· updated 2026-10-07
This is one of the most common cases clients bring us: “everything looks fine to me, but people say they end up on some other website”.
Why you do not see it
Redirect code almost always carries conditions. It usually triggers only when:
- the visitor arrived from a search engine (it checks
HTTP_REFERER); - a mobile device is used (it checks
User-Agent); - the visitor is not logged into WordPress;
- it is a first visit — after that a cookie prevents a repeat.
So an administrator who is permanently logged in and visits directly can miss it for months.
Where the code usually hides
.htaccess—RewriteCondrules at the end of the file;- the theme’s
functions.phporheader.php; - the
wp_optionsdatabase table, usually in autoloaded rows; - a separate plugin named to look legitimate.
How to check
Open the site in a private window through Google search, and again from a phone. In the browser Network panel enable “Preserve log” — you will see exactly where the redirect goes.
Finding it is only half the work. If the entry vector is not identified, the code comes back. An incident investigation starts with evidence, not with cleanup.