A security plugin says I'm infected but I can't remove it
A scanner telling you there's malware, offering a repair button that doesn't help, and then reporting the same thing tomorrow is a frustrating place to be. Scanners are genuinely useful, but they're built to notice problems, not to resolve them. Knowing what a scan result can and can't tell you is usually the difference between chasing the same alert for a week and actually fixing the site.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- Scan results that come back after you click "repair" or "delete"
- Files the scanner flags but says it can't fix automatically, often in a plugin or theme rather than in WordPress core
- Warnings about "unknown files in core", or files that don't match the official WordPress versions
- A flagged file you're afraid to delete because you don't know whether the site needs it
- Your host's scanner and your security plugin disagreeing about whether the site is infected
- A clean scan that you don't quite believe, because the site is still behaving strangely
Why it happens
Core repair doesn't reach most infections
The "repair" or "restore original file" option compares your WordPress core files with the official versions and replaces them. That works for core, and does nothing for infected plugins, themes, uploads, or code stored in the database, which is where most malware lives.
The backdoor is putting it back
If the same file reappears after deletion, something is recreating it: a backdoor, a scheduled task, or a must-use plugin. Deleting the visible file is treating a symptom on a loop.
Scanners match known patterns
Most scanning works by comparing files against signatures of malware that has been seen before. A freshly written or heavily obfuscated backdoor can score completely clean, so a clean scan is reassurance rather than proof.
False positives are real
Legitimate plugins sometimes use techniques that look suspicious to a scanner, and premium or custom code is flagged more often than most. Deleting a flagged file without checking can break the site, so it's worth confirming what a file actually is first.
The scan covers less than you think
Some scanners only check files, not the database. Others skip large directories or stop early on big sites, so content outside the scanned area is never examined at all.
What to do right now
Do this
- Export or screenshot the full scan results, including file paths and dates. That list is the starting point for a proper cleanup
- Take a backup of the current state before deleting anything, so nothing is lost if a flagged file turns out to be legitimate
- Check the flagged file's date against your own activity. A file changed at 3am on a day you didn't touch the site tells you a lot
- Look beyond the scanner: administrator accounts you don't recognize, scheduled tasks, and the must-use plugins folder
Don't do this
- Don't mass-delete everything flagged. Some of it may be legitimate code your site needs, and deleting it can take the site offline
- Don't treat a clean scan as an all-clear if the site is still misbehaving. Signature scanning misses new backdoors
- Don't reinstall WordPress core as a fix. It replaces core files only, and most infections aren't in core
How we fix it
- 1Work through the scan results with you and separate genuine infections from false positives, so nothing legitimate gets deleted
- 2Inspect the site by hand as well as by scanner: plugin and theme files, uploads, the database, .htaccess, scheduled tasks, and must-use plugins
- 3Clean each infected file properly rather than deleting it blindly, repairing the ones your site actually needs
- 4Find the backdoor and the entry point that's causing the results to reappear, and remove rogue accounts and tasks
- 5Update and harden the site, then re-scan and give you a written report of what was found and what was done
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
My scanner says it can't repair the file. What does that mean?
Usually that the file isn't part of WordPress core. Repair works by comparing against the official WordPress files and restoring the original, which is only possible for core. For an infected plugin, theme, or uploaded file there's no original to compare against, so the scanner can flag it and stop there. Those files need to be cleaned or replaced deliberately, which is the manual part of the job.
Could it be a false positive?
It genuinely could, and it's worth checking rather than assuming either way. Some legitimate plugins use code patterns that scanners treat as suspicious, and custom or premium code gets flagged more often. Checking what the file is and where it came from takes far less time than recovering from deleting something your site needed.
The scan is clean now. Am I definitely fine?
A clean scan is good news, but it isn't a guarantee. Scanners match patterns from malware that has already been cataloged, so a new or well-hidden backdoor can pass. If the site is still redirecting, sending spam, or showing up oddly in Google after a clean scan, the scanner is missing something and the site needs looking at by hand.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)