Redirect malware
WordPress is redirecting to another site. That is an active hack.
Visitors — often only on phones, or only when they come from Google — land on a casino, a fake store, or a malware download instead of your page. A WordPress redirect hack is not a permalink setting. Something is sending them away on purpose.
What this usually is
Redirects get planted in .htaccess, in JavaScript in the header or a widget, in a compromised plugin, or in PHP that inspects the user-agent and only fires for Googlebot or mobile. That is why the owner “cannot reproduce it” on the office desktop while logged in. Clearing the cache without removing the rule is a fifteen-minute holiday.
What you are probably seeing
- Only mobile visitors are redirected
- Only people arriving from Google are redirected
- You cannot see it while logged into wp-admin
- .htaccess has rewrite rules you did not write
- A JavaScript snippet in the header or footer loads a third-party domain
What not to do
- Do not only restore a default .htaccess. If a plugin or mu-plugin is writing it, the redirect returns on the next request.
- Do not change the WordPress Address (URL) and Site Address as the fix. You will break logins and leave the malware.
- Do not assume Cloudflare or the host cache is “the problem.” Cache can hide a redirect; it does not invent one to a sportsbook.
What we actually do
We reproduce the redirect the way a visitor or Googlebot would see it, find the rule or script, remove it, and close the account or file that put it there. Same published packages as any other WordPress incident. If the redirect is only the front door of a larger business compromise (365, ransomware), that is the emergency IR page — say so on the call.
Published rates live on the WordPress incident-response packages page: Phase A from $2,500, Phase B from $2,000, combined from $4,200. Remote nationwide. Onsite in the Tri-Cities and Western North Carolina if you want someone in the room. If the WordPress site is the front door to a larger business compromise, start at emergency incident response instead.
Related WordPress problems
Same practice, same packages. Different search, different first paragraph.
Hacked WordPress
The site is compromised and you need it cleaned carefully, not rebuilt from a blank theme.
Gambling / casino / loan spam
Google shows casino, loan, or pill titles. Your pages look normal when you visit them logged in.
Safe Browsing / Search Console
Chrome or Search Console flagged the site. You need cleanup, then a recrawl — in that order.
Spam links you did not add
Footer, sidebar, or post links appeared that nobody on your team added.
Packages & pricing
Phase A, Phase B, and combined. Written report. Hosting can stay yours.
If this is your WordPress site
It only happens on phones. Is it still a hack?
Yes. Mobile-only redirects are a common payload. The malware checks the user-agent. Your desktop session while logged in is the one case they try not to trigger.
Only Google sees the spam URL. Visitors see the real site.
That is cloaking aimed at search. Same incident as the gambling-links page. Cleanup first; Search Console recrawl after the public HTML is clean.
Can I just change the site URL in settings?
No. That does not remove the redirect and it can lock you out of admin. Leave the addresses alone until someone has read .htaccess and the header scripts.
Need the site cleaned without taking the store down?
Tri-Cities 423-888-0252 · Western NC 828-484-1257