Get your site clean

WordPress Malware Removal: Get Your Site Clean

Finding out your WordPress site has malware is stressful - but it can usually be fixed. Here's how to detect an infection, clean your site, and stop it happening again.

Security
12 min read
Emergency
Step-by-step

Signs Your WordPress Site Has Malware

Some infections are obvious. Others hide silently for months. Look out for any of these warning signs.

Visitors are redirected to spam or scam websites
Google shows a 'Deceptive site ahead' warning or blacklists your domain
Unknown administrator accounts appear in your users list
Unexpected files, PHP scripts or obfuscated code show up in your uploads
Your site is unusually slow, or your host suspends your account for suspicious activity
Spam posts and SEO spam pages start appearing in search results
Emails from your domain are flagged as spam because the site is sending mail you didn't author

How to Remove Malware From WordPress

Work through these steps in order. If at any point the cleanup feels beyond you, a professional removal service (like ours) can take over.

1

Take the Site Offline

Swap your site for a maintenance page so visitors and search engines stop loading the infected version. This limits the damage and stops the malware spreading further.

2

Confirm the Infection

Run a scan with a security plugin such as Wordfence or Sucuri, and review recently modified files, unknown admin users and suspicious code. Search Google for your domain to see whether you've been flagged.

3

Change Every Password and Key

Change WordPress admin passwords, FTP and SFTP access, database credentials and hosting logins. Rotate your wp-config.php authentication keys as well - old credentials are how attackers get back in.

4

Restore From a Clean Backup

The fastest reliable fix is restoring a backup from before the infection. If your most recent backup postdates the hack, cleaning the site is safer - otherwise the malware comes straight back.

5

Remove the Malicious Files

Using your security plugin's scanner or a professional cleanup, delete injected files, strip malicious entries from the database, and restore core WordPress files from a fresh download.

6

Patch the Vulnerability

Work out how the attacker got in - usually an outdated plugin, a weak password or a vulnerable theme - and fix it before the site goes back online, or it will be hacked again.

7

Clean Up and Go Live

Rescan to confirm the site is clean, remove the maintenance page and request a Google review in Search Console under Security Issues. Monitor closely for the first few weeks.

Should You Clean It Yourself or Call a Pro?

Be honest about your skills and the value of your site. A half-done cleanup is worse than none.

Do It Yourself

  • You have a clean backup from before the infection
  • You're comfortable with FTP, plugins and editing files
  • You can identify and remove the malicious code safely
  • You have time to tighten security after the cleanup

Call in a Professional

  • The infection is deep, or your backup is also infected
  • You're not sure what the malicious code actually does
  • The site handles payments or customer data
  • You want the vulnerability fixed, not just the symptom

Prevention: What Stops It Happening Again

Nearly every WordPress hack is preventable. These habits close the doors attackers use:

Update WordPress core, plugins and themes regularly
Remove unused plugins and themes entirely
Use strong passwords and two-factor authentication
Install a security plugin with a web application firewall
Keep daily backups stored off-site
Choose managed hosting with server-level security

WordPress Malware - Common Questions

Get your site cleaned fast

Our WordPress security service includes malware removal, vulnerability patching and ongoing monitoring - so a hack doesn't wreck your business.

    Cookie Consent

    We use a Google Ads cookie to measure the effectiveness of our advertising. No personal data is shared with Google.Privacy policy →