How to Remove Malware From a Hacked WordPress Site: A Step-by-Step Guide
Discovering that your WordPress site has been hacked is gut-wrenching — especially when it’s your business on the line. Take a breath: most WordPress infections are cleanable, and with a methodical approach you can remove the malware, get any blacklist warnings lifted, and lock the door behind the attacker. Here’s the step-by-step process.
Signs your WordPress site is hacked
- Unexpected redirects to spam, gambling, or adult sites
- Pharmaceutical or SEO spam injected into your pages or Google results
- A “Deceptive site ahead” warning or an antivirus/blacklist flag
- New admin accounts, unknown files, or files changed at strange times
- Your host suspended the site or emailed you about malware
- Sudden slowdowns or unexplained traffic spikes
If only one scanner flags you and nothing actually misbehaves, you may be dealing with a false positive rather than a real hack — worth ruling out before you start tearing things apart.
Before you start: back up and stay calm
Even though the site is compromised, make a full backup of the current files and database first. You want a snapshot to investigate — and to restore from if a cleanup step goes sideways. Work on a staging copy if you can.
Step 1: Confirm the infection
Run a reputable malware scan and check Google Search Console → Security Issues for the sample URLs Google flagged. Note what the malware is doing — redirects, spam, defacement — because it tells you where to look.
Step 2: Scan every layer
WordPress malware hides in more than one place. Check all of them:
- Core files — compare against a fresh copy of the same WordPress version
- Themes and plugins — especially nulled or abandoned ones
- The uploads folder — PHP files have no business living in
/html/assets/uploads/ - The database — injected scripts, spam links, and rogue admin users
- wp-config.php and .htaccess — favorite spots for backdoors and redirects
Step 3: Remove the malicious code
Delete backdoors, injected code, and any files you can’t account for. Look for telltale signs: eval(, base64_decode(, long obfuscated strings, and recently-modified timestamps. Remove unknown admin users under Users in wp-admin. Be thorough — a single leftover backdoor lets the attacker walk right back in.
Step 4: Replace core, themes, and plugins from clean sources
The safest way to clean core and reputable plugins or themes is to replace them entirely with fresh copies from WordPress.org or the official developer. Reinstall — don’t just “update” — so any modified files are overwritten.
Step 5: Clean the database
Remove injected <script> tags, spam links, and suspicious entries from your posts, options, and user meta. Drop any unfamiliar tables the malware may have created.
Step 6: Reset all the keys to the kingdom
- Change every password: WordPress admins, hosting/cPanel, FTP/SFTP, and the database user
- Regenerate your WordPress secret keys/salts to force every session to log out
- Review and remove unused FTP and admin accounts
Step 7: Harden the site so it doesn’t happen again
- Keep everything updated and delete what you don’t use
- Enforce strong passwords and two-factor authentication
- Limit login attempts and consider hiding the login URL
- Set correct file permissions and disable file editing in wp-admin
- Run a firewall or security plugin
Step 8: Request blacklist and Safe Browsing removal
Once the site is verifiably clean, ask the services that flagged you to re-check it. In Google Search Console, request a review under Security Issues. For antivirus and blacklist vendors, submit through their official channels — my blacklist removal links directory has the report forms for 100+ of them.
When to call in a professional
If the infection keeps coming back, you can’t find the backdoor, your host suspended the account, or you simply can’t afford the downtime, it’s worth handing the job to a specialist. DrGlenn provides fast, accountable WordPress malware removal — full cleanup, blacklist removal, and hardening, done by one expert who keeps you in the loop the whole way. Get in touch or order a cleanup and get back online with confidence.
Related guides
Most failed cleanups die on the same two rocks: missed backdoors and rushed first steps. Before you start, read what to do in the first hour, then how to find the backdoors scanners miss. And if you’ve already cleaned once and the malware came back, here’s why sites get reinfected.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.