New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Help Centre

BugShield Knowledge Base

Guides, walkthroughs, and answers for getting the most out of your account.

Website Hacking and Malware

A compromised website may redirect visitors, display unfamiliar content, create unknown users, send spam or contain code that gives an attacker continued access. One symptom can have an innocent cause, so confirm what changed before deciding that the site is clean or compromised.

Possible warning signs

  • A browser, search engine, host or security service warns about harmful content.
  • Unknown admin users or changed passwords.
  • Unexpected redirects, pop-ups, pages or search results.
  • Unfamiliar files or recently modified code with no known explanation.
  • Spam or phishing messages sent through the website or domain.
  • Security settings, plugins or scheduled tasks changing unexpectedly.

Protect the site and its accounts

  1. Record the warning, affected URL and time, and save relevant hosting or security alerts.
  2. Use a clean device to secure hosting, registrar, WordPress and administrator email accounts.
  3. Create a backup or forensic copy before removing files so the original state remains available for investigation.
  4. If visitors or customer data may be at risk, place the site into an appropriate restricted or maintenance state.
  5. Review the site, accounts, database, files, scheduled tasks and logs for both the visible change and its entry point.

Recover and prevent reinfection

Removing the visible file or user may not remove every access method. Recovery should clean or replace affected code, remove unauthorised access, rotate exposed credentials, update vulnerable software and verify the website before it returns to normal use. Continue with Fixing a Hacked Site for WordPress-specific guidance.

Shield Pro includes malware prevention and removal. You can also submit a Fix Request when you need a BugShield developer to investigate a suspected compromise.

Common questions

Frequently Asked Questions

Does an unexpected redirect always mean the website is hacked?

No. A redirect can also come from a configuration, advertising script or browser extension. Test from another clean device and network, then inspect the site and logs.

Can I restore a backup to remove malware?

A clean backup can support recovery, but the original entry point and exposed credentials must also be addressed or the site may be compromised again.

Why should I keep a copy before deleting suspicious files?

The original state can help identify what changed, how access was gained and whether other parts of the site are affected.

Can BugShield help with a hacked website?

Yes. Shield Pro includes malware prevention and removal, and you can submit a Fix Request when you need a developer to investigate a suspected compromise.

Still need help?

Can’t find what you need? Our team is here to help.

Contact us