OVOscar Villegas
2026-10-11 · Oscar Villegas

WordPress site redirects to a spam site: why it happens and how to fix it

When a WordPress site redirects to a spam site, malicious code was added to the site, and it often redirects only visitors who come from Google or from a phone, so the owner does not see it. The code is usually hidden in .htaccess, in wp-config.php or a theme file, in the database (site URL options or injected scripts in posts), or in a fake plugin. Removing only the redirect is not enough; the backdoor that added it has to go too.

Why you may not see the redirect

Attackers want the redirect to last, so they hide it from the site owner. Common conditions are: only visitors coming from a search engine, only phones, only the first visit, or never when you are logged in to WordPress. Test from your phone with mobile data, opening the site from a Google search result, in a private window.

Where the redirect is usually hidden

  • .htaccess: rewrite rules that send search engine visitors to another domain.
  • wp-config.php, functions.php or index.php: obfuscated PHP, often long strings with base64_decode, eval or gzinflate.
  • The database: changed siteurl or home options, or script tags injected in posts, widgets and options.
  • A fake plugin with a plausible name that does not appear in the plugins list.
  • JavaScript added to the theme or to a cached file that loads the redirect from an external domain.

How to fix it properly

  1. Take a full backup of files and database first.
  2. Change all passwords and remove unknown admin users.
  3. Replace WordPress core with a clean copy and reinstall plugins and themes from official sources.
  4. Search the database for script tags and external domains you do not recognize, and check the siteurl and home options.
  5. Check .htaccess and every PHP file in uploads, then update everything and remove plugins you do not use.
  6. Request a review in Google Search Console if Google flagged the site.

Frequently asked questions

Why does the redirect only happen on mobile?

Many redirect scripts check the device or the referrer on purpose, so the site owner, usually on a computer and logged in, never sees it.

I removed the code and it came back. Why?

There is a backdoor somewhere else that writes the redirect again, or another infected site on the same hosting account. The cleanup has to cover files, database and every site in the account.

Need it fixed?

Hacked WordPress site · Fixed price: from 59 USD. You get the price in writing before any work starts.

More guides

Something broken or worth automating?

Tell me what is happening. You get an answer the same day with what I see and a proposal.

Please enter your name.
So I can reply. Example: name@company.com or +1 555 000 0000Leave an email or WhatsApp so I can reply.
What is happening now and what result you expect. Links or screenshots can come later.Tell me in at least one sentence what you need.