Support article
How to Clean Malware from Your WordPress (Step by Step)
Detect and remove malware from your WordPress: symptoms, scanning, manual and plugin cleaning, and how to prevent reinfections.
Introduction
Discovering your WordPress has been hacked is a scare, but it’s not the end of the world. With calm and method, you can clean it and make it secure. In this article you’ll see how to detect and remove malware from WordPress step by step.
Symptoms your WordPress has malware
- Redirects to suspicious websites.
- Ads or pop-ups you didn’t put.
- Blank pages or strange errors.
- New administrator users you didn’t create.
- Google warns you your website is compromised (Search Console).
- Your antivirus or browser warns your website is dangerous.
- Modified files you haven’t touched.
If you notice any of these symptoms, act fast. The sooner you clean, the less damage.
Step 1: Back up before touching anything
Before cleaning, make a complete backup (files + database). If something goes wrong during cleaning, you can go back.
Use Softaculous’s backup or make a manual one from cPanel.
Step 2: Put the website in maintenance
If your website is sending spam or redirecting, put it in maintenance to not harm your visitors:
- Enable WordPress maintenance mode (with a plugin or adding a
.maintenancefile). - Or disable the website temporarily from cPanel.
Step 3: Scan with a security plugin
Install (or use if you already have it) a security plugin:
Wordfence
- Install Wordfence Security.
- Go to Wordfence → Scan.
- Run a complete scan.
- Wordfence shows infected files and offers to repair them.
Sucuri Security
- Install Sucuri Security.
- Go to Sucuri Security → Dashboard.
- Run the scan.
- Follow recommendations.
Wordfence is free and very effective for detecting and removing malware in WordPress.
Step 4: Remove suspicious users
- Go to Users → All users.
- Look for administrator users you didn’t create.
- Delete them or change their role to subscriber.
- Change all legitimate administrators’ passwords.
Step 5: Review plugins and themes
- Go to Plugins → Installed.
- Look for plugins you didn’t install. Delete them.
- Make sure all plugins are updated.
- Remove plugins you don’t use.
- Do the same with themes.
Many hacks enter through abandoned or outdated plugins. Remove what you don’t use.
Step 6: Clean infected files manually
If Wordfence detects infected files it can’t automatically repair:
- Go to cPanel → File Manager.
- Find the flagged files.
- Compare with a clean WordPress installation.
- If a core file is modified, replace it with the original.
- Look for suspicious files in
wp-content/uploads/(there shouldn’t be PHP files there).
.phpfiles in theuploads/folder are almost always malware. Delete them.
Step 7: Change all passwords
After cleaning, change:
- WordPress password (all administrators).
- Database password.
- cPanel password.
- FTP password.
- Security keys in
wp-config.php.
If the attacker stole passwords, changing them is essential. Generate new keys at api.wordpress.org/secret-key/1.1/salt/ and paste them in
wp-config.php.
Step 8: Update everything
- WordPress to the latest version.
- All plugins.
- The theme.
- PHP to the latest available version.
Step 9: Ask Google to review your website
If Google marked your website as dangerous:
- Go to Google Search Console → Security.
- Request a review.
- Google takes a few days to review and unmark.
How to prevent reinfections
- Keep everything updated. WordPress, plugins and theme.
- Use strong passwords. And enable 2FA.
- Install a security plugin. Wordfence or Solid Security.
- Remove plugins you don’t use.
- Download plugins and themes only from official sources.
- Back up regularly.
- Use hosting with security. At miHosting we apply patches and monitor.
Frequently asked questions
Can I clean the malware myself?
Yes, with Wordfence and a bit of patience. If you don’t feel capable, hire a professional.
How long does cleaning take?
It depends on the infection level. A light infection, 1-2 hours. A severe one, a whole day.
Can my hosting help me?
At miHosting, if you have a maintenance plan, we handle cleaning. If not, you can open a ticket and we’ll advise you.
Do I lose data when cleaning?
Not necessarily. If you back up before, you lose nothing. Cleaning removes malicious files, not your content.
Can it get infected again?
Yes, if you don’t patch the vulnerability that allowed the attack. That’s why it’s key to update and maintain security.
Clean your WordPress and protect it
A hacked WordPress is a scare, but it has a solution. With calm, a backup, a Wordfence scan and manual cleaning, you can leave your website clean and secure.
If you need help cleaning your WordPress or want a maintenance service that prevents future hacks, at miHosting we can help. Open a ticket from your client panel.