Is Your WordPress Site Infected? Here's How to Know.
Sometimes a hacked WordPress site is obvious — a big red warning screen, a homepage replaced with a hacker's message. But most modern infections are quiet by design. The malware wants to stay hidden so it can keep working: sending spam, stealing traffic, or harvesting data for as long as possible.
That means you can't rely on the site "looking broken" to know something is wrong. Here are the 12 most common warning signs, from the obvious to the ones people miss.
The Obvious Signs
1. Unexpected redirects. You (or your visitors) type your address and end up on a completely different website — often a scam, pharmacy, or gambling site. Sometimes it only happens on mobile, or only for first-time visitors.
2. A red browser or Google warning. "Deceptive site ahead" or "This site may harm your computer" means Google Safe Browsing has already flagged your site. This is one of the most damaging signs because it blocks nearly all your visitors.
3. Spam content you didn't create. Pages, posts, or pop-ups advertising pills, replicas, or casinos. Often in a foreign language like Japanese.
4. Your host suspended your account. Hosting providers scan for malware and will suspend sites that are infected or sending spam. A suspension email is a clear signal.
The Signs in Google
5. Foreign text in your search results. Search site:yourdomain.com in Google. If you see page titles in Japanese or listings for products you don't sell, your site is injected with SEO spam.
6. A sudden ranking drop. Google demotes hacked sites. An unexplained, sharp fall in rankings or traffic can be the first measurable sign of an infection.
7. A spike in indexed pages. Google Search Console showing hundreds or thousands of new indexed pages you never created means spam pages are being injected.
The Signs Most People Miss
8. Unknown admin accounts. Go to Users → All Users and filter by Administrator. Any account you don't recognize is a serious red flag — attackers create admin users to maintain access.
9. Unfamiliar files on your server. Strangely named PHP files, files in the wrong folders, or recently modified core files you didn't touch. This requires looking at the file system directly, not just the WordPress dashboard.
10. Your emails going to spam. If your legitimate business emails suddenly land in spam folders or bounce, your server may be blacklisted for sending spam — a common side effect of infection.
11. Unexplained slow performance. Malware consumes server resources. A site that suddenly becomes sluggish for no clear reason may be running malicious processes in the background.
12. The site looks fine to you but not to others. This is cloaking: the malware serves clean content to the logged-in owner and malicious content to everyone else, including Google. If customers report problems you can't reproduce, take it seriously.
Why "It Looks Fine" Isn't Proof
The most dangerous misconception is that a normal-looking site is a clean site. Modern malware specifically hides from the person most likely to remove it — you. It can detect the site owner and show a clean version, while serving spam to search engines and redirects to visitors.
This is why you can't confirm a site is clean just by looking at it in your browser. Confirmation requires scanning at the server level: inspecting the actual files and database, not just the rendered page.
What to Do Next
If you recognized one or more of these signs, the right sequence is:
- Don't delete files at random. It can destroy evidence and make cleanup harder.
- Change your admin passwords.
- Get a proper scan — one that examines the file system and database directly, not only a surface-level check.
- If Google or your host has already flagged the site, treat it as urgent.
Not Sure? Get It Checked.
With 25+ years of experience securing WordPress and PHP-based sites, WPSecureGuard can tell you definitively whether your site is infected — including the cloaked infections that don't show up in your browser.
If you've seen any of the warning signs above and want certainty, request a security check and we'll tell you exactly what's going on. →

