If your WordPress site is redirecting visitors, showing strange pages on Google, or your host has suspended it, there is a good chance it has malware. The good news is that most infections can be cleaned. The bad news is that cleaning the visible damage without closing the way in means it comes back in days.
This guide walks through what to do, in order. If you would rather have a team handle it, use our emergency page and we will take it from there.
Signs your WordPress site has malware
- Visitors are sent to casino, pharmacy or scam pages
- Google shows odd titles or Japanese or Chinese text for your pages
- Your browser or Google warns "This site may be hacked" or "Deceptive site ahead"
- Your host sends a suspension notice or reports high resource use
- New admin users you did not create
- Files you do not recognise in your folders, often with random names
- Your site is suddenly slow, or emails from your domain go to spam
Run our free scanner first. It will not find malware inside your files, but it shows missing protections that let attackers in.
Step 1: Do not panic, and do not delete everything
Deleting random files can break the site and destroy the evidence you need to find out how the attacker got in. Instead:
- Put the site in maintenance mode, or ask your host to disable it temporarily, so visitors are protected
- Change the passwords for your hosting account, WordPress admin users, FTP and database
- Take a full backup of the infected site as it is, files and database. You will need it later, even though it is dirty
Step 2: Find what was changed
Malware usually hides in three places:
- Core files. Compare WordPress core files to a fresh download of the same version. Anything extra or modified in
wp-adminandwp-includesis suspicious - The
wp-contentfolder. Look for unfamiliar plugins and themes, and PHP files insideuploads, which should only hold images and documents - The database. Check for unknown admin users, injected scripts in posts and options, and unexpected redirects stored in settings
A security plugin scan can list modified and unknown files. Treat its results as a lead, not a verdict.
Step 3: Clean it
- Reinstall WordPress core from a clean download, replacing the infected core files
- Delete every plugin and theme you do not use, then reinstall the ones you keep from the official source or the vendor, not from the old copies
- Remove unknown files from
wp-content, especially PHP files inuploads - Delete unknown admin users and any suspicious scheduled tasks
- Clean injected code from the database, or restore a known clean backup from before the date of infection
If you only have infected backups, cleaning by hand is slower and riskier. That is when a professional clean-up pays for itself.
Step 4: Close the way in
Cleaning without this step is the most common reason a site is hacked again within days. Find out how it happened and fix it:
- Update everything: WordPress core, themes and plugins. Outdated plugins are the usual cause
- Remove or replace abandoned plugins that no longer receive updates
- Use strong, unique passwords and turn on two-factor login for admins
- Limit login attempts and hide or protect the admin login page
- Check file permissions so web users cannot write to core folders
- Check your hosting account for other infected sites sharing it, since one infected site can reinfect the others
Step 5: Get off warning lists
If Google or browsers flagged your site, request a review after cleaning:
- Add your site to Google Search Console
- Open Security Issues
- Describe what you fixed and request a review
Reviews usually take a few days. Until then, browsers may keep showing the warning.
Step 6: Stop it happening again
- Daily off-site backups, tested by restoring them
- Automatic updates for security fixes
- Uptime and malware monitoring that alerts you before customers do
- A web application firewall for shops and sites that handle personal data
Our Care Plans cover these so you are not doing it by hand every month, and our security service hardens the site after a clean-up.
When to get help
Call a professional if the site handles payments or customer data, if it keeps getting reinfected, or if you do not have a clean backup. If customer data may have been exposed, you may also have a duty to tell the people affected, so write down what happened and when.
Hacked right now? Contact our emergency team or message us on WhatsApp.


