How to tell your WordPress site has a virus
An infected site rarely shouts "I have a virus". More often it gives subtle signals that are easy to ignore, until it is too late. Here are five things that should worry you.
1. Google warns your customers
The most painful scenario: someone types in your company name and, instead of your site, sees a red screen saying "This site may be dangerous". It is a sign that the search engine detected malicious code before you managed to react.
This is not a problem that "goes away on its own". Every day with such a warning means real lost customers and dented trust.
2. The site redirects to strange places
You click your address and land on an online pharmacy or a casino? A classic symptom of a redirect hack infection. Worse, it often happens only on phones or only for users coming from Google, so on your own computer you see nothing.
3. Content you did not add appears
New pages in Japanese, links to products you do not sell, strange files in the panel. If you see something you did not create, someone else has access to your site.
What to do when you notice these symptoms
A few things worth starting with:
- Do not panic and do not delete everything blindly, you may lose data needed for the repair.
- Change the passwords to the WordPress panel and hosting.
- Make a backup of the current state before you change anything.
- Ask for help before the infection spreads deeper.
Cleaning a site of malware is not just removing the visible traces, it is finding the back door the intruders came through and closing it. Otherwise the problem returns in a week.
Suspicious already? Run the free website malware test, it will check the public code for malicious scripts, redirects and spam.