
What is malware and how does it infect websites?
Malware is any malicious software designed to harm, exploit, or take control of a system, and on a website it usually takes the form of hidden code planted in your files or database that redirects visitors, injects spam, steals data, or gives attackers a backdoor. Websites typically get infected through outdated or vulnerable plugins and themes, stolen or weak passwords, insecure hosting, pirated "nulled" software, and compromised third-party scripts.
Website malware is different from the viruses you might think of on a desktop computer. It often doesn't crash anything or show obvious signs. Instead, it works quietly in the background, sometimes only showing itself to search engines or first-time mobile visitors, which is why infections can go unnoticed for weeks. This article explains the main types of website malware, exactly how infections happen, the warning signs to look for, and the practical steps you can take to prevent them.
What Does Malware Look Like on a Website?
On a website, malware is usually made of ordinary web code, such as PHP, JavaScript, HTML, or SQL data, written to do something harmful. It can live in several places:
- PHP files: Injected into theme files, plugin files, WordPress core files, or disguised as new files with harmless-sounding names.
- The database: Hidden inside posts, widgets, options, or user records.
- JavaScript files: Appended to legitimate scripts so every page loads the malicious code.
- Server configuration: Rules added to
.htaccessor other config files to redirect visitors. - Scheduled tasks: Cron jobs or WordPress scheduled events that reinfect the site after cleanup.
- Uploads folder: PHP files placed among images and documents.
Attackers often obfuscate their code, hiding it behind layers of encoding so it looks like random characters. Functions like eval(), base64_decode(), gzinflate(), and str_rot13() used together in unexpected places are a common red flag, although these functions also have legitimate uses.
Common Types of Website Malware
Backdoors
A backdoor is code that gives the attacker ongoing access to your site, even after you change passwords or remove other malware. It might be a tiny PHP file that executes commands sent to it, a hidden admin user, or a modified core file. Backdoors are the reason infections keep coming back after a partial cleanup.
Malicious Redirects
Redirect malware sends some or all visitors to another site, often scams, fake prize pages, adult content, or other malware. It frequently uses conditions to avoid detection, such as redirecting only mobile visitors, only visitors coming from search engines, or only people who aren't logged in. This means you, as the logged-in owner, may never see it.
SEO Spam
SEO spam injects links, keywords, or entire pages to manipulate search rankings for the attacker's benefit. Well-known variants include pharmaceutical spam and the Japanese keyword hack, which creates thousands of auto-generated pages in Japanese. These pages may be shown only to search engine crawlers, a technique called cloaking, so visitors can't see them.
Card Skimmers
Also known as Magecart-style attacks, card skimmers are JavaScript injected into checkout pages that capture payment card details as customers type them and send them to the attacker. They're particularly dangerous for e-commerce sites running WooCommerce or other shopping platforms.
Phishing Pages
Attackers may upload fake login pages for banks, email providers, or other services to your site, using your domain's reputation to make their phishing campaigns look more convincing.
Spam Mailers
Mailer scripts use your server to send large volumes of spam or phishing email. This can get your server's IP blacklisted, hurting deliverability for your legitimate email.
Cryptominers
Cryptojacking scripts either use your server's CPU to mine cryptocurrency or run in visitors' browsers to use their devices. Signs include unexplained high CPU usage and slow performance.
Defacements
Defacements replace your content with the attacker's message. They're obvious, less common than stealthy infections, and usually motivated by bragging or activism.
How Malware Infects Websites
Malware doesn't appear on its own. It gets in through a vulnerability or a stolen credential. Here are the most common entry points.
1. Vulnerable Plugins and Themes
This is by far the most common cause on WordPress sites. When a vulnerability is found and disclosed in a plugin or theme, attackers use automated scanners to find sites running the vulnerable version and exploit them. Common vulnerability types that lead to infections include:
- Arbitrary file upload: Letting attackers upload a PHP file directly.
- Privilege escalation: Letting a low-level user become an administrator.
- Remote code execution: Letting attackers run code on the server.
- SQL injection: Letting attackers modify the database, for example to create an admin account.
- Stored cross-site scripting: Injecting JavaScript that runs when an admin views a page.
Plugins and themes that are outdated, abandoned, or even just deactivated but still installed can be exploited.
2. Weak or Stolen Credentials
If an attacker gets valid login details for your WordPress admin, hosting control panel, SFTP, or database, they can upload malware directly. Credentials are stolen through:
- Brute force and credential stuffing attacks.
- Phishing emails.
- Malware on your own computer, such as info-stealers that grab saved passwords.
- Reused passwords leaked in breaches of other services.
- Sharing credentials insecurely with developers or contractors.
3. Nulled Plugins and Themes
"Nulled" software is pirated premium plugins or themes distributed for free on unofficial sites. They're one of the most reliable ways to get infected, because they very often contain hidden backdoors or malicious code added by whoever redistributed them. They also don't receive legitimate updates.
4. Insecure Hosting and Cross-Contamination
On poorly configured shared hosting, or when many sites live under one hosting account, one infected site can infect others. If all your sites share the same system user, a single vulnerable site can let an attacker modify every site in the account. Old, forgotten installs, like a test site from years ago, are a common source.
5. Outdated Server Software
Old versions of PHP, the web server, the database server, or the operating system can contain vulnerabilities. PHP versions that have reached end of life no longer receive security fixes. On a server you manage, this responsibility is yours.
6. Compromised Third-Party Scripts and Supply Chain
If your site loads JavaScript from a third party, such as an analytics tool, chat widget, or CDN-hosted library, and that source is compromised, malicious code can reach your visitors without anyone touching your server. Plugins can also be compromised if a developer's account is hijacked or a plugin is sold to someone with bad intentions.
7. Insecure File Permissions and Configuration
World-writable files and folders (permissions like 777), PHP execution allowed in the uploads directory, and exposed backup or config files all make it easier for attackers to plant and run malicious code.
The Anatomy of a Typical Infection
A typical infection unfolds like this:
- Scanning: A bot scans thousands of sites and finds one running a plugin version with a known file upload vulnerability.
- Exploitation: The bot uploads a small PHP file, often disguised with a name like
wp-cache.phpor placed deep in the uploads folder. - Establishing persistence: The attacker uses that file to add more backdoors, create a hidden admin account, or modify core files.
- Payload: Malicious redirects, spam pages, or skimmers are injected.
- Covering tracks: File modification dates may be changed, and the malware may hide itself from logged-in administrators.
- Consequences: Visitors are redirected, Google flags the site, and your host may suspend the account.
Warning Signs Your Website Has Malware
Watch for these symptoms:
- Visitors report being redirected to strange sites, especially from mobile or search results.
- Google Search results show spammy titles, descriptions, or pages you didn't create.
- Browsers show a "Deceptive site ahead" or similar warning.
- Google Search Console reports a security issue.
- Unknown admin users appear in Users > All Users.
- New or modified files you didn't upload, especially PHP files in
wp-content/uploads. - Unexpected spikes in server CPU usage or outgoing email.
- Your host sends a malware or abuse notice, or suspends your account.
- Your domain appears on email or security blacklists.
- Security plugins report modified core files.
How to Check for Malware
A few quick checks can reveal infections. Always take a backup before investigating so you don't lose evidence or data.
-
Run a remote scanner: Tools like Sucuri SiteCheck scan your public pages for known malware, blacklisting, and suspicious scripts.
-
Run a server-side scan: Security plugins like Wordfence scan your files and database against known malware signatures and compare core, plugin, and theme files against the official versions.
-
Verify core files with WP-CLI: If you have SSH access, check whether WordPress core files have been modified:
wp core verify-checksums
wp plugin verify-checksums --all
- Look for PHP files in the uploads folder: The uploads directory should normally contain only media files:
find wp-content/uploads -type f -name "*.php"
- Search for common obfuscation patterns: Many false positives are possible, but results are worth reviewing:
grep -rlE "eval\(base64_decode|gzinflate\(base64_decode|str_rot13\(" wp-content --include=*.php
- Check for unknown administrators:
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
- Review recently modified files:
find . -type f -name "*.php" -mtime -7 -printf '%TY-%Tm-%Td %TH:%TM %p\n' | sort -r | head -50
(The -printf option is available in GNU find on Linux servers.)
If you confirm an infection, the full cleanup process, including removing backdoors and requesting a review from Google, is covered in a separate article on recovering a hacked WordPress site.
How to Prevent Website Malware
Prevention is far easier and cheaper than cleanup. Focus on closing the entry points described above.
Keep Everything Updated
Update WordPress core, plugins, and themes promptly, and keep PHP on a supported version. Enable automatic updates for plugins you trust from Plugins > Installed Plugins.
Remove What You Don't Use
Delete inactive plugins and themes, old user accounts, and forgotten test sites. Every unused component is a potential entry point.
Use Strong Authentication
Use unique, long passwords from a password manager and enable two-factor authentication for WordPress administrators, your hosting account, and your domain registrar. Use SFTP or SSH keys instead of plain FTP.
Avoid Nulled Software
Only install plugins and themes from WordPress.org or directly from reputable commercial vendors. If you can't afford a premium plugin, a well-reviewed free alternative is always safer than a pirated copy.
Block PHP Execution in Uploads
Stopping PHP from running in the uploads folder defeats many infections that rely on uploading a malicious script. On Apache, create wp-content/uploads/.htaccess:
<FilesMatch "\.(php|phtml|php[0-9]|phar)$">
Require all denied
</FilesMatch>
On Nginx, add to your server block before your PHP handling location:
location ~* ^/wp-content/uploads/.*\.(php|phtml|phar)$ {
deny all;
}
Disable the Dashboard File Editor
Prevent attackers who gain admin access from editing theme and plugin files through the dashboard. Add this to wp-config.php above "That's all, stop editing!":
define( 'DISALLOW_FILE_EDIT', true );
Set Correct File Permissions
Use 644 for files and 755 for directories as a general rule, with wp-config.php set more restrictively (for example 600 or 640, depending on your host's setup). From your site's root directory:
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;
chmod 640 wp-config.php
Check with your host first, as some environments need different values.
Use a Firewall and Malware Scanner
A web application firewall blocks many exploit attempts before they reach your site, and a scheduled malware scan catches infections early. Options include Wordfence, Sucuri, Solid Security, MalCare, and your host's built-in tools.
Isolate Your Sites
Host important sites in separate accounts or containers so an infection on one can't spread to others.
Monitor and Back Up
Use file integrity monitoring, an activity log, and uptime monitoring so you learn about problems quickly. Keep automated, off-site backups with several versions so you can roll back to a clean copy if needed.
Limit Third-Party Scripts
Load only the external scripts you truly need, from reputable providers, and use Subresource Integrity (SRI) for static library files from public CDNs.
FAQ: Website Malware
Website malware is malicious code planted in a site's files, database, or configuration that performs harmful actions, such as redirecting visitors, injecting spam, stealing payment details, or giving attackers ongoing access.
Most infections come from vulnerable or outdated plugins and themes, weak or stolen passwords, pirated nulled software, insecure hosting, outdated server software, or compromised third-party scripts.
Much website malware is designed to hide from site owners. It may only activate for visitors who aren't logged in, mobile users, first-time visitors, or search engine crawlers, so you might never see it yourself.
Yes. If a deactivated plugin's files remain on the server, a vulnerability in those files can sometimes still be exploited. Delete plugins you don't use rather than just deactivating them.
Many hosts provide scanning, firewalls, and account isolation, which help a lot. However, they usually can't stop infections caused by your own outdated plugins or stolen credentials, so you still need good habits.
Restoring a clean backup from before the infection removes the malicious code, but it doesn't fix the vulnerability that let it in. Update software and change passwords immediately after restoring, or the site will likely be reinfected.
It can try. Some website malware redirects visitors to pages that attempt to install malicious software or trick them into downloading fake updates. This is why browsers and search engines warn users about infected sites.
Conclusion
Website malware is malicious code hidden in your files, database, or configuration that redirects visitors, injects spam, steals data, mines cryptocurrency, or gives attackers a permanent backdoor. It usually arrives through vulnerable plugins and themes, stolen credentials, nulled software, insecure hosting, or compromised third-party code, and it's often designed to stay hidden from the site owner.
The best defense is to close those entry points: keep everything updated, remove unused software, use strong authentication with two-factor, avoid nulled plugins, block PHP execution in uploads, set sensible permissions, and add a firewall and malware scanner. Pair those measures with monitoring and reliable off-site backups, and you'll greatly reduce the chance of an infection, and be able to recover quickly if one ever gets through.


