"Hacked: Malware" in Search Console: cleaning an infected WordPress site
"Hacked: Malware" means your site "has been infected by, or is hosting, malware from a malicious hacker." Visitors on Chrome will probably see a Dangerous warning and a full-page interstitial before they reach you, and results can carry a warning label, so traffic falls even if rankings do not move.
Google's own first question is whether you can fix it yourself: it takes the ability to read code and possibly server configuration. If that is beyond you, bring in your host's security team or a professional cleanup service now. Hydrogen SEO is an SEO plugin, not a malware scanner or cleaner, and cannot remove an infection. What follows is the order of work that a WordPress cleanup usually takes, so you can do it or check the work of whoever does.
Before you touch anything
- Take a full backup of the infected site, files and database, and keep it offline. You will want it to work out how the attacker got in, and it protects you if cleanup breaks something.
- Check your hosting account for other sites on the same account. One infected install can reinfect its neighbors, so they all need cleaning.
- Put the site in maintenance mode or ask your host to restrict access if it is actively serving malware to visitors.
- Look at the Security issues report details: sample URLs and the date the issue was first detected. That date narrows down which plugin update, login or file change to look at in your logs.
Google warns against opening infected pages in a normal browser, since the malware may target your machine. Use URL Inspection or a command-line fetch instead.
A cleanup order that works for WordPress
- Change every credential: WordPress admins, hosting panel, SFTP/SSH, database user (then update
wp-config.php), and any API keys stored in the site. - Reinstall WordPress core from wordpress.org and confirm it:
wp core verify-checksums. - Replace plugins and themes with fresh copies from their official source. For plugins from the WordPress.org directory,
wp plugin verify-checksums --allreports modified files. Delete anything inactive, unknown or nulled (pirated premium themes are a common source of malware). - Search what is left for code that should not be there:
wp-content/uploadsshould not contain PHP files, andwp-content/mu-pluginsshould only contain what you installed. - Clean the database: injected
<script>tags in posts and options, unknown administrator accounts, and unfamiliar scheduled tasks. - Rotate the security keys with
wp config shuffle-salts, which logs everyone out. - Update everything and remove the entry point once you have found it.
find wp-content/uploads -name '*.php' -o -name '*.phtml'
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
wp cron event list --fields=hook,next_run_relative
wp db search '<script' wp_options --one_line
Finding how they got in
Cleaning without closing the hole usually means a second infection within days, and Google says a request filed when the issue is not fixed can lengthen the next review or get you marked as a repeat offender. Common WordPress entry points:
- A plugin or theme with a known vulnerability that was not updated.
- A reused or leaked admin password, especially without two-factor authentication.
- A nulled premium plugin or theme with a backdoor built in.
- Another compromised site on the same hosting account.
- Writable files and an exposed file editor; setting
define('DISALLOW_FILE_EDIT', true);inwp-config.phpremoves the theme and plugin editor from the admin.
Your host's access logs around the first-detected date, and the modification times on changed files, usually point to the culprit.
Requesting the security review
Confirm the problem is gone on the example URLs, using URL Inspection's live test, and check that Chrome no longer warns on a clean browser profile. Then select Request Review in the Security issues report and describe what you found and fixed:
The site was infected through an outdated slider plugin. We removed
the plugin, reinstalled WordPress core, all plugins and the theme from
official sources, deleted 14 PHP files from uploads and a rogue admin
account, cleaned injected scripts from wp_options, changed all
passwords and rotated salts. Example URLs no longer serve malware.
Google says a review can take from a few days to a few weeks, and you get an email when it starts and when it ends. Warnings lift after a successful review; traffic tends to follow, but Google makes no promise about how quickly. Keep monitoring, and see Hacked: Code injection for tracing the specific scripts.
Common questions
Can Hydrogen SEO remove malware from my site?
No. Hydrogen SEO manages SEO settings such as metadata, sitemaps, schema and redirects. Malware removal needs file and database cleanup, usually with help from your host or a security service.
Why can't I see the malware warning myself?
Google Safe Browsing shows warnings based on browsing context, so you may not reproduce them. Google says the Security issues report is the source of truth for whether an issue exists or has been fixed.
Is restoring a backup enough?
Only if the backup predates the infection and you then close the entry point. Restoring an old copy with the same vulnerable plugin often leads straight back to the same infection.
How long do Chrome warnings last after cleanup?
Until Google completes a successful review. Google says a security review takes from a few days to a few weeks.