Your site shows betting ads on mobile but looks fine on your laptop. Or customers report “your site gave my phone a virus.” These are classic signs of a hacked WordPress site – and panic-reinstalling usually brings the malware straight back. Here are the warning signs, the first five steps in the right order, and how to stop it repeating.
Prevention beats cleanup: what a maintenance plan includes and hosting with care.
How do I know if my website is hacked?
Your site is likely hacked if Google shows betting, pharma or adult pages under your address, mobile visitors get redirected to spam while desktop looks normal (cloaking), Search Console reports malware or “deceptive pages”, your host suspends the account for spam mailouts, or new admin users and unknown plugins appear. One confirmed sign beats ten suspicions – check your site on a phone with mobile data and in Search Console before concluding anything.
What are the first five steps after a hack?
Step 1 – Do not just reinstall yet. Put the site in maintenance mode and take a full backup of the infected state (evidence for finding the entry point). Change hosting, FTP and database passwords from a clean device.
Step 2 – Scan and identify. Run a malware scan (Wordfence or Sucuri plugin, plus the host scanner). Note infected files, unknown admins, and recently modified files – the pattern points to the entry: usually an outdated plugin, nulled theme, or stolen admin password.
Step 3 – Clean properly. Remove unknown users and plugins, replace WordPress core and all plugins with fresh copies (never “clean” core files by hand-editing), restore the database tables only if clean or clean them row by row, and remove spam pages plus their sitemap entries.
Step 4 – Close the entry point. Update everything, delete nulled or abandoned plugins, enforce strong passwords with two-factor login, and fix file permissions. Cleaning without closing the door guarantees reinfection within weeks.
Step 5 – Delist and verify. Request a review in Search Console security issues, verify no spam URLs remain indexed, and monitor for 30 days. Tell customers honestly if their data was at risk – silence is worse than the hack.
Why do small business sites get hacked?
Because they run three-year-old plugins, share one “admin/admin123” login across staff, install nulled premium themes carrying backdoors, and keep no tested backups. Attackers automate all of this – your traffic size is irrelevant. The cheapest prevention is monthly updates plus off-server backups, which is exactly what a basic care plan covers.
FAQs
Will I lose Google rankings? Temporarily, while flagged. Clean fully, request review, and rankings typically recover over weeks. Partial cleans that leave spam pages indexed drag this out for months.
Should I pay the “ransom” or the scary email? No. Most scary mails (“we hacked your site, pay in crypto”) are bluffs sent to thousands of addresses. Verify with a real scan before believing anything.
Can DeskBees clean and protect my site? Yes – cleanup plus the maintenance routine that stops repeats. Contact us with your host and symptoms; keep admin access ready.
Last updated: 20 September 2026.

