GUIDE   2026-06-30

How to Fix a Hacked WordPress Site Step by Step

Affiliate Disclosure: This article contains affiliate links. If you click through and purchase, we may earn a commission at no extra cost to you. Full disclosure →

If you're reading this, chances are your WordPress site has been hacked. Don't panic; with the right steps, you can restore your site to its former glory. As a developer who's hosted dozens of client sites, I'll guide you through the process.

Step 1: Assess the Damage

The first step is to understand the extent of the hack. Check for:

📚 Recommended Reading

WordPress: The Missing Manual by Matthew MacDonald — ~$30.

View on Amazon →

Take note of any anomalies, as you'll need this information later.

Step 2: Put Your Site in Maintenance Mode

To prevent further damage, put your site in maintenance mode using a plugin like WP Maintenance Mode. This will display a maintenance page to visitors, preventing them from accessing compromised content.

Step 3: Update and Clean Up

  1. Update WordPress core, themes, and plugins: Ensure everything is up-to-date, as outdated software is a common vulnerability.
  2. Remove suspicious plugins and themes: Delete any plugins or themes you don't recognize or that were installed without your knowledge.
  3. Scan for malware: Use a security plugin like Wordfence (starts at $99/year) or MalCare (starts at $99/year) to scan your site for malware.

Step 4: Restore from Backup

If you have a recent backup, restore your site to a previous version. You can use a plugin like UpdraftPlus (starts at $70/year) or VaultPress (starts at $39/year). If you don't have a backup, consider seeking professional help.

Step 5: Change Passwords and Keys

  1. Change all user passwords: Update passwords for all users, especially administrators.
  2. Update security keys: Regenerate security keys in your wp-config.php file.

Step 6: Harden Your Site's Security

  1. Limit login attempts: Use a plugin like Limit Login Attempts Reloaded to prevent brute-force attacks.
  2. Enable two-factor authentication: Add an extra layer of security with a plugin like Two Factor Authentication.

Choosing a Secure Web Host

A secure web host is crucial in preventing future hacks. Here are three hosting providers to consider:

Hosting Providers Comparison

Provider Uptime SLA TTFB (avg) Support Quality Price (2026)
SiteGround 99.9% 250ms Excellent $14.99/month (StartUp)
WP Engine 99.99% 180ms Excellent $20/month (Startup)
HostGator 99.9% 350ms Good $12.95/month ( Hatchling)

Provider Pros and Cons

#### SiteGround

#### WP Engine

#### HostGator

Recommendation

If you're looking for a reliable and secure web host, I recommend SiteGround for most users. Their excellent support and robust security features make them an ideal choice. However, if you're willing to pay a premium for top-notch performance, WP Engine is the way to go. For those on a tight budget, HostGator is a decent option, but be aware of their limitations.

Ultimately, the best host for you depends on your specific needs:

By following these steps and choosing a secure web host, you'll be well on your way to recovering from a hacked WordPress site and preventing future incidents.

How to Create a Simple Website for Your Company — $17

Step-by-step guide to launching a professional business website fast — no developer needed. Covers domain, hosting, design, and SEO basics. Instant digital download.

Get Instant Access →

How to Create a Website for Your Business

Step-by-step guide to launching a professional business website fast — no developer needed. Covers domain, hosting, design, and SEO basics. Works whether you're on WordPress or a website builder.

Instant digital download via Whop. One-time purchase.

⚠️ Affiliate Disclosure: WebHostPro earns a commission when you purchase through links on this page. This doesn't affect our reviews — we only recommend hosts we've tested or thoroughly researched.