ClikIT is now Backline. Same team, same company. See what’s changing →

Help! My Client’s WordPress Site Might Be Hacked: A Recovery Guide for Non-Developers

Two hands reaching towards each other, surrounded by gray concrete structures, photo.

The email usually arrives at the worst possible time. A client writes “why does Google say your site may be hacked?” or “why is our homepage advertising pharmaceuticals?” and suddenly you, the account manager, the agency owner, the marketer, are responsible for a problem no one on your team knows how to fix.

Take a breath. Hacked WordPress sites get recovered every day, and most of the damage from a hack comes from slow or panicked responses, not the hack itself. This guide walks through what to do in the first hour, whether the site is yours or a client’s, and no step requires you to touch code.

First: Confirm It’s Actually a Hack

Look for the telltale signs before you sound the alarm:

  • Content you didn’t publish: spam pages, strange links, injected ads, redirects to other sites
  • Browser or Google warnings (“This site may be hacked” / “Deceptive site ahead”)
  • Admin users you don’t recognize in WordPress
  • A sudden slowdown, or email from the host about malicious activity
  • Traffic falling off a cliff in analytics

One of these alone can have an innocent explanation. Two or more, treat it as live.

The First Hour

1. Change every password

WordPress admin, hosting account, FTP, and the database if you have access. If several people at your agency or the client’s office share logins, change those too, and stop sharing logins after this is over. Strong, unique, stored in a password manager.

2. Contact the hosting provider

Hosts deal with compromised sites constantly. Many can tell you when the intrusion happened, isolate the site so it can’t infect anything else, and point you at their most recent clean backup. If you manage the site for a client, do this before the client’s own IT person does; you want to own the timeline.

3. Preserve the evidence

Before anyone starts deleting things, note what you found and when: screenshots of the defacement, the warning messages, the unfamiliar admin accounts. If the site handles customer data, this record matters for any disclosure conversation later.

4. Tell the client early, in plain language

If this is a client site, the worst move is hoping they don’t notice. A short, calm note works: “We detected malicious activity on the site, we’ve secured the accounts, and recovery is underway. We’ll confirm when it’s clean.” Clients forgive incidents. They don’t forgive surprises.

Cleaning the Infection

This is where non-technical guides usually wave toward a security plugin and wish you luck. A scan with Wordfence or a similar tool is a reasonable first pass, and restoring from a known-clean backup can resolve simpler compromises. But two honest cautions:

  • Backups reinfect. If the backup predates the cleanup but not the intrusion, you’re restoring the hacker’s back door along with the site. Hosts’ “most recent backup” is often not clean.
  • Scanners miss things. Malware that survives a plugin scan hides in the database, in modified core files, or in a second injected admin account, and the site gets re-hacked within weeks.

A proper cleanup means finding the entry point, removing every injected file and user, patching the vulnerability that let them in, and then hardening the site so it doesn’t happen again. If nobody on your team does this work routinely, this is the step to hand off. Backline’s malware removal service does exactly this: we remove the infection, clear the blacklists, restore the site, and harden it against reinfection. For agencies, it happens under your brand, so the recovery your client sees is yours.

After It’s Clean

  • Request a Google review. If the site was blacklisted, submit it for review in Search Console once it’s verified clean, and the warnings come down within a few days.
  • Update everything. Core, themes, plugins. Most WordPress hacks exploit a known vulnerability in something outdated.
  • Add real protection. Two-factor authentication, login attempt limits, a firewall, and monitored backups.
  • Put the site on maintenance. The pattern behind almost every hacked site we clean is the same: nobody was updating it. Ongoing care and monitoring is what turns “we got hacked” into an event that never recurs, and if you’re an agency, it’s a service you can resell under your own brand.

The Bottom Line

A hacked site is recoverable, usually within a day or two. Move fast on passwords and the host, communicate early if a client is involved, and don’t settle for a surface-level cleanup that leaves the back door open. And if you’d rather never have this day again, put every site you’re responsible for on managed maintenance, because the cheapest hack is the one that never happens.

Share on Linkedin
Share on Facebook
Share on X

In this article

Get notified of latest blog posts, web design tips and tricks!