WordPress Redirect Virus: How to Find and Remove Hidden Redirect Scripts
A malicious redirect is one of the most alarming WordPress security issues. A customer clicks on your link, but instead of seeing your homepage, their browser is bounced through multiple ad exchanges before landing on a counterfeit tech-support alert, an online casino, or a fake "Robot Verification" captcha page.
What makes this malware insidious is that it frequently hides from the site administrator. Many redirect scripts check your cookies and IP address: if you are logged into WordPress or visited recently, the redirect does not trigger. You think the site is fine, while all new mobile visitors are being redirected away.
Where Malicious Redirects Hide
- Injected Header/Footer JavaScript: Small obfuscated
<script>blocks injected into active theme templates (header.php,footer.php) or added via database hooks. - Database Posts & Options: Injected base64 strings inside
wp_postscontent or auto-loading rows inwp_options. - Core File Alterations: Injections in
wp-config.php,index.php, orwp-blog-header.phpthat prepend a remote loader before WordPress initializes. - Cached Browser Assets: Attackers modify cached JS bundles so standard file checks show clean files while visitors load infected scripts.
What You Should Do Immediately
- Test in Private Browsing on Mobile: Use your phone on cellular data (not your office Wi-Fi) in incognito mode. Most redirect scripts specifically target mobile user-agents with referrers from search engines.
- Do Not Just Reinstall Your Theme: If the payload is injected into your database or a hidden
mu-pluginsfile, reinstalling your theme will not solve the issue. The backdoor will re-infect your theme within minutes. - Audit Third-Party Scripts: Check your Google Tag Manager container and any custom code snippets plugins.
If you need this resolved permanently today with zero downtime, submit a Delvok rescue request. We sweep every file, database table, and transient cache to guarantee all backdoors are removed.