This week I was on a call with a business owner who couldn’t work out why her website kept redirecting visitors to a pharmacy site in another language. Nothing in the WordPress dashboard looked wrong. No warning banner, no obvious broken page, just a handful of customers messaging her asking why her site tried to sell them sleeping pills.
That’s malware. And it’s more common than most site owners realise.
What is WordPress malware?
Malware is malicious code that someone else has planted on your website without your permission. Think of it like a burglar getting a spare key cut for your house, they’re not smashing a window to get in, they’re quietly letting themselves in the side door and using the place while you’re not looking.
Once it’s in, that code can do almost anything: redirect your visitors, send spam email from your server, steal customer data, or just sit quietly in the background waiting to be used for something worse.
How do you actually get malware on a WordPress site?
It rarely happens because someone specifically targeted your business. Most infections are automated, bots scanning millions of sites at once for an unlocked door, and WordPress sites give them a lot of doors to try.
The most common ones I see:
- An outdated plugin or theme with a known security hole that’s never been patched
- A weak or reused admin password
- A “nulled” or pirated premium theme or plugin downloaded for free, often with malware baked in from the start
- Hosting that doesn’t isolate your site from others on the same shared server
- No firewall or malware scanning in place to catch the first attempt
None of these are exotic mistakes. They’re the kind of thing that happens when a busy business owner hasn’t looked at their website’s backend in eight months, which, to be honest, is most business owners.
Weakened security or plugins that haven’t been updated is the biggest issue I see, time and again. One of the biggest threats is that you might not even know you have malware until it’s too late.
That’s the part that catches people out. Malware doesn’t always announce itself.
How do you know if your WordPress site has malware?
Sometimes it’s obvious, a defaced homepage, a browser warning, an email from your hosting company saying your site’s been suspended. But just as often, the signs are quiet enough that you’d miss them if you weren’t looking.
Keep an eye out for:
- Your site redirecting visitors to a different website, especially one you don’t recognise
- Google flagging your site as “dangerous” or “hacked” in search results
- A sudden spike in outgoing email from your server, often reported by your host before you notice it yourself
- New admin users in WordPress that you didn’t create
- Unusual files appearing in your website’s folders, especially ones with random or garbled names
- Your site running noticeably slower, because malware is quietly using your server’s resources for something else
None of these on their own guarantee malware. But if you spot more than one, it’s worth taking seriously.
What are the dangers of leaving WordPress malware in place?
This is where it stops being an inconvenience and starts being a business problem. Google can blacklist an infected site from search results within days, and getting removed from that blacklist afterwards takes real time and effort. Your hosting provider can suspend the account entirely to protect their other customers, taking your website and your business email offline in one go.
Then there’s the data. If your site handles customer details, payments, or contact forms, malware can be a route for someone to steal that information quietly in the background. For a business trading in Ireland, that’s not just a technical headache, it’s a data protection problem too.
And there’s the trust cost, which is harder to measure but just as real. A customer who gets redirected to a suspicious site once probably won’t come back a second time to find out if it’s fixed.
How do you remove WordPress malware?
Here’s where I’ll admit something most guides skip over. There’s no single “delete this file and you’re done” fix, and anyone who tells you otherwise is probably about to leave the actual problem in place.
The biggest misconception is that removing the visible malware means the website is fixed. With a hacked WordPress site, the obvious infected file is often only the symptom. Attackers may have left backdoors, rogue admin accounts, database injections, scheduled tasks, modified core files, or hidden code elsewhere on the hosting account. If you simply delete the file that triggered the warning, the infection can reappear days later.
A proper clean-up is really three separate jobs, not one:
- Remove the infection completely, including the files, database entries, backdoors and unauthorised users involved.
- Work out how they got in, whether that’s a vulnerable plugin or theme, outdated software, a compromised password, the hosting account itself, or an abandoned site nobody’s looked at in a while.
- Close the door afterwards, through updates, password resets, access key changes, security hardening, backups and monitoring going forward.
Skip any one of those three and you’re likely to be back here again in a few months.
If you’re comfortable in WordPress and confident with your hosting control panel, a security plugin with a malware scanner is a reasonable starting point for step one. For steps two and three, most business owners are better off bringing in someone who does this regularly. It’s not that you couldn’t learn it, it’s that getting it wrong once can cost you far more time than getting help would have.
(Flagging for you: this is a natural spot to mention that a host with built-in malware scanning, like SiteGround, catches a lot of this before it becomes a full clean-up job, if you want the affiliate link worked in here, let me know and I’ll place it.)
I’ve walked a few clients in different industries through exactly this process, and the pattern’s always the same: the sooner it’s caught, the smaller the job.
If your site’s showing any of the warning signs above, the safest first move is to stop guessing and get someone to actually look at it. You can book a short call and I’ll tell you honestly what you’re dealing with and what it’ll take to fix, no pressure either way.
FAQs
Can I remove WordPress malware myself?
If you’re technically confident and catch it early, a security plugin can handle the first pass. But because attackers often leave more than one way back in, most site owners get a cleaner result bringing in help for the full clean-up.
Will Google blacklist my site if it has malware?
Yes, this can happen quickly once Google’s crawlers detect malicious code or redirects, and getting delisted afterwards takes a formal review process, not just fixing the site.
How do I stop my WordPress site getting reinfected?
Close the door that let the malware in the first time, updated plugins and themes, strong unique passwords, and ongoing monitoring, rather than just removing the infection and hoping it doesn’t come back.



