Security researchers have published details of a WordPress backdoor that survives the usual clean-up. As one analysis put it, delete the plugin and a drop-in file rewrites it. The malware hides in several places at once, across files, the database and shared memory, so removing one piece simply triggers another to rebuild it. The report appeared on 1 October.

If your business website runs on WordPress, which covers a large share of UK small business sites, this is worth ten minutes of your attention.

Why it is so hard to remove

Most site owners, or their web developer, clean a hacked site by deleting the suspicious plugin and changing the password. That works against simple infections. This backdoor is designed for exactly that response. It keeps copies of itself in different locations and checks regularly that they are all still there. Remove one and the others recreate it.

The consequences go beyond a defaced homepage. A persistent backdoor lets attackers send spam from your domain, redirect visitors to scam pages, steal customer form submissions or use your site to attack others. Search engines may then flag your site as unsafe, and your rankings and trust take the hit.

Signs your site may be affected

Watch for pages you did not create, strange redirects on mobile devices, sudden drops in search traffic, warnings in Google Search Console, or your hosting company suspending the account for sending spam. Customers telling you your site “looks odd” is often the first clue, so make it easy for them to report it.

What to check now

Update everything. Core WordPress, themes and plugins. Most compromises start through an outdated plugin, so this is the single most useful job. Delete any plugin or theme you are not actually using.

Review administrator accounts. Look for users you do not recognise and remove them. Turn on two-factor authentication for everyone with admin rights.

Look for odd files. Unexpected files in the plugins and mu-plugins folders, or a wp-content/ directory with files modified recently, deserve a closer look. Your host or developer can compare your files against clean copies of WordPress and your plugins.

Check your backups. A backup is only useful if it is clean and recent. Make sure you can restore a version from before any suspected infection, and that backups are stored away from the website itself.

If you think you are infected

Do not just delete the obvious file. Take the site into maintenance mode, ask your host or a security specialist for a full clean, and plan to rebuild from a known good backup or a fresh install with only your content moved across. Then change every password connected to the site, including hosting, database, email and any API keys.

Many small firms have more resilient options available. A static website, such as the Jekyll site you are reading now, has no database or admin login to attack, which removes this whole class of problem. If your site is mostly pages and a contact form, BuildApps can help you move to a simpler, safer set-up without losing your content or search rankings.

The takeaway

Persistence is the new normal for web attacks. Cleaning up once is not proof you are clean. This week, update your WordPress installation, remove unused plugins, switch on two-factor authentication and confirm you hold a recent, clean backup. If you suspect a problem, get it checked properly before you trust the site again.