WordPress Malware: How to Detect, Remove, and Prevent Attacks
WordPress malware isn't just a technical problem — it's a business crisis. An infected site loses customer trust, search rankings plummet, and recovery can take weeks. The worst part? Most malware infections are preventable.
In this comprehensive guide, we'll cover detection methods, removal procedures, and prevention strategies to keep your site safe.
How WordPress Sites Get Infected
Understanding attack vectors helps you defend better.
Common infection sources:
Outdated plugins and themes (45% of infections)
- Unpatched vulnerabilities in old code
- Attackers scan for known exploits
- Single vulnerable plugin compromises entire site
Weak passwords (25% of infections)
- Brute-force attacks guess admin credentials
- Once inside, attackers install backdoors
- Often undetected for months
Compromised hosting account (15% of infections)
- Shared hosting exposes all sites to neighbors' vulnerabilities
- FTP/SSH credentials leaked or guessed
- Attacker modifies core files directly
Malicious plugins (10% of infections)
- Free plugins from untrusted sources
- Plugins with legitimate facades hiding malware
- Poorly coded plugins with security holes
User accounts with elevated privileges (5% of infections)
- Compromised employee accounts
- Shared admin credentials
- Accounts never removed after user leaves
Signs Your WordPress Site Is Infected
Warning signs to watch:
Technical indicators:
- Unusual spikes in CPU or database usage
- Unexplained file modifications (check timestamps)
- Strange admin users you don't recognize
- Scheduled tasks (crons) you didn't create
- Unfamiliar plugins or themes installed
- Website redirects to malicious sites
- Slow performance without traffic increase
Search engine indicators:
- Google Search Console shows "Malware detected"
- Bing Webmaster Tools flagged your site
- Pages removed from search results
- Search results redirect to spam sites
Visitor-facing indicators:
- Suspicious ads or pop-ups appearing
- Website redirects to spam/phishing sites
- Warning messages in browsers
- Unexpected content on pages
- Backlinks to spam/gambling/pharmacy sites
Email/reporting indicators:
- Hoster sends malware warnings
- Google sends notifications
- Customers report problems
- Email getting blacklisted
Step 1: Confirm the Infection
Before removing anything, confirm malware exists.
Using WordPress plugins:
- Install Wordfence (free)
- Run malware scan
- Review detailed scan results
- Note infected files and locations
Using online scanners (external verification):
- Sucuri scanner (free): sucuri.net/sitecheck
- MalCare: malcare.com
- Sitelock: online malware check
Using your hosting provider: Most hosts offer malware scanning in control panels.
Manual inspection (advanced): Check recent file modifications:
find /var/www/html -type f -mtime -7
This shows files modified in last 7 days. Look for suspicious changes.
Step 2: Take Site Offline
Limit damage while you work on removal.
Options:
- Maintenance mode: Display "Site under maintenance" message
- Redirect: Point to holding page
- Disable completely: Take site offline entirely
Why: Prevents malware from spreading to visitors or other websites via your domain.
Implementation:
// Add to wp-config.php temporarily
if (!is_admin()) {
wp_die('Site under maintenance. Check back soon.');
}
Or use a plugin like WP Maintenance or Maintenance Mode.
Step 3: Access Your Site Safely
Use staging/admin access to remove malware, not public frontend.
Secure access methods:
- Use WordPress admin dashboard (if you can still access it)
- FTP/SFTP with secure connection only
- SSH if your host provides it
- Contact hosting support for guided removal (many hosts offer malware cleanup)
Do NOT:
- Use public WiFi to access admin
- Ignore HTTPS warnings
- Share credentials during cleanup
Step 4: Remove Malware
Different approaches depending on infection type:
Approach 1: Restore from clean backup (FASTEST)
- Have a clean backup pre-infection? Restore immediately
- Verify backup date is before infection occurred
- WordPress usually doesn't keep backups of malware
- Fastest recovery: 15 minutes vs. hours of manual cleanup
Approach 2: Use removal plugin (EASIEST) Wordfence and MalCare can automate removal:
- Run malware scan
- Review findings
- Click "Clean" button
- Plugin removes malicious code
Limitations: Works for obvious malware, but sophisticated attacks need manual review.
Approach 3: Manual removal (THOROUGH)
Remove malicious plugins:
- Access /wp-content/plugins/ via SFTP
- Identify suspicious plugins
- Delete suspicious plugin folders
- Check Plugins page; remove and deactivate any you don't recognize
Remove malicious themes:
- Check /wp-content/themes/ for unfamiliar themes
- Delete malicious theme folders
- Ensure site uses legitimate theme
Check wp-config.php for backdoors:
// Look for suspicious code like:
define('WP_HOME', 'http://malicioussite.com');
eval(base64_decode(...));
// Remove any unfamiliar code
Check .htaccess for malicious redirects:
# Malicious .htaccess might contain:
RewriteRule ^(.*)$ http://spam.com/$1 [R,L]
# Delete suspicious rules
# Keep legitimate WordPress rewrite rules
Check wp-content/index.php: Should be mostly empty. Malicious versions contain obfuscated code:
<?php
// index.php should be nearly empty
// Delete if contains suspicious code
?>
Search for suspicious functions:
grep -r "eval(" /var/www/html/wp-content
grep -r "base64_decode" /var/www/html/wp-content
grep -r "@eval" /var/www/html/wp-content
These are common obfuscation techniques.
Check for backdoor accounts:
- Users → look for unfamiliar admin users
- Delete suspicious accounts
- Change passwords for legitimate accounts
Check scheduled tasks (crons):
- Plugins → look for unfamiliar scheduled tasks
- Check WordPress cron jobs (WP Control plugin)
- Remove malicious schedules
Step 5: Security Hardening Post-Cleanup
Prevent reinfection:
Immediate actions:
- Change all passwords (admin, FTP, database, hosting)
- Update WordPress core to latest version
- Update all plugins and themes
- Remove unused plugins/themes
- Remove unnecessary user accounts
Enable security measures:
- Install Wordfence or iThemes Security
- Enable two-factor authentication
- Configure firewall rules
- Set up malware monitoring
- Enable login attempt limiting
Server-level hardening:
// In wp-config.php
define('DISALLOW_FILE_EDIT', true);
define('DISALLOW_FILE_MODS', true);
define('WP_DISABLE_FATAL_ERROR_HANDLER', false);
Step 6: Notify Google and Restore Search Visibility
Google flags infected sites. You need to notify them once cleaned.
Steps:
- Verify site is truly malware-free (re-scan with Wordfence, Sucuri)
- Go to Google Search Console
- Navigate to Security Issues report
- Click "Request a review"
- Google re-scans (usually within 1-3 days)
Important: Don't request review until truly clean. False requests delay real recovery.
Step 7: Notify Users and Stakeholders
Transparency builds trust.
Who to notify:
- Customers (if site handles personal data)
- Email subscribers
- Hosting provider
- Domain registrar
Sample message: "We detected and removed malware from our website on [date]. Your data was not compromised. We've implemented additional security measures. Thank you for your patience."
Prevention: Don't Get Infected Again
Core prevention:
- Keep WordPress updated: Enable automatic core updates
- Keep plugins updated: Update all plugins monthly
- Strong passwords: 16+ characters, unique per user
- Two-factor authentication: Blocks password-based attacks
- Remove unused plugins/themes: Fewer targets for attackers
- Regular backups: Automated daily to offsite storage
- Security monitoring: Wordfence or similar actively watches
- Limit user access: Only give admin access when needed
- Web Application Firewall: Cloudflare or Wordfence WAF
- Regular security audits: Monthly check for vulnerabilities
Cost of Malware: Prevention vs. Recovery
Cost of prevention: $100-$500/year
- Good hosting ($50/month)
- Security plugin ($99/year)
- Regular backups ($20/month)
Cost of recovery: $1,000-$10,000
- Lost revenue from downtime
- Professional malware removal ($500-$2,000)
- Reputation damage
- Customer churn
- SEO recovery time (weeks)
ROI: Prevention costs 5-10% of what recovery costs.
When to Call a Professional
Handle simple infections yourself, but call a malware specialist for:
- Sophisticated obfuscated code you can't identify
- Backdoors you keep finding
- Infection that keeps returning
- Critical business site with downtime costs
Professional removal services: $500-$2,000 per site.
Conclusion
Malware is preventable. Updates, strong passwords, and security monitoring stop 95% of attacks. If infected, restoration from backup is fastest recovery. Manual removal works but takes longer and risks missing backdoors.
The best approach: Never get infected. Implement prevention, monitor actively, and maintain good backups.
Have you dealt with WordPress malware? Share your recovery story in the comments — your experience might help someone else.
