Skip to content
July 11, 2026·4 min read

How to Tell If Your WordPress Site Is Infected With Malware — and Clean It Without Breaking Everything

The clear signs of infection, how to check calmly, and how to clean a hacked WordPress site without losing your content.

A hacked WordPress site rarely looks dramatic. Often it seems almost normal: it loads a little slower, a strange redirect appears on mobile, or you get an email from Google saying your site "contains deceptive content." Meanwhile, behind the scenes, someone is sending spam from your server or adding pages you can't even see from the admin.

The good news: in most cases an infected site can be fully cleaned without losing your posts, images, or customers. The less-good news: if you treat only the symptom — delete one file and stop — the infection comes back within days. In this guide I'll show you the real signs of infection, how to check calmly without panic, and how to clean it step by step — plus how to keep it from happening again.

Clear signs your site is infected

Don't rely on a single clue. Look for several signs that appear together:

  • Unexpected redirects — you click your site and land on a gambling, pharmacy, or scam page, especially on mobile or when arriving from Google.
  • Google shows "This site may be hacked" or "deceptive content" in the search results.
  • Pages or posts you never created, often in Japanese or with words like "replica," "casino," "loan."
  • Unknown admin users under Users → All Users.
  • Sudden slowness, or your host suspends the account for sending spam.
  • Oddly named .php files (like wp-conf9.php) scattered through folders.

If two or three of these are true, treat the site as infected and don't put it off.

Check calmly, before you touch anything

Don't delete anything in a panic. Document first, so you know what you're cleaning and can roll back if you slip.

  • Run the site through free scanners: Sucuri SiteCheck and VirusTotal show if you're blacklisted and what suspicious code loads.
  • Install a scanning plugin like Wordfence or MalCare and run a full file scan.
  • Open the site in a private window, and on mobile — many infections hide and only appear to visitors coming from Google.
  • Check Google Search Console → Security Issues.
  • Write down what you find: recently modified files, unknown users, last-modified dates. This is the key — changes from the last few days usually reveal how they got in.

Back up the whole site, even while infected

It feels wrong to save a sick site, but it's essential. If something goes wrong during cleanup, you want a way back.

Save two things separately:

  • All files (via FTP/SFTP or cPanel File Manager) — especially the wp-content folder, where your themes, plugins, and images live.
  • The database (via phpMyAdmin → Export) — that's where posts, pages, and comments live.

Your real content — the text and images — is almost never the target; malware lives in .php files and in themes/plugins, not in your posts. That's why it can be cleaned without losing content. Keep the infected backup separate from any older clean backup so you don't mix them up.

The actual cleanup, step by step

The core idea: replace everything that can be reinstalled clean, and keep only what's truly yours.

  • Immediately change all passwords: WordPress admin, hosting/cPanel, FTP, and the database user.
  • Delete unknown admin users.
  • Replace core files: delete the wp-admin and wp-includes folders and upload fresh copies from wordpress.org (don't touch wp-content or wp-config.php).
  • Reinstall your theme and plugins from official sources. Delete any "nulled" (pirated) plugin — that's where many infections come from.
  • There should be no .php files inside wp-content/uploads. If you find any, they're almost certainly malware.
  • Check wp-config.php and .htaccess for injected code at the top or bottom.

After cleaning, run another scan. Then request Google's re-review from Search Console.

How to keep it from happening again (and when to get help)

A site that's clean today can be reinfected tomorrow if the hole stays open. The basics that matter most:

  • Keep WordPress, your theme, and plugins always updated — vulnerabilities in old versions are the main cause.
  • Delete plugins and themes you don't use; unmaintained code is an open door.
  • Long, unique passwords, plus two-factor authentication on the admin.
  • A security plugin with a firewall and automatic daily backups, stored off the server.

If redirects come back after cleanup, or your host keeps the site suspended, that's a sign the infection is deeper and deserves experienced hands. At MPO Web Studio we work remotely across the country: we can take over a hacked site, clean it, and secure it without losing your content. Message us on WhatsApp, we'll take a calm look and tell you honestly what needs doing.

Frequently asked questions

Will I lose my posts and images if I clean my site of malware?+

Almost never. Your content — text, pages, images — lives in the database and the uploads folder, while malware usually lives in .php files and in themes/plugins. If you back up fully first and replace only the system files, themes, and plugins, your content stays intact.

Is installing a security plugin like Wordfence enough?+

It helps a lot with detection and scanning, but a plugin won't fix everything on its own, especially if the infection is deep in core files or the database. Use it to find the problem, then clean the files manually and change all passwords. Its firewall is most useful after cleanup, to prevent reentry.

Why was my site hacked if it's small and doesn't sell anything?+

Nearly all WordPress attacks are automated, not personal. Bots scan the internet for plugins and themes with known vulnerabilities and for weak passwords, no matter how small you are. Your server is valuable to them for sending spam or hosting scam pages.

How long does cleaning an infected site take?+

For a typical site, a careful cleanup takes from a few hours to a working day, plus the time until Google removes it from the blacklist after re-review, which can be several days. If the infection returns, it usually means the entry point wasn't fully closed.

How do I know the site is truly clean at the end?+

Run another scan with Sucuri SiteCheck and your security plugin, check Search Console → Security Issues, open the site in a private window and on mobile, and watch it for a few days. If no more redirects, foreign pages, or new users appear, it's clean.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
MThe MPO teamWe reply personally

Want to see what your business's website could look like?

Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.

Ask for a free demo websiteWe usually reply within a few minutes