Finding out your website has been compromised is stressful, and the instinct is to panic and start clicking around. A calmer, ordered process gets you back online faster and actually closes the hole that let it happen.
1. Confirm it’s actually a hack
Strange redirects, spammy content you didn’t write, or a Google “this site may be hacked” warning are the common signs. Rule out a simple plugin conflict or expired license notice first — not everything odd-looking is a compromise.
2. Restore from a clean backup
This is the single biggest reason backups matter. Restoring to a known-clean version from before the compromise is almost always faster and more reliable than trying to manually hunt down and remove malicious code file by file.
3. Change every password, not just one
WordPress admin, hosting account, database, FTP/SFTP — all of it. If one was compromised, assume any of them could have been exposed, especially if passwords were reused anywhere.
4. Figure out how it happened
An outdated plugin, a weak password, or a vulnerable theme are the usual culprits. Restoring a backup without fixing the actual entry point just invites a repeat.
5. Ask Google to review your site if it was flagged
Once it’s clean, request a security review through Google Search Console so the “hacked” warning gets removed from search results — this doesn’t happen automatically just because the site is fixed.
If this ever happens and you don’t have a clean backup to restore from, that’s the moment the value of daily backups becomes very real. Every Honest Servers plan includes them by default, for exactly this reason.
