Security
How to Find Hidden WordPress Malware in wp-content
If your WordPress site is suddenly showing spam links, strange redirects, or code you did not add, the problem often hides in wp-content, not in WordPress core. The safest approach is to back up first, then inspect the places malware usually lands: uploads, mu-plugins, themes, plugins, and database content.
The goal is not just to delete suspicious files. You also need to find how the malicious code got in, remove any backdoor, and close the door so it does not come back after the next update or cache clear.
What this usually looks like
WordPress malware and spam injections do not always announce themselves with a broken homepage. Often the site still loads, but you notice one or more of these symptoms:
- Spammy links or text appearing in posts, widgets, or the footer.
- Redirects to unfamiliar sites, especially on mobile or only for search engines.
- New admin users you did not create.
- Files appearing in
wp-content/uploadsthat look like images but are actually PHP or scripts. - Theme or plugin files changing when nobody on your team edited them.
- Search results showing strange page titles or snippets.
- Email alerts from your host about malware, phishing, or resource abuse.
Sometimes the only clue is that Google warns visitors away, or your pages start serving spam only in certain conditions. That is why this problem is easy to miss until it has already spread.
Where malware usually hides
Attackers prefer locations that blend in with normal site files or survive routine updates. In WordPress, that often means:
wp-content/uploads— especially oddly named PHP files or nested folders with scripts.wp-content/mu-plugins— must-use plugins load automatically and are easy to overlook.wp-content/plugins— especially nulled, abandoned, or modified plugins.wp-content/themes— particularlyfunctions.php,header.php, andfooter.php.- The database — spam can live in posts, widgets, options, and scheduled tasks.
If you want a broader cleanup workflow, our guide on WordPress site hacked cleanup covers the full incident response process. For sites showing spam injections specifically, this article focuses on the fastest places to check first.
Step 1: Make a safe backup before touching anything
Before deleting, editing, or replacing files, make a complete backup of the site files and database. If your host offers a snapshot or restore point, use it. If not, create a manual backup through your hosting control panel or SFTP plus database export.
This matters because malware cleanup can go wrong fast. A bad delete can take out a real file, and a forced update can overwrite evidence you may need to trace the entry point. If you are not sure how to back up safely, stop here and use a professional cleanup service.
Step 2: Compare core files against a clean WordPress install
WordPress core files should not contain custom malware. If you see altered files in wp-admin, wp-includes, or the root WordPress folders, that is a strong sign of compromise.
- Download a fresh copy of the same WordPress version if possible.
- Compare the site’s core folders against the clean copy.
- Replace any modified core files with clean originals.
Do not overwrite wp-config.php or the entire wp-content folder blindly. Those contain your settings, uploads, themes, and plugins. The goal is to restore trusted core files while preserving legitimate site data.
Step 3: Inspect uploads for PHP and other executable files
One of the most common malware patterns is a fake image or random-named file inside uploads. WordPress normally stores media files there, but it should not need executable PHP files in most setups.
Look for files that stand out because of their names, extensions, or timestamps. Red flags include:
.php,.phtml,.php5, or other script files in uploads.- Image files with strange file sizes or double extensions.
- Files with random characters in the name.
- Recently changed files in old upload folders.
If you find suspicious executable files in uploads, quarantine them first rather than deleting in bulk. Some hosts allow you to move them outside web root for review. If you remove the wrong file, you could break media or embedded content.
Step 4: Check themes, plugins, and must-use plugins
Malware often hides in places that execute on every page load. Open your active theme’s key files and look for code that seems out of place, especially long encoded strings, unfamiliar remote requests, or blocks inserted near the top or bottom of the file.
Common places to inspect:
functions.phpheader.phpfooter.php- Any recently edited plugin file
wp-content/mu-plugins
Be especially careful with plugins that were downloaded from unofficial sources. As we explain in Why Nulled Plugins Are a Time Bomb for WordPress, modified plugins are a common infection path and a common place for reinfection to persist.
The safest fix is usually to replace a suspicious plugin or theme with a fresh copy from a trusted source, not to patch it by hand.
Step 5: Search the database for spam injections
Not all malware lives in files. Spam can be injected into post content, widget text, custom fields, or site options. That is why a file-only cleanup sometimes looks successful at first and then the spam returns.
Check the database for unusual content such as:
- Unexpected links in posts or pages.
- Spam text in widgets or footer settings.
- Suspicious code in
wp_options, especially autoloaded options. - Unknown scheduled tasks or cron entries.
If you use a database tool, search for obvious spam phrases, unfamiliar domains, or code snippets you did not place there. If the site is large, this is where a lot of cleanup time gets lost, because malicious injections can be spread across hundreds of rows.
Step 6: Remove the backdoor, not just the visible spam
Cleaning the symptom is not enough if the attacker left a backdoor. Backdoors let malware return after the next page load, plugin update, or password reset.
Look for:
- Recently added admin users.
- Unknown files in unusual directories.
- Code that hides itself, decodes payloads, or fetches content from remote servers.
- Changes to
.htaccess,wp-config.php, or scheduled tasks.
After removing suspicious users and files, reset all passwords for administrators, hosting accounts, FTP/SFTP, database users, and any connected services. If the attacker had access to one credential, assume others may be exposed too.
Step 7: Replace, don’t patch, when you can
If a plugin or theme file is altered, replacing the entire component from a trusted source is usually safer than editing individual lines. Manual patching can leave behind a second payload, a hidden include, or a reinfection trigger.
Use clean versions from the official repository or the vendor you trust. Then reapply any legitimate customizations from a fresh baseline. If a plugin is abandoned, consider removing it entirely and finding a maintained alternative.
Step 8: Clear caches and verify the fix from the outside
After cleanup, clear every cache layer: WordPress caching plugins, host cache, CDN cache, and browser cache. Malware sometimes appears gone simply because the bad page is still being served from cache.
Then verify the site in a private browser window and, if possible, from another device or network. Check:
- The homepage and a few inner pages.
- Mobile and desktop views.
- Search snippets if the infection affected metadata.
- Forms, login, and any dynamic pages.
Our article on what to clear and when can help if the site still looks infected after cleanup but the underlying issue is already fixed.
How to keep it from coming back
Prevention is mostly about reducing the ways malicious code can land and stay hidden:
- Keep WordPress, plugins, and themes updated.
- Remove inactive plugins and themes you do not need.
- Avoid nulled or unofficial extensions.
- Use least-privilege admin access.
- Turn on backups and uptime monitoring.
- Review file integrity after updates, especially if the site has a history of compromise.
If you want a managed approach, Mend’s Care Plan includes updates, backups, security monitoring, and uptime checks. That is often the simplest way to prevent a repeat incident once the site is clean.
When to call a professional
Call for help if you are seeing redirects, database spam, strange admin users, or suspicious files and you are not sure which ones are safe to remove. Also get help if your host has already suspended the site, Google has flagged it, or the malware comes back after you clean it.
Those are all signs that there is more than one infection point or that a backdoor is still active. At that stage, a rushed cleanup can make the evidence harder to read and leave the site vulnerable again.
If you want a backup-first cleanup handled by senior WordPress engineers, start with a free Diagnosis or go straight to Emergency Rescue if the site is down or the infection is spreading. Every paid fix includes a plain-English report of the root cause and exactly what changed.
If you already know the site needs hands-on cleanup and you want it handled quickly, you can also use Mend Connect to share access securely without passwords.
The safest way to remove WordPress malware is to back up first, inspect the usual hiding places, replace compromised code with clean copies, and remove the backdoor that caused the infection in the first place. If that sounds like too much to juggle while your site is live, that is exactly the kind of work Mend handles every day.
Frequently asked questions
Can I just delete the suspicious file I found?
Sometimes, but not safely by default. Malware often has more than one file or a backdoor elsewhere, so deleting only the visible piece can leave the site reinfected.
Why do the spam links come back after I clean them?
Usually because the underlying infection is still present in a theme file, plugin, upload folder, database option, or scheduled task. You need to remove the source, not just the visible spam.
Is it safe to scan everything with a plugin?
Scanners can help spot common problems, but they can also miss hand-edited malware or database injections. Use them as a clue, not as the only cleanup step.
What should I do first if my host suspends the site?
Back up what you can, avoid random file edits, and contact the host to confirm what they detected. Then clean the infection and check for the entry point before restoring the site.