Malware Removal

Customers can benefit from Kinsta’s security pledge. If your WordPress site is hacked while hosted at Kinsta, we’ll work with you for free to try and undo the damage.

Limitations and eligibility

  • Our security pledge only applies to WordPress sites that do not have nulled plugins or themes. If your site uses a nulled plugin or theme, our team can’t proceed with malware removal until the offending plugins and themes are removed.
  • The pledge doesn’t cover non-WordPress software or custom scripts.
  • You must complete the post-cleanup steps we provide within one business day of our request to remain covered. If these steps aren’t completed in time, your site is no longer covered by the pledge, and any future infections will be subject to a $100 clean-up fee.
  • Our security pledge is subject to our Terms of Service. While we cannot prevent or remediate all security incidents, we will assist you in repairing damage caused by malware to your websites as long as those websites are hosted by Kinsta.

What the security pledge includes

  • An inspection of the site and a deep scan of its files to identify malware.
  • Repair of the WordPress core by installing a clean copy of the core files.
  • Identification and removal of infected plugins and themes.

If an active plugin or theme is removed as part of the malware removal process, you’re responsible for installing and configuring a new copy of it once removal is complete.

We’ll do our best to fully remove malware from your site. However, malware is often deliberately difficult to detect and remove. This is particularly true for infections injected into the site database. As a result, in some rare cases, a single round of malware remediation may not be sufficient. If you detect unexpected or malicious behavior after we’ve completed our work, get back in touch with our team and provide as many details as possible so our specialists can make a further attempt at fully removing the infection.

How sites get hacked

Due to the secure design of our infrastructure, server-level compromises are extremely unlikely. Rather, sites hacked while hosted at Kinsta are infected in one of three ways:

  • Exploits targeting WordPress: using outdated or poorly coded plugins and themes or using outdated versions of the WordPress core.
  • Compromised credentials: an attacker captures your WordPress admin, MyKinsta, database, SSH, or SFTP credentials.
  • Nulled plugins and themes: using “free” nulled versions of premium themes and plugins that contain malicious code.

Signs your site may be compromised

A compromised site doesn’t always announce itself with an obvious error; often the first clue is something looking or behaving slightly off. Here are some common signs to watch for:

  • A different or unfamiliar website is displaying at your domain. This can mean your site’s files or database have been altered, or that your domain is pointing somewhere it shouldn’t.
  • Visitors are being redirected to an unknown or suspicious site. Malicious redirects are often injected into a site’s code and may only appear for certain visitors, such as those coming from search engines.
  • Your site shows content you didn’t create (defacement). This might include unfamiliar text, images, or pop-ups, sometimes left as a visible marker by an attacker.
  • Google or your browser flags your site as dangerous or unsafe. This usually means malware or phishing content has been detected on your site, and can affect your search rankings and visitor trust until it’s resolved.
  • You notice unfamiliar admin users, files, or plugins. Attackers sometimes create hidden admin accounts or install disguised plugins to maintain access to your site.
  • Your site loads unusually slowly or behaves erratically. This can be a sign of malicious scripts running in the background, or your server resources being used for something other than serving your site.

What to do if you suspect your site is compromised

If you notice any of the signs above, acting quickly can limit the damage and make cleanup easier. Here’s what to do:

  • Contact our Support Team for a free malware cleanup. Kinsta includes malware remediation at no extra cost, so this should be your first step rather than attempting to fix it yourself.
  • Make a note of what you’ve observed: unusual URLs, screenshots, error messages, and share this with the team. This helps our team identify the type of compromise faster and locate its source.
  • Don’t delete or reset the site if it needs to be cleaned. Resetting removes evidence our team needs to properly investigate and clean the site, and won’t necessarily remove the underlying vulnerability. If you need to limit visitor exposure in the meantime, take the site offline or restrict access instead, for example, by enabling .htaccess protection or installing a maintenance mode plugin.

Malware removal process

The process of inspecting a site, scanning it for issues, and removing infections may take up to one full business day to complete. Particularly pervasive infections may require multiple rounds of inspection. In some rare cases, where a site has been corrupted beyond repair, it may be necessary to restore the site using a backup.

Removing malware can produce site-breaking results as infected plugins and themes are removed. We recommend enabling maintenance mode on your site (using a plugin) before our team begins, to avoid visitors encountering a broken site mid-cleanup.

Steps taken by Kinsta

For every repaired site, our Support team will:

  • Reinstall the WordPress core.
  • Change your SFTP, SSH, and database passwords.
  • Remove any infected plugins or themes we discover.

Steps you need to take

Once malware removal is complete, we’ll ask you to take the following additional steps to secure your site:

  • Update all plugins, themes, and WordPress core to the latest version.
  • If our team identified and removed any compromised themes or plugins, don’t attempt to manually clean and reuse the compromised files. Download fresh copies from the developer and install them on the site.
  • Review all WordPress admin users and delete any that are unused or unrecognized.
  • Update all WordPress admin user passwords.
  • Update all MyKinsta user passwords.
  • Follow any additional site-specific instructions we provide, based on the nature of the infection.

You should complete these steps within one business day of our request. If you don’t take these additional steps, your site is no longer covered by our security pledge due to violating our Terms of Service, and any future infections will be subject to a $100 clean-up fee.

Scanning additional sites

Having one of your sites infected with malware can lead to concerns about possible infection of your other sites. However, because Kinsta uses a container-based hosting infrastructure, cross-contamination between sites at the server level is not possible.

This means that if there is no specific evidence that additional sites have been compromised, then there’s no reason to think they have been infected.

Inspection of sites to identify possible infections is limited to sites that exhibit specific evidence of infection. In the absence of specific evidence, we would recommend that you use a site-scanning service or plugin such as Sucuri Security to confirm that the rest of your sites have not been infected.

Infections discovered during migration

A deep scan of all site files is a standard step in our migration process. If we determine that your site is infected during a migration, we will pause the migration and report the issue to you. At that time, you will be provided with two options:

  • Proceed with the migration and have Kinsta remove the infection.
  • Cancel the migration, work with a third party to repair the hacked site in the prior hosting environment, or repair it yourself, and then reschedule the migration.

If you choose to have Kinsta remove the malware, we quarantine infected files instead of permanently deleting them. The quarantined files are moved to the ~/private directory within your site’s WordPress files, where they remain inaccessible to the public. This allows you to review or recover the files later if needed.

Quarantining files helps preserve potentially important data while preventing infected files from being publicly accessible or executed.

Was this article helpful?

© 2013 - 2026 Kinsta Inc. All rights reserved. Kinsta®, MyKinsta®, DevKinsta®, and Sevalla® are trademarks owned by Kinsta Inc.The WordPress® trademark is the intellectual property of the WordPress Foundation, and the Woo® and WooCommerce® trademarks are the intellectual property of WooCommerce, Inc. Uses of the WordPress®, Woo®, and WooCommerce® names in this website are for identification purposes only and do not imply an endorsement by WordPress Foundation or WooCommerce, Inc. Kinsta is not endorsed or owned by, or affiliated with, the WordPress Foundation or WooCommerce, Inc. Legal information