WordPress malware
keeps coming back?
Get help cleaning up the infection and move to hosting with TopSyde Sentinel. Daily scans combine known-threat checks with AI-assisted analysis to hunt hidden backdoors, injected spam, and suspicious files.
$89/month per site. Malware cleanup and migration included when you switch. Sentinel scans begin once your site is connected.
Illustrative demo · simulated events, not live customer activity
Daily scans
Checks across WordPress files and database content.
AI-assisted analysis
Suspicious findings assessed alongside known-threat checks.
Improved by investigations
Our team adds detection rules as new threats are uncovered.
Free front-end check · ~20 seconds
Not sure if you're hacked? Paste your URL.
A front-end scan can't see server-side backdoors — it flags surface signals only. We never store your site's code.
The threat changed
The attackers automated.
Now your defense has too.
Malware used to be hand-built and rare. Now AI mass-produces it and probes thousands of sites a minute. A once-a-month manual check can't keep that pace. Sentinel runs at attack speed.
Read the deep dive: how AI is reshaping WordPress malwareYou cleaned it. It came back.
The cleanup removed the visible malware but missed the persistence vector — a hidden admin or a REST app-password quietly let them back in.
Google flagged you for content you never posted.
Cloaked casino and pharma spam was injected into your pages and database — invisible to you, fully visible to the crawler that tanked your rankings.
A plugin says you're infected but can't fix it.
It found a symptom from inside the compromised site and stopped there. Removal needs outside access to the real filesystem — which is exactly where Sentinel works.
The last line, not the only line
On top of everything you already trust
Your firewall and CDN stop the flood at the perimeter. Sentinel catches the one that gets through — reading the real filesystem and database from outside, and removing what's already inside.
Defense in depth, with the deepest layer finally automated — and included in your hosting at no extra cost.
Why it works
Four things a security plugin can't do
Outside-in protection
A plugin guards your site from inside the very site it's protecting — so when the site falls, the guard falls with it. Sentinel watches from outside over SSH, anchored on the one source of truth attackers can't fake: official WordPress core checksums.
AI eyes on everything
Deterministic rules catch the known threats instantly. An AI layer judges everything ambiguous — posts, plugins, files, options — so Sentinel catches novel, AI-generated attacks a signature list has never seen, without drowning you in false positives.
It actually removes it
Most tools email you an alert and wish you luck. Sentinel quarantines malware, restores tampered core, deletes rogue admins, revokes backdoor keys, and strips injected spam — automatically. Every action is reversible.
Whole-fleet visibility
One dashboard across every site and every provider. Live compromise badges, scan history, per-site drill-down, and an AI assistant that can recommend and run remediation on your command.
Everything we catch
A catalog of real, shipping detections
Not a marketing wish-list. Every signature below is live in production today, scoring findings by severity and category across the entire fleet.
Backdoors & webshells
- Obfuscated code execution — eval(base64_decode()), gzinflate, str_rot13
- Code execution from request input — eval / assert fed by $_POST / $_GET
- Known webshell fingerprints — WSO, FilesMan, b374k, c99, r57, IndoXploit
- Browser-based file-manager backdoors (Tiny File Manager & lookalikes)
- Unauthenticated upload shells writing attacker-chosen filenames
- Hex-obfuscated C2 URLs and packed payload arrays
Stealth persistence
- Hidden admin accounts — cloaked from the Users list, deletion-protected
- Header-less must-use plugins injecting spam on every request
- Timestomped files — backdoors with a faked-old modified date
- Application-password REST backdoors that survive password resets
- Malware staging directories left behind as empty husks
- The real answer to “the spam keeps coming back”
Core, plugin & theme integrity
- WordPress core verified against official checksums, tampered files restored
- Plugin manifest diff vs wordpress.org — catches shells hiding in real plugins
- Mandatory custom-theme scan with timestomp anchoring
- Known-bad / RCE-prone plugins (e.g. WP File Manager — CVE-2020-25213)
- .htaccess tampering — PHP handler overrides, auto_prepend_file injection
- PHP dropped where it never belongs — uploads, cache, languages
SEO spam injection
- Injected casino / pharma posts — Mostbet, 1WIN, 1xBet, kazino, bukmeker
- Cloaked off-screen link-farms pushed thousands of pixels off-screen
- Spam buried in page-builder data (Elementor _elementor_data postmeta)
- Spam stored in wp_options and echoed sitewide by a fake plugin
- Transliterated brand spam a keyword list misses — caught by AI review
- Rogue administrator inventory, including cloaked admins
How it works
Connect. Scan. Remediate.
Connect
A site joins the portal and Sentinel connects over an isolated, dedicated key — nothing to install inside the site, nothing an attacker can switch off from within.
Scan
Every day, automatically, Sentinel verifies core, sweeps the filesystem for backdoor signatures, scans the database for injected spam, and escalates anything ambiguous to AI judgment. Findings are scored by severity and category.
Remediate
High-confidence threats are auto-cleaned the moment they're found; everything else waits for one-click approval. Quarantine is reversible, content edits are revisioned, and a single click restores any false positive.
Plugin vs Sentinel
Why Sentinel beats a security plugin
| Typical WP security plugin | TopSyde Sentinel | |
|---|---|---|
| Vantage point | Runs inside the site — compromised with it | Outside-in, over SSH |
| Source of truth | Its own signature list | Official core checksums + AI judgment |
| AI-generated threats | Misses what's not in the list | AI judges anything ambiguous |
| Remediation | Alerts you; you clean it | Finds and removes it — reversibly |
| Hidden admins / app-passwords / timestomp | Usually blind | Explicitly hunted |
| Fleet view | One site at a time | Every site, every provider, one dashboard |
| Cost | Paid plugin + paid clean-up service | Included free with hosting |
Reversible by design
Aggressive on malware. Gentle on your site.
Automatic removal only makes sense if it can never make things worse. So nothing Sentinel does is permanent.
Quarantine, not delete
Malware is moved to a safe holding area and can be restored in one click — never destroyed outright.
Revisioned content
Every spam-strip or content edit creates a standard WordPress revision you can roll back.
Restore false positives
A single safety-net action bulk-reverts anything that was ever flagged in error.
The best part
All of this is included. Free. With every plan.
Not a premium tier. Not a metered add-on. Sentinel is simply how TopSyde does security — included at a flat $89/mo per site.
Proof, not promises
Sentinel's first big test: 340+ hacked-and-rehacked sites.
It found 63 backdoors every prior cleanup had missed. The re-infections stopped.
Frequently asked
Sentinel FAQ
How does Sentinel learn from new threats?
Our team uses malware investigations to improve Sentinel's detection rules and AI review prompts. Those improvements inform later scans. AI-assisted analysis helps assess suspicious code and content alongside known-threat checks; this does not mean the AI independently retrains itself after every scan.
Is Sentinel really free?
Yes. Sentinel is the security layer built into TopSyde managed hosting — included on every plan at no extra cost. It is not an add-on, an upsell, or a separate subscription. If your site is hosted with us, it's protected.
Doesn't my firewall, CDN, and Wordfence already cover this?
Those stop a lot of traffic at the door, and we keep them in place. But a firewall can't see a webshell already sitting in your uploads folder, a CDN can't revoke an attacker's REST application-password, and an in-site plugin is blind the moment the site is compromised. Sentinel works from outside, on the real filesystem and database, and removes what got through.
Do I need to install a plugin?
No. Sentinel connects from the outside — nothing runs inside your site, so nothing can be disabled by an attacker who's already in.
Will it break my site?
Remediation is reversible by design. Malware is quarantined (moved, not deleted) and can be restored; content edits create WordPress revisions; one click reverts anything wrongly flagged. Only high-confidence, unambiguous threats are ever auto-cleaned.
My site keeps getting re-infected. Can Sentinel help?
That's our specialty. Re-infection almost always means a persistence vector survived the last cleanup — a hidden admin, a timestomped backdoor, a dropped payload, or an application-password REST key. Sentinel hunts every one of these specifically.
Does it catch the spam Google is penalizing me for?
Yes — injected casino/pharma posts, cloaked off-screen link-farms in real pages, page-builder (Elementor) injections, and spam stored in the database and echoed sitewide.
Included with hosting
Put Sentinel on your site today.
Already infected? Malware cleanup and migration are included when you switch. Daily Sentinel scans begin once your site is connected.
Sentinel is included free with every TopSyde plan · read the deep dive · see how we compare
