In this guide: What is malware on a website? Learn the main types of malware, how websites get infected, warning signs, how to scan your site, and prevention tips.
Website malware is malicious code hidden in your site’s files or database. It can redirect visitors to scam sites, inject spam links, steal payment details, or use your server to attack others — often without you noticing for weeks.
Understanding how malware works is the first step to preventing it.
Types of website malware
Backdoors
Hidden scripts that give attackers ongoing access, even after you change passwords. Often disguised with innocent names inside plugin, upload, or core folders.
Malicious redirects
Visitors (often only mobile users or visitors from search engines) are redirected to scam, adult, or phishing sites. Attackers sometimes hide redirects from logged-in admins so owners don’t notice.
SEO spam
Hidden links or entire spam pages (pharmaceuticals, gambling, fake stores) injected into your site to manipulate search rankings. You might see strange titles in Google results for your domain.
Credit card skimmers
JavaScript injected into checkout pages that steals payment details — especially dangerous for online stores.
Phishing pages
Fake login pages for banks or popular services hosted on your server.
Cryptominers
Scripts that use your server’s or visitors’ CPU to mine cryptocurrency.
Malicious admin users
Hidden administrator accounts created to maintain access.
Spam mailers
Scripts that send spam emails from your server, harming your domain’s email reputation.
How infections happen
- Outdated plugins and themes with known vulnerabilities — the most common cause.
- Nulled/pirated premium themes and plugins — frequently include hidden backdoors.
- Weak or reused passwords for WordPress, hosting, FTP, or databases.
- Compromised computers — malware on your device stealing saved credentials.
- Insecure hosting with poor account isolation.
- Vulnerable custom code without proper input validation.
- Abandoned plugins that no longer receive security fixes.
- File upload features that allow dangerous files.
Warning signs
- Visitors report redirects or browser warnings.
- Google Search Console shows security issues or strange pages indexed.
- Search results show spam titles or descriptions for your site (try searching
site:yourdomain.com). - Unknown admin users or unexpected content changes.
- New or modified files you don’t recognize (especially PHP files in
/uploads/). - Sudden traffic drops or spikes.
- Slow performance or high server resource usage.
- Your host suspends your account or warns about malware.
- Your emails start landing in spam (your server may be sending spam).
- Antivirus or browser warnings when visiting your site.
Scanning your site
Use multiple methods for the best coverage:
- Server-side scan with a security plugin or your host’s scanner.
- Remote scan with an online scanner to check public pages and blacklists.
- Search Console → Security issues report.
- Check files manually via SSH: look for recently modified files and PHP files in upload directories.
- Review users and scheduled tasks for unknown entries.
Full guide: How to Scan Your Website for Malware. If you find an infection, follow How to Fix a Hacked WordPress Site.
Prevention tips
- ☐ Update WordPress, plugins, themes, and PHP regularly.
- ☐ Never use nulled software.
- ☐ Use strong, unique passwords and 2FA everywhere.
- ☐ Install a security plugin or WAF to block known attacks.
- ☐ Limit admin accounts and review users regularly.
- ☐ Disable file editing in the WordPress dashboard.
- ☐ Use secure hosting with isolation, scanning, and backups — see Is Your Hosting Secure?.
- ☐ Keep off-site backups with enough retention to go back before an infection.
- ☐ Scan regularly and monitor Search Console.
- ☐ Keep your own computer secure — updated OS, browser, and antivirus.
Further reading: OWASP Top 10 web security risks
Key Takeaways: What Is Malware
- Website malware includes backdoors, redirects, SEO spam, skimmers, and phishing pages.
- Outdated plugins, nulled software, and weak passwords cause most infections.
- Watch for redirects, spam results, unknown users, and Search Console warnings.
- Scan with multiple methods and prevent infections with updates, 2FA, WAF, and backups.

