Where creative ideas grow  ·  Building and maintaining websites since 2018, from Rajshahi, Bangladesh

WordPress security 6 min read

How to Remove Malware From WordPress: A Complete Guide

Learn how to remove malware from WordPress properly: scan, check core files, clean the database, close the entry point and confirm it is gone.

Remove malware from WordPress — developer scanning infected website files and code for malicious scripts

To remove malware from WordPress properly, you need to do more than delete a few suspicious files: you need to find every place the infection left something behind, close the hole it used to get in, and confirm it is genuinely gone before bringing the site back. This guide walks through the full process a thorough clean-up actually involves.

If you have not yet worked through the immediate first-hour steps, our guide on what to do when a WordPress site is hacked covers those first: taking the site offline, changing passwords, and identifying obvious signs. This guide picks up from there with the actual clean-up.

Keep a copy of the infected state

Before deleting anything, take a full backup of the site exactly as it is now. If the clean-up goes wrong, or you need to check what was there later, this is the only record you will have.

Where WordPress malware typically hides

LocationWhat to look for
wp-config.phpUnfamiliar code added above or below the normal configuration lines
.htaccessRedirect rules you did not add, often sending search engines to spam pages
Theme functions.phpInjected code that runs on every page load, often base64-encoded
Uploads folder.php files that should never exist among images and media
Database, wp_options tableRogue entries under active_plugins, or injected scripts in widget content
Database, wp_users tableAn extra administrator account you did not create

Step 1: scan with a dedicated security tool

A malware scanner such as Wordfence, Sucuri or MalCare checks your files against known malware signatures and flags anything suspicious. This catches most common infections quickly, but no scanner catches everything, especially custom or well-hidden code, so treat a clean scan as a starting point rather than proof the site is safe.

Step 2: compare core files against a known-clean copy

WordPress core files should never be modified directly. Download a fresh copy of the same WordPress version from wordpress.org and compare it against your live files, either with a diff tool or by simply replacing wp-admin and wp-includes entirely, since nothing in those folders should be custom.

Step 3: check every theme and plugin file

Replace your active theme and every plugin with fresh copies downloaded directly from WordPress.org or the original vendor, not copies from your infected install. If you use a premium theme or plugin from outside the official repository, download it again from the vendor’s own account area rather than trusting the version already on your server.

Delete any plugin or theme you do not actively recognise using. Unused, outdated software is one of the most common ways attackers get back in after a first clean-up. Skipping this step is why some site owners try to remove malware from WordPress once and see it return within days.

Step 4: inspect the uploads folder for hidden PHP files

The /wp-content/uploads/ folder should only ever contain images, documents and media, never executable PHP files. Search it specifically for any file ending in .php, .phtml or similar, since attackers often hide backdoors here precisely because site owners rarely look.

Step 5: clean the database, not just the files

Malware often injects itself into the database too, most commonly in the wp_options table’s widget or theme settings, or directly into post content as a hidden script. Search the database for suspicious patterns such as eval(, base64_decode(, or unfamiliar iframe tags, using phpMyAdmin’s search function or a plugin built for this. Remove anything you did not add yourself, after confirming it is not a legitimate use by a plugin you trust.

Step 6: remove unfamiliar admin users and check user roles

Go to Users → All Users and delete any administrator account you did not create, including ones with names close to legitimate-looking usernames. Check remaining accounts have the correct role too, since an attacker can sometimes upgrade an existing low-privilege account instead of creating a new one, which is easy to miss.

Step 7: change every credential and regenerate security keys

Change your WordPress admin password, hosting control panel password, database password, and FTP/SFTP credentials. Then regenerate the security keys and salts in wp-config.php using the WordPress.org secret key generator, which invalidates any stolen session cookies immediately.

Step 8: find and close the entry point

Cleaning malware without fixing how it got in is the single biggest reason it comes back. Check your host’s access logs around the time the infection started for the specific file or request that introduced it, and check whether an outdated plugin’s version at that time had a known, published vulnerability.

Step 9: confirm the site is actually clean

Run a fresh scan after finishing the steps above, and check Google Search Console’s Security Issues section if the site was flagged. Request a review once you are confident the infection is fully removed; reviews typically take a few days, and requesting one before the site is genuinely clean only delays recovery further.

How long a proper clean-up takes

A straightforward infection caught early, with a recent clean backup available, can often be resolved in a few hours by restoring the backup and confirming the entry point is closed. A deeper infection spread across many files, or one with no reliable backup to fall back on, can take a day or more to clean thoroughly and verify, since every file and database table needs checking rather than just the obvious ones.

Preventing reinfection

  • Keep WordPress core, every plugin and your theme updated at all times.
  • Use strong, unique passwords and add two-factor authentication for every admin account.
  • Remove plugins and themes you are not actively using, rather than just deactivating them.
  • Keep a security plugin running continuously for ongoing scanning, not just for the one-time clean-up.
  • Keep offsite backups so a future infection can be resolved by restoring a clean copy quickly.

Want it cleaned properly, the first time?

We remove malware from WordPress sites from $120, with an emergency lane on WhatsApp (+880 1722 859059) for sites actively serving malicious content. Get help now, or ask about our ongoing maintenance plan to stop it happening again.

Remove malware from WordPress: quick answers

Can I remove malware from WordPress myself without technical skills?

A security plugin’s scan-and-clean feature handles common infections without much technical knowledge. A deeper or custom infection, especially one hidden in the database or a backdoor file with an unusual name, is harder to catch without file comparison skills and usually worth getting help for.

Will a security plugin alone remove malware from WordPress completely?

It catches most known malware signatures reliably, but not everything, particularly custom code written specifically for your site. Combining a scanner with a manual check of core files, the uploads folder and the database gives far more confidence the site is genuinely clean.

How do I know if I successfully removed malware from WordPress?

Run a fresh scan after finishing every step, check your file modification dates for anything recent you cannot explain, and monitor for a few days afterward. If Google flagged the site, only request a review once you are confident every trace is gone.

Why does malware keep coming back after I remove it?

Almost always because the entry point was never closed: an outdated plugin, a weak password, or a backdoor file missed during clean-up. Removing the malware without fixing how it got in only buys a temporary reprieve. That is why every step above matters if you want to remove malware from WordPress for good, not just for the next few weeks.

Sukumar Mahato

Sukumar Mahato

Founder · Full-stack developer

Founded Mahatosoft in 2018. Has shipped and rescued more than 420 projects across React, Node.js and WordPress — and still takes the emergency calls himself.

Free 15-minute consultation

Let’s scope your project properly.

Tell us what you need built or fixed. You get an approach, a timeline and a fixed price — usually within a few hours.