole they used
- Step 5: Lock it down with four settings
- Step 6: Tell Google the site is clean
- Signs to watch for afterwards
- Download the files
A customer tells you your website sent them to a gambling page, a fake prize or a scam store. You open the site and it looks normal. That mismatch is typical: a WordPress site redirecting visitors elsewhere has almost always been hacked, and the malicious code is often written to hide from logged-in owners.
This guide shows how to confirm the hack, clean it safely, close the hole the attackers used and lock the site down so it does not happen again.
Step 1: Confirm the redirect
- Open your site in a private window, logged out, on your phone, preferably by clicking your site in a Google search result. Many redirect hacks only fire for visitors from search engines or on mobile.
- Check Google Search Console under Security & Manual Actions > Security issues.
- Use a free online website malware scanner to check your homepage from outside.
- Look for unknown administrator accounts under Users.
Step 2: Contain the damage
- Change every password: WordPress administrators, hosting account, FTP/SFTP, database and the email account linked to the site. Assume all of them are known to the attacker.
- Remove unknown admin users, reassigning their content to your account.
- Tell your host. Many hosts scan for and help clean malware, and they need to know if a shared account was compromised.
- If the site handles payments or personal data, consider putting it into maintenance mode while you clean.
Step 3: Clean the site
Best option: restore a clean backup
If you have a backup from before the hack, restoring it is the fastest, most reliable cleanup. Then update everything immediately (Step 4), because the original weakness is still there.
No clean backup? Clean in this order
- Back up the hacked site anyway, so you can recover content if something goes wrong.
- Reinstall WordPress core from Dashboard > Updates > Re-install, which replaces core files with clean copies.
- Reinstall every plugin and theme from the official source. Delete the plugin folders and install fresh copies. Delete anything you do not recognize or do not use.
- Check the usual hiding places in File Manager:
.htaccess(unexpected redirect rules),wp-config.php(strange code at the top), unfamiliar PHP files inwp-content/uploads(the uploads folder should only contain media), and recently modified files. - Check the database for injected scripts in posts, widgets and the
siteurl/homeoptions, ideally with a security scanner.
Important: if the infection keeps returning after cleaning, there is still a backdoor. That is the point to use your host's malware service or a professional cleanup service.
Step 4: Close the hole they used
- Update WordPress, every plugin and every theme.
- Remove nulled or pirated plugins and themes completely. They are one of the most common sources of malware.
- Delete abandoned plugins that have not been updated in a long time.
- Switch to a supported PHP version.
Step 5: Lock it down with four settings
The free SWS Site Fixer plugin (download below) has these on its Security tab:
- Limit login attempts: blocks an IP address after a few wrong passwords, which stops brute-force bots.
- Disable XML-RPC: turns off an old remote-publishing feature bots use to guess passwords at scale. Leave it on only if you use the WordPress mobile app or Jetpack features that need it.
- Hide the WordPress version so bots cannot easily match your site to known vulnerabilities.
- Disable the theme and plugin file editor, so a stolen admin login cannot be used to inject code from the dashboard.
Then add two-factor authentication for every administrator and set up automatic off-site backups.
Step 6: Tell Google the site is clean
- In Search Console, open Security issues.
- Confirm you have fixed the problems, then click Request review and briefly describe what you did.
- Reviews for malware usually take a few days; warnings disappear once Google confirms the site is clean.
Signs to watch for afterwards
- New admin users you did not create.
- Strange new pages or posts (often spam in other languages) appearing in Search Console.
- Sudden drops in traffic or a spike in outgoing links.
- Modified
.htaccessorwp-config.phpfiles.
Prevention is far cheaper than cleanup. Work through the 20-step WordPress security checklist (the PDF is included below) and repeat its monthly routine. Seeing a critical error after cleaning? Follow the critical error guide.
Download the files
Free to use in your own and client projects · no sign-up · tested before upload. Always try files on a staging site first and keep a backup.
-
SWS Site Fixer plugin (free WordPress plugin)sws-site-fixer-v1.0.0.zip · 25.8 KB · v1.0.0Download SWS Site Fixer plugin (free WordPress plugin) (25.8 KB)
-
WordPress security checklist (printable PDF)wordpress-security-checklist.pdf · 5.6 KB · v2026Download WordPress security checklist (printable PDF) (5.6 KB)
Download not working? Tell me and I'll fix it.
Frequently asked questions
Why does my WordPress site only redirect on mobile or from Google?
Many redirect hacks hide from site owners on purpose. They only trigger for visitors arriving from search engines, on phones, or for people who are not logged in, so the owner sees a normal site. Test in a private window from a Google search on your phone.
Can a security plugin remove the malware for me?
Security scanners can detect many infections and some can clean them, but no tool catches everything. Restoring a clean backup and reinstalling WordPress core, themes and plugins from official sources is the most reliable cleanup.
How did hackers get into my WordPress site?
The most common entry points are outdated or nulled plugins and themes with known vulnerabilities, weak or reused passwords, and compromised hosting or FTP accounts. Finding and closing the entry point is essential, or the site will be reinfected.
Will Google blacklist my site?
If Google detects malware or deceptive redirects, it can show a warning to visitors and in search results. Once the site is clean, request a review in Search Console under Security issues; warnings are usually removed after the review.
Should I pay for professional malware removal?
If you have no clean backup, the infection keeps coming back, or the site handles payments or customer data, professional cleanup is worth it. Many hosts also offer malware scanning and cleaning.


