← All guides

Website redirecting to another site: the malware and the fix

Your site sends visitors to a spam page, a fake update or a gambling site, but it looks fine when you open it. That is a redirect hack, and it hides on purpose. Here is where the code lives, how to see it, and the order to remove it in.

16 September 2026, 3 min read. From the cleanups where the owner had never seen the redirect themselves, because it only fired for visitors on phones.

A redirect hack is designed so that the owner never sees it. It fires for visitors arriving from Google, or on phones, or once per visitor, or only for people outside your country. You open the site from a bookmark on your desktop and everything looks normal. Meanwhile a share of your customers are landing on a fake browser update, a gambling site or a survey scam, and Google is watching it happen.

How to see it yourself

Open a private window on your phone. Search for your business on Google and tap the result. If you are sent somewhere else, there it is. If not, try again from mobile data instead of wifi, and try tapping a deeper page. Some variants only redirect once per device, so a second phone can help.

You can also check what the site sends to a crawler. The scanner follows the site’s redirect chain and shows where an address ends up, which catches the server-side versions.

Where the code lives

Redirect malware sits in a handful of predictable places. We check all of them, every time, because there is usually more than one.

  • The database. Injected script in the site settings, especially in options that hold theme or widget content. A changed site address is another version of the same trick.
  • The theme. A few lines at the top of header.php or functions.php, often disguised as a long encoded string.
  • Core files. Script added to wp-includes JavaScript files that load on every page. These survive plugin cleanups because nobody looks at core.
  • The server config. Rules in .htaccess that redirect based on the visitor’s referrer or device. Common, and easy to miss because the file looks technical anyway.
  • Fake plugins. A folder in the plugins directory with a name that sounds official, containing a single file that adds the redirect.
  • The scheduler. A scheduled task that rewrites any of the above every few hours, so the cleanup undoes itself overnight.

The removal order

  1. Snapshot first. Files and database, as they are.
  2. Log everyone out by changing the secret keys in the config file.
  3. Search the database for script tags and for the redirect destination’s domain. Fix the site address values if they were changed.
  4. Replace core, the theme and every plugin with fresh copies of the same versions. Do not clean them line by line; replace them.
  5. Read .htaccess and remove anything you did not put there. If in doubt, replace it with the platform’s default.
  6. Delete PHP files from the uploads folder and any plugin you do not recognise.
  7. List the scheduled tasks and remove the ones that are not yours.
  8. Update everything, rotate every password, including the database password and the hosting login.
  9. Test from a phone, from Google, in a private window.
  10. Find the door. Usually an outdated plugin with a known hole, or a reused password. If you skip this, the redirect comes back in a week, and it will be a slightly different version.

After

If Google flagged the site, request a review in Search Console once steps one to nine are done. Then something should be watching the site daily for changed files and new tasks for at least a month. Redirect hacks are the ones we most often see return, precisely because they are so easy to clean visibly and so easy to leave a door open for.

If the site redirects for your visitors and you have never seen it, you are not careless. It was built to hide from you. The point is to stop trusting what you see from your own desk, and check from theirs.

See where your own site stands.

The scanner checks the things this guide talks about, in about ten seconds, no signup.

Tell us about the site.

A straight answer and a fixed quote, usually the same day.