You're reading one of the top pains on Mailerlite Integrations — a free sample of the catalog. Create a free account to browse all Shopify & Atlassian pains and the basic Chrome catalog.
WordPress site owners struggle to fully clean malware and backdoors after a compromise
.24
Demand — how loud & how many (score)
Willing to payImplicit
Momentum (7d)▼ 70.2%
Cluster65 posts · 58 people
MarketplaceMailerlite Integrations
Updated3d ago
The story
The pain
We're finding that even after removing obvious malware files and admin accounts, hidden backdoors in mu-plugins and altered system files keep the infection alive. The cleanup process is painfully slow via FTP, and we can't trust that a site is truly clean without a complete wipe and rebuild from scratch.
Evidence
What people said · 65 complaints, 58 people
I found out my webhosting space is flooded with malware. I removed it from one site but after an hour it was back, probably from one of the other sites. I remove the files with my FTP-client WinSCP but it is sooooo slooooowwww.... I am working on it all day already.
Happened to me once I had to delete the site and reinstall from scratch, this time putting down all security, renaming things through security plugins, scanner plugins to look for malware and viruses, and even going so far as to rename the login page and the admin user acct name and use really tough passwords.
I had this issue a couple of years ago. I found out that also these files were altered: .user.ini php.ini .htaccess Also plugin files were "infected". So what I did: Locally: Create a fresh WordPress installation Install all plugins again from their original/trusted sources Reinstall the theme from a clean source Import the production database after thoroughly checking it, especially users, options, posts, and injected scripts Test the entire website locally Deploy the clean installation to a completely wiped production environment
They install a MU caching plugin containing malicious code, which then gets added to all your site cache files (if you use caching plugins). There was also a WP Fixit (or similar name) added that (I think) was MU too, which needed to be removed.
Export the pain — problem, evidence and market signals — as Markdown, PDF or JSON. The Markdown export ships with a built-in briefing you can hand straight to a developer or an AI agent.