Website security & hack recovery
Signs your website has been hacked, what to do first, and how ONQU Support cleans and protects hacked WordPress sites.
Signs your website has been hacked
Hacked sites often look normal to their owners. Check for these warning signs.
Admin users you didn’t create
Hidden administrator accounts are a classic backdoor — and some hacks recreate them after you delete them.
Spam pages in Google
Search site:yourdomain and look for casino, pharmacy or foreign-language pages you didn’t publish.
Strange files
Unknown PHP files in your site’s main folder, or hidden inside wp-admin and wp-content.
Redirects & warnings
Visitors sent to other sites, or browser and Google “deceptive site” warnings.
What to do first
Back up as-is
Copy files and database before changing anything — evidence and a safety net.
Scan
Run a malware scan (for example Wordfence) to find infected files and injected code.
Remove backdoors first
Delete malicious files and injected code before removing rogue users, or they come straight back.
Lock it down
Change every password, reset security keys, update everything and remove unused plugins.
Need help now?
ONQU Support cleans hacked WordPress sites, finds how the attacker got in, and keeps the site protected afterwards.