WordPress malware removal: hacked site cleaned, entry point closed and reputation restored on Google

Is your site redirecting visitors, showing a red warning in the browser or flagged as hacked on Google? Flowup treats a hack as an incident: it contains the damage, finds the vulnerability that let the attacker in, cleans files and database, requests the security review from Google and leaves the site harder to hack again.

By Guto Bertoncini, founder and lead strategist of FlowupUpdated on 15 min read

5.0 on GoogleSince 2011Proprietary B.I.N.A. Method

  • ABAL logo
  • Ayvens logo
  • IBGE logo
  • HPROJ logo
  • SCA Brasil logo
  • Rewood logo
  • Salvatore Leilões logo
  • Société Générale logo
  • KINTO logo
  • Servimed logo

Summary

WordPress malware removal in seven points

The essentials for anyone whose site is hacked right now. The details, the sources and the frequently asked questions are just below.

  • In the first hours, do not delete files or restore a backup over the site: keep a copy of the current state, change the passwords and isolate the site if it is redirecting visitors.
  • Most hacks exploit the predictable: in 2025 there were 11,334 new vulnerabilities in the WordPress ecosystem, 91% of them in plugins (Patchstack).
  • Time works against you: 46% of those vulnerabilities had no fix when they were disclosed, and the weighted median time to the first exploit was 5 hours, with vulnerabilities weighted by how heavily they were attacked.
  • A cleanup that only removes what is visible fails: almost half of the compromised sites analyzed by Sucuri had at least one backdoor, the door that reinstalls the malware.
  • Google recommends identifying the vulnerability before cleaning, because a site can have more than one independent hack.
  • Cleaning the site is half the job: the other half is removing the warnings from Google and from browsers, which depends on a review that takes from a few days to a few weeks.
  • No serious provider guarantees that the site will never be hacked again. What reduces the risk is a fixed root cause, applied hardening and ongoing maintenance.

First hours

Hacked site: what to do now, before anything else

Most of the permanent damage comes not from the hack itself but from rushed reactions. While you bring in a specialist, follow this order.

  1. Do not delete anything and do not restore a backup over the site

    Suspicious files are evidence: they show where the attacker got in and how far they went. Restoring without a diagnosis erases the trail and, if the backup is also infected, the problem comes back.

  2. Keep a copy of the current state

    A full backup of the site as it is, infected and all, allows analysis, comparison with clean versions and a safe rollback of each step.

  3. Change the passwords and end the sessions

    WordPress (all administrators), hosting, FTP or SFTP, the database and the administrators' email accounts. Turn on two-step authentication. Write down the unknown users before deleting them.

  4. Isolate the site if it is attacking visitors

    If visitors are being redirected to scams or to file downloads, a maintenance page protects the public and the domain's reputation while the incident is handled.

After these steps, bring in a professional response. Every day the malware stays live increases the indexed spam, the redirected visitors and the risk of being blocked by browsers and email providers.

Signs of a hack

How to tell if your WordPress site has been hacked or has a virus

Not every infection shows up on the home page, and some of it hides from logged-in users. These are the most common signs.

  • Strange redirects

    Visitors, sometimes only those arriving from Google or on a phone, are sent to gambling, pharmacy or scam sites. The owner, logged in, often sees nothing.

  • Warning in the browser and on Google

    The browser shows a red screen for a deceptive or dangerous site, and search labels the result with "This site may be hacked".

  • Indexed spam pages

    A search for site:yourdomain.com returns thousands of URLs you never created, often in Japanese or selling pharmaceutical products.

  • Unknown administrators and files

    Users nobody created, plugins nobody installed, PHP files in the uploads folder and changes with no author.

  • Domain emails landing in spam

    Company messages landing in spam or being blocked, a sign that the server may be sending spam or that the domain has been added to blocklists.

  • Slowness and hosting alerts

    Processing spikes, a site that is suddenly slow, a suspended account or a notice from the hosting provider about malicious files.

Any one of these signs is reason to treat the case as an active incident. The absence of visible symptoms does not guarantee a clean environment.

Process

How Flowup removes malware from WordPress sites

An incident response process, not an automated scan. Each step is logged, and the client receives the incident report.

  1. Triage, containment and entry point

    Analysis of the logs and the environment, a copy of the current state, immediate containment of redirects and spam sending, and identification of the exploited vulnerability, before any cleanup.

  2. Full cleanup

    Removal of backdoors, shells, injections in files and in the database, and malicious users and scheduled tasks, with the core, the themes and the plugins compared against the official versions.

  3. Fix and hardening

    Safe updates, replacement of abandoned extensions, file permissions, the built-in editor disabled, strong passwords, two-step authentication and firewall rules.

  4. Google review and follow-up

    Removal of the indexed spam, a security review request in Search Console, tracking of the browser warnings and monitoring over the following days.

Technical checklist

What is checked in a WordPress malware cleanup

Well-written malware hides where a quick scan does not look. The cleanup covers the layers where it usually survives.

Files and server

  • WordPress core compared against the official checksums.
  • Themes and plugins compared against the versions in the official repositories.
  • The uploads folder, where no PHP code should exist.
  • wp-config.php, .htaccess, mu-plugins and startup files.
  • FTP, SFTP and SSH accounts and scheduled tasks on the server.

Database and content

  • Altered database options, such as the site address and injected scripts.
  • Posts, pages and widgets with hidden scripts, iframes or links.
  • Administrator users created by the attacker.
  • WordPress scheduled tasks that reinstall the malware.
  • Generated spam pages and URLs indexed on Google.

Comparison

Security plugin, backup or professional cleanup?

All three exist and each one solves a different problem. The mistake is expecting from one the result of another.

Comparison of a security plugin, a backup restore and a professional malware cleanup
CriterionSecurity pluginRestore a backupProfessional cleanup
Detects the infectionPartly: known signaturesDetects nothingYes, including obfuscated code and database injections
Removes hidden backdoorsRarely, and they are what reinfects the siteOnly if the backup predates the hack, which may be months oldYes, by comparison with the official versions and manual analysis
Fixes the causeNo: the vulnerability is still thereNo: it restores the same vulnerabilityYes: it identifies and closes the entry point
Removes the Google warningsNoNoYes: spam removed, and the security review requested and followed up
Ideal rolePrevention and alertsInsurance against disasters, if testedIncident response, from diagnosis to prevention

Google and browsers

Cleaning the site is half the job: the other half is cleaning the reputation

After the hack, the damage lives on in the indexes: spam ranking under your domain, a warning in search, a red screen in the browser and blocked emails.

  • 5B+devices protected every day by Safe Browsing, the service behind the warning screens in Chrome and other browsers.Google Safe Browsing
  • Daysto a few weeks: the time Google indicates for completing a security review, once everything has been fixed.Google Search Console
  • 6 monthsis roughly how long a temporary URL removal lasts in Search Console: it hides the page but does not solve the problem.Google Search Console
  • 404or 410 is the response the spam pages need to return to leave the index for good.Google Search Console

Flowup treats this recovery as a formal stage of the service: a survey of what was improperly indexed, a 404 or 410 response for the spam pages, removal requests for the most visible ones, a fix for everything the Search Console Security Issues report flags and, only then, the review request. Requesting it before everything is fixed can delay the next review and get the site marked as a repeat offender. The follow-up continues until the warnings are gone from search and from browsers.

When the domain has landed on email blocklists, the cleanup includes checking those lists and submitting the removal requests, along with a review of the domain's email sending records.

Reinfection

Why superficial cleanups fail and the site gets hacked again

The pattern Flowup sees most often: the site was "cleaned" by a plugin, by a restore or by removing what was in plain sight, and was hacked again within days.

The reason is usually the same. Something was left behind: a backdoor hidden in a legitimate file, a hidden administrator or a scheduled task that reinstalls the malware. And the original vulnerability, the outdated plugin or the leaked password, is still open.

The numbers explain why attackers move fast: in 2025, 46% of the vulnerabilities in the WordPress ecosystem had no fix when they were disclosed, and about half of the high-impact vulnerabilities were exploited within 24 hours (Patchstack). In Sucuri's analysis, 49.21% of compromised sites had at least one backdoor.

That is why Google puts identifying the vulnerability before the cleanup in its recovery guide, and notes that a single site can have more than one independent hack.

Malware removed without closing the entry point is not a cleanup. It is a pause between hacks.

Prevention

WordPress security: what prevents the next hack

Prevention is a discipline, not a product. The official WordPress.org recommendations and the OWASP Top 10 point to the same practices.

  • Disciplined updates

    Core, themes and plugins kept up to date, tested first in a staging environment, and abandoned extensions replaced.

  • Access under control

    Strong passwords, two-step authentication, few administrators and access revoked when someone leaves.

  • Environment hardening

    Correct file permissions, the built-in editor disabled, a database user with minimum privileges and an application firewall.

  • Backups that restore

    Copies kept off the server, with a restore test. A backup that has never been restored is a hypothesis, not a guarantee.

  • Monitoring

    Alerts for file changes, availability and security issues in Search Console.

  • Fast response

    A defined plan for when something happens: who is called in, what is preserved and how fast.

WP CareFlowup's WordPress Engineering

For companies that need this discipline as a continuous operation: updates tested in staging, backups with verified restores, security and availability monitoring, and reports. The entry diagnosis is the WordPress Health Score.

Learn about WordPress Engineering

What you get

What a professional response gives back to the business

Every incident ends with the site clean, the cause addressed and documentation of what was done.

  • Site clean and running

    Malware removed from files and database, redirects stopped and integrity checked against the official versions.

  • Incident report

    Probable origin, what was found, what was removed, what was changed and what we still recommend doing.

  • Risk under management

    Vulnerability fixed, hardening applied and a prevention plan proportional to the size of the site.

Timeline and investment

How long does it take and how much does it cost to remove malware from a WordPress site?

The scope comes out of a quick triage and is put in writing, before any charge.

  • Hours to a few daysis the typical timeline for the technical cleanup, depending on the size of the site and the depth of the compromise.
  • Days to weeksis Google's timeline for the security review, counted from the request made once everything is fixed.

The price takes into account:

  • The size of the site and the number of installations on the same server.
  • The extent of the compromise: files, database, server and email.
  • The need to restore the site's reputation on Google and on blocklists.
  • The urgency: sites that are down or blocked get priority.

Next step

Is your site behaving strangely?

Tell us what is happening. The initial triage indicates whether it is a hack, how urgent it is and what the scope is, before any commitment.

Quick triageScope in writingNo impossible promises

Report the incident on WhatsApp

Clients

What clients say about working with Flowup

5.0on Google, since 2011
We have been Flowup's partners for more than 10 years and, over that time, our trust has only grown stronger. The service is excellent and the commitment to our requests is total. The team understands our needs, meets deadlines and delivers consistent quality.
Alexandre H. FerreiraHPROJ Planejamento e Projetos. Translated from Portuguese.
Read the case study
Punctuality, quality and attention to each client's needs. That is our experience of working with Flowup, always very quick to find the most suitable and up-to-date solutions. They are preferred partners of MediaLink.
Adhemar AltieriMediaLink. Translated from Portuguese.
I am glad to record my satisfaction in working with Flowup. A positive experience: an attentive team, quick service, quality deliveries and care in every detail of the website. I was pleased with the final result and recommend their services with confidence.
Gabriela RibeiroRewood. Translated from Portuguese.
Read the case study

See clients and testimonials

Frequently asked questions

Frequently asked questions about malware removal and hacked sites

The questions that come up most often in searches and in incident calls.

Dealing with a case right now? Tell us what is happening and get the initial triage.

Report the incident
My WordPress site was hacked: what should I do first?
Do not delete files or restore a backup over the site. Keep a copy of the current state, change the passwords for administrators, hosting, FTP and the database, turn on two-step authentication and, if the site is redirecting visitors, put up a maintenance page. Then bring in a professional cleanup.
How do I know if my WordPress site has a virus?
The most common signs are redirects to other sites, a red warning in the browser, the "This site may be hacked" label on Google, strange pages when you search site:yourdomain, unknown administrators, sudden slowness and domain emails landing in spam. Some malware hides from logged-in users, so the absence of symptoms does not guarantee a clean site.
How do I remove malware from a WordPress site?
In the order Google recommends: contain the damage, identify the exploited vulnerability, clean files, database, users and scheduled tasks, fix the vulnerability and harden security, and only then request the security review in Search Console. Removing only what is visible usually leaves backdoors that reinstall the malware.
Does a security plugin remove malware on its own?
Rarely in full. Plugins detect known signatures and are useful for prevention and alerts, but they tend to leave behind obfuscated code and database injections, which are exactly what reinfects the site. And no plugin fixes the vulnerability that allowed the hack or removes the Google warnings.
Does restoring a backup solve the hack?
Only if the backup is proven to predate the hack, and many infections stay hidden for weeks or months before the symptoms appear. Restoring also returns the site to the same vulnerable version that was exploited. A backup is insurance against disasters, not incident response.
Why was my site hacked?
In most cases, through a plugin or theme with a known vulnerability that was not updated, a weak or leaked password, or poorly configured hosting. In 2025, 91% of the new vulnerabilities in the WordPress ecosystem were in plugins, and WordPress core had only six, all low priority (Patchstack).
How do I remove the "This site may be hacked" warning from Google?
After the full cleanup, the spam pages need to return 404 or 410, the issues flagged in the Search Console Security Issues report need to be fixed, and only then is the review requested. Google indicates that the review takes from a few days to a few weeks. Flowup submits the request and follows it through to completion.
How do I remove the red dangerous-site screen from the browser?
The warning comes from Google Safe Browsing, used by Chrome and other browsers. It goes away after the site is cleaned and the security review is approved. Requesting the review before everything is fixed delays the process and can get the site marked as a repeat offender.
How long does malware removal take?
The technical cleanup of a typical site takes from a few hours to a few days, depending on the size of the environment and the depth of the compromise. Removing the Google warnings depends on the review carried out by Google itself, which can take from a few days to a few weeks.
How much does it cost to remove malware from a WordPress site?
It depends on the size of the site, the extent of the compromise, the need to restore the site's reputation on Google and on blocklists, and the urgency. The quote comes out of a quick initial triage, with the scope in writing. Critical cases, with the site down or blocked, get priority.
Will I lose content or data in the cleanup?
That is not the expected outcome. The cleanup removes what does not belong to the site, such as malicious code, users and tasks, and preserves legitimate content, media and settings. The copy made at the start makes it possible to roll back any step safely.
Do I need to notify customers or Brazil's data protection authority (ANPD) about the hack?
It depends on what was exposed. If personal data is involved, such as account records, forms or orders, Brazil's data protection law (LGPD) may require notifying the national authority (ANPD) and the data subjects when the incident may cause relevant risk or harm. Flowup helps map what was affected; the decision and the notification are up to the company, with legal advice.
Does the cleanup guarantee the site will not be hacked again?
No, and be wary of anyone who guarantees it: no environment is invulnerable. What consistently reduces the risk is the combination of a fixed root cause, applied hardening and ongoing maintenance, with tested updates, monitoring and verified backups.
Do you handle urgent cases, and companies outside Brazil?
Yes. Critical cases get priority, and all the work, from triage to follow-up, is done remotely. Flowup is based in São Paulo, Brazil, and serves companies in Brazil, the United States, Canada and worldwide, with projects in Portuguese, English and Spanish.

Transparency

Sources and references

This page relies on official documentation from Google, WordPress.org and OWASP, reports from security companies and Brazil's data protection law (LGPD) to support its statements about hacks, cleanup, security review and prevention.

  1. Security Issues report, Search Console Help: how to request the review after the fix, and a timeline of a few days to a few weeks.
  2. Help, I think I've been hacked, web.dev (Google): Google's recovery guide, with identifying the vulnerability before the cleanup.
  3. Identify the vulnerability, web.dev (Google): the possibility of more than one independent hack on the same site.
  4. Removals and SafeSearch reports tool, Search Console Help: temporary removal lasting about six months and the need for a 404 or 410 for permanent removal.
  5. Google Safe Browsing: the service that helps protect over 5 billion devices every day.
  6. State of WordPress Security in 2026, Patchstack (February 25, 2026): 11,334 vulnerabilities in 2025, 91% in plugins, 46% without a fix at disclosure and a weighted median of 5 hours to the first exploit, with vulnerabilities weighted by how heavily they were attacked.
  7. Backdoors: The Hidden Threat Lurking in Your Website, Sucuri (January 17, 2025): 49.21% of compromised sites with at least one backdoor, with data from the 2023 report.
  8. Hardening WordPress, WordPress.org: official security recommendations: updates, passwords, permissions, file editor and backups.
  9. OWASP Top 10:2025: a reference for security risks in web applications.
  10. Lei Geral de Proteção de Dados (LGPD), Article 48: Brazil's data protection law (in Portuguese), on notifying the national authority (ANPD) and the data subjects of a security incident.
How to cite this page

Flowup Agency. WordPress malware removal: hacked site cleaned, entry point closed and reputation restored on Google. Guto Bertoncini, updated on . flowup.agency/en/wordpress-malware-removal/

Every hour the malware stays live increases the damage

Talk to Flowup now: incident triage, scope in writing and priority for critical cases. If the site has not been hacked and you want to prevent it, start with WordPress Engineering.

5.0 on Google · Since 2011 · Case studies with stated sources