Skip to main content
All CollectionsWebsiteWebsite Security
How to fix a malware-infected WordPress website
How to fix a malware-infected WordPress website

Removing malware from WordPress and preventing infections

Updated this week

There are a few things to look for that can indicate a potential malware infection:

  • Unexpected deny rules on your .htaccess file.

  • Files on your website's root folder that you did not create either manually or via a custom script/cron job.

  • Files such as index.php containing large amounts of unreadable code.

  • Your WordPress admin page does not load the style properly.

At Hostinger, we have an automatic Malware Scanner that will help identify and remove malicious files on your account, so you will not need to worry about malware infections.

If Malware Scanner is unavailable on your panel yet, or if you want to clean up your website manually, you can use security plugins such as WordFence or Anti-Malware Security. Here's a step-by-step tutorial on how to clean up an infected WordPress site using the WordFence plugin: WordPress Malware Removal Guide.

If your website presents issues after cleanup, you can consider restoring it from a backup. Please note that this would revert any changes you made after the backup date.

To avoid similar issues in the future, we recommend the following:

  • Use strong passwords: unique, with more than 8 characters using letters, numbers, and special characters

  • Keep WordPress, themes, and plugins updated to the latest stable version

  • Avoid plugins and themes from unknown or third-party providers

  • Protect your website's contact/registration/login forms with reCAPTCHA

Did this answer your question?