- Discovering malware on your website is stressful, but a calm, methodical process fixes it faster than panic ever does.
- Here is exactly what to do, step by step.
Malware on a hosted website usually shows up as strange redirects, unexpected pop-ups, a Google "This site may be hacked" warning, or a direct notification from your hosting provider. The response process is the same regardless of how it was discovered.
Step 1: Confirm and Contain
- Change all passwords immediately — hosting account, cPanel, CMS admin, database, FTP.
- Take the site offline temporarily (maintenance mode) if it is actively serving malicious content to visitors.
- Contact your hosting provider — some offer malware scanning and removal as part of their support or a paid add-on.
Step 2: Identify the Scope
- Scan all files for recently modified timestamps around the suspected infection window.
- Use a malware scanning plugin (for WordPress) or a server-level scanner if your host provides one.
- Check for unfamiliar admin users or unexpected scheduled tasks that may have been added.
Step 3: Clean the Infection
- Restore from a clean backup taken before the infection date, if one exists — often the fastest, most reliable fix.
- If no clean backup exists, manually remove malicious code identified by scans, or reinstall core CMS files fresh while preserving only verified-clean content.
- Update every plugin, theme and CMS core to current versions — outdated software is the most common infection vector.
Step 4: Verify and Request Delisting
- Rescan thoroughly to confirm the infection is fully removed before bringing the site back online.
- If Google flagged the site, use Google Search Console to request a malware review after cleanup.
- Monitor closely for several weeks after cleanup for any signs of reinfection.
Preventing Reinfection
- Keep every plugin, theme and CMS core updated promptly.
- Remove unused plugins and themes entirely rather than leaving them deactivated.
- Enforce strong, unique passwords and enable two-factor authentication on admin accounts.
- Install a reputable security plugin with active malware scanning.
Frequently Asked Questions
Can my hosting provider clean the malware for me?
Many providers offer this as part of managed hosting or as a paid service — worth asking directly rather than attempting complex cleanup alone if uncertain.
How did the malware get in if I have a password?
Most infections come through outdated, vulnerable plugins or themes rather than password compromise — updating everything promptly is the single highest-impact prevention step.
Need help cleaning an infected website? Contact our support team or get help now.