10 Signs Your WordPress Site Has Been Hacked
Half of WordPress hacks go undetected for weeks because the symptoms are subtle. Here are the ten signals to actually look for.
1. Google Search Console shows pages you didn't publish
Attackers inject SEO spam via wp_posts. Search 'cheap viagra site:yoursite.com' — if anything shows, you're hit.
2. Random new admin users
wp_users has a row you didn't create. Textbook backdoor for later re-entry.
3. Homepage loads a different site
Header redirect injected into wp-config.php or a mu-plugin.
4. Files in wp-content/uploads with .php extensions
Nothing legitimate should ever have a .php file under uploads/.
5. Site is slow for no reason
Cryptojacking scripts consume server CPU. Check top on your host.
6. Host suspended your account
The most conclusive symptom possible.
7. Antivirus warnings when visitors load your site
Malicious JS is being served in your header or footer.
8. New scheduled cron jobs you didn't create
wp_options → cron. Look for unfamiliar hook names.
9. Emails to your users you didn't send
Compromised sites are often used as spam relays.
10. .htaccess has rules you didn't add
Redirect rules for specific user agents (Google, Bing) — visitor sees your site, crawlers see spam.
Any two of these together = you're compromised. Get help fast.