How to Tell If Your WordPress Site Has Been Hacked
Most WordPress hacks aren’t discovered by the site owner noticing anything obviously wrong. They’re discovered by Google flagging the site as dangerous, a hosting provider suspending the account for sending spam, or a customer mentioning they got a strange redirect. By the time it’s that visible, it’s usually been compromised for a while.
The quiet signs that come first
Before the obvious symptoms, there are usually quieter ones: new admin accounts nobody created, a spike in outbound email that isn’t coming from your contact form, unfamiliar files appearing in your plugin or theme folders, or your site suddenly ranking for spammy pharmaceutical or gambling terms it has nothing to do with – a classic sign of injected spam content search engines can see but a casual visitor might not.
Where to actually look
Three places catch most compromises early. First, your list of admin users – a hacked site very often gets a new administrator account added as a backdoor, and it’s rarely disguised well. Second, your plugin and theme file listing, specifically checking for files that don’t match what the plugin or theme actually ships (a plain listing of file names against the official version catches this, though comparing by hand is slow and error-prone). Third, your site’s outbound reputation – whether your domain has landed on a spam blocklist, which is often the first external signal that something is sending unwanted mail from your server.
Why “it looks fine” isn’t reassuring
A visually untouched site is not the same as a clean one. A common pattern is content that only injects itself for search engine crawlers or specific referrers, so a human visiting normally sees nothing unusual while Google’s crawler sees a page stuffed with spam links. Checking “how does the site look to me” tells you almost nothing about this category of compromise.
What to do the moment you suspect it
Don’t start by deleting things. Force-logout every user and rotate your passwords and security keys first, so whatever access the attacker had is cut off immediately – only then start investigating what changed, ideally with a tool that can compare your actual files against the official, unmodified versions rather than trusting your own memory of what “normal” looks like. Keep whatever you find rather than deleting it immediately; if you ever need to hand this off to someone else to clean up properly, having the evidence intact matters.
The uncomfortable truth about detection
Almost none of this is realistic to do manually, regularly, by eye. It needs to run as a routine check, not a one-off panic response after something’s already gone wrong. Oxyshield was built around exactly this: file integrity checks against official WordPress.org releases, admin activity monitoring, and one-click recovery tools for the moment you actually need them.