If your Wix site has been hacked, the most important thing you can do right now is secure your Wix account access before anything else — stopping the attacker's entry point is the foundation of every recovery step that follows. Most Wix hacks happen through compromised passwords, phishing attacks, or unauthorized third-party app access rather than a breach of Wix's own infrastructure. The good news is that because Wix is a fully hosted platform, you have fewer moving parts to worry about than with a self-hosted site, and recovery is achievable even if you are not a technical expert.


How to Know If Your Wix Site Has Been Hacked

Before you start recovering, confirm you are actually dealing with a hack and not a different problem such as a billing lapse or a platform outage.

Common signs your Wix site has been compromised

  • Unexpected content changes — new pages, strange text, or links to unfamiliar websites have appeared without your action.
  • You are locked out of your Wix account — your password no longer works and you did not change it.
  • Google Search Console shows a security warning — Google Search Central flags sites distributing malware or engaged in phishing, and you may receive an email notification from them.
  • Visitors report browser warnings — Chrome, Firefox, or Safari displays a "Deceptive site ahead" or "Site contains malware" interstitial.
  • Unusual account activity — the Wix dashboard shows logins from unfamiliar locations or devices.
  • Your connected domain redirects elsewhere — visitors are being sent to a spam or adult website instead of your content.
  • Wix has suspended your site — Wix may proactively suspend sites they detect distributing harmful content.

If you see one or more of these signs, proceed through the recovery steps below in order.


Step 1: Secure Your Wix Account Immediately

Change your Wix password right now

  1. Go to wix.com and click Log In.
  2. If you can still access your account, click your profile avatar (top right), then Account Settings → Security → Change Password.
  3. Choose a password that is at least 16 characters long and completely unique to Wix — use a password manager such as Bitwarden or 1Password to generate it.
  4. If you cannot log in because the attacker changed your password, click Forgot Password on the login screen and use your registered email address to reset it.

Secure the email address linked to your Wix account

Your Wix account is only as secure as the email inbox connected to it. Log into your email provider and:

  • Change the email password immediately using a strong, unique passphrase.
  • Check for forwarding rules or filters the attacker may have added to intercept your messages — remove any you did not create.
  • Enable two-factor authentication (2FA) on your email account if it is not already active.

Enable two-factor authentication on your Wix account

  1. In Wix, go to Account Settings → Security → Two-Factor Authentication.
  2. Choose either an authenticator app (such as Google Authenticator or Authy) or SMS verification.
  3. Save your backup codes somewhere offline and secure.

Wix strongly recommends 2FA, and CISA (the U.S. Cybersecurity and Infrastructure Security Agency) lists enabling multi-factor authentication as one of the single most effective actions any account holder can take to prevent re-entry.


Step 2: Review and Revoke Unauthorized Access

Check which collaborators have access to your site

Attackers sometimes add themselves as site collaborators to maintain persistence even after a password reset.

  1. In your Wix dashboard, click Settings → Roles & Permissions.
  2. Review every listed collaborator and co-owner.
  3. Remove anyone you do not recognize by clicking the three-dot menu beside their name and selecting Remove.

Audit connected third-party apps

Malicious or compromised third-party apps can be a persistent backdoor.

  1. Go to Settings → Authorized Apps (or Manage Apps in your Wix dashboard).
  2. Revoke access for any app you do not recognize or no longer use.
  3. Re-install only the apps you need from the official Wix App Market after your recovery is complete.

Check your connected social accounts

If you use "Log in with Google" or "Log in with Facebook" to access Wix, check those accounts for unauthorized activity and revoke access to any suspicious third-party applications within those platforms too.


Step 3: Assess the Damage to Your Site Content

Review recent site changes in the Wix Editor

  1. Open your site in the Wix Editor.
  2. Look for pages you did not create — check the Pages panel on the left side.
  3. Delete any pages containing spam links, malicious redirects, or injected content.
  4. Check your site's Header and Footer sections for unfamiliar code widgets or HTML embed blocks, which are common injection points.

Check for hidden or SEO-spam content

Attackers often inject hidden links or text that visitors cannot see but search engines index. In the Wix Editor, look for:

  • Very small or white-text HTML embed blocks
  • Invisible layers placed behind legitimate content
  • Code widgets added to your page background

Delete anything you did not place there yourself.

Review your blog posts and dynamic pages

If your site has a Wix Blog or dynamic database collections, check each post and collection item for injected links or redirected URLs.


Step 4: Contact Wix Support

Wix Support should be involved in every significant hack recovery. They have visibility into your account's activity logs that you do not have direct access to.

How to reach Wix Support

  1. Log into your Wix account and click the Help icon (question mark) in the dashboard.
  2. Select Contact Support and choose the Chat or Callback option — for urgent security issues, live contact is faster than email.
  3. Tell the support agent your site has been compromised. Use the phrase "my account has been accessed without my authorization" — this triggers their security escalation process.

What to ask Wix Support to do

  • Provide a log of recent logins, including IP addresses and timestamps.
  • Confirm whether your site was flagged internally for abuse.
  • Assist with restoring a clean version of your site from their backups (see Step 5).
  • Check whether your connected domain settings were altered.

Wix stores site history and may be able to provide recovery options not visible to you in the standard dashboard.


Step 5: Restore Your Site From a Previous Version

Wix maintains an automatic version history for your site, which is one of the most powerful recovery tools available to you.

How to restore a previous version of your Wix site

  1. Open the Wix Editor for your site.
  2. Click the Site History option — in newer versions of the editor this is found under the top menu: Site → Site History or accessible via the history icon.
  3. Browse the list of saved versions with their timestamps.
  4. Identify the most recent version that predates any signs of the hack.
  5. Click Restore on that version and confirm.

Important: Before restoring, take screenshots or notes of any legitimate changes you made after the compromised date that you will want to recreate — restoring will overwrite those changes.

If you cannot find a clean version

If every saved version appears compromised, or if you used an external backup tool, contact Wix Support directly and request that they attempt a server-side recovery. For sites connected to Wix's CMS (Content Management System) with database collections, confirm with Support whether collection data is included in version history or requires separate recovery.


Step 6: Scan Your Connected Domain and DNS Settings

Your Wix site's domain may connect through a third-party registrar such as GoDaddy, Namecheap, or Google Domains. Attackers who gain access to your Wix account sometimes alter DNS settings to redirect your visitors.

How to audit your domain's DNS records

  1. Log into your domain registrar's control panel (separate from Wix).
  2. Navigate to your domain's DNS settings or Zone File.
  3. Check the following records:
    • A Record — should point to Wix's IP address, not a foreign server.
    • CNAME Record — for subdomains, verify the target is a legitimate Wix address.
    • MX Records — if you use email, ensure mail routing has not been redirected.
    • NS Records — verify nameservers have not been changed entirely.
  4. If you see records you did not add, delete them and contact your registrar's support for an access log.

Wix publishes the correct DNS values for connected domains in their Help Center under "Connecting a Domain" — use those as your reference for what the records should look like.

Secure your domain registrar account

  • Change the password on your registrar account.
  • Enable 2FA on the registrar account.
  • Enable domain lock (also called Registrar Lock or Transfer Lock) to prevent unauthorized domain transfers.

Step 7: Remove Google's Security Warnings

If Google flagged your site for malware or phishing, removing the harmful content is not enough — you also need to formally request a review through Google Search Console.

Submit a reconsideration request via Google Search Console

  1. Verify ownership of your site in Google Search Console (console.google.com) if you have not already — for Wix sites, the simplest method is the HTML meta tag option available through Marketing & SEO → Google Search Console in your Wix dashboard.
  2. In Search Console, go to Security & Manual Actions → Security Issues.
  3. Review the specific issues Google has flagged and confirm you have resolved each one.
  4. Click Request a Review and provide a clear explanation of what was compromised and what steps you have taken to clean the site.

Google Search Central states that reviews typically take a few days to several weeks depending on the severity of the classification. Warnings will be removed once Google's reviewers confirm the site is clean.


Step 8: Notify Your Visitors and Stakeholders if Necessary

Under data protection regulations such as GDPR (in the EU/UK) and various U.S. state laws, you may have a legal obligation to notify users if their personal data was accessed or exfiltrated during the compromise.

Who needs to be notified

  • Your customers or subscribers — if your Wix site collects contact forms, payments, or membership data.
  • Your payment processor — if your site processes payments via Wix Payments or a connected provider, contact them even if you believe card data was unaffected. They have their own security protocols to follow.
  • Your data protection authority — if you are subject to GDPR, you generally have 72 hours from becoming aware of a breach to notify your supervisory authority.

Even if notification is not legally required, a transparent email to your audience explaining what happened, what you have done to fix it, and what (if anything) they need to do, builds trust rather than destroying it.


Step 9: Harden Your Wix Site Against Future Attacks

Recovery is not complete until you have reduced the likelihood of this happening again.

Security hardening checklist for Wix sites

  • Use a unique, strong password for your Wix account and never reuse it elsewhere.
  • Keep 2FA active on both your Wix account and your linked email address at all times.
  • Audit collaborator access regularly — remove anyone who no longer needs it.
  • Only install apps from the official Wix App Market and remove any you are not actively using.
  • Use a business email address for your Wix account rather than a personal Gmail or Yahoo address that may have weaker security controls.
  • Enable domain lock at your registrar to prevent unauthorized transfers.
  • Monitor Google Search Console for security alerts on an ongoing basis.
  • Use a strong, unique password for your domain registrar account — it is equally as critical as your Wix account.
  • Be alert to phishing emails impersonating Wix — Wix will never ask for your password by email. OWASP identifies phishing as one of the top attack vectors for account compromise.

Frequently Asked Questions

Can Wix itself get hacked, causing my site to be compromised?

Wix as a platform has its own security team and infrastructure protections. In the vast majority of cases, individual site compromises are not caused by a breach of Wix's servers — they result from the site owner's account credentials being stolen, weak passwords, phishing attacks, or compromised third-party app integrations. Treat your Wix login credentials with the same seriousness as your online banking details.

Will Wix help me recover my hacked site for free?

Yes — Wix Support is available to all paid and free plan users and will assist with account security incidents at no additional charge. The version history restore feature is also built into the platform at no extra cost. For very complex incidents, Wix may escalate your case to their Trust & Safety team.

How long does it take to recover a hacked Wix site?

If the attacker only changed site content and you can restore a previous version, the technical recovery can be completed in under an hour. If your domain DNS was altered, propagation of corrected records can take up to 48 hours. Removing a Google Safe Browsing warning typically takes several days to a few weeks after you submit a reconsideration request through Google Search Console.

Do I need to hire a security professional to recover a hacked Wix site?

In most cases, no. Because Wix is a fully managed, hosted platform, you do not have direct server access, file systems to scan, or databases to manually clean the way you would with a self-hosted WordPress site. Following the steps in this guide, combined with Wix Support assistance, is sufficient for the majority of incidents. If you believe sensitive customer data was exfiltrated, you may wish to consult a cybersecurity professional or a data protection attorney regarding your legal obligations.

How do I tell if my Wix site is being used to send spam emails?

Signs include receiving spam complaint replies in your inbox, customers reporting they received emails from your domain that you did not send, or your domain appearing on an email blacklist checker such as MXToolbox. If your Wix account was compromised, check your email marketing settings under Wix Ascend or any connected email tool for campaigns you did not create, and delete them immediately before notifying your contacts.