Sep 16, 2026 · WPGuard Team

How to Tell If Your WordPress Site Has Been Hacked (7 Real Warning Signs)

How to Tell If Your WordPress Site Has Been Hacked (7 Real Warning Signs)

Most people assume a hacked WordPress site announces itself — a defaced homepage, a browser warning, an angry customer. In practice, the average compromise sits undetected for weeks, quietly serving spam links, mining redirects, or phishing pages to a subset of visitors while the site owner sees nothing unusual in wp-admin.

1. Unexplained admin users

Check Users → All Users for an account you don’t recognize, especially one created outside business hours. Attackers who escalate a stolen editor account to administrator almost always create a second admin account as a backup entry point.

2. Search results that don’t match your site

Search site:yourdomain.com in Google. If you see pharmacy, casino, or counterfeit-goods results you never published, your site is very likely serving different content to Googlebot than it shows you — a technique called cloaking.

3. Outbound traffic spikes with no matching pageviews

A jump in server bandwidth or outbound connections that doesn’t correspond to a real traffic increase in your analytics usually means the server is being used to send spam or participate in a botnet.

4. A plugin you don’t remember installing

Or worse — one that used to be there and now isn’t, even though you never removed it. Some malicious plugins hook WordPress’s own all_plugins filter to hide themselves from the admin plugin list while staying fully active on disk.

5. Modified core files

WordPress publishes official checksums for every core release. A file in wp-admin/ or wp-includes/ that doesn’t match the checksum for your installed version has been altered by something other than a WordPress update.

6. Login attempts from IPs and countries you don’t serve

A handful of failed logins is normal internet background noise. Dozens within a few minutes, especially from multiple IPs in quick succession, is a credential-stuffing or brute-force attempt in progress.

7. Your host emails you about abuse complaints

By the time a hosting provider flags your account for abuse, the compromise has usually been active long enough to affect other users on shared infrastructure. This is the latest, not the earliest, signal — if this is the first sign you notice, everything above happened first without you seeing it.

Why these signs go unnoticed

Every one of these signs is invisible to a scanner that only checks the site from inside WordPress, using the same APIs an attacker who has already compromised the site can manipulate. Catching them requires comparing what’s on disk against what WordPress reports, watching login patterns over time instead of one at a time, and checking the site from the outside as well as the inside — which is exactly the gap continuous monitoring is built to close.

Catching these signs reliably requires continuous, outside-in monitoring rather than a one-time scan — read how WPGuard's signed agent and disk-vs-database checks work on the Security page, or see Pricing to start monitoring your first site free.

See what WPGuard would catch on your site.

Connect a site in a few minutes and get your first inventory scan back immediately.

Try free →