-
Back up the current site
Before you change anything, make a full backup of files and the database. Store it off the infected server so the backup is not rewritten by malware. -
Put the site in maintenance mode
Keep visitors off the site while you clean. A short maintenance message is enough. Estimated downtime helps set expectations. -
Find how the attack got in
Review server logs, login history, and Security Ninja findings. Look for weak passwords, outdated plugins or themes, nulled software, or unexpected admin users. You need the entry point so it does not reopen. -
Remove malware from identified files
Use Malware Scanner (and other trusted tools if needed) to list infected files. Delete or replace only what you have confirmed. Quarantine copies if you want a record before removal. -
Replace compromised WordPress core files
Restore core files to clean copies for your WordPress version. Core Scanner can help compare and restore against wordpress.org checksums. -
Inspect the database
Search for injected<script>tags, odd admin users, and spam content. Remove malicious rows carefully. Keep a database backup first. -
Update WordPress, themes, and plugins
Apply available updates after the site is stable. Remove software you no longer need, especially closed or abandoned plugins. -
Harden access
Reset passwords for all admins and hosting accounts. Review file permissions. Turn on 2FA where you can. Consider a firewall (including Security Ninja Cloud Firewall if you use Pro). -
Scan again for backdoors
Run Malware Scanner and Core Scanner again after cleanup. Attackers often leave a second door. Repeat until findings are gone or explained. -
Watch for new activity
Use Event Logger and scheduled scans so you notice new file changes or logins early. -
Brief anyone with admin access
Share simple rules: no shared passwords, no nulled plugins, report odd emails that ask for login. -
Schedule regular checks
Keep vulnerability scanning and scheduled scans enabled. Update software on a routine, not only after an incident. -
Get help if needed
If cleanup is beyond what you can finish safely, WP Security Ninja offers scoped malware cleanup and a fixed-price security review.
For a longer walkthrough, see WordPress malware removal.