Skip to content

Website security & hack recovery

Signs your website has been hacked, what to do first, and how ONQU Support cleans and protects hacked WordPress sites.

Signs your website has been hacked

Hacked sites often look normal to their owners. Check for these warning signs.

Admin users you didn’t create

Hidden administrator accounts are a classic backdoor — and some hacks recreate them after you delete them.

Spam pages in Google

Search site:yourdomain and look for casino, pharmacy or foreign-language pages you didn’t publish.

Strange files

Unknown PHP files in your site’s main folder, or hidden inside wp-admin and wp-content.

Redirects & warnings

Visitors sent to other sites, or browser and Google “deceptive site” warnings.

What to do first

  1. Back up as-is

    Copy files and database before changing anything — evidence and a safety net.

  2. Scan

    Run a malware scan (for example Wordfence) to find infected files and injected code.

  3. Remove backdoors first

    Delete malicious files and injected code before removing rogue users, or they come straight back.

  4. Lock it down

    Change every password, reset security keys, update everything and remove unused plugins.

Need help now?

ONQU Support cleans hacked WordPress sites, finds how the attacker got in, and keeps the site protected afterwards.