WordPress Malware Removal: Get Your Site Clean
Finding out your WordPress site has malware is stressful - but it can usually be fixed. Here's how to detect an infection, clean your site, and stop it happening again.
Signs Your WordPress Site Has Malware
Some infections are obvious. Others hide silently for months. Look out for any of these warning signs.
How to Remove Malware From WordPress
Work through these steps in order. If at any point the cleanup feels beyond you, a professional removal service (like ours) can take over.
Take the Site Offline
Swap your site for a maintenance page so visitors and search engines stop loading the infected version. This limits the damage and stops the malware spreading further.
Confirm the Infection
Run a scan with a security plugin such as Wordfence or Sucuri, and review recently modified files, unknown admin users and suspicious code. Search Google for your domain to see whether you've been flagged.
Change Every Password and Key
Change WordPress admin passwords, FTP and SFTP access, database credentials and hosting logins. Rotate your wp-config.php authentication keys as well - old credentials are how attackers get back in.
Restore From a Clean Backup
The fastest reliable fix is restoring a backup from before the infection. If your most recent backup postdates the hack, cleaning the site is safer - otherwise the malware comes straight back.
Remove the Malicious Files
Using your security plugin's scanner or a professional cleanup, delete injected files, strip malicious entries from the database, and restore core WordPress files from a fresh download.
Patch the Vulnerability
Work out how the attacker got in - usually an outdated plugin, a weak password or a vulnerable theme - and fix it before the site goes back online, or it will be hacked again.
Clean Up and Go Live
Rescan to confirm the site is clean, remove the maintenance page and request a Google review in Search Console under Security Issues. Monitor closely for the first few weeks.
Should You Clean It Yourself or Call a Pro?
Be honest about your skills and the value of your site. A half-done cleanup is worse than none.
Do It Yourself
- You have a clean backup from before the infection
- You're comfortable with FTP, plugins and editing files
- You can identify and remove the malicious code safely
- You have time to tighten security after the cleanup
Call in a Professional
- The infection is deep, or your backup is also infected
- You're not sure what the malicious code actually does
- The site handles payments or customer data
- You want the vulnerability fixed, not just the symptom
Prevention: What Stops It Happening Again
Nearly every WordPress hack is preventable. These habits close the doors attackers use:
WordPress Malware - Common Questions
Get your site cleaned fast
Our WordPress security service includes malware removal, vulnerability patching and ongoing monitoring - so a hack doesn't wreck your business.