Key takeaways

  • Contain first: back up for evidence and change passwords from a clean device before you start cleaning.
  • Replace WordPress core, plugins and themes from official sources rather than editing infected files by hand.
  • Malware hides in the database, must-use plugins, uploads and server cron jobs, not just theme files.
  • Find and fix the entry point, or the site will be re-infected.
  • Finish with hardening, credential rotation, monitoring and a Google review request if the site was flagged.

How do you remove malware from a WordPress site?

To remove malware from a WordPress site, first contain it: take a full backup for evidence and change every password from a clean device. Then replace WordPress core, plugins and themes from official sources, clean the database and uploads folder, remove rogue admins and server-level persistence, fix the entry point and harden the site.

That order matters. The most common mistake we see is deleting the one malicious file a scanner flagged, seeing the warning disappear and assuming the job is done. Within days, sometimes minutes, the malware is back, because a second backdoor, a hidden admin account or a cron job was left behind. A proper clean-up assumes the attacker left several ways back in and removes all of them.

This guide is written for site owners and developers with access to the hosting account and, ideally, SSH. If you do not have that access, or the site handles payments or personal data, consider our WordPress malware removal service, which includes a full forensic investigation and unlimited clean-ups.

If customers' card details may be at risk, take the checkout offline and contact your payment provider before doing anything else. See our card skimmer guide.

What should you do before you start cleaning?

Before you start cleaning, contain the infection and preserve evidence. Put the site into maintenance mode if visitors are at risk, take a complete backup of files, database and server logs, and change hosting, database, SFTP and WordPress passwords from a device you trust. This stops further damage and gives you something to investigate.

  1. Contain. Enable a maintenance page, or restrict access to your own IP address while you work.
  2. Back up everything. Files, database and access logs, stored off the server. This backup is evidence, not something to restore.
  3. Change credentials. Hosting panel, SFTP/SSH, database and all WordPress administrator passwords, from a clean device.
  4. Note what you see. Record symptoms, times and anything customers reported. It will help you find the entry point later.

A backup taken now also matters if personal data might have been accessed, because you may need to assess whether the incident must be reported to the ICO. Our guide to website hacks and UK GDPR explains how to decide.

How do you find all the malware in WordPress?

To find all the malware in WordPress, compare core files against official checksums, search the file system for PHP in uploads and for obfuscated code, list must-use plugins and recently modified files, and search the database for injected scripts. Then check the server itself for cron jobs and processes, since WordPress-level scanners cannot see those.

If you have SSH and WP-CLI, these commands give a strong start. Run them from the WordPress root:

# Verify core files against WordPress.org checksums
wp core verify-checksums
Warning: File doesn't verify against checksum: wp-includes/load.php
Warning: File should not exist: wp-includes/class-wp-cache-handler.php
# Verify plugins from the WordPress.org directory
wp plugin verify-checksums --all
# PHP files in uploads and recently modified PHP
find wp-content/uploads -name "*.php"
find . -name "*.php" -mtime -14
# Scripts injected into posts or options
wp db search "<script" --all-tables --stats
# Administrator accounts and scheduled tasks
wp user list --role=administrator
crontab -l

Pay special attention to wp-content/mu-plugins, which loads automatically and does not appear in the normal plugin list, and to .htaccess files anywhere in the tree, which are often altered to add redirects. If the server hosts other sites, repeat the checks for each one; an untouched neighbour may be where the infection started.

Do not forget the database. Injected JavaScript is often stored in wp_options rows such as siteurl, home or widget settings, or appended to the content of many posts at once. A quick look at recently changed options and any unfamiliar autoloaded entries often reveals malware that no file scan will ever see. If the siteurl or home value points somewhere unexpected, the whole site will redirect, however clean the files are.

Keep a note of every suspicious item you find, with its path, size and modification time. Patterns in those timestamps are the fastest way to find the entry point later in the process.

A server-side Malware sweep automates this across files, databases, users and scheduled tasks for every site on the server.

Security triage

Is your site showing any of this?

Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.

Start the triage

How do you clean the infected files and database?

Clean infected WordPress files by replacing rather than repairing: reinstall WordPress core, every plugin and every theme from official sources, then review the few files that are unique to your site, such as wp-config.php and any custom theme code. Clean the database by removing injected scripts, rogue options and unknown admin accounts.

  1. Replace core. Download a fresh copy of the same WordPress version and replace wp-admin and wp-includes entirely. Do not touch wp-content yet.
  2. Replace plugins and themes. Delete each plugin folder and reinstall from WordPress.org or the vendor. Delete anything unused, and replace any nulled software with licensed copies.
  3. Review custom code. Compare your custom theme and wp-config.php against a known-good copy from version control or an old backup.
  4. Clean uploads. Remove any PHP, PHTML or executable files from wp-content/uploads; move them to quarantine first.
  5. Clean the database. Remove injected <script> and <iframe> tags from posts, widgets and options, and delete unknown administrators.
  6. Remove server persistence. Delete malicious cron jobs, systemd services and processes. See why malware keeps coming back.

When you replace plugins, match the versions you had only if they are current. If a plugin was out of date, install the latest version instead, because the old one may be exactly how the attacker got in. After everything is replaced, run the checksum and uploads checks again to confirm nothing has reappeared.

Tip: keep a log of every file you remove or replace, with its path and hash. It makes the investigation clearer and gives you a record if the infection returns.

How do you find how the hacker got in?

Find the entry point by building a timeline: note the earliest malicious file modification date, then check access logs, login records and plugin versions around that time. Most WordPress infections trace back to an outdated plugin with a known vulnerability, a stolen administrator or hosting password, or another infected site on the same server.

EvidenceLikely entry point
POST requests to a plugin file just before the first malicious file appearsPlugin vulnerability
Successful wp-admin login from an unfamiliar IP, then editor or plugin upload activityStolen or reused password
Malicious files created by SFTP or SSH with no web requestsHosting or server credentials
Same malware in several sites, earliest in a different siteCross-site contamination
Malicious code inside a plugin you installed from an unofficial sourceNulled software

If you cannot identify the entry point, assume the most likely ones are still open: update everything, rotate every credential and isolate each site. Our Forensic scan builds this timeline automatically, and the wp2shell guide covers the common admin-to-webshell pattern in detail.

What should you do after the malware is removed?

After removing the malware, harden the site so it cannot be re-infected the same way, rotate every credential again, regenerate WordPress salts, set up monitoring and, if the site was flagged, request a review from Google. Then watch closely for a few weeks, because re-infection usually shows up early if something was missed.

  • Block PHP execution in wp-content/uploads.
  • Add define( 'DISALLOW_FILE_EDIT', true ); to wp-config.php.
  • Enforce two-factor authentication for every administrator.
  • Regenerate the authentication keys and salts in wp-config.php.
  • Remove unused plugins, themes and administrator accounts.
  • Switch SSH to key-based authentication and restrict access.
  • Request a review in Google Search Console if a warning was shown.
  • Set up file integrity and malware monitoring.

Our full WordPress hardening checklist goes further, and removing a Google blacklist warning covers the review process. PatientZero's plans include all of this, with unlimited malware removal and 24/7 monitoring from £99 a month per site plus a one-off £129.99 security audit and setup. See pricing.

Frequently asked questions

Can I remove WordPress malware with a plugin?

A security plugin can find and remove some malware, and is a reasonable first check. But plugins run inside WordPress, so they cannot see server cron jobs, system processes or other sites on the same account, and attackers often disable them. For a confirmed hack, a server-side investigation is much more reliable.

Should I just restore a backup instead of cleaning?

Only if you are confident the backup predates the infection and you then fix the entry point. Many infections sit unnoticed for weeks, so recent backups may already contain the malware. Even after a clean restore, you still need to update plugins, rotate credentials and check the server for persistence.

Why does my WordPress malware keep coming back?

Usually because something was missed: a second backdoor, a hidden administrator, a malicious must-use plugin, a cron job that re-downloads the malware, or another infected site on the same server. The original entry point may also still be open. A full investigation finds and removes all of these together.

How long does WordPress malware removal take?

A single site with a straightforward infection can often be cleaned within a day. Sites with many plugins, heavy database injection or infections spread across a server take longer, because every site and server component has to be checked. The clean-up is only finished once the entry point is closed and monitoring confirms no return.

PatientZero Incident Response Team · Digital forensics and incident response

Written by the PatientZero incident response team: the engineers who investigate and clean compromised WordPress sites and Linux servers every week.