Skip to main content

When to Submit a WordPress Site Cleanup Request

S
Written by Salvador Aguilar

Not every security alert requires a manual cleanup β€” but some infection patterns are clear signals that automated protection alone won't be enough. This article helps you identify those situations so you know when to escalate to a Monarx WordPress Site Cleanup request.

πŸ” Signs Your Site Needs a Cleanup

The following are the most common indicators that a WordPress site has an active infection that warrants a manual cleanup by our Threat Research team.

  1. πŸ‘» Rogue administrator accounts keep appearing
    ​
    If new WordPress admin users are being added to the site without any legitimate action by the account owner, this is a strong indicator of a persistent backdoor. Malware often creates these accounts to maintain access even after surface-level cleanups.
    ​

  2. πŸ› Spam or malicious posts are being created automatically
    ​
    If the site is generating posts, pages, or comments with spammy or malicious content β€” especially in bulk or at regular intervals β€” this suggests a malware component is actively writing to the WordPress database.​
    ​

  3. β†ͺ️ The site is redirecting visitors to a third-party website
    ​
    Malicious redirects are one of the most disruptive infection symptoms. If visitors are being sent to external sites (often phishing pages, adult content, or scam pages), there is likely malware embedded in the theme files, a plugin, or the wp-config.php file.
    ​

  4. πŸ™… Malicious links or content keep getting injected into pages
    ​
    Repeated reappearance of spam links, hidden text, or injected iframes β€” especially after you've manually removed them β€” indicates that malware is still present and actively re-injecting the content.
    ​

  5. πŸ†• Plugins are being installed without authorization
    ​
    If new plugins appear on the site without anyone having installed them, this typically means an attacker has established a persistent foothold and is using it to deploy additional tools or backdoors.
    ​

  6. 🦠 Malicious files keep getting recreated after removal
    ​
    If you or your team have deleted suspicious files, only to find them reappear shortly after, this is a classic sign of a dropper or persistence mechanism. The malware is regenerating the files from another location on the server β€” a full cleanup is needed to find and eliminate the source.

❓ Why These Symptoms Require a Manual Cleanup

All of the patterns above share one thing in common: they keep coming back. This is because surface-level removal β€” deleting a file, removing a user, deactivating a plugin β€” doesn't address the root cause. Somewhere on the server there is a backdoor, a modified core file, or a database entry that is driving the reinfection.

A Monarx Site Cleanup involves a manual, in-depth review of the site's files, plugins, themes, users, and database by one of our engineers β€” not just an automated scan. This is what makes it effective against persistent infections.

βœ‹ Before You Submit

Before submitting your request, make sure to:

  1. Review the Technical Requirements for WordPress Site Cleanup to confirm your site meets all the conditions needed for our tools to operate.
    ​

  2. Include as much detail as possible in the Notes field when submitting β€” describe the specific symptoms you are seeing, how long they've been occurring, and any steps already taken. The more context our engineers have, the faster the issue can be resolved.

When you're ready, follow the steps in How to Submit a WordPress Site Cleanup to open your request.

Did this answer your question?