An unexpected redirect from your WordPress site to a spam, scam or malware page is a likely security incident. Do not assume the site is safe because it works when you visit the homepage. Attackers commonly make redirects conditional on a Google referrer, browser, device or user agent, so they can hide from administrators. Compare the affected URL in Google Search Console with real visits, contain exposure with your host if necessary, remove malicious code and database content, close compromised accounts and persistence mechanisms, then request Google reviews after the cause is fixed.
Confirm what is happening
Before changing files, record the exact WordPress URL, unexpected destination, time, device, browser and how the visit began. Test the link from Google Search, a direct address, mobile and desktop. A redirect that appears only after a search click is still evidence of compromise; Google documents this as a form of conditional or sneaky redirect.
- Open the affected URL directly in a clean browser session.
- Open the same result from Google Search, noting whether the destination changes.
- Repeat on a phone and a desktop, and test more than one browser.
- Use Search Console’s URL Inspection to compare Google’s fetched result with your human test.
A normal-looking visit does not clear the site. Conditional logic may inspect the referrer, user agent or device and redirect only selected visitors.
Check Google’s warnings and reports
In Google Search Console, open both reports because they describe different problems:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Security Issues: hacked content, malware or other behavior that can make a site dangerous.
- Manual Actions: policy violations such as cloaking or sneaky redirects that require corrective action and, where applicable, a review request.
Search your site in Google for unfamiliar spam words, pages or domains. If Chrome or another browser displays a dangerous-site warning, check Google Safe Browsing as part of the verification process. A warning notification is evidence to investigate, not a substitute for finding the infected component.
Contain exposure without destroying evidence
If visitors may be sent to scams or malware, ask your hosting provider about temporary containment while preserving the backups, logs and access needed for investigation. Do not apply a universal DNS change or indiscriminate shutdown: the appropriate measure depends on your host, deployment and other services.
Rank #2
On shared hosting, ask the provider whether neighboring sites or the hosting account itself were affected. WordPress.org notes that one compromised account can have consequences beyond the site you first noticed.
Find the redirect logic
Inspect the whole site, not just the homepage. Google identifies JavaScript, .htaccess, the WordPress installation, themes and plugins as places to look for conditional redirects. Compare files with clean, official copies and review recently modified files, unfamiliar administrator accounts and unexpected scheduled or server-side activity.
A remote scanner can reveal what an ordinary visitor receives, but it cannot prove that the server is clean. Backdoors and server-side scripts may remain invisible in a browser, so pair remote checks with server-side file, configuration and database inspection.
Clean the infection and remove persistence
- Preserve a useful snapshot. Keep a copy of relevant files, database content and logs for comparison, while treating the snapshot as potentially infected.
- Replace compromised software. Where appropriate, install a fresh official WordPress core and clean copies of affected plugins and themes instead of editing suspicious files in place.
- Clean the database. Search posts, options, widgets and other tables for injected scripts, unfamiliar administrator content, spam URLs and redirect settings. Remove only malicious material while preserving legitimate site data.
- Remove backdoors. Investigate obscure PHP files, altered configuration, unauthorized scheduled tasks and other mechanisms that could recreate the redirect.
- Review accounts and keys. Delete unauthorized WordPress users, hosting users, database users, SSH keys and application tokens.
- Update and harden. Update WordPress, plugins, themes and server software; use unique credentials, least-privilege roles and protected administrator access.
Cleaning only the visible redirect is not remediation. If the redirect returns, assume an infected component, stolen credential or persistence mechanism remains and repeat server-side investigation with your host or a qualified incident responder.
Rank #4
Choose the right investigation route
| Route | What it can establish | Limit |
|---|---|---|
| Remote scan | Visible malicious responses and some exposed indicators | May miss backdoors and server-side scripts |
| Server-side inspection | Files, database content, configuration, accounts and persistence | Requires hosting access and technical skill |
| Self-cleanup | Direct control over the repair | Risky if you cannot confidently identify every altered component |
| Professional incident response | Specialist investigation when infection persists or access is limited | Service scope and availability vary; verify terms directly |
| Temporary containment | Can reduce visitor exposure during investigation | Does not remove the root cause |
Sucuri’s cleanup guidance describes professional malware-removal services, but you should evaluate any provider’s current scope and terms rather than assume a service guarantees recovery.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Secure every path attackers may have used
Change credentials after cleaning, not just the WordPress administrator password. Reset WordPress, hosting-panel, database, FTP/SFTP or SSH, email and deployment credentials, and revoke unknown API keys or application passwords. Enable multi-factor authentication where available, remove unused accounts and limit permissions. Ask the host to check for account-level compromise, malicious cron jobs and neighboring infections when the site is on shared hosting.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
Clear Google warnings after the fix
- Confirm that the redirect no longer occurs under the search-referrer, device and browser tests that exposed it.
- Run URL Inspection again and review representative affected URLs.
- Recheck the Security Issues and Manual Actions reports.
- Use Google Safe Browsing checks when a browser warning was shown.
- When a Manual Action or security issue remains listed, submit the available review request only after the underlying malicious code and content are gone.
Google’s review and warning systems do not promise instant removal or immediate ranking recovery. Continue monitoring logs, Search Console and real visits after the review.
Do not remove legitimate redirects by mistake
WordPress sites can legitimately redirect after a permalink change, domain move, HTTPS migration or other planned navigation. The target here is an unexpected redirect to an unrelated spam destination, especially one that varies by referrer, browser or device. Identify and remove the malicious rule; do not disable every redirect your site needs.
When to call for help
Get your host or a qualified incident-response professional involved when you lack server access, cannot distinguish legitimate custom code from malware, the redirect returns after reinstalling components, multiple sites share the account, or visitors are being exposed to active scams or malware. Persistent reinfection usually means the initial entry point or a hidden backdoor was not removed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




