Why it only happens sometimes
Redirect malware is built to stay hidden from the site owner. Typical conditions are:
- Only from search results. The code checks the
Refererheader and redirects only visitors coming from Google or Bing. Typing your address directly shows a normal site. - Only on mobile. The user agent is checked; desktop visitors see nothing unusual.
- Only once. A cookie is set after the first redirect so repeat visitors — usually you — never see it again.
- Never for logged-in admins. WordPress infections often skip anyone with a login cookie.
This is why owners often hear about the problem from customers first.
Where the redirect usually lives
- Injected JavaScript in theme files,
header.php,footer.phpor a fake plugin. - Database content: an obfuscated
<script>appended to posts, widgets or options such assiteurlandhome. - Server rules in
.htaccessor the Nginx configuration that redirect based on referrer or user agent. - A compromised third-party script or ad tag loaded from another domain.
How to confirm it from the outside
- Open your site in a private window on a phone, from a Google search result, not by typing the address.
- Compare what a normal browser and a search-engine crawler receive. A difference is called cloaking and is a strong sign of compromise.
- Run our free website security check. It follows redirects, compares the crawler and visitor view and looks for redirect code and injected spam links.
Removing it properly
Deleting the visible script is rarely enough. The attacker usually left a second way back in — a web shell, a rogue admin user or a modified core file — and the redirect returns within days. A proper cleanup:
- Takes a backup of the infected state for analysis.
- Compares every core, theme and plugin file against a clean original and removes anything that does not belong.
- Cleans the database, removes unknown admin users and rotates all passwords, keys and salts.
- Finds and closes the entry point — usually an outdated plugin, a reused password or a writable upload directory.
- Requests a review from Google if the site was flagged, and monitors for re-infection.
Frequently asked questions
Is the redirect my hosting company's fault?
Rarely. In most cases the attacker came in through an outdated plugin, theme or a reused password. Shared hosting can make cross-site infections easier, but the fix is still on the site itself.
Will restoring a backup fix it?
Only if the backup predates the infection and you also close the entry point. Otherwise the same vulnerability is exploited again, often within days.
Why do I not see the redirect myself?
Most redirect malware skips logged-in users, repeat visitors and desktop browsers. Test from a phone, in a private window, coming from a Google search result.