Skip to content
WP Hack FixEst. 2005

My WordPress site redirects to a spam site

A redirect hack is one of the most common WordPress infections, and one of the most damaging. Visitors land on someone else's site, your rankings slide, and you may not even see the problem yourself, because the redirect is often set up to skip people who are logged in.

We reply within 1 business day (Mon–Fri, 9–5 ET)

What you're seeing

  • Visitors are sent to a site you've never heard of, sometimes a fake prize page, pharmacy, or adult site
  • It happens on phones but not on your desktop, or only when arriving from Google
  • It doesn't happen when you're logged in to WordPress
  • Customers or colleagues report it, but the site looks fine to you
  • Your browser flags the site, or Google shows a warning under your listing

Why it happens

Injected JavaScript

Malicious script added to your theme files, plugin files, or directly into database records so it loads on every page.

Rewritten .htaccess

Redirect rules added to the server configuration file, which sends people away before WordPress even loads.

Hidden plugins

Malware placed in the must-use plugins folder, which loads automatically and doesn't show in the normal plugin list.

Changed site settings

The site address settings in the database swapped for the attacker's domain.

Cloaking rules

Code that checks whether the visitor is on a phone, came from a search engine, or is logged in, so the redirect hides from the site owner.

What to do right now

Do this

  • Note the exact address people get sent to, and how they got there (phone or desktop, from Google or typed in)
  • Try your site in a private browsing window, and on a phone, while logged out
  • Change your WordPress and hosting passwords from a device you trust
  • Tell your hosting company: their logs can show when the files changed

Don't do this

  • Don't just reinstall the theme. The redirect usually lives in several places at once
  • Don't restore a backup from last week without checking. It's often already infected
  • Don't ignore it because it looks fine to you. Being logged in is exactly when the hack hides

How we fix it

  1. 1Find every copy of the redirect: theme and plugin files, the database, .htaccess, and must-use plugins
  2. 2Remove the injected code and repair the files it damaged
  3. 3Hunt for the backdoor that let them in, so it can't be put back the next day
  4. 4Reset security keys and remove rogue accounts
  5. 5Update and harden the site, then request removal from any security blocklists it's on

Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing

Questions

Why can't I see the redirect myself?

Most redirect malware checks who's visiting. If you're logged in to WordPress, or on the same computer you always use, it often stays quiet, so the site owner doesn't notice while visitors are being sent away.

Will it hurt my Google rankings?

It can. Google may flag the site in search results or drop pages, and visitors bounce straight off. The faster it's cleaned and reviewed, the smaller the impact.

Can I just delete the file with the code in it?

Sometimes, but redirect hacks usually plant several copies plus a hidden backdoor. If the backdoor stays, the redirect comes back within days.

Other symptoms

Hacked right now? Let's get it fixed.

Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)