Core guide SEO 10 min read

Why Your WordPress Site Keeps Getting Hacked (And How to Make It Stop)

Cleaning a hacked WordPress site rarely holds. Why the spam pages keep coming back, what it looks like in Google, and how to end the cycle.

An old broken latch and a new brass deadlock on the stone step of a timber door
SEO

If your WordPress site keeps getting hacked, cleaned, and then hacked again a fortnight later, the problem is not that you have been unlucky twice. It is that the first clean-up never closed the door, and everything since has been the same break-in playing out on repeat.

That cycle is exhausting and expensive, and it is the reason so many business owners end up walking away from WordPress altogether. What follows is what is actually happening underneath, what it does to your position in Google while it runs, and how to stop it permanently rather than buying yourself another three weeks.

Why Does My WordPress Site Keep Getting Hacked After I Clean It?

Because a clean-up and a lock change are two different jobs, and most people only pay for the first one.

When someone compromises a WordPress site, they rarely stop at putting content on it. They leave themselves a way back, normally a small file dropped somewhere unremarkable, a scheduled task, or an extra administrator account with a plausible name. That way back is the actual asset. The spam pages are just what it gets used for.

So when you restore last month’s backup, you replace the pages and nothing else. If the compromise predates that backup, and it usually does by weeks or months, the backup contains the way back as well. The site looks fine for a few days while nobody is paying attention, then the pages reappear and you are back where you started, having lost a day and paid for the privilege.

This is why the recurrence matters more than the hack. A site that was compromised once and properly repaired stays repaired. A site that keeps producing spam pages is telling you the repair never happened, no matter how many times the content has been rolled back.

What Do Hacked WordPress Pages Actually Look Like?

They are usually not subtle once you know the shape of them, which is why so many owners are shocked at how long it had been running.

On a site I rebuilt after a long-running compromise, the injected pages fell into two consistent patterns. The first was a bare number followed by .html sitting at the root of the site, along the lines of /34304203.html. The second was a folder of five random letters containing a similar numeric file, along the lines of /weoht/k737662.html. Between them, those two shapes accounted for 795 of the 816 dead URLs still showing in Search Console months after the site had been replaced.

The content on them is almost always the same commercial categories. Online casinos, sports betting, crypto trading, pharmacy products, replica goods. What surprises people is the languages, because a site serving customers in one town will suddenly be publishing in Russian, Turkish, Polish, Hindi, Korean and a dozen others. Your domain is being borrowed to rank someone else’s pages in markets you have never sold into.

The pages are also frequently hidden from you specifically. Many injections serve the spam only to search engine crawlers, or only to visitors arriving from a search result, so the owner logging in directly sees a perfectly normal website. That is why the two checks below matter more than simply looking at your own site.

How Do I Check Whether My Site Has Been Hacked?

Two checks, neither of them technical, and both take about ten seconds.

Search Google for site:yourdomain.com, typed exactly like that with no space after the colon. That returns what Google currently holds for your domain and nothing else. If your own pages are sitting alongside betting pages, or the results run to page after page when your site has fifteen pages on it, you have your answer.

Then open your own sitemap, normally at yourdomain.com/sitemap_index.xml. A sitemap is the list your site publishes for search engines, so it hides nothing. Follow the post sitemap links and count what is in them. A small business site with a handful of blog posts should not have a sitemap running to thousands of entries, and if it does, every one of those entries is a page your website is currently publishing under your name.

Worth doing both, because they answer different questions. The sitemap tells you what your site is publishing right now. The Google search tells you how much of it the outside world can already see.

Why Forwarding Your Domain to Social Media Makes It Worse

This is the part almost nobody warns about, and it does more lasting damage than the malware.

Faced with a site that keeps breaking, a lot of owners do something that feels responsible. They point the domain at their Facebook or Instagram page so that customers still land somewhere useful while it gets sorted. It keeps a presence up, it stops people seeing casino pages, and it buys time.

Google reads that as a permanent move. A domain-wide redirect to another destination is the standard signal that a website has relocated, so the correct response is to drop the original pages and hand whatever they had earned to the new destination. Which is exactly what happens.

On the site I rebuilt, the domain sat forwarded to a social profile while the mess was dealt with. The result was fourteen months in which the domain earned no search impressions at all. Not reduced, not down by half. Zero. Every page that had ranked was gone, and the rebuild afterwards started from nothing rather than from a damaged position, which is a materially harder place to come back from.

If a site has to come down, take it down. A holding page on your own domain, a maintenance notice, even a plain page with your phone number on it, all of these are safe. Sending the domain somewhere else is the one option that turns a recoverable problem into a much longer one.

Should I Clean a Hacked WordPress Site or Rebuild It?

Search this question and the answer comes back near-unanimous, which is that you should restore or clean first and treat rebuilding as a last resort. Before taking that at face value, look at who writes it. The top results are security plugin vendors, WordPress hosting companies and page builder products. All of them sell something that only has value while you stay on WordPress. None of them earns anything from telling you to leave.

That does not make the advice wrong, and there is a real case for cleaning. If the compromise is recent, the site is otherwise well maintained, the plugins and theme are current, you know which one let them in, and you have a backup from before it happened, then cleaning is the sensible, cheaper route. Fix the hole, remove the files, move on.

The case falls apart when those conditions do not hold, which is the situation most people are in by the time they go looking for help. A site running a theme and plugins that have not been updated in years, compromised for months before anyone noticed, with no backup that predates it, is not a cleaning job. You can pay for the malware removal and still not be certain it is all gone, and at the end of it you own the same ageing site, with the same weekly maintenance obligation that produced the problem, waiting to happen again.

That is paying twice. Once to rescue something, and again later to replace the thing you rescued.

How Long Does It Take to Recover in Google?

Longer than anyone tells you, and the shape of the recovery is misleading in a way that causes real anxiety.

On the rebuilt site, the count of dead spam URLs in Search Console peaked at roughly 27,000. Taking the compromised site offline removed about 81% of them within three days, which is the single biggest thing you can do and it costs nothing. The rebuild went live shortly after, and from there the remainder fell from around 2,700 to just over 800 across the following nine weeks. Two months on from a complete platform rebuild, several hundred injected URLs were still listed.

Here is the part that catches people out. That figure does not decline smoothly. It sits at exactly the same number for eight days, fourteen days, eighteen days, then drops in a single step. Search Console updates the report in batches, so a fortnight of no movement is completely normal and means nothing has gone wrong. Owners watching it daily conclude the fix failed and start changing things, which is the worst thing to do mid-recovery.

Two things speed it up. Make sure the dead URLs return a “410 Gone” response rather than a standard “404 Not Found”, because 410 tells Google the page is permanently finished and will not be back, and it drops out faster. Second, leave it alone. Google recrawls those URLs on a decaying schedule, dropping from hundreds a month to a handful, and the tail is measured in months no matter what you do.

Can a Website Be Built So This Cannot Happen Again?

Not perfectly, and anyone who says otherwise is selling something. Your hosting login, your domain registrar and your email account all still exist and still need protecting.

What can be removed entirely is this specific category of attack. Every injection described above needs the same three things to work, which are a database to write pages into, executable code running on the server, and a login page facing the internet. A site built as static files has none of them. There is no database to insert a casino page into, no plugin to exploit, and no admin screen to break into. The attack does not fail, it has nothing to attempt.

That is the difference between hardening WordPress and moving away from it. Hardening reduces the odds while leaving the mechanism intact, and it commits you to updating a dozen separate add-ons every week forever. Removing the mechanism ends the category. It also happens to make the site considerably faster, because most of what makes a WordPress site slow is the same machinery that makes it vulnerable.

The trade-off is honest and worth stating. A static site does not come with the familiar dashboard, so updating content works differently. Either you get a small purpose-built editor for the parts that genuinely change, or you send the changes to whoever built it. For most small business sites, where the opening hours and the phone number are the only things that move in a year, that is not much of a loss against never thinking about this again.

If you are weighing that up for an Irish business, the practical questions are covered in how to choose a web designer in Ireland, and the reasons a site fails to rank are worth reading alongside it in why your Irish website isn’t ranking.

The Short Version

A WordPress site keeps getting hacked because the clean-up addressed the symptom and left the cause in place. Restoring a backup replaces your pages while preserving the way back in, so the spam returns on a loop until someone finds and closes the entry point. Meanwhile the damage in Google compounds, and the instinct to forward the domain somewhere safer quietly makes it far worse than the hack ever did.

Cleaning is the right call on a recent compromise of a well-maintained site with a clean backup. On an ageing site that has been open for months, it is money spent rescuing something you will need to replace anyway. Rebuilding on a platform with no database, no plugins and no login page does not just fix the current break-in, it retires the whole category, which is the only outcome that actually ends the cycle.

Want a straight answer about your own ranking?

Get a straight answer

Common questions

Frequently asked questions

Straight answers to what Irish business owners ask most, no jargon.

How do I know if my WordPress site has been hacked?

Search Google for site:yourdomain.com and read what comes back. If you see pages you never wrote, particularly gambling, pharmacy or replica goods pages in languages you do not publish in, the site is compromised. Then open your own sitemap at yourdomain.com/sitemap_index.xml and look at the post sitemaps. Your site publishes a list of everything on it, so the injected pages will be sitting there in plain sight.

Why do the spam pages come back after I restore a backup?

Restoring a backup replaces your content, not the way in. Whoever compromised the site left something behind, usually a small file that lets them back in whenever they want, and a backup taken after the break-in contains that file too. You restore, the site looks clean for a few days, then the pages return. That loop continues until the entry point itself is found and closed.

Will Google penalise my site for pages I did not create?

Google does not care who wrote them. A site publishing thousands of gambling pages is treated as a site publishing thousands of gambling pages, so rankings fall and the domain can pick up a security warning in search results. The good news is that it is recoverable once the pages are gone and returning the correct error code, though recovery takes months rather than days.

Should I take my website offline while I sort it out?

Taking it offline is fine and often sensible. What causes lasting damage is pointing the domain somewhere else, such as a social media profile, because that tells Google the site has moved and the pages should be dropped. A holding page on your own domain does far less harm than a redirect off it.

How much does it cost to clean a hacked WordPress site?

Specialist malware removal typically runs from a few hundred euro upwards, depending on how long the compromise has been running and how many files are involved. The figure worth weighing against it is what a rebuild costs, because a clean-up leaves you with the same site and the same maintenance burden that allowed the break-in.

Is WordPress less secure than other platforms?

WordPress core is actively maintained and reasonably solid. The risk comes from the add-ons, since a typical site runs a theme and a dozen or more plugins, each written by a different developer, each needing regular updates. Miss those updates for a year and one of them eventually becomes the way in. Roughly four in five WordPress compromises trace back to an out-of-date plugin or theme rather than to WordPress itself.

Can a website be built so it cannot be hacked at all?

Nothing is completely unhackable, and anyone promising that is overselling. What can be removed is the entire category of attack described here. A site built as static files has no database, no plugins and no login page, so there is nothing to inject content into. Your hosting account, domain registrar and email still need protecting, but the thing that put a thousand casino pages on your site no longer exists.

How long does it take for the spam pages to disappear from Google?

Expect months rather than weeks. On a site I rebuilt, the count fell from roughly 27,000 affected pages to a few thousand within days of the compromised site coming down, then took a further two months to reach the high hundreds. The figure drops in steps rather than smoothly, because Search Console updates in batches, so a fortnight of no movement is normal and not a sign that something is wrong.