>_
Delvok
← Back to Blog
Security Guide

WordPress Malware Removal: The Complete Step-by-Step Guide

June 21, 2026·Delvok Security Team·8 min read

How WordPress Sites Get Infected

Before you can remove malware, it helps to understand how it got there. The vast majority of WordPress infections we clean up trace back to one of four entry points:

Nulled Themes and Plugins

"Nulled" means pirated. That free premium theme you downloaded from a sketchy forum? It almost certainly came with a backdoor baked in. Attackers distribute these intentionally - they're betting you'll install their trojan horse on your own server for them.

Outdated Plugins and Themes

Every plugin update that mentions "security fix" is also a public announcement of a vulnerability. Once a patch is released, attackers reverse-engineer the fix to understand the hole - then scan the internet for sites that haven't updated yet. If your plugins are months behind, you're running known-vulnerable software.

Compromised Credentials

Brute-force attacks against wp-login.php are constant. If your admin password is weak, reused from another site that was breached, or shared with a contractor who got phished - attackers walk right in.

Shared Hosting Cross-Contamination

On shared hosting, your site lives on the same server as hundreds of others. One compromised neighbor can lead to your site being infected through symlink attacks or shared PHP process pools. This is why isolated hosting matters.

How to Check If Your Site Has Malware

1. Check Google Search Console

Google will flag your site if it detects malware. Log in to Search Console, navigate to Security & Manual Actions → Security Issues. If Google has blacklisted your site, you'll see it here.

2. Scan Your Files

Look for recently modified PHP files, especially in directories where PHP files shouldn't change often:

  • wp-includes/ - Core WordPress files that should never be manually edited
  • wp-content/uploads/ - Should only contain media files, not .php files
  • Theme functions.php - A favorite target for injected code

3. Check the Database

Malware frequently hides in the wp_options table or gets injected into post content. Look for <script> tags, iframes pointing to external domains, or encoded strings in your post content.

4. Inspect .htaccess

Open your .htaccess file in the WordPress root. If you see redirect rules you didn't add - especially ones sending mobile users or search engine visitors to different sites - you've found a common infection technique.

5. Review User Accounts

Check Users → All Users in your WordPress admin. Any administrator accounts you don't recognize? Attackers often create backdoor admin accounts to maintain access even after you change your password.

Manual Malware Removal Steps

If you want to attempt removal yourself, here's the process. Important: back up your site first, even though it's infected - you don't want to lose data if something goes wrong.

Step 1: Put Your Site in Maintenance Mode

This prevents visitors from being exposed to malware while you work. Use a maintenance mode plugin or simply rename your theme's index.php.

Step 2: Replace WordPress Core Files

Download a fresh copy of WordPress from wordpress.org. Replace everything in wp-admin/ and wp-includes/ with the clean versions. Do not touch wp-content/ yet - that's where your themes, plugins, and uploads live.

Step 3: Audit Your Plugins

Delete all plugins from wp-content/plugins/. Then reinstall them one by one from the official WordPress.org repository or the vendor's site. Never restore plugins from your backup - they may be the infection source.

Step 4: Clean Your Theme

If you're using a commercial theme, download a fresh copy from the vendor. Compare your functions.php and any custom template files against the clean version. If you're using a custom theme, manually review every PHP file for injected code.

Step 5: Clean the Database

Search your wp_posts table for suspicious content: base64-encoded strings, <script> tags pointing to external domains, and hidden iframes. Check wp_options for unfamiliar entries, especially any with encoded values.

Step 6: Remove Backdoor Files

Search your entire WordPress installation for files that don't belong. Pay special attention to wp-content/uploads/ - if you find .php files mixed in with your images, delete them.

Step 7: Change Everything

New passwords for every WordPress admin, FTP/SFTP, database, and hosting control panel. Generate new WordPress security salts. Revoke and regenerate any API keys.

Why Professional Removal Is Safer

Here's the honest truth: manual malware removal has a high failure rate. The problem isn't that the steps above are wrong - it's that modern malware is designed to survive cleanup attempts.

Sophisticated infections use:

  • Multiple backdoors scattered across dozens of files
  • Database-stored payloads that re-infect files on every page load
  • Obfuscated code that's nearly impossible to distinguish from legitimate plugin code
  • Scheduled re-infection via WordPress cron jobs

Missing even one backdoor means your site gets re-infected within hours. We see this pattern constantly: site owners clean their site, feel relieved, and wake up the next morning to find the malware is back.

Professional malware removal services like Delvok use automated scanning tools combined with manual expert review to find every trace of infection. More importantly, we don't just clean - we harden your site and move it to isolated hosting so the infection vector is eliminated, not just patched.

After Removal: What's Next?

Cleaning malware is only half the job. If you don't address the vulnerability that allowed the infection, you'll be cleaning malware again in a few weeks. Post-removal, you should:

  1. Update everything - WordPress core, all plugins, all themes
  2. Remove what you don't use - Deactivated plugins are still hackable
  3. Implement a Web Application Firewall (WAF) - Blocks known attack patterns
  4. Set up monitoring - So you know the moment something changes
  5. Consider managed hosting - Isolated hosting environments prevent cross-contamination

The safest WordPress site is one that's professionally maintained on infrastructure designed for security - not bolted on as an afterthought.

What Delvok Does Differently

Every site we rescue is migrated to isolated container infrastructure — your own web root, database, and server process. 24/7 monitoring catches threats before they become problems. Forensic-grade remediation ensures nothing is left behind.

Get Protected