tunzaweb
← All posts
Security9 August 2026 · 4 min read

What to Do When Your WordPress Site Gets Hacked in Kenya

A WordPress-specific step-by-step response to a hack: spotting the damage, finding the backdoor, cleaning the site and stopping it from happening again.

WordPress site hacked in Kenya - security shield and recovery steps for your business website

Most Kenyan business sites run on WordPress - which is exactly why hackers target it. The good news: almost every WordPress hack follows the same pattern, which means there's a repeatable way to respond. This guide walks through the WordPress-specific version: where the damage hides, how to find how they got in, and what to do in the right order.

How WordPress sites actually get hacked in Kenya

  • An outdated plugin or theme with a known vulnerability. This is number one by far. Someone finds a hole, and bots scan thousands of sites for it within days.
  • Nulled or pirated themes and plugins. The "free premium" theme usually contains a backdoor the attacker already knows about.
  • Weak passwords and no login protection. "Admin" as a username with a simple password is a standing invitation.
  • Shared hosting neighbours. On shared hosting, a hacked site next to yours can sometimes be the way in.
  • Abandoned sites. The longer a site sits un-updated, the more attacks it accumulates.

The first hour: contain, don't panic

  1. Change passwords, in this order: WordPress admin, hosting control panel, FTP/SFTP, then the database. If you can't remember the hosting login, your host can reset it.
  2. Log out all sessions. WordPress has a "log out everywhere" option under Users - use it. The attacker's session dies with it.
  3. Check for new admin users. Go to Users in wp-admin. Admins you didn't create are a classic backdoor.
  4. Don't delete anything yet. Copy your files and database first (via your hosting backup or cPanel). Evidence helps find the entry point, and a copy of the hacked state can be useful.

Finding the damage: where WordPress hacks hide

After immediate containment, look in the usual hiding places:

  • Unknown admin accounts - check the wp_users table in phpMyAdmin, or ask your host to.
  • Injected PHP files in wp-content/uploads/ - uploads should contain images, not .php files.
  • Modified .htaccess and wp-config.php - look for code that doesn't belong, like redirects or strange functions.
  • Suspicious cron jobs - WordPress can be set to phone home on a schedule.
  • Plugins or themes you never installed - attackers often install a "plugin" that is actually a backdoor.
  • Injected code in functions.php - check your theme's files for base64-encoded strings or links to unknown domains.

If you find something odd but aren't sure what it is, stop and get professional help. Guessing is how people delete the wrong file or miss the backdoor entirely.

Cleaning the site properly

The only reliable clean-up is: restore from your most recent clean backup, then immediately update WordPress, every plugin, and every theme - otherwise the same hole is still open. If you have no clean backup:

  1. Reinstall WordPress core from the official source (or via the dashboard's reinstall option).
  2. Delete and reinstall your plugins and theme from official sources - don't keep pirated copies.
  3. Remove unknown files and extra admin users.
  4. Reset every password again, including database credentials.

Clearing the Google warning

Once the site is clean, go to Google Search Console and request a review. Google re-scans and, if it's satisfied, removes the "This site may be hacked" label - usually within a few days. Cleaning the site without requesting the review leaves the warning up, and sales keep suffering while you wait.

Making sure it doesn't happen again

After any hack, the minimum hardening is: two-factor authentication on admin accounts, a login limiter to stop brute-force attacks, a security plugin with a firewall, automatic off-site backups, and updates on a schedule you actually keep. The sad truth is that most sites that get hacked once get hacked again through the same gap within months - precisely because the owner stops at "it's clean now."

DIY or call for help?

If your site takes payments, you have no backup, you're not sure what you're looking at, or the launch deadline is next week - don't DIY. Emergency WordPress recovery in Kenya typically runs KSh 12,000 - 35,000, and that's cheaper than a week of a down store. Our hacking repair service is built for exactly this: clean, delist, harden, done. Message us on WhatsApp with your site link and we'll look right away and tell you honestly what's needed.

Chat on WhatsApp now - same-day response.

Need help with this on your site?

We'll take a look and give you a straight answer - no obligation.