How to Fix a Hacked WordPress Site Step by Step
If you're reading this, chances are your WordPress site has been hacked. Don't panic; with the right steps, you can restore your site to its former glory. As a developer who's hosted dozens of client sites, I'll guide you through the process.
Step 1: Assess the Damage
The first step is to understand the extent of the hack. Check for:
WordPress: The Missing Manual by Matthew MacDonald — ~$30.
View on Amazon →- Unusual admin users
- Malicious plugins or themes
- Suspicious files or directories
- Changes to core WordPress files
Take note of any anomalies, as you'll need this information later.
Step 2: Put Your Site in Maintenance Mode
To prevent further damage, put your site in maintenance mode using a plugin like WP Maintenance Mode. This will display a maintenance page to visitors, preventing them from accessing compromised content.
Step 3: Update and Clean Up
- Update WordPress core, themes, and plugins: Ensure everything is up-to-date, as outdated software is a common vulnerability.
- Remove suspicious plugins and themes: Delete any plugins or themes you don't recognize or that were installed without your knowledge.
- Scan for malware: Use a security plugin like Wordfence (starts at $99/year) or MalCare (starts at $99/year) to scan your site for malware.
Step 4: Restore from Backup
If you have a recent backup, restore your site to a previous version. You can use a plugin like UpdraftPlus (starts at $70/year) or VaultPress (starts at $39/year). If you don't have a backup, consider seeking professional help.
Step 5: Change Passwords and Keys
- Change all user passwords: Update passwords for all users, especially administrators.
- Update security keys: Regenerate security keys in your
wp-config.phpfile.
Step 6: Harden Your Site's Security
- Limit login attempts: Use a plugin like Limit Login Attempts Reloaded to prevent brute-force attacks.
- Enable two-factor authentication: Add an extra layer of security with a plugin like Two Factor Authentication.
Choosing a Secure Web Host
A secure web host is crucial in preventing future hacks. Here are three hosting providers to consider:
Hosting Providers Comparison
| Provider | Uptime SLA | TTFB (avg) | Support Quality | Price (2026) |
|---|---|---|---|---|
| SiteGround | 99.9% | 250ms | Excellent | $14.99/month (StartUp) |
| WP Engine | 99.99% | 180ms | Excellent | $20/month (Startup) |
| HostGator | 99.9% | 350ms | Good | $12.95/month ( Hatchling) |
Provider Pros and Cons
#### SiteGround
- Pros: Excellent support, robust security features, and automatic updates.
- Cons: Limited storage on lower plans.
#### WP Engine
- Pros: Top-notch performance, excellent support, and robust security.
- Cons: Pricier than competitors, limited customization options.
#### HostGator
- Pros: Affordable pricing, decent performance, and good support.
- Cons: Less robust security features compared to competitors.
Recommendation
If you're looking for a reliable and secure web host, I recommend SiteGround for most users. Their excellent support and robust security features make them an ideal choice. However, if you're willing to pay a premium for top-notch performance, WP Engine is the way to go. For those on a tight budget, HostGator is a decent option, but be aware of their limitations.
Ultimately, the best host for you depends on your specific needs:
- SiteGround: Best for most users, offering a great balance of security, support, and price.
- WP Engine: Best for high-traffic or performance-critical sites, offering top-notch performance and support.
- HostGator: Best for those on a tight budget, offering affordable pricing and decent performance.
By following these steps and choosing a secure web host, you'll be well on your way to recovering from a hacked WordPress site and preventing future incidents.
Step-by-step guide to launching a professional business website fast — no developer needed. Covers domain, hosting, design, and SEO basics. Instant digital download.
Get Instant Access →