How to Tell If Your WordPress Site Has Malware: 12 Warning Signs

WPSecureGuard
How to Tell If Your WordPress Site Has Malware: 12 Warning Signs

Is Your WordPress Site Infected? Here's How to Know.

Sometimes a hacked WordPress site is obvious — a big red warning screen, a homepage replaced with a hacker's message. But most modern infections are quiet by design. The malware wants to stay hidden so it can keep working: sending spam, stealing traffic, or harvesting data for as long as possible.

That means you can't rely on the site "looking broken" to know something is wrong. Here are the 12 most common warning signs, from the obvious to the ones people miss.

The Obvious Signs

1. Unexpected redirects. You (or your visitors) type your address and end up on a completely different website — often a scam, pharmacy, or gambling site. Sometimes it only happens on mobile, or only for first-time visitors.

2. A red browser or Google warning. "Deceptive site ahead" or "This site may harm your computer" means Google Safe Browsing has already flagged your site. This is one of the most damaging signs because it blocks nearly all your visitors.

3. Spam content you didn't create. Pages, posts, or pop-ups advertising pills, replicas, or casinos. Often in a foreign language like Japanese.

4. Your host suspended your account. Hosting providers scan for malware and will suspend sites that are infected or sending spam. A suspension email is a clear signal.

The Signs in Google

5. Foreign text in your search results. Search site:yourdomain.com in Google. If you see page titles in Japanese or listings for products you don't sell, your site is injected with SEO spam.

6. A sudden ranking drop. Google demotes hacked sites. An unexplained, sharp fall in rankings or traffic can be the first measurable sign of an infection.

7. A spike in indexed pages. Google Search Console showing hundreds or thousands of new indexed pages you never created means spam pages are being injected.

The Signs Most People Miss

8. Unknown admin accounts. Go to Users → All Users and filter by Administrator. Any account you don't recognize is a serious red flag — attackers create admin users to maintain access.

9. Unfamiliar files on your server. Strangely named PHP files, files in the wrong folders, or recently modified core files you didn't touch. This requires looking at the file system directly, not just the WordPress dashboard.

10. Your emails going to spam. If your legitimate business emails suddenly land in spam folders or bounce, your server may be blacklisted for sending spam — a common side effect of infection.

11. Unexplained slow performance. Malware consumes server resources. A site that suddenly becomes sluggish for no clear reason may be running malicious processes in the background.

12. The site looks fine to you but not to others. This is cloaking: the malware serves clean content to the logged-in owner and malicious content to everyone else, including Google. If customers report problems you can't reproduce, take it seriously.

Why "It Looks Fine" Isn't Proof

The most dangerous misconception is that a normal-looking site is a clean site. Modern malware specifically hides from the person most likely to remove it — you. It can detect the site owner and show a clean version, while serving spam to search engines and redirects to visitors.

This is why you can't confirm a site is clean just by looking at it in your browser. Confirmation requires scanning at the server level: inspecting the actual files and database, not just the rendered page.

What to Do Next

If you recognized one or more of these signs, the right sequence is:

  1. Don't delete files at random. It can destroy evidence and make cleanup harder.
  2. Change your admin passwords.
  3. Get a proper scan — one that examines the file system and database directly, not only a surface-level check.
  4. If Google or your host has already flagged the site, treat it as urgent.

Not Sure? Get It Checked.

With 25+ years of experience securing WordPress and PHP-based sites, WPSecureGuard can tell you definitively whether your site is infected — including the cloaked infections that don't show up in your browser.

If you've seen any of the warning signs above and want certainty, request a security check and we'll tell you exactly what's going on. →

Originally reported by Google Search Console Help

Frequently Asked Questions

How can I tell if my WordPress site has malware?

The most common signs are: unexpected redirects to unfamiliar sites, spam pages or Japanese/pharmaceutical text appearing in Google results, a sudden drop in search rankings, browser or Google Safe Browsing warnings, unknown admin accounts, unfamiliar files on your server, your host suspending the account, slow performance, and visitors reporting pop-ups you never added. If you notice one or more of these, your site is likely infected and should be scanned professionally. Some malware shows no visible signs at all and only surfaces when Google blacklists the site.

Can a WordPress site have malware without showing any obvious signs?

Yes, and this is common. Modern malware is often designed to stay hidden from the site owner while remaining active for visitors or search engines. It may show spam only to Google's crawler, redirect only first-time visitors, or quietly send spam email from your server. Many owners have no idea their site is infected until Google blacklists it or their host suspends the account. This is why periodic professional scanning matters even when the site appears to be working normally.

My WordPress site was flagged by Google but looks fine to me. Why?

This is a classic sign of cloaking — malware that shows different content to different visitors. It detects when Google's crawler visits and serves spam or malicious content, while showing you, the logged-in owner, a completely normal site. That's why you can look at your homepage and see nothing wrong while Google sees a site full of pharmaceutical spam. The infection is real even though it's invisible to you. A server-level scan will reveal what your browser doesn't.

What should I do if I think my WordPress site has malware?

First, don't panic and don't start deleting files randomly — that can make a professional cleanup harder. Change your admin passwords, and if you have a recent clean backup, note its date. Then get the site scanned properly, either with a reputable security tool or by a professional who can inspect the file system and database directly. If Google has already flagged the site or your host has suspended it, treat it as urgent — every hour of downtime costs traffic and trust.

Keeping a WordPress site secure requires constant monitoring, updates and vulnerability management.

See our WordPress protection plans →

Stop worrying about WordPress. Start growing your business.

Get started today