Type something to search...
How to remove a backdoor from a WordPress website?

How to remove a backdoor from a WordPress website?

To remove a backdoor from a WordPress website, back up the site, put it in maintenance mode, and replace WordPress core, plugins, and themes with fresh copies from official sources. Then search the remaining files (especially wp-content/uploads, mu-plugins, wp-config.php, and .htaccess) and the database for suspicious code, delete anything malicious, remove unknown admin users, and change every password and security key. Finally, fix the vulnerability that let the attacker in, or the backdoor will simply return.

A backdoor is what turns a one-time hack into a recurring nightmare. You clean up spam pages or redirects, and a few days later they're back. That usually means the attacker left a hidden way to regain access. This guide explains what backdoors are, where they typically hide in WordPress, how to find them methodically, and how to remove them without breaking your site.

What Is a WordPress Backdoor?

A backdoor is code or access that lets an attacker get back into your site without going through normal authentication. After an initial compromise, attackers almost always plant one or more backdoors so they can return even if you change your passwords or remove the obvious malware.

Common forms include:

  • PHP web shells: Files that let the attacker run commands or upload files through a browser.
  • Code injected into legitimate files: A few lines added to a theme's functions.php, a plugin file, or a core file.
  • Hidden administrator accounts: Admin users that don't show up in the dashboard's user list.
  • Malicious must-use plugins: Files in wp-content/mu-plugins that load automatically and don't appear in the normal plugin list.
  • Database-stored code: Malicious code stored in options or post content that gets executed by other code.
  • Rogue scheduled tasks: WP-Cron events that reinstall malware periodically.
  • Server-level access: Added SSH keys, cron jobs, or FTP accounts on the server itself.

The key difference between a backdoor and visible malware is intent: a backdoor's job is to stay hidden and keep the door open.

Before You Start

Take a Backup

Before changing anything, take a complete backup of files and the database. Even though the backup is infected, you'll need it if cleanup breaks something, and it's valuable for figuring out what happened. Label it clearly so it's never restored by mistake.

Put the Site in Maintenance Mode

If your site is actively redirecting visitors or serving malware, put it in maintenance mode or restrict access while you work. This protects visitors and your reputation.

Consider Restoring a Clean Backup

If you have a backup from before the infection and you know when the compromise happened, restoring it can be faster than cleaning. You'll still need to change credentials and fix the original vulnerability, and you'll need to check that the backup is truly clean, since backdoors are often planted days or weeks before visible symptoms appear.

Step 1: Scan to Get a Starting Picture

Run a security scan to identify obvious problems and give yourself leads.

  • Wordfence: Set scan sensitivity to high and enable scanning outside the WordPress directory if possible.
  • MalCare: Scans off-site, useful if the server is slow.
  • Sucuri SiteCheck: A remote scan shows what visitors see.

Note every flagged file. Scanners won't catch everything, but they're a good first map.

Step 2: Replace WordPress Core Files

Core files are the easiest to clean because you can simply replace them with known-good copies.

With WP-CLI:

# Check which core files are modified or unexpected
wp core verify-checksums

# Re-download core files for your current version without touching wp-content
wp core download --version=$(wp core version) --force --skip-content

Without WP-CLI, download a fresh copy of WordPress from WordPress.org, then upload and overwrite the wp-admin and wp-includes folders and the root PHP files (except wp-config.php). Delete any files in the root, wp-admin, or wp-includes that aren't part of the official package. verify-checksums will list files that shouldn't be there.

Step 3: Replace Plugins and Themes

Don't try to clean plugin and theme files line by line. Replace them.

  • Make a list: Note every installed plugin and theme, and which ones are active.

  • Delete and reinstall plugins: For plugins from WordPress.org, WP-CLI can reinstall them in place:

# Verify which plugins have modified files
wp plugin verify-checksums --all

# Reinstall a plugin from WordPress.org
wp plugin install contact-form-7 --force

For premium plugins, download fresh copies from the vendor's site and replace the folders completely.

  • Replace themes: Download fresh copies of your parent theme. For child themes or custom themes, carefully review every file, since you can't download a clean copy. Compare against your own version control or an older known-clean backup if you have one.

  • Delete anything unused: Remove inactive plugins and themes entirely. Backdoors love hiding in forgotten code.

  • Look for unknown folders: Any plugin or theme folder you don't recognize should be investigated and likely removed.

Step 4: Check Common Backdoor Hiding Places

After replacing core, plugins, and themes, the remaining files are where backdoors usually survive.

The Uploads Folder

wp-content/uploads should contain media, not PHP. Find any PHP files there:

find wp-content/uploads -type f \( -name "*.php" -o -name "*.phtml" -o -name "*.php5" -o -name "*.phar" \)

Unless you know a specific plugin legitimately stores PHP there (rare), delete these files. Also look for files with double extensions like image.jpg.php.

Must-Use Plugins

Check wp-content/mu-plugins. Many sites don't have this folder at all. If it exists, you should recognize every file. Hosts like managed WordPress providers sometimes add their own mu-plugins, so check with your host if unsure.

wp-config.php

Open wp-config.php and look for:

  • include or require statements pointing to unusual files.
  • Long encoded strings.
  • Code before the opening comments or after the final require_once ABSPATH . 'wp-settings.php'; line.

.htaccess Files

Look at .htaccess in the root and in subfolders like uploads. Suspicious signs include rewrite rules that redirect based on the referrer or user agent, and directives like AddHandler or SetHandler that make non-PHP files execute as PHP.

find . -name ".htaccess" -exec ls -la {} \;

The WordPress Root and Unexpected Directories

Look for unfamiliar files in the root directory, especially ones with names that look almost legitimate, such as wp-config-sample.php being modified, or files like wp-cache.php, wp-l0gin.php, or random strings.

Step 5: Search for Suspicious Code

Backdoor code often uses a small set of PHP functions to decode and run hidden payloads. Searching for these gives you leads:

cd /var/www/example.com/public_html

# Common functions in obfuscated backdoors
grep -rnE --include="*.php" "eval\(|assert\(|base64_decode\(|gzinflate\(|gzuncompress\(|str_rot13\(|create_function\(" wp-content/ | grep -v "wp-content/plugins/known-safe-plugin"

# Code that runs request data directly
grep -rnE --include="*.php" "\\\$_(POST|GET|REQUEST|COOKIE)\[.{1,40}\]\s*\)" wp-content/ | grep -E "eval|assert|system|exec|passthru|shell_exec"

# Very long lines, typical of obfuscated code
grep -rlE --include="*.php" ".{3000,}" wp-content/

Also look for files modified recently:

find . -type f -name "*.php" -mtime -30 -printf "%TY-%Tm-%Td %p\n" | sort -r | head -50

When you find a match, open the file and look at the context:

  • Is the code in a file you replaced with a clean copy? If so, it's gone.
  • Is it in your own child theme or custom plugin? Compare with version control or ask your developer.
  • Is it a standalone file with a random name? Almost certainly malicious. Delete it.
  • Is it a few lines injected at the top of an otherwise normal file? Remove just those lines, or replace the file with a known-good copy.

Remember that legitimate plugins sometimes use base64_decode or eval. Focus on files outside official packages and code that's clearly obfuscated.

Step 6: Clean the Database

Backdoors and malware often live in the database.

Check for Hidden Admin Users

wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Compare with Users > All Users in the dashboard. If an account appears in WP-CLI but not the dashboard, it's being hidden by malicious code. Delete any administrator you don't recognize:

wp user delete 42 --reassign=1

Search Options and Posts

Look for injected scripts and suspicious values. Replace wp_ with your table prefix:

-- Scripts or iframes in post content
SELECT ID, post_title, post_type
FROM wp_posts
WHERE post_content LIKE '%<script%' OR post_content LIKE '%eval(%' OR post_content LIKE '%base64_decode%';

-- Suspicious options
SELECT option_id, option_name, LEFT(option_value, 200) AS preview
FROM wp_options
WHERE option_value LIKE '%eval(%'
   OR option_value LIKE '%base64_decode%'
   OR option_value LIKE '%<script%';

Review each result carefully. Legitimate content can contain scripts, such as analytics snippets or embeds, so don't delete blindly.

Also confirm the site URL options haven't been tampered with:

wp option get siteurl
wp option get home

Check Scheduled Tasks

Look for unfamiliar WP-Cron events that could reinstall malware:

wp cron event list --fields=hook,next_run_relative,recurrence

If you see hooks that don't belong to WordPress core or your known plugins, investigate them and delete the event with wp cron event delete hook_name.

Step 7: Check the Server Itself

If you manage your own server or VPS, backdoors can exist outside WordPress entirely.

  • Cron jobs: Check crontab -l for each user and look in /etc/cron.d for unexpected entries.
  • SSH keys: Review ~/.ssh/authorized_keys for keys you don't recognize.
  • System users: Look for new accounts in /etc/passwd.
  • FTP and SFTP accounts: In your hosting panel, remove any accounts you didn't create.
  • Other sites on the same account: On shared hosting, an infected site in another folder can reinfect yours. Clean or remove every site in the account.
crontab -l
sudo ls -la /etc/cron.d
cat ~/.ssh/authorized_keys

Step 8: Change Every Credential

Backdoors often come with stolen credentials. After cleaning, reset everything:

  1. WordPress passwords: For every administrator, and ideally every user.
  2. Database password: Change it in your hosting panel, then update DB_PASSWORD in wp-config.php.
  3. Hosting, SFTP, and SSH passwords: And rotate SSH keys if needed.
  4. Security keys and salts: Generate new ones and replace the existing block in wp-config.php. This logs everyone out and invalidates stolen session cookies.

With WP-CLI, you can regenerate salts in one command:

wp config shuffle-salts

API keys: Rotate keys for payment gateways, email services, and other integrations stored on the site.

Step 9: Close the Entry Point

If you don't fix how the attacker got in, they'll simply come back. Common entry points include:

  • An outdated plugin or theme with a known vulnerability.
  • A nulled plugin or theme.
  • A weak or reused admin password.
  • An infected site sharing the same hosting account.
  • Compromised FTP credentials from a local computer.

Update everything, remove nulled software, enable two-factor authentication for all admins, and review your activity logs and server access logs to identify the likely entry point.

Step 10: Harden and Monitor

Finally, make it harder for a backdoor to be planted again:

  • Disable file editing in the dashboard by adding this to wp-config.php above "That's all, stop editing!":
define( 'DISALLOW_FILE_EDIT', true );
  • Block PHP execution in uploads with an .htaccess file in wp-content/uploads (Apache 2.4):
<FilesMatch "\.(php|phtml|php[0-9]|phar)$">
    Require all denied
</FilesMatch>
  • Use a firewall: A plugin WAF or cloud WAF blocks many exploit attempts.
  • Enable file change monitoring: Wordfence, Sucuri, and others can alert you when files change.
  • Scan regularly: Schedule daily or weekly malware scans.
  • Request a review if flagged: If Google flagged your site, request a review in Search Console after cleanup.

Keep a close eye on the site for a few weeks after cleanup. If symptoms return, there's still a backdoor or an unpatched entry point somewhere.

When to Call a Professional

Backdoor removal can be tricky, especially on large or heavily customized sites. Consider professional help if:

  • The infection keeps coming back after cleanup.
  • You run an online store or handle sensitive data.
  • You aren't comfortable working with SSH, SFTP, or the database.
  • Your host has suspended the account.

Services from Sucuri, Wordfence, and MalCare specialize in WordPress cleanup and can often work faster than you could alone.


FAQ: Removing WordPress Backdoors

Recurring infections after cleanup are the biggest clue. Other signs include PHP files in the uploads folder, unknown files in mu-plugins, hidden admin users, and scanner warnings about obfuscated code.

Some plugins can remove known malware, but backdoors are often custom and obfuscated, so automated tools may miss them. Replacing core, plugins, and themes with clean copies and checking common hiding spots is more reliable.

Usually because a backdoor was missed or the original vulnerability wasn't fixed. Check uploads, mu-plugins, the database, cron events, other sites on the same hosting account, and update or remove vulnerable plugins.

No. A backdoor gives attackers access without needing your password. You need to remove the backdoor code, delete hidden users, and change passwords and security keys.

Only if the backup predates the compromise. Backdoors are often planted before visible symptoms appear, so verify the backup is clean and still change credentials and fix the vulnerability after restoring.

Common hiding places include the uploads folder, mu-plugins, theme functions.php files, wp-config.php, .htaccess files, unused plugins and themes, the wp_options table, and scheduled cron events.


Conclusion

Removing a backdoor from WordPress is about being thorough rather than clever. Start with a backup, replace core, plugins, and themes with fresh official copies, and then focus on the places backdoors love to hide: uploads, mu-plugins, configuration files, the database, and scheduled tasks. Delete hidden admin users, and if you run your own server, check cron jobs and SSH keys too.

Once the code is gone, change every password and regenerate your security keys, then close the vulnerability that allowed the attack in the first place. Harden the site with measures like disabling file editing and blocking PHP in uploads, and monitor it closely for the next few weeks. Done carefully, this process gets the attacker out and keeps them out.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper