A hacked WordPress site is often recognizable by strange redirects, unknown files, spam pages in Google, or warnings from your browser. Cleaning up malware involves finding the source, replacing infected files with clean versions, renewing passwords and keys, and closing vulnerabilities. In this article, you’ll read step by step how to tackle this and how to prevent reinfection.
How to recognize that your site has been hacked
Malware on a WordPress site manifests in various ways. Visitors are redirected to strange websites, your site shows advertisements you didn’t place, or Google Search Console reports that your site has been marked as unsafe. Sometimes you only notice it when your hosting provider takes the site offline due to misuse of server resources for spam or phishing.
Check for the following signals: unknown users in your WordPress admin, new files in the theme or plugin folder that you didn’t install yourself, slow loading times due to background scripts, and deviant content in the source code that you don’t see in the editor. A scan with a security plugin like Wordfence or Sucuri often provides an initial indication, but doesn’t always find everything.
Preparation before cleaning up
Before you start cleaning up, it’s important not to increase the damage. Consider temporarily putting the site in maintenance mode so visitors don’t encounter infected content. Then make a full backup of the current (infected) state, so you can always go back if something goes wrong during cleanup.
Also gather access to all necessary locations: FTP or file manager, the WordPress database, and if applicable, your hosting panel. In Plesk, you’ll find file management and database access conveniently together, making it easier to compare files with a clean installation.
Step by step removing malware
Below is an approach you can apply to most WordPress infections.
Replace WordPress core files
Download a clean, current version of WordPress and replace all folders except wp-content. Core files rarely contain legitimate modifications, so replacing is safer than cleaning.
Check themes and plugins
Remove all themes and plugins you don’t actively use. Replace the remaining plugins and the active theme with fresh downloads from the official source, instead of trusting the existing files.
Search uploads and custom files
Malware often hides in the uploads folder or in files with names resembling WordPress files. Look for functions like eval, base64_decode, or gzinflate in the source code, these are common techniques used to hide malicious code.
Check the database
Look in tables such as wp_options and wp_posts for suspicious scripts, unknown admin accounts, or unwanted links. Remove these carefully without damaging legitimate content.
Refresh all passwords and keys
Change all WordPress passwords, FTP credentials, database password, and the security keys in wp-config.php. A hacker who once gained access may have stolen login credentials.
If you’d rather not work in files and the database yourself, you can have this done by a specialist or, if you have hosting support, have it checked via your provider’s support channel.
Preventing reinfection
Once the site is clean, it’s important to ensure the malware doesn’t return. Always update WordPress, themes, and plugins immediately when an update is available, as most infections arise from outdated, vulnerable software. Limit the number of plugins to what you actually use and only choose plugins from the official WordPress directory or from trusted developers.
Also ensure strong, unique passwords and enable two-factor authentication for logging into WordPress. Regularly check user accounts for unauthorized additions. A valid SSL certificate is part of this too, as it prevents login credentials from being intercepted during transmission.
Daily backups are your last resort: if a hack does get through, you can quickly revert to a clean version from before the infection. Also properly set up your business email, so phishing emails that abuse your domain have less chance; you can arrange correct configuration for this via business email. Anyone considering switching to a hosting provider with daily backups and monitoring can see how that works via switching to Tandata.
Frequently Asked Questions
Can I remove malware without taking the site offline?
That’s possible, but there’s a risk that visitors still see infected content during cleanup or that Google has already marked the site as unsafe. Maintenance mode during cleanup is safer.
Why does the malware keep coming back after removal?
Often a backdoor remains somewhere in files or the database, or a vulnerable plugin hasn’t been updated. Therefore, always check all files and update immediately after cleaning.
Do I need to cancel my domain name or hosting after a hack?
No, that’s not necessary. A hack resides in the WordPress installation, not in your domain name or hosting account itself. After cleaning and securing, you can simply continue.
How do I know for sure all the malware is gone?
Compare files with a clean installation, check logs for suspicious activity, and run a full scan with a security plugin. If in doubt, you can have this checked by a specialist.
Does a hosting provider help with cleaning up malware?
This varies by provider. Some only offer server support, others also help with content or advise via support channels. Consult your provider’s knowledge base for specific steps.
Conclusion
Removing malware from a hacked WordPress site requires a structured approach: replacing core files, checking themes and plugins, searching the database, and renewing all passwords. Equally important is prevention afterward, with timely updates, strong passwords, and daily backups so you can recover quickly in the event of a future attack.