The WP-Detox guide

Is your WordPress hacked? Here is how to take back control.

Clear guides to spot the infection, clean the hack and close the doors behind you, written by the team that cleans hacked WordPress sites every day.

Spot the hack

WordPress hack symptoms and types

Casino redirects, indexed spam, Google warnings, rogue admin accounts: pin down exactly what is affecting your site.

Broom sweeping casino spam and junk icons off a WordPress site Symptoms & hack types

Japanese keyword hack: cleaning the Japanese hack on WordPress

Japanese pages indexed under your name, titles full of Asian characters in Google? That's the Japanese keyword hack. Here's how to identify and clean it.

Read
Pill bottle spilling onto a screen, illustrating the WordPress pharma hack Symptoms & hack types

Pharma hack WordPress: remove pills and pharmacy spam

Viagra, Cialis and pharmacies indexed under your name in Google but nowhere in your admin? Here's where the pharma hack hides and how to remove it.

Read
Magnet pulling casino chips out of a WordPress site Symptoms & hack types

Remove indexed casino spam posts on WordPress (SEO spam)

Hundreds of casino or betting pages indexed under your name in Google, but invisible from your dashboard? Here's how to remove them and stop their return.

Read
Warning triangle displayed over a hacked WordPress site Symptoms & hack types

Remove the "This site may be hacked" warning from Google

Google flags your site as hacked or shows a red warning? Here's how to clean up, request a review, and how long it takes to clear.

Read
WordPress user list with an unknown administrator account Symptoms & hack types

An unknown admin account on WordPress: what to do

An admin you never created shows up in WordPress? That's a clear sign of a hack. Here's how to remove it without locking yourself out.

Read
Broom sweeping casino spam and junk icons off a WordPress site Symptoms & hack types

Is your WordPress redirecting to a casino or betting site? Here's how to stop it

Your WordPress site sends visitors to a casino or betting site, mostly from Google? That's a redirect hack. Here's where it hides and how to remove it.

Read
Broom sweeping casino spam and junk icons off a WordPress site Symptoms & hack types

Your WordPress is sending spam: how to stop it

Your domain is sending spam without your knowledge, your host is warning you, or your mail is blacklisted? Here's the cause and how to stop it.

Read
Security dashboard monitoring a WordPress site Symptoms & hack types

WordPress slow or server overloaded: could it be a hack?

Site suddenly slow, CPU pinned, your host warning about resource usage? It may not be a performance issue but a cryptominer or a hidden botnet.

Read
Diagnose & clean

Clean and repair a hacked WordPress

Recognise an infection, find the backdoors, remove the malware and get your WordPress site back on its feet, step by step.

Hack alert on a WordPress site screen Clean & repair

Guide Hacked WordPress: what to do? The guide to cleaning and securing your site

Is your WordPress site hacked? Here's the complete playbook to keep your cool, clean the infection without breaking anything, and close the hole for good.

Read
Hacked WordPress site restored: before and after cleanup Clean & repair

Clean a hacked .htaccess file on WordPress

The .htaccess is the favorite hiding spot for malicious redirects and access blocks. Here's how to spot injected rules, remove them, and restore a clean file.

Read
Monitoring dashboard for a WordPress site with a validation shield Clean & repair

How to know if your WordPress site is hacked: 10 telltale signs

Not sure your site is clean? Here are 10 concrete signs of a hacked WordPress and how to check each one before you clean up.

Read
Cloud backup and restore of a WordPress site Clean & repair

Cleanly reinstall WordPress core (without losing your site)

Replacing WordPress core files with a clean version clears out a good chunk of an infection. Here's how to do it without touching your content or your settings.

Read
Hidden trapdoor locked with a padlock in a WordPress site Clean & repair

Finding and removing a backdoor on WordPress

A backdoor is the door the attacker keeps open to come back after every cleanup. Here's where they hide in WordPress and how to track them down for good.

Read
WordPress site restored from a warning state to a healthy state Clean & repair

Restoring WordPress after a hack: getting your content back

Content erased or hidden by the attacker? Here's how to recover your posts and pages: backups, Google cache, Wayback Machine, and what to do with no backup.

Read
Magnifying glass revealing hidden malware in WordPress pages Clean & repair

Scanning a WordPress site for malware: the methods that actually work

Online tools, plugins, manual inspection: here's how to scan an infected WordPress, which to choose for your situation, and what no scanner can see.

Read
After the cleanup

Secure WordPress and prevent reinfection

Harden WordPress, close the security holes an attacker exploited and build the habits that prevent reinfection: strong logins, updates and backups.

Know your enemy

WordPress malware library: identify and remove

wp-vcd, lock360.php, webshells, cloaked injectors: each entry describes a real-world malware — files, symptoms, persistence and removal — straight from our cleanups.

Malware library

lock360.php: what this file is and how to remove it

Found a lock360.php file on your site? It's a backdoor. Here's what it does, where it hides and how to remove it without leaving a door open.

Read
Malware library

sc_, wp_custom_, home_links_custom_ options: spam hidden in wp_options

Spotted sc_, wp_custom_ or home_links_custom_ options in your wp_options table? That's database spam persistence. Here's how to identify and clean it.

Read
Malware library

Sky Login / redirect hijack: removing this fake plugin from WordPress

A 'Sky Login' plugin you never installed, and your site redirecting visitors? That's a redirect injection. Here's how to identify and remove it.

Read
Malware library

Vitrina Site Connector / SEO Client: the cloaked mu-plugins injector

A 'Vitrina Site Connector' or 'SEO Client' mu-plugin you never installed? It's an injector cloaking a casino redirect. Here's how to recognise and remove it.

Read
Malware library

wp-vcd: the nulled-theme malware and how to get rid of it

wp-vcd is one of the most widespread WordPress malwares, spread through nulled themes and plugins. Here's how to recognise it, remove it and stop it coming back.

Read
Malware library

WSO, FilesMan, c99: recognising and removing a WordPress web shell

A PHP file that shows a file manager in the browser? That's a web shell. Here's how to recognise WSO, FilesMan or c99 and remove them properly.

Read

Want us to handle it for you?

Run a free scan: we show you what is detected, then clean everything in ~30 minutes. €149 excl. VAT, refunded if we can't fix it.

Scan my site