Malware on a hosted website usually shows up as strange redirects, unexpected pop-ups, a Google "This site may be hacked" warning, or a direct notification from your hosting provider. The response process is the same regardless of how it was discovered.

Step 1: Confirm and Contain

  • Change all passwords immediately — hosting account, cPanel, CMS admin, database, FTP.
  • Take the site offline temporarily (maintenance mode) if it is actively serving malicious content to visitors.
  • Contact your hosting provider — some offer malware scanning and removal as part of their support or a paid add-on.

Step 2: Identify the Scope

  1. Scan all files for recently modified timestamps around the suspected infection window.
  2. Use a malware scanning plugin (for WordPress) or a server-level scanner if your host provides one.
  3. Check for unfamiliar admin users or unexpected scheduled tasks that may have been added.

Step 3: Clean the Infection

  • Restore from a clean backup taken before the infection date, if one exists — often the fastest, most reliable fix.
  • If no clean backup exists, manually remove malicious code identified by scans, or reinstall core CMS files fresh while preserving only verified-clean content.
  • Update every plugin, theme and CMS core to current versions — outdated software is the most common infection vector.

Step 4: Verify and Request Delisting

  • Rescan thoroughly to confirm the infection is fully removed before bringing the site back online.
  • If Google flagged the site, use Google Search Console to request a malware review after cleanup.
  • Monitor closely for several weeks after cleanup for any signs of reinfection.

Preventing Reinfection

  1. Keep every plugin, theme and CMS core updated promptly.
  2. Remove unused plugins and themes entirely rather than leaving them deactivated.
  3. Enforce strong, unique passwords and enable two-factor authentication on admin accounts.
  4. Install a reputable security plugin with active malware scanning.

Frequently Asked Questions

Can my hosting provider clean the malware for me?

Many providers offer this as part of managed hosting or as a paid service — worth asking directly rather than attempting complex cleanup alone if uncertain.

How did the malware get in if I have a password?

Most infections come through outdated, vulnerable plugins or themes rather than password compromise — updating everything promptly is the single highest-impact prevention step.

Need help cleaning an infected website? Contact our support team or get help now.