Title: PHP Code is not legit (new user)
Last modified: September 21, 2026

---

# PHP Code is not legit (new user)

 *  Resolved [krahentash1](https://wordpress.org/support/users/krahentash1/)
 * (@krahentash1)
 * [1 week, 2 days ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/)
 * Hi, I just signed up and when connecting my page etc it asks if the PHP file 
   is legit, and its 100% not. It also says to create a ticket… so here I am. My
   site is certainly hacked as I typed in site and my domain name and it leads to
   other shady places… supper annoying. Please help so I can get this fixed. Thank
   you

Viewing 6 replies - 1 through 6 (of 6 total)

 *  [Zeba Afia Shama](https://wordpress.org/support/users/zebaafiashama/)
 * (@zebaafiashama)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19025890)
 * Hi [@krahentash1](https://wordpress.org/support/users/krahentash1/)
 * _(Disclaimer: I am not a Wordfence staff member, just a fellow WordPress user/
   developer, but here is a clear plan to help get your site back under control.)_
 * What you are describing is a classic redirect injection (often paired with SEO
   spam or malicious scripts injected into core files/database). Wordfence is flagging
   an unrecognized or modified PHP file because the attacker likely placed a backdoor
   or edited an existing file.
 * Here is the recommended sequence to isolate and clean this up:
   **1. Take an immediate
   backup**
 * Before modifying or deleting anything, generate a full backup of your site files
   and database via your web hosting control panel (**cPanel/Plesk/hPanel**). Even
   a infected backup is crucial so you don’t accidentally lose site content or media
   if a cleanup goes wrong.
   **2. Complete Wordfence Setup & Run a Deep Scan**
 * Even though Wordfence flagged the file:
    1. Go to **Wordfence > Scan > Scan Options and Scheduling**.
    2. Select **High Sensitivity** (this will scan image files for injected code and
       check outside WordPress directories).
    3. Click **Start New Scan**.
    4. Wordfence will list the suspicious files and give you the option to view differences
       or delete/restore original core files.
 * **3. Replace WordPress Core Files**
 * Malicious scripts often hook into standard WordPress files:
    - In your WordPress Admin, go to **Dashboard > Updates** and click **“Re-install
      version [x.x]”**. This replaces all official WordPress core files with fresh,
      clean copies while keeping your content and plugins intact.
 * **4. Check Root Server Files Manually (via FTP or Host File Manager)**
 * Attackers frequently modify root directives to force the redirects you noticed:
    - **`.htaccess`** (Apache / LiteSpeed): Check if there are rewrite rules redirecting
      search traffic or specific user agents. You can replace it with the [default WordPress .htaccess](https://www.google.com/search?q=https://developer.wordpress.org/advanced-administration/server/web-server/apache/&utm_source=gemini).
    - **`index.php` and `wp-config.php`**: Check the very top of these files (before`
      <?php` or right below it) for long obfuscated strings (`eval(base64_decode(...))`
      or strange `include`/`require` lines).
    - **`.user.ini` or `php.ini`**: Look for directives like `auto_prepend_file`
      pointing to rogue `.php` or `.ico` files.
 * **5. Reset Credentials & Invalidate Sessions**
 * Once the files are cleaned:
    - Change your **WordPress Admin passwords**, **database password**, **FTP/SSH
      credentials**, and **Hosting account password**.
    - In your hosting file manager or via wp-config.php, update the **WordPress 
      Security Salts** ([WordPress Salt Generator](https://api.wordpress.org/secret-key/1.1/salt/?utm_source=gemini))
      to automatically log out all active sessions, including any the attacker might
      have open.
 * Wordfence team members monitor these forums regularly and will likely respond
   with their standard cleaning guide as well, but starting these steps now will
   help stop the redirect and prevent further damage. 
   Thank You
 *  Thread Starter [krahentash1](https://wordpress.org/support/users/krahentash1/)
 * (@krahentash1)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19025921)
 * Thank you for replying that is so nice of you, when i click delete file wordfence
   give me an error which says “Could not delete file wp-content/uploads/.cache/.
   30d77af1.php. The error was: unlink({WordPress Root}/wp-content/uploads/.cache/.
   30d77af1.php): Permission denied”
 *  [Zeba Afia Shama](https://wordpress.org/support/users/zebaafiashama/)
 * (@zebaafiashama)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19025939)
 * Hi [@krahentash1](https://wordpress.org/support/users/krahentash1/)
 * The “Permission denied” error happens because the malicious file or directory
   has strict file permissions, or it is locked by an immutable attribute (`chattr
   +i`). Because PHP running through Wordfence doesn’t have elevated server rights,
   it can’t delete it automatically.
 * Here is how you can remove it:
 * **1. Delete via Hosting File Manager or FTP (SSH)**
    - Log into your hosting control panel (cPanel, Plesk, hPanel, etc.) and open**
      File Manager**.
    - Navigate to `wp-content/uploads/`.
    - Enable **“Show Hidden Files”** (dotfiles) in your File Manager settings so
      you can see `.cache`.
    - Change the file permissions (chmod) of `.30d77af1.php` and the `.cache` folder
      to `755` or `777`.
    - Delete the file and folder manually.
 * **2. Check for File Immutability (If on SSH/VPS)**
 * If you have SSH access and still can’t delete it as root or cPanel user, run:
 * `lsattr wp-content/uploads/.cache/.30d77af1.php`
 * If it has the `i` (immutable) attribute set, unlock it first:
 * `chattr -i wp-content/uploads/.cache/.30d77af1.php`
 * Then delete it:
 * `rm wp-content/uploads/.cache/.30d77af1.php`
 * **3. Contact Hosting Support**
 * If you don’t have SSH access or file manager permissions, reach out to your web
   hosting support team and give them the exact error message and path. They can
   delete the locked file from the root level in seconds.
 * Once deleted, continue with replacing the WordPress core files and updating your
   credentials as mentioned above!
 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19025987)
 * Hi [@krahentash1](https://wordpress.org/support/users/krahentash1/),
 * I’m not sure I follow which of our services asked you to manually confirm the
   legitimacy of a PHP file, but when a site has been compromized we normally recommend
   that you make a **full backup of the site before making any further changes**.
   In fact, [@zebaafiashama](https://wordpress.org/support/users/zebaafiashama/)’
   s steps start with this and are also helpful. I won’t try to over-complicate 
   or repeat too much.
 * It’s also a good idea to **remove any users with administrative access that you
   don’t recognize** as a priority. That’s just in case somebody has created a new
   account to retain access to your site. It’s possible that an attack vector outside
   of WordPress has been used, though.
 * **As a rule, any time I think someone’s site has been compromised I also tell
   them to update their passwords for their hosting control panel, FTP,  WordPress
   admin users, and database. Make sure to do this.**
 * I will provide our site cleaning instructions for you, just in case the steps
   can help: [https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/](https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/)
 * Additionally, you might find the WordPress Malware Removal section in [our free Learning Center](https://wordfence.com/learn/)
   helpful. We provide a site cleaning service should you need further assistance,
   as do other companies. If you find files that seem suspicious and Wordfence isn’t
   picking them up, email them to **samples @ wordfence . com** and we’ll take a
   look.
 * Many thanks,
   Peter.
 *  Thread Starter [krahentash1](https://wordpress.org/support/users/krahentash1/)
 * (@krahentash1)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19026602)
 * Ive already accepted it, as I couldnt wait any longer for help.. im just waiting
   on my host to send through my log in details, yes, i have removed him and i honestly
   think its from his account as it has his username over everything… so i should
   make him bloody do it! but once i get logins ill go in and delete it, wordfence
   must be working as it alerted me they tried to log in overnight, ive put 2fa 
   on too. thanks everyone
 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [1 week ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19027084)
 * Thanks [@krahentash1](https://wordpress.org/support/users/krahentash1/). Hopefully
   our site cleaning link can also be of use if you are able to clean it yourself
   with assistance from your host.
 * Peter.

Viewing 6 replies - 1 through 6 (of 6 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fphp-code-is-not-legit-new-user%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 6 replies
 * 3 participants
 * Last reply from: [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * Last activity: [1 week ago](https://wordpress.org/support/topic/php-code-is-not-legit-new-user/#post-19027084)
 * Status: resolved