The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Technical SEO Issues
    4. Malware & Wordpress

    Malware & Wordpress

    Technical SEO Issues
    6 4 376
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NileCruises
      NileCruises last edited by

      Google has identified Malware on on eof our Wordpress sites. In webmaster tools it names the 10 pages where code has been injected.

      I cant' find them easily via the WP dashboard and wondered if anyone had had any experience of this and what steps they took?

      Plus are there any measure I can take to fight against this? The site is on the latest WP version.

      Thanks,

      Colin

      1 Reply Last reply Reply Quote 0
      • MarieHaynes
        MarieHaynes last edited by

        Definitely keep your plugins updated.  Plus, if you use Timthumb on any of your sites, do some research on Timthumb vulnerabilities.

        Make sure you change all of your wordpress passwords after cleaning up.

        And, if you get hit again, despite your cleanup, hire a professional!  I had a nasty job done on one of my sites.  My host thought they'd fixed it and it came back.  I hired sucuri.net to fix it and after 3 weeks they were no further ahead.  I hired a professional guy (pm me for the name if you want to hire him) and it took him a while but he figured it out.  Not all malware issues are that complicated though.

        1 Reply Last reply Reply Quote 0
        • evolvingSEO
          evolvingSEO last edited by

          Colin

          Any luck with this yet? I'd follow Marie's good advise and first be sure everything is updated. Then try these things to find it;

          • Disable each plugin one by one and see if it goes away.
          • Can you see the code when you view source or use a tools like browseo.net or shut off CSS? If you can see the location of the injected code you may be able to tell where it was inserted.
          • If you can't see it viewing source or with browseo etc - try doing a Google cache: search and view in text only.
          • Check your widgets.
          • Check your .htaccess file

          Once you find it definitely check out this document on securing wordpress.

          Let us know how it goes.

          -Dan

          1 Reply Last reply Reply Quote 1
          • mhadaily
            mhadaily last edited by

            That would be ok if you use these plugin as well :

            http://wordpress.org/extend/plugins/sucuri-scanner/

            http://wordpress.org/extend/plugins/gotmls/

            http://wpantivirus.com/

            NileCruises 1 Reply Last reply Reply Quote 0
            • NileCruises
              NileCruises last edited by

              Thanks Marie (and Dan and Majid),

              I am going through the plugins and widgets now. I re-installed a clean version of the Theme too but not sure if I've done that too soon if the script is still there.

              I can see the page titles in Webmaster Tools but cant' find the actual pages on the server to delete, in case that helps.

              I will definitely look at the security suggestions and resources suggested. Thanks for the tips.

              Marie I will PM you too if I may.

              Thanks guys,

              Colin

              1 Reply Last reply Reply Quote 0
              • NileCruises
                NileCruises @mhadaily last edited by

                Thanks Majid,

                Sucuri Scanner looks good. I wonder if you had any experience of it?

                If it can remove the malware as well as alerting me of any future hacks it would seem money well-spent.

                Colin

                1 Reply Last reply Reply Quote 0
                • 1 / 1
                • First post
                  Last post
                • My WP website got attack by malware & now my website site:www.example.ca shows about 43000 indexed page in google.
                  0
                  1
                  82

                • How important is AMP?
                  donsilvernail
                  donsilvernail
                  0
                  3
                  669

                • Wordpress rel next & previous for SEO
                  evolvingSEO
                  evolvingSEO
                  0
                  5
                  192

                • ATG & Endeca Integration & SEO implications
                  0
                  1
                  803

                • Wordpress Pods and Wordpress SEO by Yoast
                  Ron_McCabe
                  Ron_McCabe
                  1
                  7
                  1.1k

                • Wordpress & use of 'www' vs not for webmaster tools - explanation needed
                  dnaynay
                  dnaynay
                  0
                  5
                  917

                • Redirecting ?iframe=true&width=80%&height=80%
                  JAARON
                  JAARON
                  0
                  4
                  1.0k

                • Wordpress speedup
                  sandlappercreative
                  sandlappercreative
                  0
                  6
                  602

                Get started with Moz Pro!

                Unlock the power of advanced SEO tools and data-driven insights.

                Start my free trial
                Products
                • Moz Pro
                • Moz Local
                • Moz API
                • Moz Data
                • STAT
                • Product Updates
                Moz Solutions
                • SMB Solutions
                • Agency Solutions
                • Enterprise Solutions
                • Digital Marketers
                Free SEO Tools
                • Domain Authority Checker
                • Link Explorer
                • Keyword Explorer
                • Competitive Research
                • Brand Authority Checker
                • Local Citation Checker
                • MozBar Extension
                • MozCast
                Resources
                • Blog
                • SEO Learning Center
                • Help Hub
                • Beginner's Guide to SEO
                • How-to Guides
                • Moz Academy
                • API Docs
                About Moz
                • About
                • Team
                • Careers
                • Contact
                Why Moz
                • Case Studies
                • Testimonials
                Get Involved
                • Become an Affiliate
                • MozCon
                • Webinars
                • Practical Marketer Series
                • MozPod
                Connect with us

                Contact the Help team

                Join our newsletter
                Moz logo
                © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                • Accessibility
                • Terms of Use
                • Privacy