Signs That a Website Has Been Hacked: How to Check Safely

by

website has been hacked featured image

If you think your WordPress site has been hacked, or your website is behaving strangely, or a visitor has reported something you cannot reproduce, the signs may appear in Google, in a visitor’s browser, inside WordPress, or in your hosting and email accounts. A normal-looking homepage is not enough to prove that the site is clean.

Malware, meaning harmful software, can show different content to Google, logged-out visitors, mobile users, or people in particular locations. That is why a site owner may see a normal page while a customer sees a redirect or a fake login form.

The signs that a website has been hacked can appear on the public site, in search, inside WordPress, in files, email, or business data. A complete check has to compare more than one surface.

TL;DR: Redirects, warnings, spam pages, unknown accounts or files, suspicious email, and unexplained performance changes are warning signs, not proof by themselves.To check: Scan the WordPress files and database with a good malware scanner, then cross-check Search Console, search results, your host, users, files, and logs.

A normal homepage does not settle the question

MalCare site hacked report

The first mistake is to check the homepage once and assume everything is fine. Hacked websites often use cloaking, which serves different content depending on the visitor, referrer, device, location, or login state. A redirect may appear only after someone arrives from Google. Spam pages may show to search engines but return a 404 or redirect home when opened directly.

The opposite mistake is to treat every strange event as proof of malware. A single symptom is not proof of malware. A failed update, certificate problem, traffic spike, or routine bot request can have an ordinary explanation.

Use the signs below to decide what to investigate. The strongest cases combine what visitors see, what Google reports, what changed inside WordPress, and what the host or email provider observed.

1. Redirected or trapped in a refresh loop

A visitor who is sent to a pharmacy, gambling page, adult site, scam, or phishing form instead of the requested page may be seeing a redirect hack.Some infections repeatedly refresh the page, trapping the visitor in an endless loop. Others redirect only after a visitor arrives from Google, uses a phone, or is logged out.

Redirects-to-online-pharmacy

That behavior explains why an owner may not reproduce the problem during a direct desktop visit. Ask for the exact URL, time, device, browser, route, and any screenshot already captured. Do not ask the person to open the suspicious page again.

🧭 Note: Do not reproduce a redirect by exposing another person to malware. Record the context and investigate safely.

2. Pop-ups, fake CAPTCHA pages, or a broken front end

Unexpected pop-ups, unfamiliar ads, download prompts, fake CAPTCHA screens, and login forms can indicate injected code. A fake login or payment form is particularly serious because it may be designed to collect credentials or card details. Do not enter information into a page that appeared unexpectedly.

Frontend page visibly unstyled after a blocked stylesheet request

A compromise can also make the site look damaged without showing an obvious redirect. Missing images, distorted layouts, broken links, unfamiliar banners, a visibly defaced page, unexplained header or footer code, a blank white screen, a sudden group of 404 errors, or a site that is inaccessible to visitors are all clues worth checking.

A plugin conflict, failed deployment, memory limit, broken asset URL, or hosting problem can produce the same front-end damage. The sign becomes more meaningful when it appears with an unknown user, a file change, a warning, or a matching event in the logs.

3. Google or the browser warns visitors

Google may show a warning such as “This site may be hacked” or “This site may harm your computer” beside a search result. A browser may also display a red interstitial before loading a page. These warnings can mean that Google detected hacked content, malware, unwanted software, or deceptive pages.

this-site-may-harm-your-computer

Search Console’s Security Issues report can identify hacked content, harmful software, or social engineering. Sample URLs are not a full inventory.

🛡️ Note: A Google warning is strong evidence, but a clean report is not proof that every file, database record, or conditional redirect is clean.

“Not secure” or a certificate warning needs more careful interpretation. An expired certificate, a configuration error, or mixed content can produce a browser warning without malware being present. It still needs prompt attention, especially if the site handles logins or payments, but it is not standalone proof of a hack.

4. Search results contain spam or unexpected languages

Search your domain for pages, titles, and snippets you did not publish. A WordPress pharma hack, which injects fake pharmaceutical pages into search results, is one of the most common forms of search spam. Gambling pages, counterfeit products, adult content, and unrelated foreign-language pages are common forms of search spam. Japanese SEO spam or Chinese search results spam may appear when automated pages have been injected.

Search results showing unexpected spam and foreign-language content

The pages may be hidden from menus, show to Google, and return a 404 or redirect home when opened directly. That is cloaking, not evidence that the result is harmless. Use Search Console tools where possible, and avoid opening an unfamiliar result directly on your everyday device.

🔎 Note: Search results help discover problems, but a disappearing page can still be present in the database or shown to another visitor.

5. The indexed page count suddenly jumps

An established site may suddenly show hundreds or thousands more indexed pages than it normally has. Spam titles, unrelated products, foreign-language text, or strange URL patterns often point to unauthorized content in the database or a compromised publishing path.

Check the change against your publishing history, sitemap, and Search Console data. Faceted navigation, a migration, a staging site, or a configuration change can also increase the count. Identify examples and compare them with user, file, and hosting changes. A sudden Google Analytics spike or a sharp drop in legitimate-page visits can be related, but analytics alone cannot identify malware.

6. WordPress shows unknown users, plugins, or settings

An unfamiliar administrator accounts is a strong clue because the account may control the site. Also look for a removed or downgraded administrator, strange signups, login failures that do not match a forgotten password, and an unfamiliar Google Search Console owner.

Review the plugin and theme lists for software you did not install. A fake plugin may imitate a legitimate name, use an unusual name such as “abc” or “zzz,” or fail to appear in the normal WordPress plugin screen. An attacker may also disable a security tool or change an important setting.

Compare every change with a maintenance record, agency access, automated deployment, or legitimate installation. Preserve enough information to understand when an account or plugin appeared before removing it.

🧰 Note: Record an unknown user’s name, email, role, and creation date before removing access. Rotate credentials from a trusted device.

7. Files or code change, recur, or look out of place

Unexpected changes to WordPress files, uploads, configuration, or shared headers and footers deserve investigation. Pay particular attention to .htaccess, index.php, wp-config.php, and long or unrelated code that loads redirects, pop-ups, mail-sending functions, or a WordPress backdoor. Unexplained code in a file, an unfamiliar scheduled task or cron job, and a change that returns after you remove it are all persistence clues.

File permissions

File timestamps can help establish when something changed, but they are only clues. Updates and legitimate plugins can rewrite files, and timestamps can be altered. If a change returns after removal, a scheduled task may be restoring it, although a legitimate plugin can also rewrite a file on a schedule. A change that will not stay changed needs a wider review instead of repeated manual edits.

🧩 Note: Do not delete a suspicious file or replace .htaccess blindly. Save a copy first; deletion can break the site or leave reinfection in place.

8. Traffic, speed, uptime, or server usage changes suddenly

A sudden traffic drop or spike, a country or language anomaly, an unusual bounce rate, or visits to pages that should not exist can indicate redirects, search spam, or automated abuse. Marketing activity or a reporting error can look similar. Malware may also send spam or run background processes that cause slow server responses, crash, go offline, trigger server-usage warnings, or produce a higher hosting bill.

sudden traffic spike

📈 Note: A resource spike says that capacity was used, not why. Compare its timing with logs and changes.

9. Host or email provider reports abuse

A host suspension, warning, or removal from the network is an urgent signal. The host may have found malware, phishing, spam, or abuse reported by another customer. Ask the host what it detected and whether logs, a snapshot, or isolation are available.

Email symptoms can continue while the homepage looks normal. Subscribers may receive emails you did not send, legitimate mail may go to spam, or an email provider may block or blacklist the domain or server IP address. A blacklisted server IP is an operational warning, not a complete diagnosis. Check both systems.

✉️ Note: If the host reports spam, preserve the notice and review website, hosting, email, database, and API credentials from a trusted device.

10. Customers report checkout or account behavior you cannot reproduce

Customer reports can reveal conditional malware because visitors have different referrers, devices, locations, and login states. An unsafe checkout redirect, fake login screen, or phone-only form problem may be the first sign.

For a WooCommerce store, a sudden increase in abandoned carts can be a business signal. Malware may interfere with checkout, redirect customers to an unsafe payment page, or make the site too slow to complete a purchase. Pricing, shipping, payment, and usability problems can also increase abandonment, so abandoned carts need matching security clues before they are treated as evidence of a hack.

🛒 Note: Do not ask customers to reproduce a suspicious payment or login flow. Capture the URL, time, device, browser, and screenshot they already have.

How to check if your website is hacked safely

Once you have a symptom, resist changing files immediately. Preserve evidence before investigating.

  1. Record what happened. Save the warning, URL, time, device, browser, referrer, screenshot, and login state. Avoid suspicious pages, downloads, and forms.
  2. Check Google without treating it as the whole answer. Review Security Issues and URL Inspection. Search your domain, compare results with genuine pages, and do not open suspicious results. A clean search does not prove that the server is clean.
  3. Compare WordPress and host activity with known changes. Review users, signups, plugins, themes, settings, files, scheduled tasks, Search Console owners, and available activity logs. Ask the host what it detected.
  4. Separate probing from a confirmed breach. Bots regularly request paths such as .env or .aws/credentials. That proves an address was tried, not that a file existed, was readable, or was used. Check response status, exposure, account activity, and later changes before calling it a compromise.
  5. Run a deep scan. A public URL scanner may miss server-side code, database content, backdoors, mailers, uploads, and conditional behavior. A WordPress malware scanner plugin that inspects files and the database is a stronger confirmation step than checking one page. Use its result alongside other evidence.

MalCare is one WordPress-focused option for this step. Its current scanner feature page describes on-demand file-and-database scanning, daily scanning, and dangerous file-change monitoring. If a scan identifies malware, use a deliberate cleanup process rather than deleting files at random.

What to do when the evidence points to a hack

Most hacked WordPress sites can be recovered. The method depends on scope, persistence, host state, data, and backups.

Backup details

First, preserve the current files and database in a separate copy. An old backup may contain the infection, so do not restore one blindly. Contact the host if the site is suspended, sending spam, handling payments, or sharing an account.

Next, rotate WordPress, hosting, email, database, and connected-service credentials from a trusted device when access may be unauthorized. Review related sites, shared hosting, Search Console owners, and API connections.

MalCare site clean report

Choose a cleanup method that fits the evidence, using hacked website repair guidance when the scope is unclear. Manual cleanup can miss persistent malware; read why it is difficult to manually clean a hacked WordPress site. Use incident-response help when reinfection continues, payment or personal data may be involved, or several sites share the account.

After cleanup, scan the files and database again and repeat the original checks. Confirm that redirects, warnings, spam, suspicious users, email abuse, and host restrictions are addressed. If Google reported an issue, fix every listed problem, test the site, and request review.

How to reduce the chance of another compromise

Keep WordPress, plugins, and themes updated, remove unused software and accounts, and give each user only the permissions required. Use unique passwords and two-factor authentication where appropriate.

Maintain protected backups with BlogVault and test that they can be restored. A firewall, recurring scans, and file-change monitoring can reveal a problem earlier. Review access regularly.

An outdated plugin may increase risk, but it does not prove that it caused a particular hack. Establish the entry path only when logs or other evidence support it. Investigate traffic spikes, SSL warnings, failed logins, and odd log requests instead of assigning a cause too early.

FAQs

Can a hacked website look normal?

Yes. Cloaking can show a normal page to the owner while showing spam or a redirect to selected visitors. Check independent surfaces and scan deeply.

Is a Google warning proof that my site is hacked?

A Google security warning is strong evidence that Google detected hacked content, harmful software, or deceptive behavior. It is not a complete inventory.

Are random requests in my server logs proof of a hack?

No. Automated requests show that a bot tested an address, not that access succeeded. Review response codes, exposure, account activity, and later changes.

Is a slow site or an SSL warning proof of malware?

No. Slowness can come from a plugin, host, traffic surge, or database problem. An SSL setup error can cause “Not secure.” Neither confirms malware alone.

What should I do first if I think my site is hacked?

Record the symptom, avoid suspicious pages, preserve a copy, contact the host when needed, and scan the WordPress files and database. Rotate credentials from a trusted device.

Conclusion

The signs that a website has been hacked can be loud, such as a Google warning or redirect, or quiet, such as a new administrator, changed file, suspicious email, or resource drain. One symptom can have a harmless explanation, but several matching clues warrant treating the site as an incident until a deep scan and cross-checks say otherwise.

Protect the evidence, avoid random deletion, and investigate the full WordPress site rather than only the homepage. Then patch it, limit access, maintain tested backups, and monitor for recurrence.

Category:

You may also like


How can we help you?

If you’re worried that your website has been hacked, MalCare can help you quickly fix the issue and secure your site to prevent future hacks.

My site is hacked – Help me clean it

Clean your site with MalCare’s AntiVirus solution within minutes. It will remove all malware from your complete site. Guaranteed.

Secure my WordPress Site from hackers

MalCare’s 7-Layer Security Offers Complete Protection for Your Website. 300,000+ Websites Trust MalCare for Total Defence from Attacks.