Scanner says core files were modified? Open the diff. After wp2shell, that is often leftover access.

How to read it

WordPress Malware Cleanup: DIY or Hire Help?

After you confirm a WordPress hack: when to clean malware yourself, when to hire cleanup, what a good incident response includes, and how to avoid paying twice.

Topics Malware & cleanup

WordPress Malware Cleanup: DIY or Hire Help? Open larger image: WordPress Malware Cleanup: DIY or Hire Help?

You confirmed the hack. Now the question is whether you clean WordPress malware yourself or hire help. This page is only that decision. It is not a second services catalog.

Start with signs if you are not sure yet: how to tell if your WordPress site is hacked. For step-by-step removal, use the WordPress malware removal guide. For the broader plugin vs retainer picture, see WordPress security services.

What cleanup actually means

Cleanup is not one scan click. The useful order:

  1. Contain so visitors and customers are not harmed
  2. Regain access via hosting, SFTP, or database if wp-admin is gone
  3. Restore or remove malicious files and database junk
  4. Rotate credentials for WordPress, hosting, FTP, and email
  5. Close the entry point (vulnerable plugin, weak login, nulled software)
  6. Rescan and watch for reinfection

Skip a step and you often pay twice: once for a shallow clean, again when the backdoor wakes up.

When DIY cleanup is reasonable

DIY works when most of these are true:

  • You still have hosting panel, SFTP, or database access
  • You have a known-good backup from before the compromise (and you tested restores before)
  • Traffic is low enough that a few hours of maintenance mode is acceptable
  • You can rotate passwords and API keys without breaking integrations you forgot about
  • You are willing to read file diffs, trash unknown plugins, and update everything after

Tools that help: malware scanner, vulnerability scanner, core scanner, and the full playbook in WordPress malware removal.

Free Security Ninja covers tests, vulns, and core integrity. Pro adds scheduled malware scans for after you are back online.

When to hire cleanup instead

Call for help when:

  • You are locked out of wp-admin and hosting credentials may be compromised
  • Malware returns within 24 to 48 hours after you “cleaned” it
  • The site takes payments and you need checkout back fast with less guesswork
  • Search Console or customers already report phishing or card skimming
  • You do not know which backup is clean, or backups stopped months ago
  • Legal or client SLA pressure means you need a documented incident response

WP Security Ninja offers a fixed-scope security review and malware cleanup. That is human time, not another dashboard subscription.

DIY vs hire at a glance

SituationLean toward
Clean backup exists, low traffic, you have SFTPDIY with the removal guide
Unknown admins, redirects live, no backupHire or restore from host snapshots first
Reinfection after shallow cleanHire or escalate DIY to full credential rotation
Store checkout affectedHire or take checkout offline until restore is proven
“We just need someone to watch it”Plugin + care plan, not emergency cleanup

What to ask any cleanup provider

Before you pay anyone (including us):

  • Do they restore from backup or hand-edit live files?
  • Will they document what was found and what changed?
  • Are credentials rotated included, or only file deletion?
  • Is there a follow-up scan window if it comes back?
  • What is out of scope (SEO recovery, legal notices, PCI)?

Vague “we secure WordPress” without those answers is a red flag. More on choosing vendors: WordPress security services.

After cleanup: do not stop at removal

Removal without hardening invites the same door:

If the incident was scary, use the removal guide and your plugin stack. You do not need a permanent retainer unless scope says so.

Bottom line

DIY cleanup is viable when you have access, a clean backup, and time to rotate everything. Hire help when you are locked out, reinfection returns, or the business cost of guessing is too high. Either way, removal is one chapter. Hardening and monitoring are the next.

Found this useful? Share it.

Frequently asked questions

Can I remove WordPress malware myself? +

Often yes, if you still have hosting or SFTP access, a clean backup to restore from, and time to rotate every credential. DIY fails when you are locked out, the infection returns within hours, or you cannot find the backdoor. Then hire help or use a documented cleanup service.

When should I hire WordPress malware cleanup? +

Hire when wp-admin is gone, reinfection keeps happening, customer data may be exposed, you have an SLA to hit, or you do not trust your own file review. A one-time cleanup beats guessing under pressure.

Is a security plugin the same as malware cleanup? +

No. A plugin helps you scan, block, and harden going forward. Cleanup is the incident work: contain, remove or restore, rotate access, close the entry hole. Plugins support recovery. They do not replace hands-on removal when the site is already owned.

How much does WordPress cleanup cost? +

DIY costs your time plus possible downtime. Paid cleanup varies by scope: a review is cheaper than full removal on a busy store. WP Security Ninja offers fixed-price review and cleanup options on the consultation page. Get scope in writing before you pay.

Larger screenshot

Enlarged image