My WordPress site redirects to a spam site
A redirect hack is one of the most common WordPress infections, and one of the most damaging. Visitors land on someone else's site, your rankings slide, and you may not even see the problem yourself, because the redirect is often set up to skip people who are logged in.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- Visitors are sent to a site you've never heard of, sometimes a fake prize page, pharmacy, or adult site
- It happens on phones but not on your desktop, or only when arriving from Google
- It doesn't happen when you're logged in to WordPress
- Customers or colleagues report it, but the site looks fine to you
- Your browser flags the site, or Google shows a warning under your listing
Why it happens
Injected JavaScript
Malicious script added to your theme files, plugin files, or directly into database records so it loads on every page.
Rewritten .htaccess
Redirect rules added to the server configuration file, which sends people away before WordPress even loads.
Hidden plugins
Malware placed in the must-use plugins folder, which loads automatically and doesn't show in the normal plugin list.
Changed site settings
The site address settings in the database swapped for the attacker's domain.
Cloaking rules
Code that checks whether the visitor is on a phone, came from a search engine, or is logged in, so the redirect hides from the site owner.
What to do right now
Do this
- Note the exact address people get sent to, and how they got there (phone or desktop, from Google or typed in)
- Try your site in a private browsing window, and on a phone, while logged out
- Change your WordPress and hosting passwords from a device you trust
- Tell your hosting company: their logs can show when the files changed
Don't do this
- Don't just reinstall the theme. The redirect usually lives in several places at once
- Don't restore a backup from last week without checking. It's often already infected
- Don't ignore it because it looks fine to you. Being logged in is exactly when the hack hides
How we fix it
- 1Find every copy of the redirect: theme and plugin files, the database, .htaccess, and must-use plugins
- 2Remove the injected code and repair the files it damaged
- 3Hunt for the backdoor that let them in, so it can't be put back the next day
- 4Reset security keys and remove rogue accounts
- 5Update and harden the site, then request removal from any security blocklists it's on
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
Why can't I see the redirect myself?
Most redirect malware checks who's visiting. If you're logged in to WordPress, or on the same computer you always use, it often stays quiet, so the site owner doesn't notice while visitors are being sent away.
Will it hurt my Google rankings?
It can. Google may flag the site in search results or drop pages, and visitors bounce straight off. The faster it's cleaned and reviewed, the smaller the impact.
Can I just delete the file with the code in it?
Sometimes, but redirect hacks usually plant several copies plus a hidden backdoor. If the backdoor stays, the redirect comes back within days.
Other symptoms
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)