20 Jul 2026 12 min read
How to tell if your WordPress site is infected
Wondering whether your WordPress site is infected? A few tell-tale signs usually give it away. Watch for the tell-tale signs: your...
Read the answerChecking a WordPress site for malware is the step people skip. Before you pay for a clean-up, it is worth knowing what is actually wrong.
1 answer in Diagnostics
Some symptoms are obvious: a browser warning, a redirect to a betting page, adverts you did not add. Others are quiet — a slow admin area, search results listing pages you never wrote, email that suddenly lands in spam.
A scanner is a starting point, not a verdict. Checking a WordPress site for malware properly means looking at the files, the database, the user accounts and the scheduled tasks together, and comparing what you find against a known-good copy of WordPress and its plugins.
Two mistakes make this harder than it needs to be. The first is cleaning before you look, which destroys the evidence that would tell you how the site was reached. The second is trusting a green tick from a scanner that only reads the front page. Plenty of infections show nothing to a logged-out visitor and everything to someone arriving from Google on a phone. If the symptom only appears for some people, that is a clue, not a false alarm — check the site the way the people reporting it did, on the same kind of device, arriving the same way, logged out.
Get a free security checkRather skip the reading?