WordPress malware removal: hacked site cleaned, entry point closed and reputation restored on Google
Is your site redirecting visitors, showing a red warning in the browser or flagged as hacked on Google? Flowup treats a hack as an incident: it contains the damage, finds the vulnerability that let the attacker in, cleans files and database, requests the security review from Google and leaves the site harder to hack again.
Summary
WordPress malware removal in seven points
The essentials for anyone whose site is hacked right now. The details, the sources and the frequently asked questions are just below.
- In the first hours, do not delete files or restore a backup over the site: keep a copy of the current state, change the passwords and isolate the site if it is redirecting visitors.
- Most hacks exploit the predictable: in 2025 there were 11,334 new vulnerabilities in the WordPress ecosystem, 91% of them in plugins (Patchstack).
- Time works against you: 46% of those vulnerabilities had no fix when they were disclosed, and the weighted median time to the first exploit was 5 hours, with vulnerabilities weighted by how heavily they were attacked.
- A cleanup that only removes what is visible fails: almost half of the compromised sites analyzed by Sucuri had at least one backdoor, the door that reinstalls the malware.
- Google recommends identifying the vulnerability before cleaning, because a site can have more than one independent hack.
- Cleaning the site is half the job: the other half is removing the warnings from Google and from browsers, which depends on a review that takes from a few days to a few weeks.
- No serious provider guarantees that the site will never be hacked again. What reduces the risk is a fixed root cause, applied hardening and ongoing maintenance.
First hours
Hacked site: what to do now, before anything else
Most of the permanent damage comes not from the hack itself but from rushed reactions. While you bring in a specialist, follow this order.
Do not delete anything and do not restore a backup over the site
Suspicious files are evidence: they show where the attacker got in and how far they went. Restoring without a diagnosis erases the trail and, if the backup is also infected, the problem comes back.
Keep a copy of the current state
A full backup of the site as it is, infected and all, allows analysis, comparison with clean versions and a safe rollback of each step.
Change the passwords and end the sessions
WordPress (all administrators), hosting, FTP or SFTP, the database and the administrators' email accounts. Turn on two-step authentication. Write down the unknown users before deleting them.
Isolate the site if it is attacking visitors
If visitors are being redirected to scams or to file downloads, a maintenance page protects the public and the domain's reputation while the incident is handled.
After these steps, bring in a professional response. Every day the malware stays live increases the indexed spam, the redirected visitors and the risk of being blocked by browsers and email providers.
Signs of a hack
How to tell if your WordPress site has been hacked or has a virus
Not every infection shows up on the home page, and some of it hides from logged-in users. These are the most common signs.
Strange redirects
Visitors, sometimes only those arriving from Google or on a phone, are sent to gambling, pharmacy or scam sites. The owner, logged in, often sees nothing.
Warning in the browser and on Google
The browser shows a red screen for a deceptive or dangerous site, and search labels the result with "This site may be hacked".
Indexed spam pages
A search for site:yourdomain.com returns thousands of URLs you never created, often in Japanese or selling pharmaceutical products.
Unknown administrators and files
Users nobody created, plugins nobody installed, PHP files in the uploads folder and changes with no author.
Domain emails landing in spam
Company messages landing in spam or being blocked, a sign that the server may be sending spam or that the domain has been added to blocklists.
Slowness and hosting alerts
Processing spikes, a site that is suddenly slow, a suspended account or a notice from the hosting provider about malicious files.
Any one of these signs is reason to treat the case as an active incident. The absence of visible symptoms does not guarantee a clean environment.
Process
How Flowup removes malware from WordPress sites
An incident response process, not an automated scan. Each step is logged, and the client receives the incident report.
Triage, containment and entry point
Analysis of the logs and the environment, a copy of the current state, immediate containment of redirects and spam sending, and identification of the exploited vulnerability, before any cleanup.
Full cleanup
Removal of backdoors, shells, injections in files and in the database, and malicious users and scheduled tasks, with the core, the themes and the plugins compared against the official versions.
Fix and hardening
Safe updates, replacement of abandoned extensions, file permissions, the built-in editor disabled, strong passwords, two-step authentication and firewall rules.
Google review and follow-up
Removal of the indexed spam, a security review request in Search Console, tracking of the browser warnings and monitoring over the following days.
Technical checklist
What is checked in a WordPress malware cleanup
Well-written malware hides where a quick scan does not look. The cleanup covers the layers where it usually survives.
Files and server
- WordPress core compared against the official checksums.
- Themes and plugins compared against the versions in the official repositories.
- The uploads folder, where no PHP code should exist.
- wp-config.php, .htaccess, mu-plugins and startup files.
- FTP, SFTP and SSH accounts and scheduled tasks on the server.
Database and content
- Altered database options, such as the site address and injected scripts.
- Posts, pages and widgets with hidden scripts, iframes or links.
- Administrator users created by the attacker.
- WordPress scheduled tasks that reinstall the malware.
- Generated spam pages and URLs indexed on Google.
Comparison
Security plugin, backup or professional cleanup?
All three exist and each one solves a different problem. The mistake is expecting from one the result of another.
| Criterion | Security plugin | Restore a backup | Professional cleanup |
|---|---|---|---|
| Detects the infection | Partly: known signatures | Detects nothing | Yes, including obfuscated code and database injections |
| Removes hidden backdoors | Rarely, and they are what reinfects the site | Only if the backup predates the hack, which may be months old | Yes, by comparison with the official versions and manual analysis |
| Fixes the cause | No: the vulnerability is still there | No: it restores the same vulnerability | Yes: it identifies and closes the entry point |
| Removes the Google warnings | No | No | Yes: spam removed, and the security review requested and followed up |
| Ideal role | Prevention and alerts | Insurance against disasters, if tested | Incident response, from diagnosis to prevention |
Google and browsers
Cleaning the site is half the job: the other half is cleaning the reputation
After the hack, the damage lives on in the indexes: spam ranking under your domain, a warning in search, a red screen in the browser and blocked emails.
- 5B+devices protected every day by Safe Browsing, the service behind the warning screens in Chrome and other browsers.Google Safe Browsing
- Daysto a few weeks: the time Google indicates for completing a security review, once everything has been fixed.Google Search Console
- 6 monthsis roughly how long a temporary URL removal lasts in Search Console: it hides the page but does not solve the problem.Google Search Console
- 404or 410 is the response the spam pages need to return to leave the index for good.Google Search Console
Flowup treats this recovery as a formal stage of the service: a survey of what was improperly indexed, a 404 or 410 response for the spam pages, removal requests for the most visible ones, a fix for everything the Search Console Security Issues report flags and, only then, the review request. Requesting it before everything is fixed can delay the next review and get the site marked as a repeat offender. The follow-up continues until the warnings are gone from search and from browsers.
When the domain has landed on email blocklists, the cleanup includes checking those lists and submitting the removal requests, along with a review of the domain's email sending records.
Reinfection
Why superficial cleanups fail and the site gets hacked again
The pattern Flowup sees most often: the site was "cleaned" by a plugin, by a restore or by removing what was in plain sight, and was hacked again within days.
The reason is usually the same. Something was left behind: a backdoor hidden in a legitimate file, a hidden administrator or a scheduled task that reinstalls the malware. And the original vulnerability, the outdated plugin or the leaked password, is still open.
The numbers explain why attackers move fast: in 2025, 46% of the vulnerabilities in the WordPress ecosystem had no fix when they were disclosed, and about half of the high-impact vulnerabilities were exploited within 24 hours (Patchstack). In Sucuri's analysis, 49.21% of compromised sites had at least one backdoor.
That is why Google puts identifying the vulnerability before the cleanup in its recovery guide, and notes that a single site can have more than one independent hack.
Malware removed without closing the entry point is not a cleanup. It is a pause between hacks.
Prevention
WordPress security: what prevents the next hack
Prevention is a discipline, not a product. The official WordPress.org recommendations and the OWASP Top 10 point to the same practices.
Disciplined updates
Core, themes and plugins kept up to date, tested first in a staging environment, and abandoned extensions replaced.
Access under control
Strong passwords, two-step authentication, few administrators and access revoked when someone leaves.
Environment hardening
Correct file permissions, the built-in editor disabled, a database user with minimum privileges and an application firewall.
Backups that restore
Copies kept off the server, with a restore test. A backup that has never been restored is a hypothesis, not a guarantee.
Monitoring
Alerts for file changes, availability and security issues in Search Console.
Fast response
A defined plan for when something happens: who is called in, what is preserved and how fast.
For companies that need this discipline as a continuous operation: updates tested in staging, backups with verified restores, security and availability monitoring, and reports. The entry diagnosis is the WordPress Health Score.
Learn about WordPress EngineeringWhat you get
What a professional response gives back to the business
Every incident ends with the site clean, the cause addressed and documentation of what was done.
Site clean and running
Malware removed from files and database, redirects stopped and integrity checked against the official versions.
Incident report
Probable origin, what was found, what was removed, what was changed and what we still recommend doing.
Risk under management
Vulnerability fixed, hardening applied and a prevention plan proportional to the size of the site.
Timeline and investment
How long does it take and how much does it cost to remove malware from a WordPress site?
The scope comes out of a quick triage and is put in writing, before any charge.
- Hours to a few daysis the typical timeline for the technical cleanup, depending on the size of the site and the depth of the compromise.
- Days to weeksis Google's timeline for the security review, counted from the request made once everything is fixed.
The price takes into account:
- The size of the site and the number of installations on the same server.
- The extent of the compromise: files, database, server and email.
- The need to restore the site's reputation on Google and on blocklists.
- The urgency: sites that are down or blocked get priority.
Next step
Is your site behaving strangely?
Tell us what is happening. The initial triage indicates whether it is a hack, how urgent it is and what the scope is, before any commitment.
Quick triageScope in writingNo impossible promises
Report the incident on WhatsAppWe have been Flowup's partners for more than 10 years and, over that time, our trust has only grown stronger. The service is excellent and the commitment to our requests is total. The team understands our needs, meets deadlines and delivers consistent quality.
Read the case study
Punctuality, quality and attention to each client's needs. That is our experience of working with Flowup, always very quick to find the most suitable and up-to-date solutions. They are preferred partners of MediaLink.
I am glad to record my satisfaction in working with Flowup. A positive experience: an attentive team, quick service, quality deliveries and care in every detail of the website. I was pleased with the final result and recommend their services with confidence.
Read the case study
Frequently asked questions
Frequently asked questions about malware removal and hacked sites
The questions that come up most often in searches and in incident calls.
Dealing with a case right now? Tell us what is happening and get the initial triage.
Report the incidentMy WordPress site was hacked: what should I do first?
How do I know if my WordPress site has a virus?
How do I remove malware from a WordPress site?
Does a security plugin remove malware on its own?
Does restoring a backup solve the hack?
Why was my site hacked?
How do I remove the "This site may be hacked" warning from Google?
How do I remove the red dangerous-site screen from the browser?
How long does malware removal take?
How much does it cost to remove malware from a WordPress site?
Will I lose content or data in the cleanup?
Do I need to notify customers or Brazil's data protection authority (ANPD) about the hack?
Does the cleanup guarantee the site will not be hacked again?
Do you handle urgent cases, and companies outside Brazil?
Transparency
Sources and references
This page relies on official documentation from Google, WordPress.org and OWASP, reports from security companies and Brazil's data protection law (LGPD) to support its statements about hacks, cleanup, security review and prevention.
- Security Issues report, Search Console Help: how to request the review after the fix, and a timeline of a few days to a few weeks.
- Help, I think I've been hacked, web.dev (Google): Google's recovery guide, with identifying the vulnerability before the cleanup.
- Identify the vulnerability, web.dev (Google): the possibility of more than one independent hack on the same site.
- Removals and SafeSearch reports tool, Search Console Help: temporary removal lasting about six months and the need for a 404 or 410 for permanent removal.
- Google Safe Browsing: the service that helps protect over 5 billion devices every day.
- State of WordPress Security in 2026, Patchstack (February 25, 2026): 11,334 vulnerabilities in 2025, 91% in plugins, 46% without a fix at disclosure and a weighted median of 5 hours to the first exploit, with vulnerabilities weighted by how heavily they were attacked.
- Backdoors: The Hidden Threat Lurking in Your Website, Sucuri (January 17, 2025): 49.21% of compromised sites with at least one backdoor, with data from the 2023 report.
- Hardening WordPress, WordPress.org: official security recommendations: updates, passwords, permissions, file editor and backups.
- OWASP Top 10:2025: a reference for security risks in web applications.
- Lei Geral de Proteção de Dados (LGPD), Article 48: Brazil's data protection law (in Portuguese), on notifying the national authority (ANPD) and the data subjects of a security incident.
How to cite this page
Flowup Agency. WordPress malware removal: hacked site cleaned, entry point closed and reputation restored on Google. Guto Bertoncini, updated on . flowup.agency/en/wordpress-malware-removal/
Every hour the malware stays live increases the damage
Talk to Flowup now: incident triage, scope in writing and priority for critical cases. If the site has not been hacked and you want to prevent it, start with WordPress Engineering.
5.0 on Google · Since 2011 · Case studies with stated sources









