What is a WordPress redirect hack?
A redirect hack occurs when unauthorised code or configuration changes cause a website visitor to be sent to another URL. The destination may contain spam, scams, unwanted downloads or other content unrelated to your business.
Attackers often avoid redirecting every request because an obvious site-wide redirect would be detected quickly. Google documents hacked redirects that depend on the referrer, user agent or device. A site can therefore work when the owner types the address directly into a desktop browser but redirect somebody who arrives from a search result or uses a phone.
The redirect itself is a symptom. The underlying compromise can sit in a plugin or theme, a modified WordPress file, injected JavaScript, the database, .htaccess or another part of the hosting configuration. Removing one visible redirect without finding the source can leave the attacker with continued access.
How to find a malicious WordPress redirect
Test the affected URL in more than one context. Compare desktop and mobile visits and check what happens when arriving from a search engine rather than typing the URL directly. Avoid repeatedly following a suspicious redirect to an unknown destination.
Review Google Search Console for Security Issues and inspect the Pages report for unexpected URLs. Google's inspection information can also help compare what its crawler encountered with what you see in a normal browser.
Check the page source for unfamiliar scripts or externally loaded resources. On the server, investigate unexpected changes to .htaccess, WordPress core, active plugins and themes. In the database, wp_options deserves attention because site URLs, plugin settings and injected values can influence behaviour, although malicious data can exist elsewhere too.
Check administrator users and recent file modification times and compare application files with trusted clean versions. Our free WordPress security scanner can add an external check, but server and database investigation is still required when the symptoms indicate a compromise.
How to clean a WordPress redirect hack
- Preserve the compromised site. Take a complete copy of the files and database before deleting or replacing anything.
- Change credentials. Reset WordPress, hosting, database and FTP or SFTP passwords. Replace the WordPress salts in wp-config.php and remove accounts that should not exist.
- Trace the redirect. Identify the script, PHP code, database value, .htaccess rule or compromised component responsible for it.
- Clean all affected components. Replace altered WordPress core files and compromised plugin or theme files with legitimate clean copies where appropriate, and remove malicious database content.
- Check for persistence. Search for backdoors or additional modifications that could recreate the redirect.
- Close the route in. Patch or remove vulnerable software and secure the account or hosting weakness involved.
Recheck the original behaviour from the conditions that triggered it before treating the incident as resolved. Our Hacked Site Rescue costs £349 fixed price.
Preventing malicious redirects from returning
Keep WordPress, plugins and themes current and remove software that is no longer used. Use strong unique passwords, two-factor sign-in where available and the lowest practical account permissions.
File integrity monitoring can identify application files that change outside expected updates. Keep daily or regular backups away from the live hosting environment so a clean recovery point is available if the server is compromised.
Continue monitoring Search Console and the website after cleanup, including mobile behaviour. A redirect that was conditional before cleaning should be tested under the same conditions afterwards.
Care plans start from £59 a month and include weekly updates, daily off-server backups, uptime monitoring and security scanning. See website security for related protective measures.