Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If your Hostinger-hosted WordPress site is redirecting visitors, showing unfamiliar content or triggering a malware alert, first preserve a copy of its files and database. Then contain the site, scan it, clean or restore it, and check for hidden persistence before reopening it. Hostinger’s exact entry-point warning is important: “The exact entry point of a malware infection usually can’t be confirmed after the fact.”

How to tell whether your WordPress site may be infected

These symptoms warrant investigation, but none alone proves malware is present. A broken site can also result from a failed update, a plugin conflict or a configuration change.

  • Visitors are redirected to unfamiliar websites, or the site displays content you did not publish.
  • You find unknown files, suspicious code or unexpected rules in .htaccess.
  • The WordPress administration area has broken styling, or you see an unfamiliar administrator account.
  • A security scanner reports a threat, or visitors encounter an unexpected fake verification prompt.

Hostinger lists these as warning signs, not a forensic diagnosis. Its support guidance also cautions that the original entry point usually cannot be established afterward.

Step 1: Preserve evidence and limit exposure

Before deleting files or restoring a backup, save a copy of the current site files and database if you can. This gives you a recovery point for legitimate recent work and material to review if cleanup does not succeed. Keep the copy somewhere separate from the hosting account and ensure it can be restored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If visitors are being redirected or served suspicious content, restrict public access while you investigate. Hostinger’s cleanup tutorial recommends preparing backups and reviewing recent changes as part of the response. Avoid editing or deleting unfamiliar files casually: a legitimate file removed or changed in error can break the site.

Step 2: Run Hostinger’s Malware Scanner

Hostinger documents a Malware Scanner for Web Hosting and Cloud Hosting plans. Plan eligibility and dashboard navigation can change, so confirm availability and the current location in your Hostinger account. The scanner can be run outside WordPress admin, which is useful if you cannot sign in to the site.

  1. Sign in to the Hostinger dashboard and open Malware Scanner if it is available for your plan.
  2. Run a scan and review the flagged files or other results before taking action.
  3. Save or record the results so you can compare them with any changes made during cleanup.

A scanner result is a lead for investigation, not a guarantee that every compromised file or persistence mechanism has been found. Do not assume a clean scan means the site is safe if symptoms continue.

Step 3: Choose a cleanup method

Choose based on what you can safely inspect, whether WordPress admin is accessible, and whether the infection appears to return. Plugin-based cleanup may be easier to start; manual work offers more direct control but has a higher risk of damaging the site if you are unfamiliar with WordPress files and databases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Route Useful when Limits to keep in mind
Hostinger Malware Scanner Your plan includes it, particularly if WordPress admin is inaccessible. Availability depends on plan and the dashboard’s current interface; a scan alone may not expose every persistence location.
Security plugin You can access WordPress admin and want to start with a plugin-based scan or cleanup. Hostinger names Wordfence and Anti-Malware Security as options. A plugin is not a guaranteed complete cure. Confirm what it detects and changes, and retain your backup.
Manual inspection and cleanup You have the technical confidence to compare files, verify WordPress core files and inspect suspicious code. Incorrect edits or deletions can break the site, and removing visible files alone may leave other persistence behind.
Restore a clean backup You have a restorable backup from before the infection and can accept losing later changes or preserve them separately. A full WordPress restore replaces both files and database with the selected backup state.

Plugin cleanup

Hostinger identifies Wordfence and Anti-Malware Security as plugin options. Use a plugin’s scan and cleanup features according to its own guidance, then verify the result rather than treating installation or one scan as proof that the site is clean.

Manual cleanup

Hostinger’s tutorial describes reinstalling and comparing WordPress core files, checking file checksums, and inspecting PHP files in locations such as wp-content/uploads. If you take this route, compare suspicious files against known-good versions for the same software version and inspect before changing anything. Do not overwrite custom work or delete a file solely because its name is unfamiliar. If you cannot confidently distinguish legitimate site code from malicious changes, use a qualified technician instead of making broad edits.

Step 4: Check for persistence if malware returns

Repeated infection after cleanup suggests that the source may not be limited to the files you removed. Hostinger identifies several places to investigate:

  • Unknown administrator accounts: review WordPress users and remove or secure accounts you cannot verify.
  • Authentication keys and cookies: generate new WordPress authentication keys so existing sessions are invalidated.
  • mu-plugins: inspect wp-content/mu-plugins for unfamiliar code. Must-use plugins may not appear in the ordinary plugins list.
  • Database content: consider whether suspicious content or changes remain in the database, particularly if files have been cleaned but symptoms persist.

Changing a password or deleting visible files alone may not address all of these locations. If restoring is necessary to clear a persistent infection, Hostinger advises restoring website files and the database together from the same backup point.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Step 5: Restore carefully when cleanup is not enough

Hostinger’s full WordPress restore returns both files and the database to the state captured on the selected date. Choose a point before the suspected infection and keep a separate copy of current files and data first: restoring can overwrite newer posts, orders, form submissions or other legitimate changes.

After the restore, check the site and WordPress admin, update software, and change credentials. If the same symptoms reappear, investigate persistence and access routes rather than repeatedly restoring the same state.

Step 6: Close likely entry points and get help

  • Update WordPress core, themes and plugins, and remove extensions you do not trust or no longer use.
  • Remove cracked or unlicensed themes and plugins; they may expose the site to risk.
  • Use strong, unique passwords for hosting, WordPress, database and related accounts.
  • Protect forms from abuse and keep backups that are separate and restorable.
  • Scan the computer or device used to access the site, since compromised devices can expose credentials.

If the infection continues, Hostinger says eligible WordPress sites whose domains point to Hostinger can request paid cleanup. Confirm current eligibility, scope and price with Hostinger before choosing that service.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.