How to Clean Malware From a WordPress Site

How to Clean Malware From a WordPress Site

Discovering malware on a WordPress website can be stressful.

You may notice strange redirects, unknown administrator accounts, spam pages, unwanted advertisements, or browser security warnings.

The correct response is not simply to delete the first suspicious file you find.

A proper cleanup should identify the cause, remove malicious changes, secure the environment, and verify that the website is clean.

Confirm That the Website Is Actually Compromised

Not every website problem is malware.

A broken plugin, incorrect redirect, expired SSL certificate, or server configuration problem can look suspicious.

Look for signs such as:

  • Unknown files
  • Unexpected administrator accounts
  • Strange redirects
  • Unknown JavaScript
  • Spam pages
  • Modified theme files
  • Suspicious PHP files
  • Unexpected outgoing email
  • Unusual hosting resource usage

Take a Backup Before Cleanup

If possible, preserve a copy of the affected website before making major changes.

This can help with investigation and recovery.

Do not overwrite your only copy of the compromised website with another backup without understanding what happened.

Put the Website in Maintenance Mode

If the website is actively serving malicious content, temporarily restrict public access where practical.

This can reduce exposure while the cleanup is being performed.

Change Important Passwords

A malware infection may be associated with compromised credentials.

Change passwords for:

  • WordPress administrators
  • Hosting account
  • FTP/SFTP accounts
  • Database users
  • Email accounts
  • Other related services

Use new passwords that have not been used elsewhere.

Remove Unknown WordPress Users

Open the WordPress user list.

Look for:

  • Unknown administrators
  • Strange usernames
  • Unexpected email addresses
  • Recently created accounts

Do not delete a legitimate account simply because you do not recognize the name. Verify first.

Check Recently Modified Files

Review website files for unexpected changes.

Malware may be hidden inside:

  • Theme files
  • Plugin files
  • Upload directories
  • Configuration files
  • Other PHP files

File modification dates can provide useful clues, but they are not proof by themselves.

Replace Core WordPress Files

If WordPress core files have been modified, replacing them with clean official files can help remove malicious changes.

Do not replace configuration files or legitimate custom files blindly.

Review Plugins and Themes

Remove plugins and themes that are:

  • Unused
  • Abandoned
  • Suspicious
  • Unnecessary

Update legitimate software to supported versions.

If a plugin is the source of the compromise, simply cleaning the website without addressing the plugin can lead to reinfection.

Check the Upload Directory

WordPress media directories should normally contain media files, but attackers may attempt to place executable files in writable directories.

Review unexpected files carefully.

Check the Database

Malicious code can also be stored in the database.

Review suspicious:

  • Options
  • Posts
  • Pages
  • Widgets
  • User records

Database cleanup should be performed carefully because incorrect changes can damage the website.

Check Redirects

Review:

  • .htaccess
  • WordPress settings
  • Theme code
  • Plugins
  • DNS settings

Unexpected redirects can be caused by malicious modifications or normal configuration mistakes.

Scan the Website

Use an appropriate malware scanner to identify suspicious files and code.

A scan is useful, but do not assume that one automated scan proves that the website is completely clean.

Manual review may still be necessary.

Find the Entry Point

Cleaning the visible malware is only half the job.

Ask:

"How did the attacker get in?"

Possible causes include:

  • Vulnerable plugin
  • Outdated WordPress
  • Stolen password
  • Compromised hosting account
  • Weak FTP credentials
  • Insecure custom code

If the original vulnerability remains, the website can be infected again.

Restore From a Known-Clean Backup

If a recent verified clean backup exists, restoring it may be safer than manually cleaning every file.

However, do not restore a backup without checking whether it predates the compromise.

Secure the Website After Cleanup

After cleaning:

  • Update WordPress
  • Update plugins
  • Update themes
  • Remove unused software
  • Change passwords
  • Review users
  • Enable MFA where possible
  • Check file permissions
  • Maintain backups
  • Monitor the website

Check Email Security

If the website was compromised, check whether attackers used it to send spam.

Review outgoing email behavior and domain authentication.

Monitor After Cleanup

A clean website should be monitored for reinfection.

Watch for:

  • New unknown files
  • New administrators
  • Redirects
  • Suspicious resource usage
  • Unexpected email
  • Repeated security alerts

Final Thoughts

Malware cleanup is not simply deleting suspicious files.

A complete cleanup involves identifying the infection, preserving useful evidence, removing malicious changes, closing the entry point, changing credentials, and monitoring the website afterward.

If you are not comfortable handling infected files or databases, professional technical assistance is recommended.

THE HOSTGURU hosting customers should also investigate hosting-level issues when an infection involves multiple websites or unusual server activity.

Frequently Asked Questions

Can I clean WordPress malware myself?

Simple infections may be manageable, but complex compromises often require experienced technical investigation.

Should I delete suspicious PHP files?

Do not delete files blindly. First determine whether they are legitimate or malicious.

Can malware come back after cleaning?

Yes, if the original vulnerability or compromised credentials are not fixed.

Is restoring a backup enough?

Only if the backup is known to be clean and the vulnerability that caused the infection has been addressed.

Back to Blog