Home About

Services

Custom Web Design Custom eCommerce Custom Web Apps Search Engine Optimisation Speed Optimisation SEO Blog Writing Maintenance & Hosting Hacked Website Repair Projects Blog Contact Free Quote
Security 6 min read

WordPress Malware Removal: How to Properly Clean a Hacked Site

Why WordPress sites get hacked, the infections we see most, why plugin scanners rarely finish the job, and what a proper manual malware clean involves.

WordPress malware removal explained

Most of the hacked websites in the world are WordPress websites. That is not a knock on WordPress so much as arithmetic: it powers around 43% of the web, so it is where the attackers point their bots. But it does mean that if your site runs WordPress and it has been hacked, the infection follows well-worn patterns, and so does the clean-up.

This guide explains how WordPress gets infected, why running a security plugin is not the same as removing malware, and what a clean that actually sticks involves.

Why do WordPress sites get hacked so often?

Because WordPress is the biggest target on the internet, and because its flexibility comes from plugins, each one a piece of third-party code with its own security record. Most WordPress hacks come through an outdated or vulnerable plugin or theme, a weak admin password, or a pirated "nulled" theme with malware built in.

The core software itself is well maintained. The trouble is everything bolted onto it: the average business site runs 20 or more plugins, and every unpatched one is a possible way in. Unmaintained WordPress gets hacked; maintained WordPress mostly does not.

What are the most common WordPress infections?

The same handful of infections make up most of what we see on Irish business sites:

  • Spam redirect hacks. Visitors get bounced to gambling, pharmacy or scam pages, often only on mobile or only from Google, so the owner sees nothing wrong.
  • SEO spam injections. Thousands of junk pages ranked under your domain, the "Japanese keyword hack" and pharma spam being the classic versions.
  • Phishing pages. Fake bank or courier login forms hidden in your uploads folder, which is what earns the "Deceptive site ahead" flag.
  • Fake admin users. Accounts the attacker creates to keep access after a clean-up.
  • Backdoors. Small PHP files disguised as legitimate ones, or code injected into wp-config.php and theme files, that let the attacker back in on demand.
  • Malicious cron jobs. Scheduled tasks that quietly reinstall the malware on a timer, which is why some sites appear to "re-hack themselves" every weekend.

Can a security plugin remove the malware?

Sometimes, but treat a plugin scan as triage rather than the cure. Scanners match files against known malware signatures, so they catch commodity infections and miss the rest: freshly obfuscated code, backdoors that look like ordinary files, database-level injections, and anything sitting outside the folders they check.

There is also a structural problem: the scanner runs inside the compromised site. Malware with admin-level access can hide files from the plugin, tamper with its reports, or simply reinfect the site the moment the scan finishes. A clean that starts and ends with a plugin is the reason so many WordPress sites get "fixed" three times in a month.

Lines of PHP code on a screen in a dark editor

What does a proper WordPress malware clean involve?

A real clean works from outside the site, at hosting level, and rebuilds trust file by file: replace the WordPress core with a fresh copy, reinstall every plugin and theme from its official source, sweep the uploads folder for executable files, clean the database, audit the users, rotate every secret, and only then bring the site fully back.

In practice that means:

  1. Forensic backup first. The infected state is the evidence of how they got in. It gets preserved, then worked on.
  2. Fresh core. WordPress core files replaced wholesale with a clean download, which wipes out most file infections in one move.
  3. Plugins and themes from source. Every plugin and theme reinstalled from the official repository or the developer. Anything nulled or abandoned gets binned, not reinstalled.
  4. Uploads sweep. The uploads folder should contain media, not code. Any PHP hiding in there is malware by definition.
  5. Database clean. Injected scripts and spam content removed from posts, options and widgets, where file-level cleans never look.
  6. User audit and secret rotation. Unknown admins removed, every password changed, WordPress security keys and salts regenerated so stolen login cookies die instantly.
  7. Close the entry point and verify. The vulnerable plugin, weak login or hosting hole that let them in gets fixed, then the site is re-scanned from outside and any Google warnings are sent for review.

The first moves before any of this, passwords, your host, preserving evidence, are covered in our guide on what to do when your website is hacked. And if you would rather not spend your week inside wp-content, our hacked website repair service does the entire sequence for a fixed quote.

How do you stop WordPress being reinfected?

Reinfection is not bad luck, it is a missed backdoor or an unfixed entry point. Once the clean is genuinely complete, staying clean is a maintenance habit: updates applied weekly, as few plugins as the site can manage, two-factor authentication on every admin account, decent hosting, off-site backups and monitoring that flags file changes.

That is exactly the routine a maintenance and hosting plan exists to take off your plate, and our guide to website maintenance explains what good upkeep involves month to month.

Is it time to leave WordPress?

Not necessarily. A well-maintained WordPress site with a short plugin list is a perfectly reasonable thing to run, and plenty of our clients do, with us looking after the upkeep as part of our WordPress web design work.

But if you are reading this for the second or third infection, the honest answer is that the problem is structural. Every plugin is attack surface, and the only way to remove attack surface is to remove the need for it. A hand-coded custom site has no plugin ecosystem to exploit, which is why "clean it again" eventually loses to "rebuild it properly" for repeatedly-hit sites. We will always tell you which side of that line your site is on.

Frequently asked questions

How did malware get into my WordPress site?

Most likely through a vulnerable plugin or theme that missed an update, a weak or reused admin password, or a nulled theme that shipped with malware inside. Hosting-level breaches and infected neighbouring sites on shared accounts make up most of the rest.

How much does WordPress malware removal cost?

It depends on the size of the site and how deep the infection goes. A typical small business clean costs a few hundred euro; sprawling or repeatedly-infected sites cost more. We quote each job after a quick look, fixed price, before any work starts. The full breakdown is in how much malware removal costs in Ireland.

Can I just delete WordPress and reinstall it?

A bare reinstall replaces the core files but keeps your database, uploads and themes, which is usually where the infection lives. Without cleaning those and closing the entry point, the fresh install inherits the problem. Reinstalling is one step of a clean, not a substitute for it.

Are free malware scanners worth running?

As a first check, yes: a scan that finds something confirms the infection quickly. Just do not read a clean result as proof of health, because scanners miss backdoors and database infections, and a compromised site can mislead software running inside it.

WordPress site infected? We clean WordPress properly, at hosting level, and keep it clean afterwards. Get emergency help.

Want this handled for you?

We design, build and grow fast custom websites for Irish businesses.