Skip to main content
WordPress security incident Investigation · Cleanup · Recovery

Malware on your
WordPress site? Act carefully.

Get specialist help investigating suspicious behaviour, removing malicious code and restoring a safer, working WordPress website.

Do not delete evidence or overwrite the website before the current condition and available backups have been reviewed.

WordPress malware and website security investigation
Security review required Potential compromise detected High
Modified PHP files Review
Unknown administrator Investigate
External redirect Detected
Common warning signs
Unexpected redirects Browser warnings Spam pages Unknown users Hosting suspension
01 — Assessment

Understand the incident
before changing the evidence

A security warning does not explain how the compromise happened or how far it spread. The first step is to review the website, hosting environment, accounts, available backups and recent changes.

This helps distinguish infected files from legitimate custom code and reduces the risk of restoring the same vulnerability.

INCIDENT REVIEW CASE #WP-042
Risk level Elevated
WordPress access
Required
Hosting access
Required
Backup review
Recommended
Database inspection
As needed
Server investigation
Scope dependent
Cleanup scope is confirmed after access and website condition are reviewed.
02 — Response process

Investigate, clean and
reduce the chance of reinfection

Cleanup is handled as a controlled incident response rather than a blind file deletion or automatic scan.

  1. 01
    Contain

    Protect the current state

    Access, backups and the live website condition are reviewed before destructive work begins. Immediate exposure may be reduced where practical.

    Website condition Preserved
  2. 02
    Investigate

    Find malicious changes and likely entry points

    Files, database content, administrator accounts, software versions and suspicious behaviour are reviewed according to the incident.

    Technical review Engineer-led
  3. 03
    Clean

    Remove or replace compromised components

    Malicious code and unauthorised content are removed where identified. Legitimate WordPress files may be replaced from trusted sources.

    Malicious content Removed where found
  4. 04
    Recover

    Harden, validate and return the website to service

    Software, users, passwords and relevant security controls are reviewed. Important pages and included website functions are checked after cleanup.

    Post-cleanup Validated
03 — Warning signs

Malware does not always
look like a broken website

Some compromises remain hidden from normal visitors while abusing search traffic, sending spam or creating unauthorised access.

Investigate suspicious activity
01

Unexpected redirects

Visitors are sent to advertising, scam, pharmaceutical or unrelated websites.

High concern
02

Unknown pages in search results

Search engines display spam pages or titles that do not exist in the normal WordPress administration area.

Investigate
03

New administrator accounts

Unrecognised users have elevated permissions or legitimate administrators can no longer log in.

High concern
04

Modified files and recurring changes

PHP, JavaScript or configuration files reappear after deletion or change without an authorised deployment.

Investigate
05

Browser or search-engine warnings

Browsers, Google Search Console or security services flag the domain as deceptive or harmful.

Urgent
06

Hosting suspension or unusual resource use

The provider reports outgoing spam, malicious files, excessive CPU use or other prohibited activity.

Urgent
04 — Cleanup scope

Every layer of WordPress
may need to be reviewed

The final cleanup scope depends on how the website was compromised and whether the problem is limited to WordPress or extends into the hosting account.

A

WordPress files

Core files, uploads, configuration and suspicious PHP or JavaScript.

B

Database content

Spam entries, malicious options, injected scripts and unauthorised changes.

C

Users and access

Administrator accounts, passwords, API keys and hosting credentials.

D

Plugins and themes

Vulnerable, abandoned, modified or untrusted extensions and templates.

E

Redirects and SEO spam

Hidden pages, doorway content, unwanted redirects and search spam.

F

Hosting environment

Other websites, scheduled tasks, server configuration and account-level persistence.

post-cleanup validation
WordPress website recovery and post-cleanup validation
Validation completed Pages · login · forms · SSL
05 — Recovery

Cleaning is not finished
until the site is checked

After malicious changes are addressed, important website functions and security-related configuration are reviewed according to the agreed scope.

  • 01
    Administrator access Legitimate users can access the website as expected.
  • 02
    Public pages and redirects Important URLs are checked for unexpected behaviour.
  • 03
    Forms and customer journeys Included website functions are reviewed after cleanup.
  • 04
    Security recommendations Relevant software, password and maintenance actions are explained.
06 — Aftercare

Reduce the chance of
facing the same incident again

Reinfection commonly happens when the original vulnerable software, stolen credentials or another compromised website remains active.

01 Keep software current

Review WordPress, plugin and theme updates regularly.

02 Use unique credentials

Replace potentially exposed passwords and remove unused accounts.

03 Maintain clean backups

Retain recovery points outside the live website where practical.

04 Monitor website health

Review uptime, security alerts and unexpected website changes.

Loved by Customers Trustpilot 4.8/5

The ones who switched
and stayed

4.8/5
★★★★★
Rated Excellent across hundreds of Trustpilot reviews
★★★★★
“Managing our website is simple and stress-free. The uptime has been excellent, and help is always available when needed.”
Charlotte Brown Charlotte Brown Salon Owner
★★★★★
“Rock-solid hosting and genuinely responsive support. Our firm's site has been fast and reliable since day one — exactly what a busy practice needs.”
Matt Gingell Matt Gingell Specialist Employment Lawyer
07 — FAQ

Questions during a
WordPress security incident

Clear answers about investigation, cleanup, recovery and what happens after a compromised website is restored.

Ask a security specialist →
How do I know if my WordPress website has malware?

Common signs include redirects, browser warnings, unknown users, spam pages, modified files, search-engine warnings and hosting suspension. A technical investigation is needed to confirm the cause.

What does the malware removal service include?

Work can include website assessment, malicious-code removal, infected file replacement, database review, user checks, software review, security hardening and post-cleanup validation.

How quickly can you remove malware?

Timing depends on the website size, available access and extent of the damage. Reinfections, large websites and server-level compromises require deeper investigation.

Can every compromised website be recovered?

No. Recovery depends on the website condition, backups, access and extent of the compromise. The likely options are explained after assessment.

Will cleaning remove a Google security warning?

Cleaning is an important first step. Google or browser-security providers may require a separate review and can take time to reassess the site.

Can you clean a WooCommerce website?

Yes. Additional care may be required around customer data, payment integrations, active orders and the timing of maintenance work.

What access details do you need?

WordPress administrator and hosting-level access are normally required. Database, SFTP, cPanel, Plesk or SSH access may also be needed.

What happens if the website becomes infected again?

A new investigation may be required. Reinfection can happen when the original entry point, compromised credentials or another infected website remains active.

Is malware removal included with maintenance?

Major incident cleanup is normally separate work. Maintenance can help reduce avoidable risk after recovery by managing updates, backups and website-health checks.

Should I restore an old backup instead?

A known clean backup can help, but restoring it without addressing the entry point may cause reinfection. The backup and restored software should be reviewed first.

Security incident support

Get your WordPress website investigated.

Share the warning signs, hosting provider and access available. A specialist will review the likely investigation and cleanup path.