Your WordPress Site Redirects Somewhere You Don't Recognize. Here's Why.
A customer tells you they clicked your website and ended up on a strange page — maybe a fake online store, a sketchy "you've won a prize" screen, or a pharmacy selling pills. You type your address yourself and everything looks normal. So you assume they made a mistake.
They didn't. Your WordPress site has been infected with redirect malware, and the reason you can't see it yourself is the most clever and frustrating part of the whole problem.
What Redirect Malware Actually Does
Redirect malware is malicious code injected into your WordPress site that automatically sends visitors to a different website — one controlled by the attacker. The destination is usually a spam site, a scam page, a fake store, or a site that tries to install more malware on the visitor's device.
The attacker makes money in a few ways: getting paid for the traffic they steal from you, running scams on your visitors, or selling fake products. Your website becomes the unwilling delivery system, and your reputation pays the price.
Why You Can't See the Redirect Yourself
This is the part that confuses almost everyone. You visit your site and it works perfectly. Your customers visit and get redirected to spam. How?
The malware uses conditional redirection. It inspects each visitor and decides whether to redirect based on rules the attacker set:
- It often redirects only visitors coming from Google. If you type your address directly, you see the normal site. Visitors who find you through search get hijacked.
- It frequently targets mobile devices only. You check on your desktop and see nothing wrong. Your customers on phones get sent to spam.
- It can skip logged-in administrators. Since you're usually logged into WordPress, the malware leaves you alone and targets everyone else.
This is deliberate. By hiding from you, the infection survives longer — which means more stolen traffic and more damage before you discover it.
How It Got In
Redirect malware almost always enters through one of these doors:
- An outdated plugin or theme with a known security hole that wasn't patched.
- A nulled (pirated) plugin or theme — these are frequently distributed with malware already built in.
- A weak or reused admin password that was guessed or found in a data breach.
- A vulnerability in another site on the same shared hosting account.
The attack is almost never personal. Automated bots scan the internet constantly, looking for any site with an opening. When they find one, they inject the redirect code and move on to the next target.
Where the Malicious Code Hides
This is why removing redirect malware is harder than it looks. The code is rarely in just one place. It can live in:
- The WordPress database, particularly the
wp_optionsandwp_poststables. - The
.htaccessfile, which controls how the server handles requests. - Theme files, especially
functions.phpand header templates. - Injected JavaScript loaded from an external server the attacker controls.
- Hidden PHP files dropped into obscure folders with innocent-looking names.
Most importantly, the attacker leaves backdoors — hidden code that lets them back in. If you remove the visible redirect but miss a single backdoor, the infection returns within hours.
Why Quick Fixes Fail
People typically try these first, and they usually don't work:
Deleting the suspicious code they find. Unless every piece and every backdoor is removed, the redirect comes back.
Restoring an old backup. If the backup was taken after the infection (which is common, since the malware hides for weeks), you just reinstall the problem. And the vulnerability that let them in is still there.
Installing a security plugin. Scanners catch some redirect malware, but the obfuscated, conditional variants are specifically designed to evade them. We've cleaned many sites where the plugin reported "no threats found" while visitors were still being redirected.
What a Real Cleanup Involves
Removing redirect malware permanently requires working through every layer:
- Reproducing the redirect by simulating a Google referral on a mobile device, to confirm exactly what's happening.
- Scanning every file on the server for injected and obfuscated code.
- Cleaning the database of malicious entries.
- Finding and removing every backdoor — the most critical step.
- Closing the entry point by updating everything and changing all credentials.
- Verifying the redirect is gone for all visitor types, not just for you.
What Happens If You Ignore It
Left alone, a redirect infection almost always gets worse. Google eventually detects the malicious redirects and can blacklist your domain, replacing your site with a red "deceptive site ahead" warning for every visitor. At that point you lose not just the redirected traffic, but all of it. Acting while the problem is still "just" a redirect is far cheaper than waiting for the blacklist.
WPSecureGuard Removes Redirect Malware for Good
With 25+ years of experience securing WordPress and PHP-based websites, we've cleaned dozens of redirect infections. We know how conditional redirects hide, where the backdoors live, and how to make sure the redirect doesn't come back.
Our Recovery service is $349 one-time — full cleanup, backdoor removal, .htaccess repair, basic hardening, and a 30-day reinfection guarantee. If the redirect returns within 30 days, we fix it at no charge.
For ongoing protection, our Complete plan ($199/month or $1,999/year) includes continuous monitoring, updates, patching, and emergency hack recovery as part of the subscription.
Get emergency help now — every redirected visitor is a lost customer.

