You open your Faisalabad clinic site, textile brand store, or agency portfolio and see spam pages, a redirected homepage, or Google Safe Browsing warnings. Clients message on WhatsApp: "link pe red screen aa raha hai." That is a hacked WordPress site — common on cheap shared hosting across Pakistan — and the first hour of response decides whether you recover cleanly or lose weeks of SEO and trust.
This guide covers what to do first, how to clean and restore, and how to prevent the next break-in without buying every security plugin on the market.
What "Hacked" Usually Looks Like
Typical symptoms on Pakistani business WordPress installs:
- Homepage redirects to gambling, pharma, or adult URLs (often only for Googlebot or mobile users) - New admin users you did not create - Spam posts or pages in Urdu/English you never published - `index.php` or `.htaccess` rewritten with injects - Email delivers fail because the domain is blacklisted after spam blasts - Google Search Console: "Hacked content" or "Social engineering" security issue - Hosting panel shows high CPU from crypto miners or mail queues
Do not ignore a "small" defacement. Attackers often leave backdoors for later.
Hour 1: Contain the Damage
1. **Take the site offline or into maintenance mode** if customers can still be phished. A short downtime is better than spreading malware. 2. **Change all passwords** off the infected machine: WordPress admin, hosting cPanel/Plesk, FTP/SFTP, database, domain registrar, and email. Use a password manager. 3. **Enable 2FA** on hosting and registrar where available. 4. **Export a full backup now** (files + database) even if infected — you may need it for forensics. Label it `infected-YYYY-MM-DD`. 5. **Note the symptoms** with screenshots: redirects, strange users, modified dates on core files. 6. **Warn your team** not to "just reinstall a theme" on top of a live infected site — that often leaves backdoors.
If the site processes payments (JazzCash/Easypaisa plugins, Stripe, PayPal), treat this as a security incident: pause campaigns, check for fraudulent orders, and rotate API keys.
Hour 2–4: Confirm Hosting and Access Path
Many hacks in Pakistan start with:
- Outdated WordPress core, themes, or nulled/pirated plugins - `admin` / `admin123` style passwords - Vulnerable contact forms and file upload plugins - Compromised FTP credentials shared with freelancers - Neighboring sites on the same cheap shared server (cross-account infection)
Ask your host: Was there a server-wide incident? Can they restore a clean snapshot from before the attack? Get the exact restore point timestamp in writing.
Prefer SFTP over plain FTP. Disable unused FTP accounts.
Clean or Restore? Choose Deliberately
**Best path when you have a known-good backup from before the hack:** restore files + database to that point, then immediately update everything and harden (below). Re-apply only content published after that date carefully.
**If you have no clean backup:** you need malware cleanup:
1. Update WordPress core, themes, and plugins on a **staging copy**, not blindly on production mid-attack. 2. Remove unused themes/plugins entirely. 3. Delete unknown admin users; verify legitimate ones. 4. Scan with a reputable security tool (Wordfence, Sucuri, or host malware scanner) and manually review flagged files. 5. Compare core checksums (WordPress integrity tools) and replace modified core files. 6. Check `wp-config.php`, `functions.php` in the active theme and mu-plugins for obfuscated PHP. 7. Review `uploads` for `.php` files — uploads should not execute PHP. 8. Reset all salts/keys in `wp-config.php`.
Hiring a specialist for cleanup is often cheaper than a week of DIY mistakes. CortVista and similar agencies regularly inherit sites where a "quick fix" left three backdoors.
After Cleanup: Submit for Review and Recover SEO
1. Request a review in Google Search Console for security issues once the site is clean. 2. Remove spam URLs from the sitemap; submit a clean sitemap. 3. Check `site:yourdomain.com` for spam URLs and use Removals sparingly for the worst offenders while Google recrawls. 4. Restore from Search Console any accidentally noindexed pages. 5. Tell customers via WhatsApp/email the site is safe again — silence fuels distrust. 6. Monitor uptime and file changes for two weeks.
Expect rankings to wobble. Fast, transparent recovery beats pretending nothing happened.
Prevention Checklist for Pakistani WordPress Sites
- Keep core, themes, and plugins updated on a weekly cadence - Never install nulled themes/plugins "from Telegram" - Limit login attempts; disable XML-RPC if unused - Use strong unique passwords + 2FA for admins - Host on a provider that patches servers and offers malware scanning (not the cheapest unknown reseller) - Disable PHP execution in `uploads` - Take automated daily offsite backups you have tested restoring - Give freelancers temporary users, then delete them when the project ends - Separate email, hosting, and WordPress credentials - Use a WAF / security plugin with sensible rules — not twenty overlapping plugins
When to Migrate Instead of Patch Forever
If the site is a five-year pile of abandoned page builders, unknown child themes, and five form plugins, cleanup alone will fail again. Plan a rebuild on a maintained stack (modern WordPress with minimal plugins, or a proper Next.js/headless setup) once the emergency is stable.
Bottom Line
A hacked WordPress site in Pakistan is usually outdated software plus weak passwords plus risky hosting — not bad luck. Contain first, restore or clean second, harden third, then ask Google to trust you again. If you need a clean restore, hardening, or a safer rebuild, get help before the next spam blast hits your clients' phones.
How CortVista Can Help
CortVista cleans hacked WordPress sites, removes malware and spam redirects, restores Google trust, and hardens the site so it does not happen again. If your site is showing warnings or sending visitors to spam, contact the CortVista team at cortvista.com.