How to Find and Remove Backdoors in a Hacked WordPress Site
What WordPress backdoors are, where attackers hide them (uploads, fake plugins, mu-plugins, core files, database, cron), warning signs in code, how to verify files and how to stop reinfection.

On this page
- Missed backdoors are the main reason cleaned sites get reinfected.
- Check uploads, fake plugins, mu-plugins, modified files, hidden admins and cron jobs.
- Verify files against checksums, block PHP in uploads and disable dashboard file editing.
The main reason cleaned WordPress sites get hacked again is a missed backdoor: hidden code that lets the attacker regain access even after passwords change and visible malware is removed. Finding backdoors is the most important part of a proper clean-up.
What a backdoor is
A backdoor is code that gives an attacker a way back in: uploading files, running commands or creating admin users on demand. It's often small, disguised and placed where site owners rarely look.
Where backdoors hide
- wp-content/uploads: PHP files disguised as images or with random names
- Fake plugins: folders with convincing names that don't appear in the plugin list, or that do but you never installed
- mu-plugins folder: loads automatically and doesn't show up in the normal plugins list
- Modified legitimate files: a few lines added to a real plugin, theme or core file
- Files mimicking WordPress names: like wp-configs.php or files in wp-includes that don't belong there
- Database: hidden admin users, malicious options or code stored in settings
- Scheduled tasks: server cron jobs or WordPress events that re-download malware
Warning signs in code
Legitimate code sometimes uses these too, so context matters, but they deserve a close look in unexpected places:
- Heavily obfuscated code: long strings of random characters
- Functions that decode and run hidden code, such as combinations of
eval,base64_decode,gzinflateorstr_rot13 - Code that runs whatever is sent in a request
- File upload handlers in odd places
- Very long single lines of code at the start or end of files
Verify files against official copies
WP-CLI can compare WordPress core files, and plugins from WordPress.org, against official checksums, flagging modified or extra files. For premium plugins, reinstall fresh copies from the vendor.
Check users and access
- List all administrators, including any not visible in the dashboard, by checking the database
- Review SFTP and hosting users, and remove unknown ones
- Check Search Console owners
- Regenerate WordPress security keys
Remove, then harden
- Block PHP execution in the uploads folder
- Disable file editing in the dashboard (the DISALLOW_FILE_EDIT setting in wp-config.php)
- Correct file permissions
- Add a firewall and file-change monitoring
- Keep everything updated
When in doubt, rebuild clean
For heavily infected sites, it can be safer to build a fresh WordPress install with clean plugins and themes, then import only the verified content and uploads (images, not PHP files).
Full process: removing WordPress malware step by step. Or get professional malware removal.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


