Skip to content
Webcrab
All posts

Security · 2 October 2026 · 7 min read

How to remove malware from a WordPress website, step by step

A calm, practical guide to finding and cleaning malware on a WordPress site, closing the way in, and getting off Google's warning list.

If your WordPress site is redirecting visitors, showing strange pages on Google, or your host has suspended it, there is a good chance it has malware. The good news is that most infections can be cleaned. The bad news is that cleaning the visible damage without closing the way in means it comes back in days.

This guide walks through what to do, in order. If you would rather have a team handle it, use our emergency page and we will take it from there.

Signs your WordPress site has malware

  • Visitors are sent to casino, pharmacy or scam pages
  • Google shows odd titles or Japanese or Chinese text for your pages
  • Your browser or Google warns "This site may be hacked" or "Deceptive site ahead"
  • Your host sends a suspension notice or reports high resource use
  • New admin users you did not create
  • Files you do not recognise in your folders, often with random names
  • Your site is suddenly slow, or emails from your domain go to spam

Run our free scanner first. It will not find malware inside your files, but it shows missing protections that let attackers in.

Step 1: Do not panic, and do not delete everything

Deleting random files can break the site and destroy the evidence you need to find out how the attacker got in. Instead:

  1. Put the site in maintenance mode, or ask your host to disable it temporarily, so visitors are protected
  2. Change the passwords for your hosting account, WordPress admin users, FTP and database
  3. Take a full backup of the infected site as it is, files and database. You will need it later, even though it is dirty

Step 2: Find what was changed

Malware usually hides in three places:

  • Core files. Compare WordPress core files to a fresh download of the same version. Anything extra or modified in wp-admin and wp-includes is suspicious
  • The wp-content folder. Look for unfamiliar plugins and themes, and PHP files inside uploads, which should only hold images and documents
  • The database. Check for unknown admin users, injected scripts in posts and options, and unexpected redirects stored in settings

A security plugin scan can list modified and unknown files. Treat its results as a lead, not a verdict.

Step 3: Clean it

  1. Reinstall WordPress core from a clean download, replacing the infected core files
  2. Delete every plugin and theme you do not use, then reinstall the ones you keep from the official source or the vendor, not from the old copies
  3. Remove unknown files from wp-content, especially PHP files in uploads
  4. Delete unknown admin users and any suspicious scheduled tasks
  5. Clean injected code from the database, or restore a known clean backup from before the date of infection

If you only have infected backups, cleaning by hand is slower and riskier. That is when a professional clean-up pays for itself.

Step 4: Close the way in

Cleaning without this step is the most common reason a site is hacked again within days. Find out how it happened and fix it:

  • Update everything: WordPress core, themes and plugins. Outdated plugins are the usual cause
  • Remove or replace abandoned plugins that no longer receive updates
  • Use strong, unique passwords and turn on two-factor login for admins
  • Limit login attempts and hide or protect the admin login page
  • Check file permissions so web users cannot write to core folders
  • Check your hosting account for other infected sites sharing it, since one infected site can reinfect the others

Step 5: Get off warning lists

If Google or browsers flagged your site, request a review after cleaning:

  1. Add your site to Google Search Console
  2. Open Security Issues
  3. Describe what you fixed and request a review

Reviews usually take a few days. Until then, browsers may keep showing the warning.

Step 6: Stop it happening again

  • Daily off-site backups, tested by restoring them
  • Automatic updates for security fixes
  • Uptime and malware monitoring that alerts you before customers do
  • A web application firewall for shops and sites that handle personal data

Our Care Plans cover these so you are not doing it by hand every month, and our security service hardens the site after a clean-up.

When to get help

Call a professional if the site handles payments or customer data, if it keeps getting reinfected, or if you do not have a clean backup. If customer data may have been exposed, you may also have a duty to tell the people affected, so write down what happened and when.

Hacked right now? Contact our emergency team or message us on WhatsApp.

Let's build something that lasts.

Tell us about your business. You'll get a written quote with a fixed price within one working day.

Get a quote