How to Clean Malware From a WordPress Site
Discovering malware on a WordPress website can be stressful.
You may notice strange redirects, unknown administrator accounts, spam pages, unwanted advertisements, or browser security warnings.
The correct response is not simply to delete the first suspicious file you find.
A proper cleanup should identify the cause, remove malicious changes, secure the environment, and verify that the website is clean.
Confirm That the Website Is Actually Compromised
Not every website problem is malware.
A broken plugin, incorrect redirect, expired SSL certificate, or server configuration problem can look suspicious.
Look for signs such as:
- Unknown files
- Unexpected administrator accounts
- Strange redirects
- Unknown JavaScript
- Spam pages
- Modified theme files
- Suspicious PHP files
- Unexpected outgoing email
- Unusual hosting resource usage
Take a Backup Before Cleanup
If possible, preserve a copy of the affected website before making major changes.
This can help with investigation and recovery.
Do not overwrite your only copy of the compromised website with another backup without understanding what happened.
Put the Website in Maintenance Mode
If the website is actively serving malicious content, temporarily restrict public access where practical.
This can reduce exposure while the cleanup is being performed.
Change Important Passwords
A malware infection may be associated with compromised credentials.
Change passwords for:
- WordPress administrators
- Hosting account
- FTP/SFTP accounts
- Database users
- Email accounts
- Other related services
Use new passwords that have not been used elsewhere.
Remove Unknown WordPress Users
Open the WordPress user list.
Look for:
- Unknown administrators
- Strange usernames
- Unexpected email addresses
- Recently created accounts
Do not delete a legitimate account simply because you do not recognize the name. Verify first.
Check Recently Modified Files
Review website files for unexpected changes.
Malware may be hidden inside:
- Theme files
- Plugin files
- Upload directories
- Configuration files
- Other PHP files
File modification dates can provide useful clues, but they are not proof by themselves.
Replace Core WordPress Files
If WordPress core files have been modified, replacing them with clean official files can help remove malicious changes.
Do not replace configuration files or legitimate custom files blindly.
Review Plugins and Themes
Remove plugins and themes that are:
- Unused
- Abandoned
- Suspicious
- Unnecessary
Update legitimate software to supported versions.
If a plugin is the source of the compromise, simply cleaning the website without addressing the plugin can lead to reinfection.
Check the Upload Directory
WordPress media directories should normally contain media files, but attackers may attempt to place executable files in writable directories.
Review unexpected files carefully.
Check the Database
Malicious code can also be stored in the database.
Review suspicious:
- Options
- Posts
- Pages
- Widgets
- User records
Database cleanup should be performed carefully because incorrect changes can damage the website.
Check Redirects
Review:
- .htaccess
- WordPress settings
- Theme code
- Plugins
- DNS settings
Unexpected redirects can be caused by malicious modifications or normal configuration mistakes.
Scan the Website
Use an appropriate malware scanner to identify suspicious files and code.
A scan is useful, but do not assume that one automated scan proves that the website is completely clean.
Manual review may still be necessary.
Find the Entry Point
Cleaning the visible malware is only half the job.
Ask:
"How did the attacker get in?"
Possible causes include:
- Vulnerable plugin
- Outdated WordPress
- Stolen password
- Compromised hosting account
- Weak FTP credentials
- Insecure custom code
If the original vulnerability remains, the website can be infected again.
Restore From a Known-Clean Backup
If a recent verified clean backup exists, restoring it may be safer than manually cleaning every file.
However, do not restore a backup without checking whether it predates the compromise.
Secure the Website After Cleanup
After cleaning:
- Update WordPress
- Update plugins
- Update themes
- Remove unused software
- Change passwords
- Review users
- Enable MFA where possible
- Check file permissions
- Maintain backups
- Monitor the website
Check Email Security
If the website was compromised, check whether attackers used it to send spam.
Review outgoing email behavior and domain authentication.
Monitor After Cleanup
A clean website should be monitored for reinfection.
Watch for:
- New unknown files
- New administrators
- Redirects
- Suspicious resource usage
- Unexpected email
- Repeated security alerts
Final Thoughts
Malware cleanup is not simply deleting suspicious files.
A complete cleanup involves identifying the infection, preserving useful evidence, removing malicious changes, closing the entry point, changing credentials, and monitoring the website afterward.
If you are not comfortable handling infected files or databases, professional technical assistance is recommended.
THE HOSTGURU hosting customers should also investigate hosting-level issues when an infection involves multiple websites or unusual server activity.
Frequently Asked Questions
Simple infections may be manageable, but complex compromises often require experienced technical investigation.
Do not delete files blindly. First determine whether they are legitimate or malicious.
Yes, if the original vulnerability or compromised credentials are not fixed.
Only if the backup is known to be clean and the vulnerability that caused the infection has been addressed.