October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Google Search Console

How to Stop WordPress Redirecting to Spam Websites

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An unexpected redirect from your WordPress site to a spam, scam or malware page is a likely security incident. Do not assume the site is safe because it works when you visit the homepage. Attackers commonly make redirects conditional on a Google referrer, browser, device or user agent, so they can hide from administrators. Compare the affected URL in Google Search Console with real visits, contain exposure with your host if necessary, remove malicious code and database content, close compromised accounts and persistence mechanisms, then request Google reviews after the cause is fixed.

Confirm what is happening

Before changing files, record the exact WordPress URL, unexpected destination, time, device, browser and how the visit began. Test the link from Google Search, a direct address, mobile and desktop. A redirect that appears only after a search click is still evidence of compromise; Google documents this as a form of conditional or sneaky redirect.

  1. Open the affected URL directly in a clean browser session.
  2. Open the same result from Google Search, noting whether the destination changes.
  3. Repeat on a phone and a desktop, and test more than one browser.
  4. Use Search Console’s URL Inspection to compare Google’s fetched result with your human test.

A normal-looking visit does not clear the site. Conditional logic may inspect the referrer, user agent or device and redirect only selected visitors.

Check Google’s warnings and reports

In Google Search Console, open both reports because they describe different problems:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Security Issues: hacked content, malware or other behavior that can make a site dangerous.
  • Manual Actions: policy violations such as cloaking or sneaky redirects that require corrective action and, where applicable, a review request.

Search your site in Google for unfamiliar spam words, pages or domains. If Chrome or another browser displays a dangerous-site warning, check Google Safe Browsing as part of the verification process. A warning notification is evidence to investigate, not a substitute for finding the infected component.

Contain exposure without destroying evidence

If visitors may be sent to scams or malware, ask your hosting provider about temporary containment while preserving the backups, logs and access needed for investigation. Do not apply a universal DNS change or indiscriminate shutdown: the appropriate measure depends on your host, deployment and other services.

On shared hosting, ask the provider whether neighboring sites or the hosting account itself were affected. WordPress.org notes that one compromised account can have consequences beyond the site you first noticed.

Find the redirect logic

Inspect the whole site, not just the homepage. Google identifies JavaScript, .htaccess, the WordPress installation, themes and plugins as places to look for conditional redirects. Compare files with clean, official copies and review recently modified files, unfamiliar administrator accounts and unexpected scheduled or server-side activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A remote scanner can reveal what an ordinary visitor receives, but it cannot prove that the server is clean. Backdoors and server-side scripts may remain invisible in a browser, so pair remote checks with server-side file, configuration and database inspection.

Clean the infection and remove persistence

  1. Preserve a useful snapshot. Keep a copy of relevant files, database content and logs for comparison, while treating the snapshot as potentially infected.
  2. Replace compromised software. Where appropriate, install a fresh official WordPress core and clean copies of affected plugins and themes instead of editing suspicious files in place.
  3. Clean the database. Search posts, options, widgets and other tables for injected scripts, unfamiliar administrator content, spam URLs and redirect settings. Remove only malicious material while preserving legitimate site data.
  4. Remove backdoors. Investigate obscure PHP files, altered configuration, unauthorized scheduled tasks and other mechanisms that could recreate the redirect.
  5. Review accounts and keys. Delete unauthorized WordPress users, hosting users, database users, SSH keys and application tokens.
  6. Update and harden. Update WordPress, plugins, themes and server software; use unique credentials, least-privilege roles and protected administrator access.

Cleaning only the visible redirect is not remediation. If the redirect returns, assume an infected component, stolen credential or persistence mechanism remains and repeat server-side investigation with your host or a qualified incident responder.

Choose the right investigation route

Route What it can establish Limit
Remote scan Visible malicious responses and some exposed indicators May miss backdoors and server-side scripts
Server-side inspection Files, database content, configuration, accounts and persistence Requires hosting access and technical skill
Self-cleanup Direct control over the repair Risky if you cannot confidently identify every altered component
Professional incident response Specialist investigation when infection persists or access is limited Service scope and availability vary; verify terms directly
Temporary containment Can reduce visitor exposure during investigation Does not remove the root cause

Sucuri’s cleanup guidance describes professional malware-removal services, but you should evaluate any provider’s current scope and terms rather than assume a service guarantees recovery.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Secure every path attackers may have used

Change credentials after cleaning, not just the WordPress administrator password. Reset WordPress, hosting-panel, database, FTP/SFTP or SSH, email and deployment credentials, and revoke unknown API keys or application passwords. Enable multi-factor authentication where available, remove unused accounts and limit permissions. Ask the host to check for account-level compromise, malicious cron jobs and neighboring infections when the site is on shared hosting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clear Google warnings after the fix

  1. Confirm that the redirect no longer occurs under the search-referrer, device and browser tests that exposed it.
  2. Run URL Inspection again and review representative affected URLs.
  3. Recheck the Security Issues and Manual Actions reports.
  4. Use Google Safe Browsing checks when a browser warning was shown.
  5. When a Manual Action or security issue remains listed, submit the available review request only after the underlying malicious code and content are gone.

Google’s review and warning systems do not promise instant removal or immediate ranking recovery. Continue monitoring logs, Search Console and real visits after the review.

Do not remove legitimate redirects by mistake

WordPress sites can legitimately redirect after a permalink change, domain move, HTTPS migration or other planned navigation. The target here is an unexpected redirect to an unrelated spam destination, especially one that varies by referrer, browser or device. Identify and remove the malicious rule; do not disable every redirect your site needs.

When to call for help

Get your host or a qualified incident-response professional involved when you lack server access, cannot distinguish legitimate custom code from malware, the redirect returns after reinstalling components, multiple sites share the account, or visitors are being exposed to active scams or malware. Persistent reinfection usually means the initial entry point or a hidden backdoor was not removed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.