Security

How to Find and Remove Backdoors in a Hacked WordPress Site

What WordPress backdoors are, where attackers hide them (uploads, fake plugins, mu-plugins, core files, database, cron), warning signs in code, how to verify files and how to stop reinfection.

How to Find and Remove Backdoors in a Hacked WordPress Site
On this page
  1. What a backdoor is
  2. Where backdoors hide
  3. Warning signs in code
  4. Verify files against official copies
  5. Check users and access
  6. Remove, then harden
  7. When in doubt, rebuild clean
Key takeaways
  • Missed backdoors are the main reason cleaned sites get reinfected.
  • Check uploads, fake plugins, mu-plugins, modified files, hidden admins and cron jobs.
  • Verify files against checksums, block PHP in uploads and disable dashboard file editing.

The main reason cleaned WordPress sites get hacked again is a missed backdoor: hidden code that lets the attacker regain access even after passwords change and visible malware is removed. Finding backdoors is the most important part of a proper clean-up.

What a backdoor is

A backdoor is code that gives an attacker a way back in: uploading files, running commands or creating admin users on demand. It's often small, disguised and placed where site owners rarely look.

Where backdoors hide

  • wp-content/uploads: PHP files disguised as images or with random names
  • Fake plugins: folders with convincing names that don't appear in the plugin list, or that do but you never installed
  • mu-plugins folder: loads automatically and doesn't show up in the normal plugins list
  • Modified legitimate files: a few lines added to a real plugin, theme or core file
  • Files mimicking WordPress names: like wp-configs.php or files in wp-includes that don't belong there
  • Database: hidden admin users, malicious options or code stored in settings
  • Scheduled tasks: server cron jobs or WordPress events that re-download malware

Warning signs in code

Legitimate code sometimes uses these too, so context matters, but they deserve a close look in unexpected places:

  • Heavily obfuscated code: long strings of random characters
  • Functions that decode and run hidden code, such as combinations of eval, base64_decode, gzinflate or str_rot13
  • Code that runs whatever is sent in a request
  • File upload handlers in odd places
  • Very long single lines of code at the start or end of files

Verify files against official copies

WP-CLI can compare WordPress core files, and plugins from WordPress.org, against official checksums, flagging modified or extra files. For premium plugins, reinstall fresh copies from the vendor.

Check users and access

  • List all administrators, including any not visible in the dashboard, by checking the database
  • Review SFTP and hosting users, and remove unknown ones
  • Check Search Console owners
  • Regenerate WordPress security keys

Remove, then harden

  • Block PHP execution in the uploads folder
  • Disable file editing in the dashboard (the DISALLOW_FILE_EDIT setting in wp-config.php)
  • Correct file permissions
  • Add a firewall and file-change monitoring
  • Keep everything updated

When in doubt, rebuild clean

For heavily infected sites, it can be safer to build a fresh WordPress install with clean plugins and themes, then import only the verified content and uploads (images, not PHP files).

Full process: removing WordPress malware step by step. Or get professional malware removal.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now