Security

How to Remove Malware from a Hacked WordPress Site: A Step-by-Step Clean-up Process

The clean-up process I follow for hacked WordPress sites: backup, access reset, scanning, replacing core and plugins, checking uploads and the database, removing backdoors, hardening and Google review.

How to Remove Malware from a Hacked WordPress Site: A Step-by-Step Clean-up Process
On this page
  1. Step 1: Contain the damage
  2. Step 2: Take a backup of the infected site
  3. Step 3: Reset access
  4. Step 4: Scan and find what changed
  5. Step 5: Replace core, plugins and themes with clean copies
  6. Step 6: Check the places malware hides
  7. Step 7: Clean the database
  8. Step 8: Check scheduled tasks and caches
  9. Step 9: Close the entry point
  10. Step 10: Clean up with Google and monitor
  11. Want it done for you?
Key takeaways
  • Contain the damage, back up the infected site and reset every password and security key.
  • Replace core, plugins and themes with clean copies, then check uploads, .htaccess, wp-config and the database.
  • Close the entry point, clear caches, handle Google warnings and add monitoring.

Cleaning a hacked WordPress site isn't just deleting one bad file. Attackers usually leave several ways back in, so a partial clean-up often gets reinfected within days. This is the process I follow when cleaning sites. If you're not comfortable working with files and databases, use it to understand what a proper clean-up involves, and get help.

Step 1: Contain the damage

  • Tell your host; they may already see the problem and can help
  • If visitors are being redirected or infected, put up a maintenance page or restrict access temporarily
  • Note what you've seen: redirects, spam pages, warnings, new users

Step 2: Take a backup of the infected site

Back up all files and the database before changing anything. It preserves evidence and lets you recover real content if something goes wrong during clean-up.

Step 3: Reset access

  • Change hosting, SFTP, database and all WordPress admin passwords
  • Remove WordPress users you don't recognise, especially administrators
  • Generate new security keys (salts) in wp-config.php, which logs everyone out

Change passwords again after the clean-up is complete, in case anything was captured during it.

Step 4: Scan and find what changed

  • Run a server-side scan (many hosts provide one) and a WordPress security plugin scan
  • Use a remote scanner to see what visitors and Google see
  • List recently modified files; a burst of changes around the infection date is a clue
  • Verify WordPress core and plugin files against official checksums (WP-CLI can do this)

No scanner catches everything; see malware scanners compared.

Step 5: Replace core, plugins and themes with clean copies

  • Replace the wp-admin and wp-includes folders with fresh copies of your WordPress version, and check root files like index.php and wp-config.php by hand
  • Delete and reinstall every plugin and theme from official sources
  • Delete unused plugins and themes entirely
  • Remove any nulled (pirated) plugins or themes; see the risks of nulled themes

Step 6: Check the places malware hides

  • wp-content/uploads: PHP files here are almost always malicious
  • mu-plugins: "must-use" plugins load automatically and are easy to miss
  • .htaccess files in every folder: look for unfamiliar redirects and rewrite rules
  • wp-config.php: look for injected code at the top or bottom
  • Unfamiliar files and folders with random names or names mimicking WordPress files

See finding and removing backdoors.

Step 7: Clean the database

  • Search posts, pages and widgets for injected scripts, iframes and hidden links
  • Check the site URL and home URL settings
  • Look for spam posts or pages created by the attacker
  • Check user roles and capabilities for hidden administrators

Step 8: Check scheduled tasks and caches

Look for unfamiliar server cron jobs and WordPress scheduled events that could reinstall malware. Then clear all caches, including plugin cache, server cache and CDN, so infected copies of pages stop being served.

Step 9: Close the entry point

Find out how they got in: an outdated plugin, a weak password or a vulnerable theme. Update everything, remove what you don't need and secure logins. Otherwise the same hole lets them straight back in. See why WordPress sites get hacked.

Step 10: Clean up with Google and monitor

  • Check Search Console for security issues and unknown owners
  • Request a review if the site was flagged; see fixing "Deceptive site ahead"
  • Remove spam URLs from search; see fixing SEO spam hacks
  • Set up a firewall, file-change monitoring and off-site backups

Afterwards, see how to recover Google rankings after a hack.

Want it done for you?

I clean hacked WordPress sites urgently, usually within 24–48 hours of getting access, and harden them so it doesn't happen again. See WordPress malware removal.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now