WordPress powers over 40% of all websites on the internet — and that enormous popularity makes it the single most targeted platform by hackers worldwide. When your WordPress site gets infected with malware, the consequences go far beyond a minor inconvenience: Google may flag your domain as dangerous, your hosting provider can suspend your account for sending thousands of spam emails per hour, and your carefully built search rankings can collapse overnight. This guide walks you through every step — from recognizing the early warning signs, to cleaning infected files by hand, to hardening your site so it never gets hit again.

Warning Signs That Your WordPress Site Has Malware

Malware on WordPress is often designed to operate quietly for weeks before site owners notice. The goal is to exploit your server resources and your site's reputation without triggering an obvious outage. Watch for these red flags:

If you observe any of these symptoms, act immediately. Every hour of delay gives the malware more time to spread, lets Google gather more negative signals about your domain, and increases the recovery time for your search rankings.

Common Types of WordPress Malware

Understanding what kind of malware has infected your site helps you find and remove it more efficiently. WordPress infections generally fall into several categories:

Malware Type How It Works Visible Symptom Severity
Backdoor Hidden script that lets attackers re-enter the site anytime Unknown PHP files; modified core files Critical — site can be reinfected after cleaning if any instance remains
SEO Spam Injects hidden spam links or creates fake pages targeting search engines Google indexes pages you never created High — causes long-term SEO damage
Malicious Redirect Redirects visitors to dangerous or spam sites Visitor complaints; Google blacklisting High — destroys reputation and rankings
Spam Mailer Uses your server to send mass spam emails Hosting suspension; CPU/RAM spikes High — your IP gets blacklisted; legitimate emails bounce
Phishing Page Embeds fake login pages for banks or popular services Search Console reports phishing Critical — Google blacklists domain immediately
Cryptominer Mines cryptocurrency using your server's CPU Persistently high CPU; very slow site Medium–High — wastes hosting resources

Before You Start Cleaning: Essential Preparation Steps

Rushing into the clean-up without preparation can make things worse. Follow these steps first to ensure you have a safety net and that the attacker cannot simply walk back in while you work.

Step 1: Back Up Everything — Even the Infected Files

A backup of the infected site serves two purposes: it gives you a restore point if something breaks during the clean-up, and it preserves evidence for post-incident analysis. Create a full backup via DirectAdmin's Backup/Restore feature, or use the command line if your hosting supports SSH access:

# Full file backup
tar -czf backup-before-clean-$(date +%Y%m%d).tar.gz public_html/

# Database backup
mysqldump -u DB_USER -p DB_NAME > backup-db-$(date +%Y%m%d).sql

Step 2: Enable Maintenance Mode

Create a .maintenance file in your WordPress root to prevent visitors from being exposed to malicious scripts while you work:

<?php $upgrading = time(); ?>

Save this as public_html/.maintenance — WordPress will automatically show a maintenance screen to all visitors.

Step 3: Change All Passwords Immediately

If the attacker still holds valid credentials, any cleaning you do can be undone within minutes. Before touching a single file, rotate every password associated with this site:

Scanning for Malware Using a Plugin (Easiest Method)

If you can still access your WordPress Admin dashboard, start with a plugin scan to understand the scope of the infection before performing any manual work.

Wordfence Security

Wordfence is the most widely used WordPress security plugin and includes a powerful malware scanner that compares every file on your server against the official WordPress repository and Wordfence's constantly updated malware signature database:

# Install via WordPress Admin:
# Plugins → Add New → search "Wordfence Security" → Install → Activate

# After activation:
# Wordfence → Scan → Start New Scan
# Scan time varies: 5–30 minutes depending on site size

Wordfence lists all suspicious files with severity ratings (Critical / High / Medium / Low) and offers one-click Repair or Delete options for each finding. For many common infections, Wordfence can restore modified core files automatically by replacing them with clean copies from WordPress.org.

MalCare Security

MalCare performs its scanning on its own cloud infrastructure rather than your server, making it an excellent choice for shared hosting environments with tight CPU limits. After connecting your site to a MalCare account, it can deep-scan your site without causing resource spikes that might trigger hosting throttling.

Manual Malware Removal via File Manager (Most Thorough Method)

When a plugin cannot fully clean the infection — or when you cannot access WordPress Admin at all — manual removal through DirectAdmin File Manager or FTP is necessary. This is more time-consuming but gives you complete control.

Step 1: Check WordPress Core Files

Malware commonly modifies core WordPress files like wp-settings.php, wp-load.php, wp-blog-header.php, and files inside wp-includes/ to inject malicious code. Download a clean copy of the exact same WordPress version from WordPress.org and use diff to compare:

# Download the same WordPress version installed on your site
wget https://wordpress.org/wordpress-6.5.zip
unzip wordpress-6.5.zip

# Compare core files (excluding wp-config.php and wp-content which you customized)
diff -rq wordpress/ public_html/ \
  --exclude="wp-config.php" \
  --exclude-dir="wp-content" \
  --exclude-dir=".git"

# Files that differ unexpectedly = potentially modified by malware

Step 2: Search for Dangerous PHP Functions

Malware heavily relies on certain PHP functions to obfuscate and execute malicious code. Search your entire installation for these patterns:

# Search for common malware obfuscation functions
grep -rn "eval(base64_decode" public_html/ --include="*.php"
grep -rn "str_rot13\|gzinflate\|gzuncompress\|str_ireplace" public_html/ --include="*.php"
grep -rn "preg_replace.*\/e\b" public_html/ --include="*.php"
grep -rn "assert\s*(" public_html/ --include="*.php"
grep -rn "system\s*(\|exec\s*(\|shell_exec\s*(\|passthru\s*(" public_html/ --include="*.php"

# PHP files in the uploads folder should not exist — any found here are malicious
find public_html/wp-content/uploads/ -name "*.php" -type f

Step 3: Inspect wp-config.php and .htaccess

These two files are prime targets. Check wp-config.php for any require or include statements that reference unknown files. For .htaccess, a clean WordPress installation contains only the standard rewrite block:

# Clean WordPress .htaccess — anything beyond this block is suspicious
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

# Example of malicious redirect rule to look for and remove:
# RewriteCond %{HTTP_REFERER} .*google.* [OR]
# RewriteCond %{HTTP_REFERER} .*yahoo.*
# RewriteRule ^(.*)$ https://spam-site.com/ [R=301,L]

Step 4: Clean Themes and Plugins

Remove every inactive theme — attackers frequently plant backdoors in themes that are installed but not activated, knowing site owners rarely check them. For active plugins and themes, reinstall them fresh from WordPress.org or the original developer's site rather than restoring from a potentially infected backup. Delete all unused plugins as well.

# Using WP-CLI (if your hosting supports it)
wp plugin list --status=inactive
wp plugin delete plugin-slug-1 plugin-slug-2

# Force-reinstall WordPress core (replaces all modified core files)
wp core download --force

# Reinstall specific plugins from official source
wp plugin install woocommerce --force
wp plugin install contact-form-7 --force

Step 5: Clean the Database

Some malware injects code directly into the database — for example changing the siteurl value in wp_options, or embedding JavaScript in post content. Inspect the database using phpMyAdmin:

-- Verify siteurl, home, and admin_email are correct
SELECT option_name, option_value
FROM wp_options
WHERE option_name IN ('siteurl', 'home', 'admin_email');

-- Search for injected JavaScript in published posts
SELECT ID, post_title, LEFT(post_content, 200)
FROM wp_posts
WHERE post_content LIKE '%<script%'
  AND post_status = 'publish'
LIMIT 20;

-- Search for links to suspicious external domains
SELECT ID, post_title FROM wp_posts
WHERE post_content LIKE '%spam-domain.com%'
  OR post_content LIKE '%eval(base64%';

Pro tip: After completing every cleaning step, regenerate all WordPress Secret Keys in wp-config.php. Visit https://api.wordpress.org/secret-key/1.1/salt/, copy the new values, and replace the existing keys. This action immediately invalidates all active login sessions — including any sessions the attacker may still have open — forcing everyone to log in again with the new credentials.

Correcting File Permissions After Cleaning

Insecure file permissions are one of the most common root causes of repeated WordPress infections. After cleaning, set permissions to the recommended values:

# All directories: 755 (Owner: rwx, Group: r-x, Others: r-x)
find public_html/ -type d -exec chmod 755 {} \;

# All files: 644 (Owner: rw-, Group: r--, Others: r--)
find public_html/ -type f -exec chmod 644 {} \;

# wp-config.php: 640 or 600 (prevents web-accessible reading)
chmod 640 public_html/wp-config.php

# .htaccess: 644
chmod 644 public_html/.htaccess

Never set any file or folder to 777 (world-writable). This allows any script running on the server — including malicious ones — to create, modify, or delete files freely. It is the single most dangerous permission setting on a shared hosting environment.

Requesting Google to Remove the Malware Warning

Once your site is completely clean, you need to ask Google to re-evaluate it and remove any security warnings from search results. This does not happen automatically — you must submit a review request:

  1. Go to Google Search Console at search.google.com/search-console and select your property.
  2. Navigate to Security & Manual Actions → Security Issues.
  3. Click Request a Review and provide a detailed description of what malware was found and all the specific steps you took to remove it.
  4. Google typically processes review requests within 1–3 business days.

You can verify your site's current status in Google Safe Browsing by visiting transparencyreport.google.com/safe-browsing/search?url=yourdomain.com. If it still shows as unsafe after your clean-up, ensure you have also submitted an updated sitemap in Search Console to accelerate re-crawling.

Preventing Future WordPress Malware Infections

A site that has been hacked once is statistically more likely to be hacked again because attackers often leave multiple layers of backdoors as insurance. Prevention is far less costly than recovery. Here are the most impactful measures:

1. Keep Everything Updated

Outdated WordPress core, plugins, and themes with known vulnerabilities are the number-one attack vector. Enable automatic updates for security releases:

# Add to wp-config.php to auto-apply minor and security updates
define('WP_AUTO_UPDATE_CORE', 'minor');

2. Install a Security Plugin From Day One

Wordfence's free tier functions as both a Web Application Firewall and a file integrity monitor. It blocks IP addresses attempting brute-force login attacks, alerts you when core files are modified, and runs scheduled scans in the background without requiring manual intervention.

3. Use Strong Passwords and Enable Two-Factor Authentication

Brute-force attacks against wp-login.php remain extremely common. Set your Admin password to at least 16 characters mixing uppercase, lowercase, numbers, and symbols. Enable Two-Factor Authentication using a plugin like WP 2FA or Google Authenticator — this alone stops the vast majority of credential-based attacks even if your password is compromised.

4. Limit Login Attempts and Protect the Login URL

Install the Limit Login Attempts Reloaded plugin to automatically block IP addresses after a configurable number of failed login attempts. You can also use WPS Hide Login to change the login URL from the default /wp-login.php to a custom path that bots and scanners do not know about.

5. Delete Unused Plugins and Themes

Every installed plugin and theme is a potential attack surface, even if it is not activated. Remove anything you are not actively using. A lean WordPress installation with only the plugins you genuinely need is dramatically harder to compromise than one with dozens of dormant plugins.

6. Set Up Automated Daily Backups

Good shared hosting includes daily backups, but configure an additional off-server backup using a plugin like UpdraftPlus to send copies to Google Drive or Dropbox. Having backups stored outside your hosting account ensures you can recover even in catastrophic scenarios where your hosting account itself is compromised.

Frequently Asked Questions

How do I know if my WordPress site has malware?

Common signs include: the site redirecting visitors to unknown or suspicious websites, Google displaying a "This site may be harmful" warning in search results, your hosting provider sending alerts about excessive CPU or RAM usage, unfamiliar PHP files appearing in your public_html directory, Google Search Console reporting security issues or spam pages you did not create, or being unable to log into your WordPress Admin because your password was changed.

Can I remove WordPress malware myself without a plugin?

Yes, you can clean malware manually through your hosting control panel's File Manager or FTP. The process involves comparing your WordPress core files against a clean download from WordPress.org, searching for PHP files containing dangerous functions like eval(base64_decode), gzinflate, or preg_replace with the /e modifier, checking .htaccess for malicious redirect rules, and scanning your database for injected JavaScript or spam links. For mild infections, security plugins like Wordfence or MalCare can automate much of this work.

What should I do after cleaning WordPress malware?

After cleaning, you must: change all passwords immediately (WordPress Admin, FTP, DirectAdmin, MySQL), update WordPress core, all plugins, and themes to their latest versions, delete any unused plugins and themes, install a security plugin like Wordfence, correct file permissions (755 for directories, 644 for files), regenerate WordPress secret keys in wp-config.php, and submit a review request in Google Search Console to remove the malware warning from search results.

Can malware on shared hosting spread to other accounts on the same server?

On well-configured shared hosting, account isolation prevents malware from directly spreading between accounts. However, if the malware exploits a server-level or PHP vulnerability, cross-account infection is possible. Quality shared hosting equipped with Imunify360 or similar security tools automatically detects and quarantines malicious files before they can spread. Regardless, you should treat any infection as urgent and clean it immediately to protect both your site and the server environment.

AsiaGB Hosting — Full DirectAdmin Package

AsiaGB Hosting supports DirectAdmin with full PHP 8.3 and MySQL support. Plans start at 500 THB/year.

View Hosting Plans

View all cheap Thailand web hosting plans →