A hacked WordPress site is rarely a coincidence and almost never just bad luck. Most often, it’s the result of neglected maintenance, combined with attackers who, thanks to artificial intelligence, now operate faster and more automatically than they did just a few years ago. This makes it all the more important to know how to prevent attacks and what really matters in the first few hours after an attack.
It’s just a normal morning—you open your website, and instead of the usual homepage, you see unfamiliar ads for dubious products. Or the page doesn’t load at all. Or, most unpleasant of all, Google is already warning your visitors about your own website. For many website owners, this is the moment when it becomes clear: Someone who wasn’t invited has been here.
The frustrating thing is that it could almost always have been avoided. WordPress itself isn’t insecure. A site only becomes insecure when it’s left unmaintained for months, when updates are neglected, and when no one checks on it. And that’s exactly what makes it more dangerous today than it used to be.
Why Every Page Is a Goal Today
For a long time, people comforted themselves with the assumption that their own small club or company website was too insignificant to attract attackers. That assumption no longer holds true. Attacks are no longer carried out manually but are now automated. Programs scan the web around the clock for websites with known vulnerabilities and strike as soon as they find one. These machines don’t care whether the site belongs to a global corporation or a local gymnastics club.
Artificial intelligence has further accelerated this trend. Whereas an attacker used to need specialized knowledge and days of work, attack tools are now created in minutes. As soon as a new security vulnerability becomes public, a ready-made script to exploit it is often circulating just a few hours later. The time window between “vulnerability known” and “vulnerability exploited” has shrunk from weeks to hours. Even phishing emails designed to steal login credentials are now more convincing and error-free thanks to AI than they were just a short time ago.
In short: If you wait for something to happen, you’ll wait too long.
Prevention is easier than you think
The most important safeguard is also the least spectacular: keeping everything up to date. WordPress itself, its extensions (plugins), and its design (theme) receive regular updates, and a large portion of these updates address precisely these kinds of security vulnerabilities. A site that is updated promptly is simply not a worthwhile target for automated attackers because the known entry points have already been closed.
In addition, the rule is: Less is more. Every plugin and theme you don’t really need increases your attack surface and should be removed. Strong, unique passwords for each service are just as important as two-factor authentication, which requires a second verification step in addition to the password. A reliable web host that prioritizes security and an upstream firewall that blocks suspicious requests round out the picture. And very importantly—even if no one likes to hear it—regular, automatic backups stored in a separate location. In an emergency, they’re often the difference between a scare and a catastrophe.
That sounds like a lot, and to be honest, it’s more than you can handle on the side. That’s why the most sensible advice is usually also the simplest: Put the maintenance in professional hands. A fair maintenance contract ensures that updates are tested and installed regularly, that someone keeps an eye on the site, and that backups not only run but actually work in an emergency. The cost is manageable compared to what an attack would cost in terms of time, stress, and lost trust. You insure your car and your home. The website through which customers and the public perceive a company deserves the same level of care.
The Site Has Been Hacked – The Emergency Guide
If it does happen, one thing is most important: don’t panic and don’t rush to delete anything. The traces of the attack are valuable for understanding what happened. The first sensible step is to temporarily take the site offline or put it into maintenance mode. This prevents further damage, protects visitors from harm, and stops your site from distributing malware without your consent.
After that, it’s time for an expert to take over—whether that’s your IT manager or an agency. The first thing this person should do is assess the situation and reset all access credentials—and do so thoroughly: the WordPress login, the hosting account, the database, and file transfer credentials. This is best done from a device that is guaranteed to be clean. At the same time, it’s worth checking the server’s log files, which often reveal when and how someone gained unauthorized access.
The core of the cleanup process revolves around two areas: the files and the database. Malicious code is often hidden within the files, while new, unknown administrator accounts or manipulated content and links may appear in the database. Both must be found and removed, which requires experience because the code is often cleverly disguised. Very often, the fastest and safest way to recover is to restore from a clean backup taken before the attack. That’s exactly why backups are so valuable, and that’s exactly why they must be checked regularly. A backup that doesn’t work when you need it isn’t a backup at all.
Just cleaning up isn’t enough. It’s just as important to find the actual cause—that is, the vulnerability through which the attacker gained access. If it isn’t patched, the same attacker will be back at the door shortly thereafter. Finally, make sure to update all software to the latest versions and keep a close eye on the site for a while.
One point to keep in mind in Switzerland: If personal data—such as addresses or contact information from forms—was compromised during the attack, there may be a reporting requirement. The revised Data Protection Act requires that serious data security breaches be reported, under certain circumstances, to the Federal Data Protection Commissioner and the affected individuals. When in doubt, it’s better to consult an expert early on than to regret it later.
In the end, almost every one of these stories leads to the same conclusion: The effort required to restore a hacked site to a clean and trustworthy state is many times greater than the effort needed to maintain it properly from the start. Those who learn the right lesson from this nightmare and entrust future maintenance to reliable hands have at least gained something: the peace of mind to open their own website in the morning without holding their breath.















