Harmonic Design

My WordPress Site Was Hacked: A Step-by-Step Recovery Guide

published August 2, 2026 article

Waking up to find your website has been hacked is a gut-wrenching experience. You see the defaced homepage, the spammy links in your footer, or perhaps you simply notice your hosting provider has sent you a warning about malicious activity. It’s stressful, it’s expensive, and it’s a direct hit to your brand’s credibility.

In our experience rescuing sites for clients around the world, we’ve learned that the speed at which you react matters, but the way you react matters even more. Panic leads to mistakes that can make the recovery much harder. Here is our professional, step-by-step guide to recovering your site and ensuring it doesn’t happen again.

Step 1: Assessment and Isolation

The first thing you need to do is determine the scope of the breach. Is it just your homepage? Is it your entire database? Are your emails being used to send spam?

Once you know what’s wrong, isolate the site. If you can, put the site into maintenance mode. This prevents visitors from seeing the hack and stops search engines from indexing the malicious content. If the hack is severe, you may need to temporarily take the site offline entirely while you work.

Step 2: The Great Cleanup

There are two main ways to clean a hacked site. We always recommend the first one if you have a clean, recent backup.

  • Option A: Restore from a Clean Backup. If you have a verified, clean backup from before the hack occurred, this is by far the fastest and safest way to recover. However, you must ensure you aren’t restoring the vulnerability along with the files.
  • Option B: Manual Cleanup. If you don’t have a backup (which is common), you will need to manually replace your WordPress core files, themes, and plugins with fresh, untainted copies from the official sources. You must also scan your wp-content/uploads folder for malicious files—often, hackers hide “shells” (malicious scripts) inside image files.

Step 3: Hardening the Perimeter

Cleaning the files is only half the battle. You have to close the door the hacker used to get in. A site that is cleaned but not hardened is just a ticking time bomb.

  • Change All Credentials: Change every single password associated with the site. This includes WordPress admins, FTP/SFTP accounts, Database users, and your Hosting Control Panel.
  • Update Everything: Once the site is clean, update WordPress core, every single plugin, and every theme. Vulnerabilities in outdated software are the #1 entry point for hackers.
  • Audit Your Users: Check the “Users” section in your WordPress dashboard. Hackers often create new “Administrator” accounts to maintain access.
  • Check for Backdoors: Even after a cleanup, hackers often leave behind “backdoors”—tiny snippets of code hidden in legitimate files that allow them to get back in even after you’ve changed your password. This is why manual cleanup is so difficult and why professional inspection is often required.

Step 4: Implement Ongoing Security

Security is architecture, not just a plugin checklist. While a good security plugin is a helpful layer, true security comes from a hardened environment.

  • Use Strong, Unique Passwords: And use a password manager.
  • Limit Login Attempts: Prevent brute-force attacks by limiting how many times someone can try to log in.
  • Two-Factor Authentication (2FA): This is one of the most effective ways to prevent unauthorized access.
  • Regular Backups: Have an automated, off-site backup system in place. If all else fails, you need to be able to revert to a “known good” state quickly.

Don’t Try to DIY a Disaster

If you realize your site has been compromised and you aren’t an expert in digital forensics, don’t try to fix it yourself. You might miss the subtle backdoor that allows a hacker to return in 48 hours. We specialize in “site rescues”—taking over slow, hacked, or abandoned WordPress sites and returning them to a secure, high-performance state.

If you need professional help with a site rescue, contact us today.

Leave a reply

👍 😆 😠 😢 😍
Reply