The most common signs a website has been hacked are unexpected pop-ups or redirects, unfamiliar new pages or content, a Google “this site may be harmful” warning, a sudden traffic drop, new admin accounts you didn’t create, and the site running slow or going down. If you’re seeing any of these, act quickly — the faster you respond, the less damage a compromise can do. Most of these signs are also things monitoring would catch before you — or a customer — ever noticed.
Here’s how to recognize a hacked site, what to do about it, and how to avoid getting caught off guard again.
Warning signs your website has been hacked
Watch for these, roughly in order of how obvious they are:
- Unexpected redirects — visitors land on your site and get bounced to a spammy or unrelated page.
- Pop-ups or ads you didn’t add — especially sketchy ones for pharmaceuticals, gambling, or “you’ve won.”
- A browser or Google Safe Browsing warning — “this site may be hacked” or “deceptive site ahead.”
- New pages or posts you didn’t create — often spammy content stuffed with keywords and links.
- New admin or user accounts you don’t recognize in your dashboard.
- A sudden, unexplained drop in traffic — often the first sign Google has flagged or delisted the site.
- The site is slow, erroring, or down without an obvious cause.
- Changed files or unfamiliar code in your site’s files, especially recently modified ones.
- Your host or a customer tells you — sometimes the hosting provider suspends the site, or a visitor reports something wrong.
Any single one of these is worth investigating. Several at once means you should treat the site as compromised and move.
What to do if your website has been hacked
Stay calm and work in order — panicking and deleting things at random usually makes cleanup harder.
- Confirm it’s actually a compromise, not a plugin conflict or caching issue. Check for the signs above and note what changed.
- Take the site into maintenance mode if you can, so visitors aren’t exposed while you work.
- Change all passwords — hosting, admin, FTP/SFTP, and database — and force a logout of all sessions.
- Scan for malware and identify infected or modified files.
- Remove the malicious code, or restore from a known-clean backup taken before the compromise.
- Update everything — core, themes, and plugins — and delete anything unused or unknown.
- Remove unauthorized accounts and revoke any suspicious access.
- Request a review from Google Search Console if the site was flagged, so the warning is lifted.
- Monitor closely afterward — reinfection is common if the entry point wasn’t fully closed.
If you’re not comfortable with steps 4 through 6, this is the point to bring in a professional. A partial cleanup that leaves the backdoor open is worse than no cleanup, because it looks fixed while staying vulnerable.
How monitoring catches a hack before your customers do
The worst way to find out your site was hacked is from a customer — or from Google delisting it. By then the damage to trust is already done.
Continuous monitoring closes that gap. It watches for the exact signals above — file changes, injected code, blocklist status, new vulnerabilities, downtime — and alerts you the moment something shifts. That turns a compromise from a crisis you discover late into a small issue you catch early, often before it’s visible to anyone else.
How to prevent your website from being hacked
You can’t make a site unhackable, but you can make it a much harder target:
- Keep core, themes, and plugins updated — outdated plugins are the single most common entry point.
- Use strong, unique passwords and two-factor authentication on every admin account.
- Remove unused plugins and themes — every extra one is another door.
- Keep clean, tested backups so you can restore fast if the worst happens.
- Monitor continuously so you’re alerted to change instead of finding out the hard way.
Frequently asked questions
How do I know if my website has been hacked? Look for unexpected redirects or pop-ups, a Google “this site may be harmful” warning, new pages or admin accounts you didn’t create, a sudden traffic drop, or the site running slow or going down. Any of these warrants investigating right away.
What’s the first thing to do if my website is hacked? Confirm it’s a real compromise, then change all passwords (hosting, admin, FTP, database) and take the site into maintenance mode so visitors aren’t exposed while you clean up.
Can a hacked website be fixed? Yes. Most sites can be cleaned by removing the malicious code or restoring a clean backup, updating everything, closing the entry point, and requesting a review if Google flagged the site. The key is closing the vulnerability so it doesn’t get reinfected.
Does getting hacked only happen to WordPress sites? No. WordPress is targeted most because it’s the most popular platform, but any website can be compromised. The warning signs and response steps apply regardless of how a site is built.
How can I tell if my site was hacked if it looks normal? Some compromises are hidden — spam pages only search engines see, or code that only triggers for certain visitors. That’s why external monitoring matters: it catches file changes and blocklist flags you wouldn’t notice by just looking at the site.
Centry Secure continuously monitors the sites you manage for signs of compromise, vulnerabilities, and unexpected changes — alerting you early and showing a clear security score across every site. Schedule a demo to see it on your own sites.
Was this article helpful?
Thanks for your feedback.
Have a question about this topic?
