Cleaning up a hacked WordPress site
A practical guide to recovering a hacked WordPress site by scanning for malware, cleaning compromised files, removing backdoors, resetting credentials and hardening security.
Discovering that your WordPress site has been hacked is stressful, but the recovery process is well established. Most WordPress hacks are automated rather than targeted. Bots scan the internet for known security problems in outdated plugins, themes and WordPress itself, then use them to plant harmful code. So any WordPress site can be affected, whatever its size.
The priorities are to stop further harm, remove all malicious code, find and close the way in and make the site harder to break into again. Missing any of these, especially finding the way in, makes it much more likely the site will be hacked again.
This guide gives an overview of the process. A thorough clean-up can be complex, and there's no guarantee of catching everything yourself. If the site handles customer data or payments, or you're not confident, it's worth getting professional help from the start.
Signs of a hack
Hacked WordPress sites don't always look obviously broken. WordPress's own documentation lists signs such as your site being flagged by Google or other services, your host disabling it, visitors' antivirus software warning about it and changes you didn't make, like new user accounts.1 Other common signs include:
- Redirects that send visitors to spam, scam or phishing sites, sometimes only on mobile or only when arriving from Google
- Pages, links or pop-ups you didn't create
- Administrator accounts you don't recognise
- A warning next to your site in Google's search results, or a full-page browser warning such as "Deceptive site ahead"2
- Unexpected spikes in server load or traffic to pages you didn't create
- Unexpected
.phpfiles inwp-content/uploads/, which should normally only contain images, documents and other media
Contain the damage and take stock
Write things down. Note what you're seeing, when you first noticed it and anything that changed recently (a new plugin, an update, a new user). WordPress's documentation recommends starting with this, since it helps whoever does the clean-up, whether that's you or a professional.1
Contact your hosting provider. Tell them the site has been compromised. They may have tools and logs that show what happened and when, and on shared hosting the problem may affect more than just your site.1
Protect visitors. If the site is sending visitors to harmful pages, consider taking it offline while you clean it, using a maintenance plugin if you can reach the dashboard, or asking your host to restrict access.
Take a backup of the hacked site. It may seem odd, but a copy of the infected files and database helps work out how the attacker got in and what they changed, and gives you something to go back to if the clean-up goes wrong.1 Keep it separate from your clean backups and label it clearly so it's never restored by mistake.
Check your own computer. WordPress's documentation also recommends scanning the computers you use to manage the site, since stolen login details are sometimes taken from an infected computer.1
Consider restoring a clean backup
If you have a backup from before the hack, restoring it can be the fastest route back. But you need to be confident the backup is clean, and restoring it doesn't close the security hole the attacker used. You'll still need to find and fix the way in, update everything and change passwords, or the site is likely to be hacked again. Anything added since the backup (orders, form entries, posts) will also be lost, so check with your host or a developer before restoring a shop.
Scan the site
WordPress's documentation suggests using both kinds of scanner, since each finds different things:1
- Remote scanners such as Sucuri SiteCheck check your public pages for known malware and suspicious links. They only see what visitors see.
- Scanner plugins check the files on your server, and can compare WordPress's files against the official versions and flag changed plugin and theme files.
If you have WP-CLI, wp core verify-checksums compares your WordPress core files against the official release and lists any that have been changed or added,3 and wp plugin verify-checksums --all does the same for plugins from WordPress.org.4
Scanners won't catch everything, so treat a clean scan as reassuring rather than proof. Note anything flagged for the steps below.
Find the way in
Understanding how the attacker got in is essential to stopping it happening again. Common ways in include outdated plugins or themes with known security problems, weak or reused passwords, stolen hosting or SFTP logins and "nulled" (pirated) plugins or themes, which often contain hidden backdoors.
Your host can help you look through the server's access logs around the time of the hack for unusual activity, such as requests to unexpected files. If you find the security problem that was used, make sure it's fixed before bringing the site back online. Our guide to handling a plugin security vulnerability covers updating safely, and if the plugin is no longer maintained, see our guide to dealing with closed or abandoned plugins.
Replace WordPress, plugin and theme files
WordPress core. Replace WordPress's own files with a fresh copy of the same version you're running. Using a different version can break the site.1 WordPress's documentation recommends replacing the wp-admin and wp-includes folders completely, rather than using the "Re-install" button in the dashboard, since that only overwrites existing files and won't remove new files an attacker has added.1 Don't overwrite or delete wp-content or wp-config.php, which hold your content and settings.
Plugins and themes. Replace each one with a fresh copy from its official source (WordPress.org for free plugins, or the developer's site for premium ones). Delete any you don't use. Never reinstall nulled or pirated plugins or themes. If you've made custom changes to a theme, compare it against a clean copy rather than replacing it outright, or ask whoever built it.
Check other files. Look at .htaccess, which attackers often change, and at recently modified files in wp-content/uploads/, your theme and your plugins.1 Code containing functions like eval() or base64_decode(), or long strings of scrambled text, deserves a close look, though some legitimate plugins use these too. If you're not sure whether something is malicious, compare it against a clean copy or ask a professional before deleting it.
Clean the database
Attackers sometimes put malicious content directly into the database, such as spam links or harmful JavaScript in posts, pages, comments, widgets or the wp_options table.
Take a fresh backup of the database before changing anything in it. Then search it, using phpMyAdmin or WP-CLI, for things like <script tags you didn't add, eval(, base64_decode( and long encoded strings.
Be very careful editing the database directly. It's easy to delete legitimate content or break your site's settings. If you're not confident, this is a good point to get professional help.
Remove backdoors and unknown users
Backdoors are hidden pieces of code that let the attacker back in after the obvious malware has gone. Common places include .php files in wp-content/uploads/, files with random-looking names in theme or plugin folders, code added to functions.php or wp-config.php, and plugins you didn't install (including in the must-use plugins list).
Remove what you're sure is malicious, keeping a copy in your backup of the hacked site. Delete user accounts you don't recognise. When WordPress asks what to do with a deleted user's content, check it first, since attackers sometimes attach spam posts to accounts they create. If an attacker has changed your own password or email address, our guide to regaining access to WordPress admin shows how to get back in.
Change every password and key
Assume every login connected to the site has been exposed, and change them all: every WordPress administrator and editor account, your hosting control panel, SFTP and FTP accounts and the database password. If you change the database password, update DB_PASSWORD in wp-config.php to match, with a copy of the file saved first.1
Also replace the security keys and salts in wp-config.php with fresh ones from the WordPress key generator. This logs everyone out, including any attacker who's still logged in.1
WordPress's documentation recommends changing passwords again once you're sure the site is clean, in case they were captured during the clean-up.1
If customer data may have been exposed
If the site holds personal information (customer accounts, orders, form submissions or mailing lists), a hack may count as a personal data breach, which can come with legal obligations such as reporting it within a set time. That's outside the scope of this guide. In the UK, the Information Commissioner's Office has guidance on data breaches and how to report one,5 and you should take appropriate advice promptly. If card payments may be affected, contact your payment provider too.
Request a review from Google
If Google flagged your site, request a review once you're confident it's clean. In Google Search Console, go to Security issues and submit a review request. Google says phishing reviews take about a day, malware reviews a few days and reviews for sites hacked with spam up to several weeks. Once Google confirms the site is clean, browser and search warnings are removed within about 72 hours.6 Other services, such as Bing and antivirus vendors, have their own processes.1
Make the site harder to hack again
- Update WordPress, every plugin and every theme to their latest versions, taking a backup first.
- Turn on two-factor authentication for administrator accounts and use strong, unique passwords.
- Limit repeated login attempts and consider a web application firewall. Our guide to dealing with WordPress spam covers login protection.
- Set up regular malware scans and file change monitoring.
- Keep regular backups stored away from your web server, so you always have a clean copy to go back to.
WordPress's hardening guide covers these and other security measures in more depth.7
Need professional help with a hacked site?
If you suspect a deep compromise, keep getting reinfected or aren't comfortable with these steps, my freelance WordPress development and emergency WordPress support services include malware removal, finding the cause, password and key resets and monitoring afterwards.
FAQ My site was hacked, WordPress.org Documentation. ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩
Why is my site labeled as dangerous in Google Search?, Search Console Help. ↩
wp core verify-checksums, WP-CLI Commands. ↩
wp plugin verify-checksums, WP-CLI Commands. ↩
Report a breach, Information Commissioner's Office. ↩
Request a review, Google for Developers. ↩
Hardening WordPress, WordPress Advanced Administration Handbook. ↩