How to Remove Malware from a Hacked WordPress Site: A Step-by-Step Clean-up Process
The clean-up process I follow for hacked WordPress sites: backup, access reset, scanning, replacing core and plugins, checking uploads and the database, removing backdoors, hardening and Google review.

On this page
- Step 1: Contain the damage
- Step 2: Take a backup of the infected site
- Step 3: Reset access
- Step 4: Scan and find what changed
- Step 5: Replace core, plugins and themes with clean copies
- Step 6: Check the places malware hides
- Step 7: Clean the database
- Step 8: Check scheduled tasks and caches
- Step 9: Close the entry point
- Step 10: Clean up with Google and monitor
- Want it done for you?
- Contain the damage, back up the infected site and reset every password and security key.
- Replace core, plugins and themes with clean copies, then check uploads, .htaccess, wp-config and the database.
- Close the entry point, clear caches, handle Google warnings and add monitoring.
Cleaning a hacked WordPress site isn't just deleting one bad file. Attackers usually leave several ways back in, so a partial clean-up often gets reinfected within days. This is the process I follow when cleaning sites. If you're not comfortable working with files and databases, use it to understand what a proper clean-up involves, and get help.
Step 1: Contain the damage
- Tell your host; they may already see the problem and can help
- If visitors are being redirected or infected, put up a maintenance page or restrict access temporarily
- Note what you've seen: redirects, spam pages, warnings, new users
Step 2: Take a backup of the infected site
Back up all files and the database before changing anything. It preserves evidence and lets you recover real content if something goes wrong during clean-up.
Step 3: Reset access
- Change hosting, SFTP, database and all WordPress admin passwords
- Remove WordPress users you don't recognise, especially administrators
- Generate new security keys (salts) in wp-config.php, which logs everyone out
Change passwords again after the clean-up is complete, in case anything was captured during it.
Step 4: Scan and find what changed
- Run a server-side scan (many hosts provide one) and a WordPress security plugin scan
- Use a remote scanner to see what visitors and Google see
- List recently modified files; a burst of changes around the infection date is a clue
- Verify WordPress core and plugin files against official checksums (WP-CLI can do this)
No scanner catches everything; see malware scanners compared.
Step 5: Replace core, plugins and themes with clean copies
- Replace the wp-admin and wp-includes folders with fresh copies of your WordPress version, and check root files like index.php and wp-config.php by hand
- Delete and reinstall every plugin and theme from official sources
- Delete unused plugins and themes entirely
- Remove any nulled (pirated) plugins or themes; see the risks of nulled themes
Step 6: Check the places malware hides
- wp-content/uploads: PHP files here are almost always malicious
- mu-plugins: "must-use" plugins load automatically and are easy to miss
- .htaccess files in every folder: look for unfamiliar redirects and rewrite rules
- wp-config.php: look for injected code at the top or bottom
- Unfamiliar files and folders with random names or names mimicking WordPress files
See finding and removing backdoors.
Step 7: Clean the database
- Search posts, pages and widgets for injected scripts, iframes and hidden links
- Check the site URL and home URL settings
- Look for spam posts or pages created by the attacker
- Check user roles and capabilities for hidden administrators
Step 8: Check scheduled tasks and caches
Look for unfamiliar server cron jobs and WordPress scheduled events that could reinstall malware. Then clear all caches, including plugin cache, server cache and CDN, so infected copies of pages stop being served.
Step 9: Close the entry point
Find out how they got in: an outdated plugin, a weak password or a vulnerable theme. Update everything, remove what you don't need and secure logins. Otherwise the same hole lets them straight back in. See why WordPress sites get hacked.
Step 10: Clean up with Google and monitor
- Check Search Console for security issues and unknown owners
- Request a review if the site was flagged; see fixing "Deceptive site ahead"
- Remove spam URLs from search; see fixing SEO spam hacks
- Set up a firewall, file-change monitoring and off-site backups
Afterwards, see how to recover Google rankings after a hack.
Want it done for you?
I clean hacked WordPress sites urgently, usually within 24–48 hours of getting access, and harden them so it doesn't happen again. See WordPress malware removal.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


