Home › WordPress Hacked — What to Do
Incident
WordPress Hacked — What to Do
If you're reading this with a defaced homepage, skip the shame. Patch first. Then decide whether you want to live on a CMS that gets exploited for a living.
If WordPress is hacked: take it offline, snapshot, rotate every password and key, restore from a clean backup, scan for webshells, and patch. Then leave WordPress. A static Hugo site has no wp-admin, no plugins, no PHP. That's how you stop the next hack. WordPressEscape migrates you off after the fire is out.
Scan your URL free — 60 seconds, no login. SEO, Performance, Responsive grades, then a done-for-you escape if you want it.
Scan my site free →Do this in the first hour
- Put the site in maintenance / block PHP if you can.
- Snapshot files + database before you 'clean' anything.
- Rotate host, FTP, WP admin, and every plugin API key. Use the ESC'dashboard env locker later so keys aren't in wp-config.
- Restore from a backup from before the intrusion, then update core/plugins on a staging copy — or don't go back to WordPress at all.
Why it happened
Nulled plugins, old PHP, wp-login exposed, phpunit eval-stdin in a vendor folder — the same junk that shows up in Search Console as exploit queries. WordPress is a magnet. Static HTML is not. See WordPress security problems.
The durable fix
Migrate to Hugo, delete the install, host on Cloudflare. No wp-admin to brute force. We did this on our own family of sites after a real incident. Ditch WordPress when the bleeding stops.
We're the 'don't get owned again' layer. Scan when the site loads; we'll tell you if WordPress is still live.
Scan your URL free — 60 seconds, no login. SEO, Performance, Responsive grades, then a done-for-you escape if you want it.
Scan my site free →Frequently asked questions
What do I do if my WordPress site is hacked?
Isolate, snapshot, rotate credentials, restore clean, then get off WordPress so PHP/plugins aren't waiting for the next CVE.
Will migrating off WordPress remove malware?
A clean static rebuild from known-good content does. Don't copy infected PHP. We mirror HTML, not the exploit.
How fast can I leave after a hack?
As soon as you have a crawlable site or a backup. Scan for a page count and track.
wordpress hacked what to dowordpress malwarewordpress compromised