1. PHP files where they don’t belong
Uploads folders should contain images and documents only. Any .php file in wp-content/uploads or similar folders is suspicious. Also look for .php files disguised as images, such as logo.png.php or .ico files included from PHP.
2. Recently modified files
In System Info & Files then File Manager, sort folders by modification date. Files changed on a date you didn’t update anything — especially core files — deserve a look. Attackers sometimes fake dates, so this finds many but not all.
3. Obfuscated code
Open suspicious PHP files and look for:
eval(,assert(orcreate_function(with dynamic inputbase64_decode,gzinflate,str_rot13chains- Long lines of random-looking characters
$_POST,$_REQUESTor$_COOKIEvalues being executedpreg_replacewith the/emodifier
Legitimate plugins use some of these functions occasionally; context matters. Random-looking blobs at the very top of a file are almost always malicious.
4. Unfamiliar files with plausible names
wp-configs.php, class-wp-cache-x.php, admin-ajax1.php next to real files.
5. Compare with a clean copy
Download the same version of your CMS, plugins and themes from their official sources and compare. Core files should match exactly. This is why rebuilding from fresh copies is more reliable than hunting file by file.
6. Check outside the website folder
Cron jobs you didn’t create, and unfamiliar files in your home folder.
After finding them
Don’t just delete them and carry on; follow My website has been hacked: what to do so the entry point is closed.