Modular puzzle-piece blocks under a translucent shield dome with a scanning beam passing across
Blog · SECURITY

WordPress Plugin Security: A Practical Checklist and Malware Scan Guide

Most hacked WordPress sites are not hacked through WordPress itself. They are hacked through an outdated or badly written plugin. Here is how to keep plugins from becoming the way in.

By Nitish, Biz HoistPublished 22 September 20265 min read
Last updated September 2026

Why plugins are the weak point

The short answer: Good WordPress plugin security means installing only well-maintained plugins from trusted sources, keeping them updated, deleting anything you do not use, and limiting who can install them. Run a website malware scan regularly with a reputable security plugin or scanner, keep off-server backups, and act quickly if a scan finds something.

WordPress core is maintained by a large team and patched quickly. Plugins are written by thousands of different developers, some of whom stop maintaining them. Public security databases record new plugin vulnerabilities every week, and attackers scan the web for sites still running vulnerable versions. An outdated plugin is often all they need.

Before you install: how to vet a plugin

Good WordPress plugin security starts before anything is installed. Check these five things first:

  • Source: install from the official WordPress.org directory or a reputable developer's own site. Never use "nulled" or pirated premium plugins; they frequently contain malware.
  • Last updated: avoid plugins not updated in the past year.
  • Active installs and reviews: more users usually means problems are found and fixed faster.
  • Compatibility: check it is tested with your WordPress version.
  • Do you need it? Every plugin is extra code to maintain. If a few lines of code or an existing plugin can do the job, skip it.

WordPress plugin security checklist

  1. Update weekly. Apply plugin, theme and core updates promptly, testing on a staging copy first for important sites.
  2. Delete, do not just deactivate. Deactivated plugins can still be exploited if their files remain.
  3. Limit admin accounts. Give people the lowest role they need; only admins can install plugins.
  4. Use strong passwords and two-factor login for every admin account.
  5. Disable the file editor in the dashboard so a stolen login cannot edit plugin code directly.
  6. Keep off-server backups and test restoring one.
  7. Use a web application firewall, either a security plugin or a service such as Cloudflare in front of the site.
  8. Watch vulnerability alerts for the plugins you run. Several security plugins and the WPScan database publish them.

How to run a website malware scan

A website malware scan checks your files and database for injected code, backdoors and known malicious patterns. Options include:

  • Security plugins that scan from inside WordPress and compare core and plugin files against clean versions.
  • External scanners that check what visitors and Google see, such as blacklists and injected scripts.
  • Server-level scanning if you manage your own hosting, which catches malware plugins cannot see.

Scan at least weekly, and immediately if you see strange redirects, new admin users you did not create, spam pages in Google results, or a warning in Search Console. The official WordPress hardening guide covers the server side in more depth.

What to do if your site is hacked

  1. Put the site into maintenance mode or take it offline to protect visitors.
  2. Change all passwords: WordPress admins, hosting, database and FTP or SFTP.
  3. Restore from a clean backup taken before the infection, or clean the files manually.
  4. Update everything and remove the plugin that let the attacker in.
  5. Check Google Search Console for security issues and request a review once clean.

If the site has been infected more than once, the cause is usually still there. That is the point to bring in someone who can check the server as well as WordPress.

The most common plugin security problems

  • Outdated plugins with publicly known vulnerabilities, which attackers scan for automatically.
  • Abandoned plugins that no longer receive fixes at all.
  • Nulled premium plugins downloaded from unofficial sites, often with backdoors built in.
  • Weak admin passwords that let attackers install their own malicious plugin.
  • Too many plugins, each one adding code, updates and potential holes.

Almost every one of these is prevented by the routine in the checklist above, which is why WordPress plugin security is mostly about habits rather than tools.

How to audit the plugins you already have

  1. List every installed plugin, active and inactive.
  2. For each, ask: do we still need it, and when was it last updated?
  3. Delete anything unused or abandoned, after taking a backup.
  4. Replace plugins that duplicate each other with one good option.
  5. Check each remaining plugin against a vulnerability database.
  6. Repeat every three months.

Many sites can remove a third of their plugins without losing any feature, which improves speed as well as security.

Hosting matters too

Plugins are only one layer. Cheap shared hosting can expose your site to problems from other sites on the same server, and outdated PHP versions carry their own risks. Good hosting keeps PHP current, isolates sites from each other, runs a firewall and takes backups you can restore. Strong WordPress plugin security on weak hosting still leaves the door half open.

A monthly WordPress security routine

  1. Apply all plugin, theme and core updates, testing important sites on staging first.
  2. Run a full website malware scan and review the report.
  3. Check the list of admin users and remove anyone who no longer needs access.
  4. Confirm last night's backup exists off the server, and test a restore every few months.
  5. Look at Google Search Console for security warnings or strange new pages.
  6. Review any plugins flagged in vulnerability alerts that month.

It takes under an hour for most small sites and prevents the majority of problems. Put it in the calendar, because WordPress plugin security fails most often when the routine quietly stops.

Maintenance beats clean-up

Cleaning a hacked site costs far more than keeping it secure, in money, lost enquiries and search rankings. A simple monthly routine of updates, scans, backups and a check of admin users prevents most problems. If you would rather not do it yourself, a website maintenance service covers all of it.

Frequently asked questions

Are WordPress plugins safe?

Most well-maintained plugins from reputable developers are safe when kept up to date. Risk comes from outdated, abandoned or pirated plugins, which is why vetting and regular updates matter more than avoiding plugins entirely.

How often should I update WordPress plugins?

Check for updates at least weekly and apply security updates as soon as they appear. For business-critical sites, test updates on a staging copy first.

How do I scan my WordPress site for malware?

Use a reputable security plugin to scan files and the database, and an external scanner to check what visitors see. Server-level scanning catches more if you manage your own hosting.

Is deactivating a plugin enough?

No. A deactivated plugin's files remain on the server and can still be exploited. Delete plugins you do not use.

What are the signs my WordPress site is hacked?

Unexpected redirects, unknown admin users, spam pages in Google results, sudden slowdowns, and security warnings from Google or your host are common signs. Scan immediately if you see any of them.

Want someone to keep your site secure?

We handle updates, malware scans, backups and security hardening on servers we run ourselves. See our website maintenance services.

Get a fixed quoteRun the free check