My WordPress Site Redirects to Another Website. Here's What Happened.

WPSecureGuard
My WordPress Site Redirects to Another Website. Here's What Happened.

Your WordPress Site Redirects Somewhere You Don't Recognize. Here's Why.

A customer tells you they clicked your website and ended up on a strange page — maybe a fake online store, a sketchy "you've won a prize" screen, or a pharmacy selling pills. You type your address yourself and everything looks normal. So you assume they made a mistake.

They didn't. Your WordPress site has been infected with redirect malware, and the reason you can't see it yourself is the most clever and frustrating part of the whole problem.

What Redirect Malware Actually Does

Redirect malware is malicious code injected into your WordPress site that automatically sends visitors to a different website — one controlled by the attacker. The destination is usually a spam site, a scam page, a fake store, or a site that tries to install more malware on the visitor's device.

The attacker makes money in a few ways: getting paid for the traffic they steal from you, running scams on your visitors, or selling fake products. Your website becomes the unwilling delivery system, and your reputation pays the price.

Why You Can't See the Redirect Yourself

This is the part that confuses almost everyone. You visit your site and it works perfectly. Your customers visit and get redirected to spam. How?

The malware uses conditional redirection. It inspects each visitor and decides whether to redirect based on rules the attacker set:

  • It often redirects only visitors coming from Google. If you type your address directly, you see the normal site. Visitors who find you through search get hijacked.
  • It frequently targets mobile devices only. You check on your desktop and see nothing wrong. Your customers on phones get sent to spam.
  • It can skip logged-in administrators. Since you're usually logged into WordPress, the malware leaves you alone and targets everyone else.

This is deliberate. By hiding from you, the infection survives longer — which means more stolen traffic and more damage before you discover it.

How It Got In

Redirect malware almost always enters through one of these doors:

  • An outdated plugin or theme with a known security hole that wasn't patched.
  • A nulled (pirated) plugin or theme — these are frequently distributed with malware already built in.
  • A weak or reused admin password that was guessed or found in a data breach.
  • A vulnerability in another site on the same shared hosting account.

The attack is almost never personal. Automated bots scan the internet constantly, looking for any site with an opening. When they find one, they inject the redirect code and move on to the next target.

Where the Malicious Code Hides

This is why removing redirect malware is harder than it looks. The code is rarely in just one place. It can live in:

  • The WordPress database, particularly the wp_options and wp_posts tables.
  • The .htaccess file, which controls how the server handles requests.
  • Theme files, especially functions.php and header templates.
  • Injected JavaScript loaded from an external server the attacker controls.
  • Hidden PHP files dropped into obscure folders with innocent-looking names.

Most importantly, the attacker leaves backdoors — hidden code that lets them back in. If you remove the visible redirect but miss a single backdoor, the infection returns within hours.

Why Quick Fixes Fail

People typically try these first, and they usually don't work:

Deleting the suspicious code they find. Unless every piece and every backdoor is removed, the redirect comes back.

Restoring an old backup. If the backup was taken after the infection (which is common, since the malware hides for weeks), you just reinstall the problem. And the vulnerability that let them in is still there.

Installing a security plugin. Scanners catch some redirect malware, but the obfuscated, conditional variants are specifically designed to evade them. We've cleaned many sites where the plugin reported "no threats found" while visitors were still being redirected.

What a Real Cleanup Involves

Removing redirect malware permanently requires working through every layer:

  1. Reproducing the redirect by simulating a Google referral on a mobile device, to confirm exactly what's happening.
  2. Scanning every file on the server for injected and obfuscated code.
  3. Cleaning the database of malicious entries.
  4. Finding and removing every backdoor — the most critical step.
  5. Closing the entry point by updating everything and changing all credentials.
  6. Verifying the redirect is gone for all visitor types, not just for you.

What Happens If You Ignore It

Left alone, a redirect infection almost always gets worse. Google eventually detects the malicious redirects and can blacklist your domain, replacing your site with a red "deceptive site ahead" warning for every visitor. At that point you lose not just the redirected traffic, but all of it. Acting while the problem is still "just" a redirect is far cheaper than waiting for the blacklist.

WPSecureGuard Removes Redirect Malware for Good

With 25+ years of experience securing WordPress and PHP-based websites, we've cleaned dozens of redirect infections. We know how conditional redirects hide, where the backdoors live, and how to make sure the redirect doesn't come back.

Our Recovery service is $349 one-time — full cleanup, backdoor removal, .htaccess repair, basic hardening, and a 30-day reinfection guarantee. If the redirect returns within 30 days, we fix it at no charge.

For ongoing protection, our Complete plan ($199/month or $1,999/year) includes continuous monitoring, updates, patching, and emergency hack recovery as part of the subscription.

Get emergency help now — every redirected visitor is a lost customer.

Frequently Asked Questions

Why does my WordPress site redirect to another website?

Your WordPress site has been infected with redirect malware. Hackers injected malicious code into your site that automatically sends your visitors to spam sites, scam pages, or fake stores — usually without you noticing, because the redirect often only triggers for visitors coming from Google or on mobile devices. The infection typically enters through an outdated plugin, a nulled (pirated) theme or plugin, or a weak admin password. The malicious code can live in your WordPress database, your theme files, your .htaccess file, or hidden PHP files on the server.

How do I stop my WordPress site from redirecting to spam sites?

Stopping a redirect requires finding and removing every piece of the malicious code, which is often spread across multiple locations: the database (wp_options and wp_posts tables), the .htaccess file, theme functions files, and injected JavaScript. Simply deleting one instance is not enough — most redirect malware includes backdoors that reinstall the redirect within hours. A complete removal means scanning all files, cleaning the database, removing every backdoor, and then changing all passwords and updating every plugin and theme to close the entry point. Because the code is usually obfuscated and hidden, professional cleanup is the reliable way to stop it permanently.

Why does my WordPress site only redirect on mobile or from Google?

This is a deliberate technique called conditional redirection. The malware checks where the visitor is coming from and what device they use. It often redirects only visitors arriving from Google search results, or only those on mobile phones, while showing the normal site to anyone who types the address directly or visits from a desktop. This is intentional — it keeps the site owner from noticing the problem (since you usually visit your own site directly on a desktop) while still hijacking the valuable traffic coming from search engines. If visitors report redirects you can't reproduce yourself, this conditional behavior is almost certainly why.

Can redirect malware on WordPress come back after I remove it?

Yes, and this is the most common frustration site owners face. Redirect malware almost always installs hidden backdoors — small pieces of code that let the attacker re-enter and reinfect the site even after the visible redirect is removed. If the backdoors are not all found and removed, the redirect returns within hours or days. This is why deleting the obvious malicious code is not enough. A proper cleanup finds every backdoor, closes the original entry point, and changes all credentials. At WPSecureGuard our Recovery service includes a 30-day reinfection guarantee for exactly this reason.

Keeping a WordPress site secure requires constant monitoring, updates and vulnerability management.

See our WordPress protection plans →

Stop worrying about WordPress. Start growing your business.

Get started today