The most common mistake in WordPress malware removal isn’t missing the malware — it’s removing the obvious infection while leaving the backdoor that put it there in the first place, so the site gets reinfected within days.
Put the site in maintenance mode and, if possible, take a full file and database backup of the site in its current (infected) state before changing anything. You will want this snapshot later to confirm what was actually removed, and to check for a backdoor you missed if the site gets reinfected.
The visible symptom — a spam redirect, a defaced page — is rarely the actual vulnerability. Check for: an outdated plugin or theme with a known CVE, a stolen admin password, a vulnerable contact form or file upload handler, and any recently modified core file. Removing the payload without closing the entry point means the attacker walks back in the same way they walked in the first time.
Diff every core, plugin, and theme file against the official checksums for the exact installed version. Anything that doesn’t match is either a legitimate customization (rare, and should already be documented) or an injected payload. Pay special attention to wp-content/mu-plugins/ — must-use plugins load before regular plugins and don’t appear in the standard plugin list at all, making them a favorite hiding spot.
Before you consider the site clean, review every user with publish or administrator capability. Attackers frequently create a second admin account as insurance in case the original compromised account gets noticed and locked.
WordPress admin passwords, database password, SFTP/SSH keys, and any API keys stored in wp-config.php or plugin settings. If the attacker had file write access, assume they read everything readable, including anything stored in plaintext.
Rather than trying to manually clean every modified file, it is faster and more reliable to delete and reinstall WordPress core and every plugin/theme from the official source, keeping only wp-content/uploads and the database (after cleaning any injected content from posts/options).
A clean scan today doesn’t guarantee a clean site next week if the underlying weakness (an outdated plugin, a weak password policy) isn’t addressed. The sites that get reinfected are almost always the ones that were cleaned once and then never checked again.
Once a site is clean, the real work is making sure it stays that way — continuous file integrity and malware-signature monitoring catches a reinfection attempt within minutes instead of weeks. See the Security page for how that detection actually works, or Pricing to set it up.
Connect a site in a few minutes and get your first inventory scan back immediately.
Try free →