Evidence-led field research
WordPress Malware Research
Find evidence-led WordPress malware research by the symptom you are seeing, including redirects, hidden users, spam, unknown plugins, and recurring infections.
Start with what changed on your site. Each result then separates the visible warning signs from the code, file, database, and screenshot evidence retained during an anonymized investigation.
Directly tied to retained code, paths, screenshots, or database evidence.
Professional interpretation is labeled separately from direct observation.
Each entry states what the available evidence cannot establish.
Find research by symptom
What problem are you seeing on your WordPress site?
Choose a symptom or search for a filename, plugin name, warning, or behavior. A match is an investigation lead—not an automatic diagnosis.
Showing all 39 research entries
- 01 WordPress functions.php Credential Logger Writing to a Fake PNG Filename This entry matters when a security review finds login-hook code in a theme even though users have not noticed a broken login form. The supplied code appended submitted credentials to a local file disguised with a PNG extension. Can WordPress theme code record passwords while login still works? Login & credential risk Suspicious files & code Credential logging
- 02 menu-queue-bit.php and the Compact Extension Vox Identity This entry helps owners investigate a large, unfamiliar PHP file in wp-content/mu-plugins that is not explained by their normal plugin inventory. The retained filename, size, and location are distinctive; execution was not demonstrated. What is menu-queue-bit-compact-extension-vox.php in mu-plugins? Unknown plugins Suspicious files & code Obfuscated must-use plugin artifact
- 03 wp-perf-analytics Plugin Deployer Embedded in functions.php This research is relevant when an unfamiliar wp-perf-analytics plugin appears and the obvious installer code is hard to find afterward. The supplied theme code wrote the plugin and then removed the marked deployment block from functions.php. Why did a wp-perf-analytics plugin appear without being installed? Unknown plugins Malware returns Suspicious files & code Theme-based fake-plugin deployer
- 04 wp-user-query.php MU-Plugin Concealing a Stored User ID This entry is relevant when the user total and visible rows do not match, especially when no ordinary plugin explains the change. The supplied must-use plugin altered user queries and count data for one stored user ID. Why does WordPress show a different user count from the visible user list? Hidden users Login & credential risk MU-plugin hidden-user concealment
- 05 media-patcher-lab.php Found in WordPress mu-plugins This entry is relevant when a plugin repeatedly disappears or deactivates and an unfamiliar media-named PHP file is present in mu-plugins. The two observations occurred in one investigation, but the retained evidence does not prove causation. Why does a WordPress plugin keep disappearing or deactivating? Unknown plugins Malware returns Fake MU-plugin with plugin tampering
- 06 system-control Plugin Restored from wp-content/.sc-backup This research is directly relevant when an unfamiliar System Control must-use plugin reappears after its visible loader is removed. The supplied code checked a backup file and rewrote the destination when it was missing or changed. Why does an unknown WordPress plugin return after I delete it? Unknown plugins Malware returns Self-restoring fake plugin persistence
- 07 WP Security Helper Plugin and User-List Concealment This research is relevant when a WP Security Helper directory exists on the server but routine wp-admin views do not account for it, or user listings appear incomplete. The code altered both plugin-list and user-query behavior. Why is WP Security Helper present in hosting files but missing from WordPress? Unknown plugins Hidden users Fake plugin with administrative concealment
- 08 StateMesh MU-Plugin Self-Copy and Plugin-List Concealment This page is relevant when an unfamiliar StateMesh plugin is found on disk, does not appear normally in wp-admin, or seems to return after incomplete removal. The supplied code included both concealment filters and self-copy logic. Why is StateMesh missing from my WordPress Plugins screen? Unknown plugins Malware returns Self-copying concealed MU plugin
- 09 hide-hidden-posts.php MU-Plugin and Concealed Post IDs This investigation is relevant when spam posts are publicly reachable or appear in search results but cannot be found normally in wp-admin. A must-use plugin filtered selected post IDs and adjusted administrative post counts. Why are casino posts on my WordPress site but not in the Posts screen? Spam & unwanted content Hidden users Post-concealment MU plugin
- 10 esc_html Array-Assembly eval Loader Found in PHP This page supports investigation of unfamiliar search-result language or spam alongside a suspicious PHP modification in a plugin file. The retained code shows a compact loading path, but it does not preserve the loaded content or prove the search symptom by itself. Why does Google show unfamiliar language for my WordPress pages? Spam & unwanted content Suspicious files & code Array-assembled PHP eval loader
- 11 PrivDayz-Branded Obfuscated index.php in a Random Directory This page is for owners who receive a malware alert for an unfamiliar index.php in a randomly named directory. The location and PrivDayz identifier are useful investigation leads, but the retained evidence does not prove that the file executed. What is a PrivDayz file found in my WordPress hosting account? Suspicious files & code Obfuscated PHP tool artifact
- 12 Recurring wk Directories with a Hex-Fragment PHP Loader This research helps an owner investigate repeated unfamiliar directories found across a WordPress installation. The retained evidence shows the locations and a hexadecimal loading structure, but it does not establish a complete persistence chain. Why do similar unknown directories appear in several WordPress folders? Malware returns Suspicious files & code Distributed PHP loader artifacts
- 13 Advanced LinkFlow Control Plugin Concealment and Remote Fetching This entry is relevant when hosting files contain an unfamiliar plugin directory that does not appear normally in wp-admin. The supplied code used plugin-list filters and a remote response path; the remote response itself was not retained. Why is a plugin folder present on the server but missing from WordPress? Unknown plugins Redirects & pop-ups Fake plugin with conditional fetching
- 14 TokensDeGuards Payload Verification and eval in index.php This entry is for owners whose scanner or developer finds a TokensDeGuards-style index.php artifact. The file’s identifier and structure support further investigation, but no request log or execution trace was retained. What is TokensDeGuards in a WordPress index.php file? Suspicious files & code Authenticated compressed PHP loader
- 15 Hidden Administrator Query Hooks Found in functions.php This entry is relevant when the WordPress Users screen shows fewer accounts than its count, or an unfamiliar administrator cannot be accounted for. The retained code targeted one stored user ID and altered normal user-list behavior. Why does my WordPress user count not match the visible users? Hidden users Login & credential risk Hidden administrator backdoor
- 16 c-i.icu Click-Triggered Redirect Script in index.php This research is useful when visitors report that clicking the site opens an unrelated page or new window. The supplied code attached a document-level click listener and constructed an external destination, although no browser trace was retained. Why does clicking anywhere on my WordPress site open another page? Redirects & pop-ups Suspicious files & code Click-triggered JavaScript redirect
- 17 WordPressCore Fake Plugin with cURL-to-eval Loader Files This entry helps owners investigate a plugin named WordPressCore that may be mistaken for a legitimate platform component. The retained files contained a remote PHP loading path; the response and resulting behavior were not preserved. Is WordPressCore a legitimate WordPress core plugin? Unknown plugins Suspicious files & code Fake plugin remote PHP loader
- 18 Repeated _0x3023 Obfuscated JavaScript Found Across 17 Files This entry is relevant when a scanner or developer finds the same unreadable JavaScript across themes and plugins. The investigation retained the repeated marker in 17 files; visitor-side execution was not captured. Why is the same obfuscated JavaScript in many WordPress files? Redirects & pop-ups Malware returns Suspicious files & code Repeated obfuscated JavaScript injection
- 19 xdiff.php XOR Loader Using Writable Temporary Directories This entry is for owners or developers who find unfamiliar xdiff-based patching code during a WordPress file review. The structure is unusual and security-relevant, but no triggering request or patched output was retained. Why is xdiff_string_patch used in my WordPress PHP files? Suspicious files & code Request-gated temporary-file PHP loader
- 20 ushort.company Meta-Refresh and JavaScript Redirect in post_content This investigation is directly relevant when opening a particular post or page immediately sends visitors elsewhere. The retained database content contained both a zero-delay meta refresh and JavaScript navigation to the same destination. Why does one WordPress post redirect immediately to another website? Redirects & pop-ups Spam & unwanted content Database-stored dual redirect
- 21 SavvyWolf MANAGER PHP Web-Shell Variant This entry is relevant when a scanner finds a SavvyWolf-named PHP file or a browser request exposes an unfamiliar server file-manager interface. The retained sample included filesystem controls and attempts to create additional copies. What is a SavvyWolf file manager found on my WordPress server? Suspicious files & code Malware returns PHP web shell
- 22 Hello Aili Plugin Fetching and Evaluating Remote PHP This entry is relevant when an owner finds a Hello Aili plugin they did not install, or a familiar-looking plugin file contains remote loading code. The retained artifact fetched and evaluated a response, but that response was not preserved. What is the Hello Aili plugin in my WordPress installation? Unknown plugins Spam & unwanted content Suspicious files & code Fake plugin remote PHP loader
- 23 Selective PHP Allowlist Rules Found in a Malicious .htaccess This entry is useful when most PHP files become inaccessible or return 403 responses while a small allowlist remains reachable. The investigation found restrictive .htaccess rules beside an unexpected about.php file, but no server log was retained. Why did WordPress start returning 403 errors after an .htaccess change? Errors & warnings Suspicious files & code Selective .htaccess PHP allowlist
- 24 goto-Obfuscated Remote Loader Found in index.php This entry is intended for an owner whose host, developer, or security scanner found heavily obfuscated PHP in an unexpected index.php file. The code structure is documented, but the evidence does not establish a visitor-facing symptom. Why is my WordPress index.php full of goto statements and unreadable strings? Suspicious files & code Obfuscated remote PHP loader
- 25 PHP Shell Ultimate Artifact Found Among Upload-Like Folders This research helps owners assess PHP files discovered where media or static uploads are expected. The retained names and shell-style structure are higher-confidence investigation leads, but the evidence does not show who accessed the files. Why are PHP files present inside my WordPress uploads area? Suspicious files & code Login & credential risk PHP web-shell artifact
- 26 Mixed-Case PHP Deny Rule with an index.php Exception This entry is useful when PHP endpoints fail across multiple nested directories after unexpected .htaccess files appear. The retained directives deny PHP access recursively, although no server request log linked them to a specific visitor report. Why are PHP files returning 403 errors across several WordPress folders? Errors & warnings Suspicious files & code Restrictive .htaccess access control
- 27 HTTP-Header-Gated PHP Loader Found in a Plugin File This research helps evaluate a short injected PHP block that selected an HTTP header before passing derived data into a loader path. It may leave the public site looking normal until a matching request is made. Why is a WordPress plugin reading an unfamiliar HTTP header? Suspicious files & code Header-gated PHP loader
- 28 Cookie-Indexed PHP Loader Found in an .htaccess-Named File This entry helps owners and responders assess an unusually small PHP file named like .htaccess inside a plugin directory. The artifact selected cookie data and passed it to an include operation, but no visible front-end symptom was retained. Why is there PHP code inside an .htaccess file? Suspicious files & code Cookie-indexed PHP loader
- 29 XOR-Decoding Temporary-File Loader in wp-config.php This entry is relevant when wp-config.php contains unreadable PHP before the normal WordPress configuration. The supplied code decoded data, wrote a temporary PHP file, included it, and attempted cleanup; the decoded payload was not retained. Why is there XOR-obfuscated PHP in wp-config.php? Suspicious files & code Malware returns Request-gated PHP loader
- 30 hexagoncontrail-js External Script Injection in WordPress HTML This research is useful when a page contains an unfamiliar third-party script and visitors report unexpected browser behavior. The retained evidence confirms the script reference, while the response served by that external host was not captured. Why does my WordPress site load JavaScript from an unfamiliar domain? Redirects & pop-ups Errors & warnings External JavaScript injection
- 31 PHP Footer Loader Fetching Remote Hidden-Link Markup This investigation connects a WordPress footer hook to remotely supplied markup containing concealed outbound links. It is most relevant when owners see unfamiliar search-result keywords, hidden links, or a security service reporting a redirect from a page. Why are hidden spam links appearing in my WordPress footer? Spam & unwanted content Redirects & pop-ups Errors & warnings Remote content injection
- 32 WP-Security Fake Plugin with an eval Decode Wrapper This entry helps owners assess a plugin directory discovered through hosting or file-manager access when the code is encoded or absent from routine plugin review. The available wrapper is suspicious, but its decoded payload was not retained. Why is there an unknown encoded plugin folder in wp-content/plugins? Unknown plugins Suspicious files & code Fake security plugin encoded loader
- 33 Hostname-Keyed XOR JavaScript Loader with new Function This entry is relevant when a checkout or site audit uncovers hostname-dependent, obfuscated JavaScript. The code structure warrants investigation, but the supplied fragment does not show collection or transmission of payment-card data. Why does this obfuscated JavaScript check my website hostname? Login & credential risk Suspicious files & code Hostname-keyed JavaScript loader
- 34 Database-Stored fetch() Calls Injecting Remote Spam Content This entry is relevant when unexpected blocks, links, or spam appear in rendered pages and the source is not found in theme files. The retained database script made remote requests and inserted returned text into selected page elements. Why is remote content appearing on WordPress pages from a database record? Spam & unwanted content Suspicious files & code Database-stored remote-content injection
- 35 wpinfo-pst1 Obfuscated Redirect Stored in post_content This entry is relevant when owners see intermittent redirects or discover an external script stored in page or database content. The retained record confirms the injected script reference; it does not preserve what the external server returned. Why is an unfamiliar script stored in my WordPress database? Redirects & pop-ups Suspicious files & code Database-stored packed redirect script
- 36 woocommerce_inputs Plugin with Redirect and Concealment Hooks This entry is relevant when an unfamiliar woocommerce_inputs directory appears in hosting files, the plugin is absent from wp-admin, or redirects seem conditional. The code filtered plugin views and contained a redirect branch. Why is woocommerce_inputs on my server but missing from the Plugins screen? Unknown plugins Redirects & pop-ups Fake plugin with conditional redirect logic
- 37 Hourly cPanel PHP Cron Job Running an Encoded eval Wrapper This entry helps owners investigate recurring suspicious files or behavior when a hosting-level cron task survives normal WordPress cleanup. The retained cron command ran hourly and invoked decoded PHP, although its complete payload effect is unknown. Why does WordPress malware return every hour after cleanup? Malware returns Suspicious files & code Server cron encoded PHP execution
- 38 M6bMm64 Hidden Anchor and Off-Screen CSS in post_content This page helps owners investigate unfamiliar links found in page source or SEO audits even though the visible design looks normal. The retained markup moved an outbound anchor far outside the viewport with inline CSS. Why is there a hidden outbound link in my WordPress page source? Spam & unwanted content Suspicious files & code Database-stored hidden-link injection
- 39 WP Compatibility Patch Plugin Creating and Hiding an Administrator This page is relevant when a compatibility-themed plugin appears alongside unexplained user-count differences or an unfamiliar administrator. The supplied code hid one selected account from queries and interfered with ordinary account-management actions. Why is WP Compatibility Patch hiding a WordPress administrator? Hidden users Login & credential risk Fake plugin hidden administrator
Need a diagnosis, not just a matching article?
I can investigate what is actually happening on your site.
I review the files, database, users, scheduled tasks, and server evidence, then separate confirmed findings from assumptions before cleanup.