Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareWordPress Backdoor: Find and Remove Hidden Web Shells

WordPress Backdoor: Find and Remove Hidden Web Shells

A WordPress backdoor gives an attacker a hidden way back into a website after the obvious malware has been removed. Finding the visible infection without finding the backdoor is a common reason compromised sites become infected again.

Signs you might see

  • Reinfection after cleaning
  • Unknown PHP files in uploads or wp-includes
  • Unexplained admin users or file changes

Not sure? Run our free WordPress security scanner for a quick outside check.

What a WordPress backdoor or web shell is

A backdoor is code or an account that provides unauthorised access while bypassing the site's normal login process. A web shell is one form of backdoor, usually server-side code that allows an attacker to issue commands or manipulate files remotely.

On WordPress, malicious PHP may be placed in an unexpected file, concealed inside a legitimate plugin or theme, added to a must-use plugin, or disguised with a harmless-looking filename. The uploads directory deserves particular attention because it normally contains media rather than executable PHP. Changes inside wp-includes, unfamiliar files around WordPress core and unexplained administrator accounts also warrant investigation.

Backdoors are designed for persistence. An attacker may use one to restore deleted malware, create new users, inject spam, redirect visitors or alter files again after a superficial cleanup.

How to check WordPress for a hidden backdoor

Begin with evidence from both WordPress and the server. Review administrator accounts, recent file modification times, server logs where available and files that do not belong to the installed versions of WordPress, your theme or your plugins. Compare WordPress core files against clean official copies rather than judging a file solely by its name.

Check Google with a site:yourdomain.co.uk search and review Search Console Security Issues and Pages reports. Backdoors do not necessarily produce indexed spam, but unexpected URLs, redirects or hacked-content warnings can identify what the persistent access is being used for.

Test suspicious pages from a normal browser and a phone, inspect their source and compare the response Google receives where Search Console provides inspection information. Some malware changes behaviour according to device, referrer or user agent.

Database inspection matters as well. Look for unknown users, altered site URLs, unexpected scheduled tasks, injected scripts and suspicious content in options or posts. The free WordPress security scanner can add an external security check, although server-side backdoors can require direct file and database inspection.

How to remove a WordPress backdoor safely

  1. Back up everything before cleaning. Save the complete filesystem and database and keep an untouched copy of the infected site as evidence.
  2. Identify the compromise path. Check vulnerable plugins and themes, stolen credentials, unexpected users, exposed hosting accounts and suspicious server activity. A cleanup is incomplete until the route used by the attacker has been closed.
  3. Remove unauthorised persistence. Delete confirmed backdoors and rogue accounts. Replace modified WordPress core files with clean official copies, and reinstall compromised plugins or themes from their trusted source.
  4. Inspect beyond the first malicious file. A backdoor may exist alongside loaders, scheduled tasks or secondary web shells. Search the rest of the account and database for related changes before declaring the site clean.
  5. Replace credentials and keys. Change all WordPress passwords, hosting access, database credentials, FTP or SFTP credentials and relevant keys. Generate new WordPress salts in wp-config.php to invalidate existing sessions.
  6. Test again. Rescan files and database content, check users and scheduled activity, review logs where possible and confirm the original vulnerability or access route can no longer be used.

Hacked Site Rescue costs £349 fixed price if you need the backdoor, associated malware and entry point investigated professionally.

Preventing WordPress backdoors and reinfection

Apply WordPress, plugin and theme updates promptly and remove unused extensions entirely. Restrict administrative access, use unique passwords and two-factor sign-in, and give users the lowest role that allows them to perform their work.

File integrity monitoring is particularly useful after a backdoor incident because unexpected PHP changes can indicate that persistence remains. Review server permissions as well. WordPress recommends keeping file permissions as restrictive as practical and using encrypted SFTP rather than unencrypted FTP where the host supports it.

Keep independent off-server backups and test restoration periodically. Our care plans start from £59 a month and include weekly updates, daily off-server backups, security scanning and 24/7 uptime monitoring.

Common questions

Answers to the questions we hear most about this.

Why does my WordPress site keep getting hacked again after cleaning?

A remaining backdoor, stolen credential or unpatched vulnerability can allow the attacker to return. The investigation needs to cover persistence and the original entry point, not only the malware that was easiest to see.

Is every PHP file in wp-content/uploads malicious?

Not automatically, because individual plugins can create unusual files. However, executable PHP in an uploads area deserves investigation because normal WordPress media uploads generally do not require arbitrary PHP scripts there.

Can changing my WordPress password remove a backdoor?

No. Password changes are important after a compromise, but a file-based web shell or other persistent code can continue working independently of the WordPress login. The malicious code and the way it was installed must also be addressed.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support