WordPress Malware: How to Detect, Remove, and Prevent Attacks

Arafat Islam Sep 29, 2026 7 min read
WordPress Malware: How to Detect, Remove, and Prevent Attacks

WordPress Malware: How to Detect, Remove, and Prevent Attacks

WordPress malware isn't just a technical problem — it's a business crisis. An infected site loses customer trust, search rankings plummet, and recovery can take weeks. The worst part? Most malware infections are preventable.

In this comprehensive guide, we'll cover detection methods, removal procedures, and prevention strategies to keep your site safe.

How WordPress Sites Get Infected

Understanding attack vectors helps you defend better.

Common infection sources:

Outdated plugins and themes (45% of infections)

  • Unpatched vulnerabilities in old code
  • Attackers scan for known exploits
  • Single vulnerable plugin compromises entire site

Weak passwords (25% of infections)

  • Brute-force attacks guess admin credentials
  • Once inside, attackers install backdoors
  • Often undetected for months

Compromised hosting account (15% of infections)

  • Shared hosting exposes all sites to neighbors' vulnerabilities
  • FTP/SSH credentials leaked or guessed
  • Attacker modifies core files directly

Malicious plugins (10% of infections)

  • Free plugins from untrusted sources
  • Plugins with legitimate facades hiding malware
  • Poorly coded plugins with security holes

User accounts with elevated privileges (5% of infections)

  • Compromised employee accounts
  • Shared admin credentials
  • Accounts never removed after user leaves

Signs Your WordPress Site Is Infected

Warning signs to watch:

Technical indicators:

  • Unusual spikes in CPU or database usage
  • Unexplained file modifications (check timestamps)
  • Strange admin users you don't recognize
  • Scheduled tasks (crons) you didn't create
  • Unfamiliar plugins or themes installed
  • Website redirects to malicious sites
  • Slow performance without traffic increase

Search engine indicators:

  • Google Search Console shows "Malware detected"
  • Bing Webmaster Tools flagged your site
  • Pages removed from search results
  • Search results redirect to spam sites

Visitor-facing indicators:

  • Suspicious ads or pop-ups appearing
  • Website redirects to spam/phishing sites
  • Warning messages in browsers
  • Unexpected content on pages
  • Backlinks to spam/gambling/pharmacy sites

Email/reporting indicators:

  • Hoster sends malware warnings
  • Google sends notifications
  • Customers report problems
  • Email getting blacklisted

Step 1: Confirm the Infection

Before removing anything, confirm malware exists.

Using WordPress plugins:

  1. Install Wordfence (free)
  2. Run malware scan
  3. Review detailed scan results
  4. Note infected files and locations

Using online scanners (external verification):

  • Sucuri scanner (free): sucuri.net/sitecheck
  • MalCare: malcare.com
  • Sitelock: online malware check

Using your hosting provider: Most hosts offer malware scanning in control panels.

Manual inspection (advanced): Check recent file modifications:

find /var/www/html -type f -mtime -7

This shows files modified in last 7 days. Look for suspicious changes.

Step 2: Take Site Offline

Limit damage while you work on removal.

Options:

  1. Maintenance mode: Display "Site under maintenance" message
  2. Redirect: Point to holding page
  3. Disable completely: Take site offline entirely

Why: Prevents malware from spreading to visitors or other websites via your domain.

Implementation:

// Add to wp-config.php temporarily
if (!is_admin()) {
  wp_die('Site under maintenance. Check back soon.');
}

Or use a plugin like WP Maintenance or Maintenance Mode.

Step 3: Access Your Site Safely

Use staging/admin access to remove malware, not public frontend.

Secure access methods:

  1. Use WordPress admin dashboard (if you can still access it)
  2. FTP/SFTP with secure connection only
  3. SSH if your host provides it
  4. Contact hosting support for guided removal (many hosts offer malware cleanup)

Do NOT:

  • Use public WiFi to access admin
  • Ignore HTTPS warnings
  • Share credentials during cleanup

Step 4: Remove Malware

Different approaches depending on infection type:

Approach 1: Restore from clean backup (FASTEST)

  1. Have a clean backup pre-infection? Restore immediately
  2. Verify backup date is before infection occurred
  3. WordPress usually doesn't keep backups of malware
  4. Fastest recovery: 15 minutes vs. hours of manual cleanup

Approach 2: Use removal plugin (EASIEST) Wordfence and MalCare can automate removal:

  1. Run malware scan
  2. Review findings
  3. Click "Clean" button
  4. Plugin removes malicious code

Limitations: Works for obvious malware, but sophisticated attacks need manual review.

Approach 3: Manual removal (THOROUGH)

Remove malicious plugins:

  1. Access /wp-content/plugins/ via SFTP
  2. Identify suspicious plugins
  3. Delete suspicious plugin folders
  4. Check Plugins page; remove and deactivate any you don't recognize

Remove malicious themes:

  1. Check /wp-content/themes/ for unfamiliar themes
  2. Delete malicious theme folders
  3. Ensure site uses legitimate theme

Check wp-config.php for backdoors:

// Look for suspicious code like:
define('WP_HOME', 'http://malicioussite.com');
eval(base64_decode(...));
// Remove any unfamiliar code

Check .htaccess for malicious redirects:

# Malicious .htaccess might contain:
RewriteRule ^(.*)$ http://spam.com/$1 [R,L]
# Delete suspicious rules
# Keep legitimate WordPress rewrite rules

Check wp-content/index.php: Should be mostly empty. Malicious versions contain obfuscated code:

<?php
// index.php should be nearly empty
// Delete if contains suspicious code
?>

Search for suspicious functions:

grep -r "eval(" /var/www/html/wp-content
grep -r "base64_decode" /var/www/html/wp-content
grep -r "@eval" /var/www/html/wp-content

These are common obfuscation techniques.

Check for backdoor accounts:

  1. Users → look for unfamiliar admin users
  2. Delete suspicious accounts
  3. Change passwords for legitimate accounts

Check scheduled tasks (crons):

  1. Plugins → look for unfamiliar scheduled tasks
  2. Check WordPress cron jobs (WP Control plugin)
  3. Remove malicious schedules

Step 5: Security Hardening Post-Cleanup

Prevent reinfection:

Immediate actions:

  1. Change all passwords (admin, FTP, database, hosting)
  2. Update WordPress core to latest version
  3. Update all plugins and themes
  4. Remove unused plugins/themes
  5. Remove unnecessary user accounts

Enable security measures:

  1. Install Wordfence or iThemes Security
  2. Enable two-factor authentication
  3. Configure firewall rules
  4. Set up malware monitoring
  5. Enable login attempt limiting

Server-level hardening:

// In wp-config.php
define('DISALLOW_FILE_EDIT', true);
define('DISALLOW_FILE_MODS', true);
define('WP_DISABLE_FATAL_ERROR_HANDLER', false);

Step 6: Notify Google and Restore Search Visibility

Google flags infected sites. You need to notify them once cleaned.

Steps:

  1. Verify site is truly malware-free (re-scan with Wordfence, Sucuri)
  2. Go to Google Search Console
  3. Navigate to Security Issues report
  4. Click "Request a review"
  5. Google re-scans (usually within 1-3 days)

Important: Don't request review until truly clean. False requests delay real recovery.

Step 7: Notify Users and Stakeholders

Transparency builds trust.

Who to notify:

  • Customers (if site handles personal data)
  • Email subscribers
  • Hosting provider
  • Domain registrar

Sample message: "We detected and removed malware from our website on [date]. Your data was not compromised. We've implemented additional security measures. Thank you for your patience."

Prevention: Don't Get Infected Again

Core prevention:

  1. Keep WordPress updated: Enable automatic core updates
  2. Keep plugins updated: Update all plugins monthly
  3. Strong passwords: 16+ characters, unique per user
  4. Two-factor authentication: Blocks password-based attacks
  5. Remove unused plugins/themes: Fewer targets for attackers
  6. Regular backups: Automated daily to offsite storage
  7. Security monitoring: Wordfence or similar actively watches
  8. Limit user access: Only give admin access when needed
  9. Web Application Firewall: Cloudflare or Wordfence WAF
  10. Regular security audits: Monthly check for vulnerabilities

Cost of Malware: Prevention vs. Recovery

Cost of prevention: $100-$500/year

  • Good hosting ($50/month)
  • Security plugin ($99/year)
  • Regular backups ($20/month)

Cost of recovery: $1,000-$10,000

  • Lost revenue from downtime
  • Professional malware removal ($500-$2,000)
  • Reputation damage
  • Customer churn
  • SEO recovery time (weeks)

ROI: Prevention costs 5-10% of what recovery costs.

When to Call a Professional

Handle simple infections yourself, but call a malware specialist for:

  • Sophisticated obfuscated code you can't identify
  • Backdoors you keep finding
  • Infection that keeps returning
  • Critical business site with downtime costs

Professional removal services: $500-$2,000 per site.

Conclusion

Malware is preventable. Updates, strong passwords, and security monitoring stop 95% of attacks. If infected, restoration from backup is fastest recovery. Manual removal works but takes longer and risks missing backdoors.

The best approach: Never get infected. Implement prevention, monitor actively, and maintain good backups.


Have you dealt with WordPress malware? Share your recovery story in the comments — your experience might help someone else.