Home About Services Projects Blog Contact Policy
Malware Removal

Hacked WordPress Site? Step-by-Step Recovery and Malware Removal

AuthorEslam Abdullah

Published

Reading time

10 min read

Hacked WordPress site recovery guide cover with a shield-virus icon and chips for scan, clean, harden and Google review

Quick answer

If your WordPress site is hacked, first contain it: take a copy of the infected site for evidence, change every password (hosting, SFTP, database, admin) and put the site in maintenance mode. Then replace core, plugins and themes with clean copies, remove backdoors and rogue admin users from files and the database, and fix the vulnerability that let the attacker in. Finally, request a review in Google Search Console so warnings are removed.

Finding out your WordPress site has been hacked is stressful: customers see spam, Google shows a red warning, or your host suspends the account. The good news is that almost every hacked WordPress site can be recovered if you work methodically. The bad news is that a quick "delete the bad file" cleanup usually fails, and the site gets reinfected within days.

This is the recovery process I follow when I remove malware from WordPress sites. It works whether you do it yourself or hand it to a professional.

Signs your WordPress site has been hacked

Some hacks are obvious; many are designed to stay hidden from the site owner. Watch for:

  • Google Search results showing spam titles (often pharma, casino or Japanese keywords) for your domain.
  • A "This site may be hacked" or "Deceptive site ahead" warning, or an alert in Search Console's Security issues report.
  • Visitors redirected to other sites, often only on mobile or only when they arrive from Google, so you never see it when logged in.
  • New administrator accounts you did not create, or your own password no longer working.
  • Unknown files in wp-content/mu-plugins, PHP files inside uploads, or plugins you never installed.
  • Sudden CPU spikes, outgoing spam emails, or a suspension notice from your host.

Sucuri's research shows how common these patterns are: SEO spam was found on 20.30% of the sites it remediated, and in 2025 it documented malware hiding in the mu-plugins folder that redirected visitors, opened a remote-code backdoor and hijacked links.

The first hour: contain the damage

  1. Stay calm and document. Note what you saw, when, and any recent changes (new plugin, new user, theme update). Take screenshots.
  2. Back up the infected site. Download all files and export the database. This copy is evidence and a safety net; label it clearly as infected.
  3. Change every credential. Hosting panel, SFTP/SSH, database user, every WordPress admin, and the email account tied to the admin. Do it from a clean device.
  4. Limit the damage. Put the site in maintenance mode or restrict it by IP, especially for stores that take payments.
  5. Tell your host. On shared hosting, other sites on the same account may be infected too, and the host may have useful logs.
  6. Scan your own computer. Stolen admin sessions sometimes come from malware on the owner's laptop.

Do not restore a random old backup or delete files blindly before you have a copy. You may destroy the evidence you need to find the entry point, and you may restore a backup that already contains the backdoor.

How to find the malware

Scan from outside and inside

Use a remote scanner such as Sucuri SiteCheck to see what visitors and Google see, then a server-side scanner such as Wordfence to inspect files. Scanners are a starting point, not a verdict: new or obfuscated code is often missed.

Verify files against official checksums

If you have SSH access, WP-CLI is the fastest way to spot modified files. wp core verify-checksums --include-root compares core files with WordPress.org and lists anything that does not belong in the root, and wp plugin verify-checksums --all does the same for plugins from the official directory.

Where malware usually hides

  • wp-content/mu-plugins: loads automatically and does not appear in the normal plugins list.
  • wp-content/uploads: there should be no PHP files here at all.
  • .htaccess, index.php, wp-config.php and the theme's functions.php, header.php and footer.php.
  • Recently modified files: find . -name "*.php" -mtime -7 lists PHP files changed in the last seven days.
  • Suspicious functions such as eval, base64_decode, gzinflate and long encoded strings.

Do not forget the database

Check the users table for unknown administrators, the options table for changed siteurl/home values and injected scripts, and posts for hidden links or <script> tags. Sucuri reported that 55.2% of sites with database malware also had malicious admin accounts.

Step-by-step WordPress malware removal

  1. Reinstall WordPress core. Replace wp-admin and wp-includes completely with a fresh download of the same or latest version.
  2. Replace plugins and themes. Delete each plugin folder and install a fresh copy from WordPress.org or the vendor. Remove anything nulled, abandoned or unused.
  3. Clean wp-content. Remove PHP files from uploads, inspect mu-plugins, and review custom code line by line.
  4. Clean the database. Delete rogue admins, remove injected scripts and spam posts, and check scheduled tasks (cron) for strange entries.
  5. Rebuild wp-config.php. Start from a clean copy, regenerate the salts and keys, and add DISALLOW_FILE_EDIT.
  6. Reset all passwords again. Now that the backdoors are gone, change them once more and enforce 2FA for every admin.
  7. Update everything. Bring core, plugins, themes and PHP to supported versions.
  8. Rescan and monitor. Scan again, check the site as a logged-out mobile visitor, and watch logs for a few weeks.

Why so thorough? Because Sucuri found at least one backdoor in 49.21% of compromised sites. If you remove the visible spam but leave one backdoor, the attacker simply walks back in.

Extra steps for WooCommerce stores and membership sites

When a site handles orders, payments or student and customer accounts, a hack is also a data question, not just a cleanup job. On these sites I add a few more checks:

  • Inspect the checkout page as a real customer, because card-skimming scripts often load only on checkout.
  • Review payment gateway settings, webhook URLs and API keys, and rotate every key after the cleanup.
  • Check for new shop managers, changed order emails or modified refund settings.
  • Ask customers to reset their passwords if the users table may have been read.
  • Take legal advice on whether you must notify customers under the data protection rules that apply to you.

Restore a backup or clean manually?

OptionBest whenRisk
Restore a clean backupYou know when the hack started and have a backup from before that dateYou lose content since the backup; the vulnerability is still there unless you patch it
Manual cleanupNo clean backup, or the site changes daily (stores, news)Takes longer and needs experience to find every backdoor
Rebuild on a fresh serverHeavy or repeated infection, or the whole hosting account is compromisedMost work, but the most reliable result

In practice I often combine them: restore or rebuild the code from clean sources, then carefully migrate the current content and orders from the infected database.

Remove Google warnings and blacklists

Once the site is clean, open the Security issues report in Google Search Console, confirm every listed issue is fixed across the whole site, and click Request review. Explain what you found, what you removed and how you closed the entry point.

Google's web.dev documentation gives these typical timings: phishing reviews take about a day, malware reviews a few days, and reviews for sites hacked with spam can take several weeks. After Google confirms the site is clean, warnings are removed from browsers and search results within about 72 hours. Also check other blocklists, such as Bing Webmaster Tools and your antivirus vendors.

Stop the site from getting hacked again

Cleaning without finding the cause is the most common reason sites are reinfected. Check access logs around the infection date to identify the vulnerable plugin, stolen login or weak server setting, then fix it.

  • Update or remove the plugin that was exploited, and follow security news such as the 30+ plugins backdoored in April 2026.
  • Enforce 2FA, least-privilege roles and login rate limiting.
  • Add a web application firewall (WAF) and file integrity monitoring.
  • Keep automatic off-site backups with at least 30 days of history.

My full prevention checklist is in the WordPress security checklist 2026.

How much does WordPress malware removal cost in Egypt?

These are approximate 2026 market ranges in Egypt, not my price list. Every infected site is quoted after an initial scan.

CaseApproximate range (EGP)
Simple infection on a small site (redirect or injected script)2,500 – 7,000
SEO spam, backdoors and database cleanup6,000 – 15,000
WooCommerce or LMS site, or repeated reinfection12,000 – 30,000+
Full rebuild on a new server with data migrationQuoted per project

For reference, a Saudi hosting provider lists a basic WordPress malware cleanup at 450 SAR. What drives the price: the size of the site and database, how many sites share the hosting account, whether there is a clean backup, whether payment or customer data is involved, Google blacklist removal, and how urgently the site must be back online.

Need your hacked site fixed today?

I am Eslam Abdullah, a WordPress developer and web security specialist with 8+ years of experience and 450+ delivered projects. I clean the site, remove backdoors from files and the database, close the entry point, handle the Google review and hand you a clear report of what happened.

Send me your site details through the contact form and I will start with a quick assessment.

Key takeaways

  • Contain first, clean second: back up the infected site for evidence and change every password before touching files.
  • Assume there is a backdoor: Sucuri found at least one backdoor in 49.21% of the compromised sites it cleaned.
  • Replace, do not repair: reinstall core, plugins and themes from official sources and verify them with WP-CLI checksums.
  • Check the database too: rogue admin users and injected scripts often survive a file-only cleanup.
  • Close the entry point and request a Google review, or the site will be reinfected and stay flagged.

Frequently asked questions

Can a hacked WordPress site be fully recovered?

In almost all cases, yes. Core, plugins and themes can be replaced with clean copies, and content can be cleaned or migrated from the database. The key is removing every backdoor and fixing the vulnerability that was used.

Is a security plugin enough to remove malware from WordPress?

Plugins help you find infected files, but they often miss obfuscated backdoors, database injections and rogue admin accounts. A reliable cleanup combines scanning, checksum verification, manual review and hardening.

Why does my WordPress site keep getting hacked again?

Usually because a backdoor was left behind or the original vulnerability was never fixed. Sucuri found at least one backdoor in 49.21% of compromised sites, so a surface cleanup is rarely enough.

How long does Google take to remove the hacked warning?

According to Google, phishing reviews take about a day, malware reviews a few days, and spam hack reviews can take several weeks. Warnings are then removed within about 72 hours.

Should I just restore an old backup?

Only if you are sure the backup predates the infection, and you still need to patch the entry point and change all passwords. Otherwise you may restore the backdoor along with the site.

Need a hand with this?

I can do it for you – fast, secure and done right the first time. Free consultation on WhatsApp.

Sources