HostingRank AI
Tutorial

WordPress Malware Recovery: Clean a Hacked Site Fast (2026)

Recover a hacked WordPress site: identify the hack, clean files and database, and harden everything. Includes a step-by-step recovery checklist.

Updated: 2026-08-19·8 min read

First: the honest truth about recovery

If your WordPress site is hacked, the fastest reliable fix is usually a clean restore, not a cleanup. Hand-deleting malware is a race against obfuscated backdoors you might not see — while the hacker still holds their access. The proven sequence below minimizes both downtime and recurrence. Prevention is the real cure — that's the security checklist.

Step 1: Assess the damage

Before touching anything, document:

  • Signs — redirects to spam, weird pages, admin logins failing, Google "this site may be hacked" warnings
  • Timeline — when did it start? What changed right before (a plugin update, a password reuse)?
  • Scope — unknown admin users, files in /uploads that aren't yours, modified theme files

Run a scanner (Wordfence, or your host's malware scanner) to map what it finds. Screenshot everything — you'll need it if you involve your host or a cleanup service.

Step 2: Restore or clean

If you have a clean backup (from before the hack):

  1. Wipe everything on the server
  2. Restore the files and database from the clean backup
  3. Update WordPress, themes, and plugins immediately

If you have no clean backup, clean in place:

  1. Reinstall WordPress core (Update → Reinstall)
  2. Delete unknown plugins/themes; reinstall clean copies of the ones you use
  3. Replace wp-config.php (it's safe to regenerate) and check for injected code
  4. Clean the database — unknown admin users and injected content — via phpMyAdmin or a cleanup plugin

A fresh restore is 30 minutes and definitive. Hand-cleaning can take a day and still miss a backdoor.

Step 3: Rotate every credential

The hacker's access survives a cleanup unless you kill it:

  • [ ] WordPress admin passwords (every user, especially admins)
  • [ ] Database user password (update wp-config.php after)
  • [ ] Hosting panel password
  • [ ] FTP/SFTP passwords
  • [ ] Email passwords (a hacked mailbox re-hacks you)
  • [ ] Any API keys the site uses

Then add 2FA to every admin account and the hosting panel. This is the step people skip — it's the one that stops round two.

Step 4: Harden and monitor

Apply the full security checklist:

  • Strong unique passwords + 2FA
  • Automatic updates for core, themes, and plugins
  • A web application firewall (Cloudflare or Wordfence)
  • Limit login attempts
  • Daily backups — off-site, tested

Then set up monitoring so an injection triggers an alert instead of a silent infection. Consider telling your host — many will scan for you and confirm the site is clean.

When to call in help

If the hack is severe (spam redirects at scale, blacklisted IPs, ransom notes, or you lack a clean backup):

  • Your host — many include malware cleanup (SiteGround's are famous; others charge)
  • Sucuri / Wordfence cleanup services — professional malware removal for ~$100–200 one-time
  • Google Search Console — request review after the site is verified clean, to clear the "hacked" flag

Frequently asked questions

How do I know if my WordPress site is hacked? Redirects, unknown admins, strange files in uploads, failing logins, or Google's hacked warning. Scanner tools (Wordfence, Sucuri SiteCheck) confirm it.

What is the fastest way to remove malware from WordPress? Restore from a clean pre-hack backup — it wipes the infection in one step. If no backup exists, reinstall core, replace plugins/themes, and clean the database. Backups guide.

Do I need to pay for malware removal? Often not — a clean restore plus credential rotation fixes most sites. Paid cleanup (Sucuri, host services) is for severe infections or when you lack a clean backup.

Why does my WordPress site keep getting hacked? Because something was left vulnerable — usually an old password, no 2FA, or an outdated plugin. The security checklist closes each one.

Will my host clean a hacked WordPress site? Some do — SiteGround offers malware removal; others scan but don't clean. Ask during the support conversation, and check what your plan includes.

Get the monthly benchmark report

New TTFB and uptime data, price drops, and hosting deals. No spam.

More tutorials