Malware in WordPress
It's not a virus that 'got on' your site. It's a tenant with keys.
WordPress malware isn't a file you delete — it's an occupancy. Modern infections install multiple ways back in before doing anything visible, which is why the delete-the-weird-file approach produces the classic pattern: clean Tuesday, reinfected Friday. Eviction means finding every key, not just the tenant.
Same-day diagnosis. Flat quote before any fix.
What’s actually happening
Understand the occupancy and the cleanup logic follows. An infection's first act is persistence: backdoor files scattered in innocent-looking places (wp-content/uploads is a favorite — nobody audits image folders for PHP), rogue administrator accounts, malicious cron jobs that re-download the payload on schedule, and code appended to legitimate plugin and theme files so the 'infection' is inside software you'd never delete. The visible symptoms — spam pages, redirects, defacement — are the tenant's business operations. The keys are the point.
This architecture explains both scanner limits and reinfection. Scanners pattern-match known signatures; obfuscated payloads, freshly-written backdoors, and database-resident injections (malicious code living in wp_options or widget content, not in any file) walk past them. And a cleanup that removes what the scanner found — but not the cron job, the extra admin, or the uploads-folder backdoor — has simply annoyed the tenant. Complete eviction is systematic: core and plugin files verified against known-good copies, uploads audited for executables, database swept, accounts and scheduled tasks reviewed, and the original entry point (usually an outdated component or stolen credential) closed so the story doesn't repeat.
The usual causes, ranked
After twenty-seven years of these calls, the odds are well mapped. Start at the top.
Outdated components as the door
Known vulnerabilities in old plugins, themes, and core — automated exploitation at internet scale. The overwhelmingly common entry.
Stolen or weak credentials
Reused passwords, phished logins, no two-factor — the attacker walks in the front door as you.
Nulled 'premium' themes and plugins
Pirated software with malware pre-installed — infection by invitation, at setup time.
Cross-contamination on shared hosting
One infected site in an account infecting its neighbors through shared file permissions — cleanup must cover the whole account or it's theater.
What you can safely try first
Nothing below can make things worse — that’s the selection criterion. Anything riskier belongs in professional hands, on a backup.
- 1
Change passwords from a clean device
Hosting, WordPress admins, database, FTP — from a computer you trust, not the possibly-keylogged one. Do this first; everything else assumes it.
- 2
Inventory the visible symptoms
Redirects (to where?), spam pages (site:yourdomain.com shows them), browser warnings, host suspension notice. The symptom set hints at the infection family and its age.
- 3
Check Search Console's Security Issues
If Google flagged the site, the panel lists example infected URLs — free reconnaissance, and the same panel where the post-cleanup review gets requested.
Stop and call when…
- Reinfection after cleanup attempts — proof of surviving backdoors that pattern-matching won't find
- Google flags, browser warnings, or host suspension — third parties are involved and their review processes have sequences
- The site takes payments or holds customer data — disclosure obligations may attach, and the cleanup must preserve evidence
From there it’s our job: same-day look, flat quote, and the $579 flat repair covers most cases of exactly this.
Malware Cleanup — buy it now, skip the hunt.
Hacked site cleaned, secured, and submitted for blacklist review — done right, done once.
Covers one WordPress or PHP site: infection removal, core and plugin integrity restore, admin lockdown, and Google review submission. Includes a 30-day recheck.
Questions we hear a lot.
I deleted the malicious files. Why is it back?
Because you evicted the furniture and left the keys. Reinstallation-on-schedule is the signature of a surviving persistence mechanism — a cron job, a backdoor in the uploads folder, code inside a legitimate plugin file, or a database injection. Each survives file-deletion cleanups by design. Finding all of them is the actual job; the visible malware was the easy part.
Won't a security plugin's scanner handle this?
Scanners are useful smoke detectors and mediocre firefighters. They catch known signatures; they miss obfuscated payloads, novel backdoors, database-resident code, and anything the attacker wrote last week. Post-infection, a scanner's 'clean' verdict means 'nothing I recognize' — which is exactly what a well-hidden backdoor is. Verification against known-good files is the standard that matters.
What does the $579 cleanup include?
The complete eviction: every file verified against clean copies, uploads and database swept, rogue accounts and cron jobs removed, the entry point identified and closed, hardening applied (updates, credentials, lockdown), Google review requested if flagged — plus a 30-day recheck, because the honest test of a malware cleanup is the month after it. Same scope as our malware cleanup service, flat.
Related symptoms & help
Errors travel in packs. If this one visited, check its friends.
Every key found. Every door closed. Rechecked in 30.
Send the symptom, get a same-day look and a flat quote from the developer who's fixed this exact thing more times than either of us can count.