Capability
WordPress Security & Malware Cleanup
Evidence-first malware cleanup and hardening — backups before deletion, verification before cleanup.
If your WordPress site is hacked, the worst thing to do is start deleting files. I use an evidence-first workflow that protects your legitimate data while removing the real problem.
My repeatable workflow
- Isolate — maintenance mode and containment
- Snapshot — back up files and database before anything else
- Verify core — checksum WordPress core files
- Scan — plugins, themes and uploads for injected code
- Inspect the database — spam posts, options, users, submissions
- Confirm — separate real malware from false positives
- Clean — replace or remove injected records safely
- Harden & monitor — WAF, 2FA, disable file editing, watch logs
This is defensive cleanup only. Security work reduces risk but cannot guarantee a site will never be attacked again. I never delete anything I’m not confident is malicious.