Skip to content

Malware

Malware is software written to do harm. On a WordPress site it is code someone planted to send visitors elsewhere, publish spam pages, take what people type or keep a way back in. A warning or a scan result is a reason to check, not proof either way.

By
WP Ministry
Published

In short

  • Malware on a WordPress site is code someone planted. It can sit in a PHP file, in the database or in .htaccess.
  • It is often written to hide from the owner and act only on visitors who arrive from a search, or only on search engines.
  • A warning or a scan result is a sign to check, not a verdict. A scan that finds nothing is not proof of a clean site.

Malware is any software written to harm a computer, the software it runs or the people using it. That is Google's definition, and it covers far more than websites. On a WordPress site the word means code that someone placed there without the owner's permission, so that the site does something for them.

What it does falls into four kinds:

  • Redirects. Visitors are sent to another site. Google's guidance notes that some malware acts only on people who arrive from a search, so the owner, who types the address, never sees it.
  • Spam pages. Pages you did not write, or links and text added to your own. They may be shown to search engines and hidden from everyone else.
  • Stolen data. Google's example is harmful code that records what visitors type and takes their login details.
  • A backdoor. A way for the attacker to return after the rest has been removed.

It need not be a file. Google describes malware in database records, in server configuration files such as .htaccess, and in the template used for error pages.

Where you meet it

Malware is written to stay out of the owner's sight, so you usually meet a report of it first.

  • Google Search Console. The Security issues report lists what Google found, under headings such as "Hacked: Malware", "Hacked: Code injection", "Hacked: Content injection", "Hacked: URL injection" and "Harmful downloads".
  • A warning before the page. Affected pages can carry a warning label in search results, or the browser can show a full-page warning in place of the site.
  • Your host. WordPress's documentation lists a host disabling the site among the clear indicators of a hack.
  • A scan. A security plugin reports a file, or visitors say their antivirus flags the site.

What goes wrong

  • A sign is taken for a verdict. A redirect can be a setting, and WordPress's documentation notes that a host may be able to confirm whether a hack is a hack or a loss of service. A sign says look closer. How to check whether your WordPress site has been hacked goes through the checks from outside and from inside, and the hacked site check reports the signs that show from outside.
  • A clean scan is taken for a clean site. Google says hacks are often invisible to users. WordPress's documentation says no one scanner is the best approach, and that using several improves the odds.
  • Cleaning starts before anything is written down. The site as it stands is the record of what was done to it. The hacked site runbook covers the first hour.
  • The visible part is removed and the rest stays. Google's guidance warns that a site may carry more than one type of malware. How to remove malware from a hacked WordPress site has the full cleanup.
  • A quote covers only the symptom. What WordPress malware removal costs sets out what a complete cleanup contains.

Common questions

Is malware the same as a virus?

A virus is one kind of malware: Google's definition includes installing harmful software such as viruses. When people say a WordPress site "has a virus", they nearly always mean the wider thing, code planted on the site by someone else.

Can malware on my own computer infect my site?

Yes. WordPress's documentation says that in many instances the infection begins on the owner's computer, where a trojan captures the logins for FTP and the dashboard. Its hardening guide adds that no security on the server makes any difference if there is a keylogger on the computer you log in from. Scan the computers you work from as part of any cleanup.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.