Opens in a new tab

WordPress file permissions after malware cleanup: hardening to prevent reinfection

Technician hardening WordPress file and folder permissions after malware cleanup
Technician hardening WordPress file and folder permissions after malware cleanup

Quick answer: After WordPress malware cleanup, deleting malicious files is not enough. Harden file and folder permissions, wp-config, uploads, plugins/themes, backups, system users and change logs to reduce reinfection risk.

Many sites still come back infected after fixing form spam or strange outbound emails because folders remain too writable, backups are public, uploads can execute PHP, or old accounts can still edit source code. This is a core part of WordPress malware and error repair.

Why permissions matter after cleanup

Malware needs a place to persist: creating new files, modifying old files, writing into uploads, injecting theme/plugin code or abusing cache and backup paths. If write access remains too broad, a site can look clean for a few hours and then become infected again.

Areas to harden

AreaControlGoal
WordPress foldersAvoid broad write access; allow writes only where neededReduce malware recreating files
wp-config.phpProtect the configuration and database detailsReduce secret exposure or config tampering
uploadsBlock PHP execution where the server supports itStop webshells disguised as uploaded files
plugins/themesKeep only valid, updateable, non-nulled codeReduce reinfection through untrusted code
backup/cacheDo not leave database/code backups publicPrevent data and source exposure
FTP/SFTP usersSeparate access by role and remove old accountsLimit abuse of leaked credentials

Do not apply one permission recipe to every host

Shared hosting, VPS, LiteSpeed, Nginx, Apache, containers and managed hosting may run PHP differently. Copying a random chmod command can break the site or leave it exposed. Correct permissions allow the site to run and update under control without giving every process broad write access.

Uploads need special attention

The uploads directory normally needs to accept images, PDFs or documents. But if PHP can execute there, a webshell can live in uploads and run as active malware. After cleanup, review suspicious files, double extensions, fake media and server rules that block script execution.

wp-config.php and backup files

wp-config.php contains database details and security salts. If it is modified or a copy is publicly exposed, sensitive data may leak. Also check old zip, sql and tar.gz files inside webroot, because public backups are a common post-repair risk.

Plugins, themes and update permissions

Hardening does not mean locking the site so updates fail. The right approach is to keep legitimate plugins/themes, update with backup and testing, limit direct production edits and remove unused code. With nulled plugins or themes, permissions alone cannot fix the problem because the source itself is untrusted.

System accounts are part of permissions

If FTP/SFTP, hosting panel or old administrator accounts remain active, attackers may return without exploiting WordPress again. After an incident, rotate passwords, revoke unused accounts, separate access by role and enable stronger authentication where available.

Test after tightening permissions

After hardening, test key workflows: media upload, plugin updates, contact forms, cache, backup jobs, WooCommerce checkout when applicable and legitimate cron jobs. Over-tightening can break updates, cache writes or form file uploads.

SEO/AIO impact

Hardening reduces reinfection. When the site stays stable, Google and AI crawlers are less likely to encounter junk URLs, wrong titles, strange redirects or malicious files again. This technical stability supports service pages, schema, sitemap and internal link recovery.

Post-hardening checklist

The checklist should include changed-file review, no script execution in uploads, protected wp-config, no public backups, clean plugins/themes, revoked old users, normal mail/form logs, no junk sitemap URLs and recurring WordPress maintenance. For repeatedly compromised sites, add ongoing WordPress security services.

FAQ

Should chmod 777 be used so uploads work?

No. 777 is usually too broad and can allow malicious file writes.

Can tighter permissions break plugin updates?

Yes, if done incorrectly. Test updates, cache, uploads and backups after changing permissions.

Should PHP be blocked in uploads?

Usually yes where the server supports it, because many webshells hide in upload paths.

Does hardening fully prevent reinfection?

No. It reduces risk, but updates, backups, log monitoring and account review are still required.

Cleaned the malware but not hardened the site yet?

IT Systems reviews file/folder permissions, uploads, wp-config, plugins, themes, backups and logs to reduce reinfection risk after cleanup.