WordPress site redirects to a spam site: why it happens and how to fix it
When a WordPress site redirects to a spam site, malicious code was added to the site, and it often redirects only visitors who come from Google or from a phone, so the owner does not see it. The code is usually hidden in .htaccess, in wp-config.php or a theme file, in the database (site URL options or injected scripts in posts), or in a fake plugin. Removing only the redirect is not enough; the backdoor that added it has to go too.
Why you may not see the redirect
Attackers want the redirect to last, so they hide it from the site owner. Common conditions are: only visitors coming from a search engine, only phones, only the first visit, or never when you are logged in to WordPress. Test from your phone with mobile data, opening the site from a Google search result, in a private window.
Where the redirect is usually hidden
- .htaccess: rewrite rules that send search engine visitors to another domain.
- wp-config.php, functions.php or index.php: obfuscated PHP, often long strings with base64_decode, eval or gzinflate.
- The database: changed siteurl or home options, or script tags injected in posts, widgets and options.
- A fake plugin with a plausible name that does not appear in the plugins list.
- JavaScript added to the theme or to a cached file that loads the redirect from an external domain.
How to fix it properly
- Take a full backup of files and database first.
- Change all passwords and remove unknown admin users.
- Replace WordPress core with a clean copy and reinstall plugins and themes from official sources.
- Search the database for script tags and external domains you do not recognize, and check the siteurl and home options.
- Check .htaccess and every PHP file in uploads, then update everything and remove plugins you do not use.
- Request a review in Google Search Console if Google flagged the site.
Frequently asked questions
Why does the redirect only happen on mobile?
Many redirect scripts check the device or the referrer on purpose, so the site owner, usually on a computer and logged in, never sees it.
I removed the code and it came back. Why?
There is a backdoor somewhere else that writes the redirect again, or another infected site on the same hosting account. The cleanup has to cover files, database and every site in the account.
Hacked WordPress site · Fixed price: from 59 USD. You get the price in writing before any work starts.