Blog

WordPress Backdoors: What They Are and How to Find Them

WordPress Backdoors: What They Are and How to Find Them

A WordPress backdoor is the hacker’s spare key to your website.

You can remove the obvious malware, change a few passwords, and feel like the problem is fixed. But if a backdoor is still hiding somewhere, the attacker can quietly walk right back in.

That is why backdoors are one of the most frustrating parts of WordPress security. They are often small, deliberately hidden, and designed to survive basic cleanup attempts.

What Is a WordPress Backdoor?

A WordPress backdoor is hidden code or access that lets someone bypass normal login and security controls.

Instead of logging in through wp-admin with a username and password, the attacker may use a hidden file, injected code, a fake plugin, a database change, or a server-level script to regain access.

Think of it like changing the front door lock after a break-in, but missing the basement window the intruder left unlocked.

Backdoors are commonly used to:

  • Reinfect a cleaned website
  • Create new administrator users
  • Upload spam pages or phishing files
  • Redirect visitors to scam websites
  • Send spam email from your hosting account
  • Steal form submissions or customer data
  • Keep control of a site after a plugin vulnerability is patched

If your website keeps getting hacked after you “cleaned it,” there is a good chance a backdoor was missed.

How Backdoors Usually Get Into WordPress

Backdoors rarely appear out of nowhere. They are usually installed after the attacker gets in through another weakness.

Common entry points include:

  • Outdated plugins or themes with known vulnerabilities
  • Weak or reused admin passwords
  • Compromised FTP, SFTP, or hosting control panel credentials
  • Pirated “nulled” themes or plugins
  • Old WordPress installs left in subfolders
  • Insecure file permissions
  • Poorly protected staging or development copies

Outdated plugins are one of the biggest causes we see. If you want a deeper explanation of that risk, read How Hackers Exploit Outdated WordPress Plugins.

The important thing to understand is this: removing the backdoor is only half the job. You also have to fix the original weakness, or the attacker may get back in the same way.

Where WordPress Backdoors Hide

Backdoors can hide almost anywhere PHP code can run. Some are obvious once you know what to look for. Others are intentionally disguised as normal WordPress files.

1. Theme Files

Attackers often hide code in active theme files because those files are loaded regularly.

Common hiding places include theme function files, header files, footer files, and template files. A small block of malicious code can be added to a legitimate file, making it harder to spot at a glance.

Child themes can also be abused. Many site owners forget to check them because they focus only on the main theme.

2. Plugin Files

Plugins are another favourite hiding place.

A backdoor may be inserted into a real plugin, or the attacker may create a fake plugin folder with a boring name that looks harmless. Names like “cache,” “backup,” “seo,” or “tools” should not automatically be trusted.

That does not mean every unfamiliar plugin is malicious. But if you see a plugin you did not install, do not ignore it.

3. Uploads Folder

The WordPress uploads folder is supposed to store images, PDFs, and media files.

It should not normally contain executable PHP files. If you find PHP files mixed in with images, that is a serious warning sign.

Attackers like this location because site owners rarely inspect old upload folders. A file can sit there for months without being noticed.

4. Must-Use Plugins

WordPress has a must-use plugin area, often called MU plugins.

These files can run automatically and may not appear in the regular plugin screen the same way normal plugins do. That makes them useful for legitimate developers, but also attractive to attackers.

If your site has MU plugins, confirm they were added by your developer, host, or maintenance provider.

5. WordPress Core Files

Attackers may modify WordPress core files to hide malicious code.

This is dangerous because many people assume core files are safe. If a core file has been changed, the safest approach is usually to replace WordPress core with a clean copy from the official source rather than manually editing suspicious lines.

Tools like WP-CLI can help verify WordPress core checksums, but if you are not comfortable with command-line tools, ask your host or developer to help.

6. Database Entries

Not all backdoors are files.

Some attackers hide malicious code in WordPress database content, widget areas, plugin settings, scheduled tasks, or site options. This can be harder to find because a file scanner may not catch it.

If a suspicious redirect keeps returning even after files are cleaned, the database should be checked too.

7. Server Configuration Files

Some backdoors use server configuration rules to redirect visitors, load malicious files, or control access.

On many WordPress sites, this can involve configuration files used by the web server. Be careful here: legitimate rules for caching, redirects, SSL, and security may also exist.

Do not delete server rules randomly unless you understand what they do. You can break permalinks, redirects, or HTTPS handling.

Signs Your Site May Have a Backdoor

A backdoor does not always announce itself. Sometimes the site looks normal while the attacker uses it quietly in the background.

Watch for these warning signs:

  • Malware returns after cleanup
  • New admin users appear without explanation
  • Unknown files show up in WordPress folders
  • Visitors report redirects you cannot reproduce
  • Google Search Console shows strange indexed pages
  • Your host warns about spam, phishing, or high CPU usage
  • Security plugins keep flagging the same issue
  • File modification dates do not match your recent work
  • Contact form submissions or orders behave strangely

Some signs overlap with other types of malware. For more general symptoms, see Signs Your WordPress Site Has a Hidden Infection.

How to Find WordPress Backdoors

Finding backdoors takes patience. The mistake many people make is searching for one “bad file,” deleting it, and calling the site clean.

A serious cleanup should check files, users, plugins, themes, database content, scheduled tasks, and server logs.

Start With a Safe Backup

Before touching anything, take a full backup of the current site.

Yes, even if the site is hacked. That backup may be needed for investigation, comparison, or recovery if something breaks during cleanup.

Label it clearly as a possibly infected backup so nobody restores it later by mistake.

Compare Core WordPress Files

WordPress core files should match the official WordPress release you are using.

If you use WP-CLI, the core checksum verification command can help identify modified core files. If you do not use WP-CLI, your host or maintenance provider may be able to run this check for you.

Modified core files are not always malicious, but they should be treated as suspicious. In most cases, replacing core files with clean official copies is safer than trying to manually clean them.

Check Recently Modified Files

Sort your website files by modified date in your hosting file manager, SFTP client, or command-line tools.

Look for files changed around the time the hack likely happened. Pay close attention to PHP files in unusual locations, especially inside uploads, cache, backup, or temporary folders.

This method is useful, but not perfect. Attackers can sometimes alter file timestamps, so do not rely on dates alone.

Look for PHP Files Where They Do Not Belong

On a normal WordPress site, PHP files belong in WordPress core, plugins, themes, and some legitimate system areas.

They usually do not belong inside media upload folders. If you see a PHP file pretending to be an image, or sitting among old uploads, investigate it carefully.

Do not open suspicious files in a browser. View them safely through your file manager or download them to a secure local environment if you know what you are doing.

Review Plugins and Themes

Go through every installed plugin and theme.

Ask three questions:

  • Do we actually use this?
  • Did we install it from a trusted source?
  • Is it still maintained?

Inactive themes and plugins can still be risky if their files remain on the server. If you are not using them, remove them rather than simply deactivating them.

Be careful with premium plugins. Download fresh copies only from the official vendor account or trusted source. Do not grab random ZIP files from old email threads or file-sharing links.

Check for Unknown Admin Users

Review all WordPress users with administrator access.

If you see an account you do not recognize, do not just delete it and move on. First, note the username, email address, creation timing if available, and any related activity.

After that, remove unauthorized admin users and reset passwords for all remaining administrators.

This is also a good time to enable two-factor authentication. We have a separate guide here: How to Set Up Two-Factor Authentication for WordPress Admin Access.

Inspect Scheduled Tasks

WordPress uses scheduled tasks for normal things like publishing scheduled posts, running plugin jobs, and maintenance routines.

Attackers can abuse scheduled tasks to recreate malicious files or keep reinfecting the site.

If malware keeps returning after you delete it, a scheduled task may be involved. Use a reputable WordPress management or security tool to inspect scheduled events, and compare anything unfamiliar against the plugins you actually use.

Search for Suspicious Code Patterns

Backdoors often use obfuscation, which means the code is intentionally made hard to read.

Security scanners may flag functions commonly used in malicious files. Examples include encoded strings, compressed code, remote file loading, or code that executes hidden instructions.

Be careful with this step. Some legitimate plugins use advanced PHP functions too. A suspicious pattern is a clue, not automatic proof.

Tip: If a file contains a large unreadable block of characters and you cannot explain why it exists, treat it as suspicious until proven otherwise.

Review Server Logs

Server logs can show which files were accessed, when they were accessed, and from what IP addresses.

You may see repeated requests to strange PHP files, unusual POST requests, or access to files inside upload folders. These clues can help identify the backdoor and the original entry point.

Logs can be noisy, and many legitimate bots crawl websites constantly. Look for patterns rather than one-off requests.

Use Multiple Scanning Layers

A WordPress security plugin can help, but do not depend on one scanner alone.

Different tools catch different things. A good process may include a WordPress-level scanner, host-level malware scanning, file comparison, manual review, and log analysis.

Ambrite’s cloud web hosting uses LiteSpeed, NVMe SSD storage, and Imunify360 to help detect and block many common threats at the server level. Hosting starts at $7.99/month CAD, which is useful for small Canadian businesses that want better protection without managing server security themselves.

What to Do If You Find a Backdoor

Do not panic-delete the first suspicious file you find.

If one backdoor exists, there may be several. Attackers often leave more than one way back in.

A safer response looks like this:

  1. Take a full backup of the infected site for reference.
  2. Put the site into maintenance mode if visitors are at risk.
  3. Identify suspicious files, users, database entries, and scheduled tasks.
  4. Replace modified WordPress core files with clean official copies.
  5. Replace plugins and themes with clean copies from trusted sources.
  6. Remove unused plugins, themes, and old site copies.
  7. Reset WordPress admin, hosting, database, FTP/SFTP, and email passwords where relevant.
  8. Update WordPress, plugins, and themes after cleanup.
  9. Review file permissions and harden access.
  10. Monitor closely for reinfection.

If you are dealing with an active infection, our guide WordPress Malware Removal: A Complete Guide explains the broader cleanup process.

When Not to Clean It Yourself

DIY cleanup is fine for a small personal website where the risk is low and you have good backups.

It is not always the right call for a business website.

Get professional help if:

  • Your site collects payments, form submissions, bookings, or client information
  • You run WooCommerce or take online deposits
  • Your site belongs to a law firm, clinic, financial firm, or other sensitive business
  • Your host has suspended the account
  • Malware keeps coming back
  • You are not comfortable reviewing PHP files
  • You do not know whether customer data was accessed

For Canadian businesses, a hacked site can become more than a technical issue. If personal information may have been exposed, you may need to assess your obligations under Canadian privacy law, including PIPEDA. This article is a helpful starting point: How to Comply with PIPEDA: Essential Privacy Policy Requirements for Canadian Websites.

If there is any chance sensitive information was accessed, document what happened, when you discovered it, what systems were affected, and what you did in response. That record matters.

How to Prevent Backdoors from Coming Back

Backdoor prevention is mostly about reducing opportunities.

No setup is impossible to hack, but a maintained WordPress site is much harder to compromise than one that has been ignored for months.

Keep WordPress, Plugins, and Themes Updated

Most small business WordPress hacks are not highly targeted attacks.

They are automated scans looking for known weaknesses. Updates close many of those doors.

Do not update blindly on a complex WooCommerce or booking site, though. Use a staging site when changes could affect checkout, forms, calendars, or integrations.

Remove What You Do Not Use

Every unused plugin is extra risk.

If you are not using a plugin or theme, delete it. Deactivated code can still contain vulnerable files if it remains on the server.

This also makes future security reviews easier because there is less clutter to inspect.

Use Strong Access Controls

Every administrator should have their own account.

Avoid shared logins like “admin” or “office.” Use strong unique passwords and enable two-factor authentication for administrator access.

Also review who has hosting panel, FTP/SFTP, DNS, and email access. WordPress is not the only doorway into your site.

Harden File Permissions

File permissions control who can read, write, and execute files on your hosting account.

If permissions are too loose, attackers may have an easier time modifying files or adding backdoors. If they are too strict, your site may stop working properly.

For a practical overview, see WordPress File Permissions: A Security Guide.

Monitor After Cleanup

A cleaned site should be watched closely for at least the next few weeks.

Look for new file changes, strange traffic, unknown users, failed login spikes, and security alerts. Reinfection usually means the original entry point or another backdoor was missed.

This is where a maintenance plan can be worth it. Ambrite’s WordPress maintenance and security plans start at $49/month CAD and include ongoing care for Canadian small business websites.

Backdoors Are a Persistence Problem

The real danger with a WordPress backdoor is not just the file itself.

It is the persistence. The attacker wants access that survives password resets, plugin updates, and quick malware cleanups.

So if your site was hacked, do not stop after removing the obvious spam page or redirect. Check how the attacker got in, look for hidden access, clean from trusted sources, reset credentials, and monitor the site afterward.

If you are unsure whether your site is clean, ask for help before restoring random backups or deleting files you do not understand. A careful cleanup takes longer, but it is far better than fighting the same infection over and over again.

Need a second set of eyes on a suspicious WordPress site? You can contact Ambrite and we’ll help you figure out the safest next step.

This article was written with the help of AI and reviewed by the Ambrite team. Pricing, features, and technical details may change — always verify with official sources before making decisions.

Was this article useful?

Related Articles

How to Comply with PIPEDA: Essential Privacy Policy Requirements for Canadian Websites
Your website collects personal information from visitors — even just their IP address counts....
How to Set Up Two-Factor Authentication for WordPress Admin Access
Two-factor authentication (2FA) is like adding a deadbolt to your WordPress admin door — and in...
How Hackers Exploit Outdated WordPress Plugins
That outdated WooCommerce shipping plugin you've been meaning to update? It's probably already...
How a Hacked Website Damages Your Firm's Reputation
Your website just got hacked. The sinking feeling in your stomach is real — and it should be. A...
WordPress Security Best Practices for Law Firms
Your law firm's website handles sensitive client data every single day. One security breach...