How to remove a virus from WordPress: a complete technical guide
Removing a virus from WordPress should not consist solely of running a scanner and deleting the files it detects. Effective cleanup requires checking core files, plugins, the theme, the database, user accounts, hosting configuration, and other websites running on the same account.
The following instructions are intended for people with experience administering WordPress, databases, and servers. Deleting the wrong file or record can cause data loss or take the website completely offline.
Before you begin
Prepare access to the hosting control panel, SFTP or SSH access, database access, a backup of the files and database, a way to check server logs, a clean computer for changing passwords, and a list of recent updates and changes to the website. Do not clean the website without first backing up its current state, even if it is infected.
Step 1 — Restrict the website's operation
If the website redirects visitors, displays malicious content, or steals data, temporarily restrict its availability. You can put up a technical notice, limit access to selected IP addresses, or ask your hosting provider to isolate the account temporarily.
A standard maintenance-mode plugin may not stop malicious code running outside WordPress.
Step 2 — Make a complete backup
Secure all WordPress files, the complete database, the .htaccess and wp-config.php files, PHP configuration, cron jobs, server logs, and lists of active plugins and users. Store the backup outside the website's public directory.
Step 3 — Change all access credentials
From a secure device, change the passwords for the hosting control panel, SFTP and FTP, SSH, the WordPress dashboard, the database, email accounts, the domain registrar, and backup services.
After changing the database password, remember to update the credentials in wp-config.php. Also replace the WordPress security keys to invalidate existing user sessions.
Step 4 — Check user accounts
In the WordPress dashboard and directly in the database, check administrator accounts, email addresses, account creation dates, assigned roles, unusually named accounts, and users that are not visible in the standard dashboard.
Delete accounts whose origin cannot be verified. Change the passwords of legitimate administrators. Also check whether a plugin or malicious code is recreating a user.
Step 5 — Replace WordPress core files
Download a clean copy of WordPress from the official source and replace the wp-admin and wp-includes directories. In the root directory, replace the standard WordPress files, taking care with wp-config.php, .htaccess, and verification files.
Do not automatically overwrite the wp-content directory, because it contains website content, themes, plugins, and user files.
Step 6 — Reinstall plugins
The safest approach is to remove a plugin's files and upload a clean version from an official or verified source. Check whether every plugin is needed, is still maintained, comes from a legitimate source, and has any known security issues.
Remove inactive and unused extensions. So-called nulled plugins and themes downloaded from unofficial sources are particularly risky.
Step 7 — Check the active theme
Compare the theme files with a clean version from its developer. Pay particular attention to functions.php, header.php, footer.php, files responsible for redirects, additional PHP files, JavaScript files, and directories with random names.
If you use a child theme, check both the parent theme and the child theme.
Step 8 — Inspect the uploads directory
In wp-content/uploads, check for PHP files, executable files, hidden directories, additional .htaccess files, randomly named files, and scripts disguised as images.
Do not automatically delete all PHP files. Some legitimate extensions may create them, although they require careful verification.
Step 9 — Check wp-config.php
Review the entire wp-config.php file and look for code placed before the PHP opening tag, code added at the end of the file, decoding functions, references to external domains, additional files loaded with include or require, and unknown variables and constants.
Step 10 — Check .htaccess files and PHP configuration
An infection may use redirects, rules that run PHP files, automatic inclusion of a malicious file, or changes to how file extensions are handled. Check .htaccess, .user.ini, php.ini, and additional .htaccess files in subdirectories.
Not every custom rule is malicious; it may come from a cache or security plugin, or from the hosting configuration.
Step 11 — Check mu-plugins and drop-ins
Frequently overlooked locations include the wp-content/mu-plugins directory and drop-ins such as object-cache.php, advanced-cache.php, db.php, and sunrise.php. These files may be loaded automatically even if they do not appear in the standard plugin list.
Step 12 — Check the database
Search for suspicious content in the options table, post and page content, widgets, theme settings, user data, scheduled tasks, and configuration for active plugins.
Look for foreign JavaScript, iframes, encoded strings, references to unknown domains, and SEO spam. Do not run bulk find-and-replace operations without a database backup.
Step 13 — Check cron jobs
WordPress and the hosting environment can run automated tasks. Check WordPress Cron, cron jobs in the hosting control panel, scripts that run periodically, and tasks that restore deleted files.
If malware reappears after a few minutes or hours, an active scheduled task may be the cause.
Step 14 — Check other websites on the hosting account
The same account may contain other WordPress websites, Joomla installations, old versions of the website, test copies, unused subdomains, or archived directories. Any of them could be the source of reinfection; cleaning just one domain is not enough.
Step 15 — Run a security scanner
A scanner can help detect modified core files, known malware signatures, suspicious URLs, and unsafe extensions. Do not treat the scanner's results as definitive confirmation: malicious code may be in the database, cron jobs, or server configuration.
Step 16 — Update and secure the website
After cleanup: update WordPress, plugins, and the theme; remove unused components; enable two-factor authentication; limit the number of administrators; apply secure file permissions; configure regular backups; and enable file-change monitoring.
Step 17 — Test the website
Check logins, forms, email delivery, store functionality, payments, the administrator dashboard, mobile display, server errors, redirects, and any new files created after the website starts running. Monitor logs and file modification dates for the following days.
Step 18 — Ask Google to review the website
If the website was flagged as unsafe, check the security report, confirm that all reported issues have been resolved, describe the actions taken, and submit a review request in Google Search Console. Do not submit a request before cleanup is complete.
Why might the virus return?
The most common causes of reinfection are a backdoor left behind, an uncleaned database, another infected website on the hosting account, a compromised FTP account, a vulnerable plugin, a cron job, an unknown administrator, or automatic restoration of an old backup. If malware returns, it usually means that the entire infection mechanism was not removed.
When should you not clean the website yourself?
Arrange professional help if the website is an online store, stores customer data, the hosting provider has blocked the entire account, the infection keeps returning, you do not have a reliable backup, you do not recognize most of the files, the website contains custom code, or the hosting account contains multiple installations.