Key takeaways

  • Many hacks are hidden from the site owner, so check as a logged-out visitor, on mobile and from a search result.
  • Visitor-facing signs include redirects, browser warnings, spam in search results and customer fraud reports.
  • Admin-side signs include unknown administrator accounts, unfamiliar PHP files and changed core files.
  • Server-side signs include host warnings, resource spikes, outgoing spam and suspicious cron jobs.
  • One sign is enough to act on. Contain first, then investigate the whole server, not just one site.

How can you tell if your website has been hacked?

You can usually tell a website has been hacked from one of three places: what visitors see, such as redirects or browser warnings; what you find in the admin area, such as unknown users or files; and what the server shows, such as host warnings, spam email or strange scheduled tasks. Any one of them is reason to investigate.

The difficulty is that most modern website malware is built to hide from the owner. It may only activate for first-time visitors, for mobile devices, for people arriving from Google, or for search engine crawlers. If you are logged in to WordPress and visit your site every day on the same laptop, you may be the last person to see anything wrong.

Tip: check your site in a private browsing window, on a mobile phone using mobile data, and by clicking through from a Google search result. These three views catch most cloaked infections.

The twelve signs below are grouped by where you will notice them. They are the ones we encounter most often when investigating compromised WordPress and PHP sites.

What signs do visitors and customers notice first?

Visitors usually notice a hack first through redirects to unrelated sites, browser or Google warnings, spam in search results for your brand, or problems after buying from you. These signs do the most damage because they hit trust and revenue immediately, and customers often report them before you spot them.

If a customer tells you about one of these, take it seriously even if you cannot reproduce it. Ask what device and browser they used, how they reached the site and the time it happened. Those details help pinpoint cloaked malware quickly.

1. Visitors are redirected to other sites

Visitors land on scam, adult, fake prize or "your device is infected" pages instead of your site. The redirect often happens only on mobile, only once per visitor or only from search results. Our guide to the malicious redirect hack explains how it works.

2. Browsers or Google show a warning

Chrome shows a red "Deceptive site ahead" page, or search results show "This site may be hacked" under your listing. Google Safe Browsing has detected malware, phishing or spam. See how to remove a Google blacklist warning.

3. Spam pages appear in search results

A site:example.co.uk search shows pages you never created, often in Japanese or advertising pharmaceuticals, counterfeit goods or gambling. This is SEO spam; read our SEO spam hack removal guide.

4. Customers report fraud after buying

Several customers report card fraud after purchasing, or your checkout shows an unexpected extra payment form. This points to a card skimmer and needs immediate action. See WooCommerce card skimmers.

What signs appear in WordPress admin and site files?

Inside the site, the clearest signs of a hack are administrator accounts you did not create, PHP files you do not recognise, modified WordPress core or theme files, and access changes you did not make, such as reset passwords or a disabled security plugin. These signs show that someone has, or had, control of the site.

5. Unknown administrator accounts

New admin users appear, often with generic names such as wpadmin, support or adm1n. Some malware hides these accounts from the Users screen, so check the database or use WP-CLI rather than relying on the dashboard.

6. Unfamiliar PHP files

PHP files appear in wp-content/uploads, which should normally only hold media, or in theme and plugin folders with names that look almost, but not quite, like WordPress files. These are frequently webshells.

7. Core or theme files have changed

Files such as index.php, wp-config.php, .htaccess or a theme's functions.php have recent modification dates or unfamiliar code at the top or bottom. A replaced wp-config.php or a site showing a fake "maintenance" page are both signs we see regularly.

8. You are locked out or protections are switched off

Your admin password no longer works, your email address has been changed on your account, or your security plugin has been deactivated or deleted. Attackers routinely disable anything that might detect them.

Security triage

Is your site showing any of this?

Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.

Start the triage

What signs show up on the server and hosting account?

At server level, a hack typically shows up as a warning or suspension from your host, unexplained spikes in CPU or bandwidth, outgoing spam and blocklisted email, or scheduled tasks and processes nobody on your team created. These signs often mean the infection has spread beyond one website to the account or operating system.

9. Your host sends a warning or suspends the account

Hosting providers scan for malware, phishing and spam. A warning email or suspended account is a strong sign of compromise, even if the site looks fine to you.

10. The site or server is suddenly slow

High CPU use, bandwidth spikes or a full disk with no increase in genuine traffic can indicate cryptocurrency mining, spam sending, or attacks being launched from your server against others.

11. Email bounces or is blocklisted

Your legitimate email starts bouncing or landing in spam, or your server's IP appears on mail blocklists. A spam mailer script is often sending bulk mail through your server.

12. Unknown cron jobs or processes

Scheduled tasks you did not create appear in crontab, or unfamiliar processes run under the web user. These are how malware re-infects a site minutes after it is cleaned. See why malware keeps coming back.

How do you check for these signs yourself?

To check for these signs yourself, run an external check for blocklisting and redirects, then, if you have SSH access, look for recently modified PHP files, PHP files in uploads, unknown admin users and unfamiliar cron jobs. These checks take a few minutes and will confirm most compromises, though they will not find everything.

Start with our two-minute security triage and we will tell you what to do next. Then, on the server, these read-only commands are a good first look. Run them from the site's root folder:

# PHP files modified in the last 7 days
find . -name "*.php" -mtime -7 -type f
# PHP files inside uploads (should normally be none)
find wp-content/uploads -name "*.php" -type f
./wp-content/uploads/2026/08/wp-cache.php
# Administrator accounts (WP-CLI)
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
# Scheduled tasks for the web user
crontab -l

Look closely at anything these commands return. A recently modified PHP file might simply be a plugin update, so compare dates with your update history. A PHP file in uploads, an administrator you do not recognise or a cron entry that downloads something with curl or wget from an unfamiliar address is far more serious. Also check the database: injected scripts are often stored in the wp_options table, in widgets or in post content, where file searches will never find them.

If you do not have SSH access, most hosting control panels provide a file manager and a cron job screen that show the same information more slowly.

Do not start deleting files as soon as you find something. Take a full backup first for evidence, and remember that the file you found is rarely the only one.

What should you do if you spot any of these signs?

If you spot any of these signs, contain the problem first: take a full backup for evidence, change passwords from a clean device and, if customers are at risk, put the site into maintenance mode. Then investigate the whole server, not just the affected site, clean every infected file and database entry, and close the entry point.

SignUrgencyFirst action
Customer card fraud (4)CriticalTake checkout offline, contact your payment provider
Redirects or Google warning (1, 2)HighContain, clean, then request review
Unknown admins or files (5, 6, 7)HighBack up, rotate credentials, scan server-side
Cron jobs or processes (12)HighInvestigate at server level before cleaning files
Slow server or spam email (10, 11)Medium to highCheck processes and mail queue, scan all sites

Our first-hour emergency guide gives the full containment checklist. If you would rather hand it over, PatientZero's hacked website repair covers investigation, clean-up and hardening, and our emergency team starts triage as soon as you get in touch. Call 01932 593642.

Frequently asked questions

Can my website be hacked without me noticing?

Yes, and this is common. Much website malware is designed to hide from logged-in administrators and returning visitors, showing spam or redirects only to search engines, mobile users or first-time visitors. Sites can stay infected for months before a customer, host or Google warning reveals the problem.

Is a slow website a sign of being hacked?

It can be. Malware such as cryptocurrency miners, spam mailers and attack tools can consume CPU, memory and bandwidth. A slow site is not proof of a hack, since plugins and hosting also affect speed, but a sudden slowdown with no change in real traffic is worth investigating.

Why can I not see the redirect my customers are reporting?

Redirect malware often checks who is visiting. It may skip logged-in users, visitors it has already redirected once, desktop browsers, or anyone not arriving from a search engine. Test in a private window on a mobile phone using mobile data, and click through from a Google result.

Should I restore a backup if I think I have been hacked?

Restoring a backup can help, but only if you know the backup predates the infection and you fix the entry point afterwards. Otherwise the site may be re-infected quickly, or the backup may already contain the malware. Take a copy of the infected site first so it can be investigated.

PatientZero Incident Response Team · Digital forensics and incident response

Written by the PatientZero incident response team: the engineers who investigate and clean compromised WordPress sites and Linux servers every week.