Home › WordPress Hacked — What to Do

Incident

WordPress Hacked — What to Do

If you're reading this with a defaced homepage, skip the shame. Patch first. Then decide whether you want to live on a CMS that gets exploited for a living.

Quick answer

If WordPress is hacked: take it offline, snapshot, rotate every password and key, restore from a clean backup, scan for webshells, and patch. Then leave WordPress. A static Hugo site has no wp-admin, no plugins, no PHP. That's how you stop the next hack. WordPressEscape migrates you off after the fire is out.

After you're stable — scan the URL

Scan your URL free — 60 seconds, no login. SEO, Performance, Responsive grades, then a done-for-you escape if you want it.

Scan my site free →

Do this in the first hour

  1. Put the site in maintenance / block PHP if you can.
  2. Snapshot files + database before you 'clean' anything.
  3. Rotate host, FTP, WP admin, and every plugin API key. Use the ESC'dashboard env locker later so keys aren't in wp-config.
  4. Restore from a backup from before the intrusion, then update core/plugins on a staging copy — or don't go back to WordPress at all.

Why it happened

Nulled plugins, old PHP, wp-login exposed, phpunit eval-stdin in a vendor folder — the same junk that shows up in Search Console as exploit queries. WordPress is a magnet. Static HTML is not. See WordPress security problems.

The durable fix

Migrate to Hugo, delete the install, host on Cloudflare. No wp-admin to brute force. We did this on our own family of sites after a real incident. Ditch WordPress when the bleeding stops.

Not a malware cleaner

We're the 'don't get owned again' layer. Scan when the site loads; we'll tell you if WordPress is still live.

After you're stable — scan the URL

Scan your URL free — 60 seconds, no login. SEO, Performance, Responsive grades, then a done-for-you escape if you want it.

Scan my site free →

Frequently asked questions

What do I do if my WordPress site is hacked?

Isolate, snapshot, rotate credentials, restore clean, then get off WordPress so PHP/plugins aren't waiting for the next CVE.

Will migrating off WordPress remove malware?

A clean static rebuild from known-good content does. Don't copy infected PHP. We mirror HTML, not the exploit.

How fast can I leave after a hack?

As soon as you have a crawlable site or a backup. Scan for a page count and track.

wordpress hacked what to dowordpress malwarewordpress compromised