Title: Wordfence not seeing javascript hack
Last modified: August 30, 2016

---

# Wordfence not seeing javascript hack

 *  Resolved [VickeyWilliams](https://wordpress.org/support/users/vickeywilliams/)
 * (@vickeywilliams)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/)
 * Word fence not picking up a redirect hack that injects code like this in the 
   header.php file,
 * _[Moderated – Please don’t post that on the forums. Use PasteBin if necessary]_
 * Please advise.
 * [https://wordpress.org/plugins/wordfence/](https://wordpress.org/plugins/wordfence/)

Viewing 5 replies - 1 through 5 (of 5 total)

 *  Plugin Author [WFMattR](https://wordpress.org/support/users/wfmattr/)
 * (@wfmattr)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/#post-6511977)
 * Thank you for contacting us. You may have a compromised password, or there may
   be other files on your server that are responsible for placing the code in header.
   php. It is best to follow this guide on cleaning hacked sites — you may have 
   a new infection that is different from all of the signatures included in scans:
   
   [How do I clean my hacked site using Wordfence?](http://docs.wordfence.com/en/How_do_I_clean_my_hacked_site_using_Wordfence%3F)
 * If the high sensitivity scan finds additional files, you can send them to samples[
   at] wordfence.com, so they can be reviewed and included in future scans.
 * If removing a file breaks the site, check wp-config.php for an “include” or “
   require” statement with that file’s name.
 *  [007dutchy](https://wordpress.org/support/users/007dutchy/)
 * (@007dutchy)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/#post-6512145)
 * I have this problem also..
    Removed all the code in header.php 2 days go and 
   changed all my passwords. Now it is back again..
 * What can I do?
 *  [DebraCuming](https://wordpress.org/support/users/debracuming/)
 * (@debracuming)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/#post-6512147)
 * The other thread about this closed so I’m here to say I’ve changed all passwords,
   am running the latest versions of everything and the problem is back after two
   days. What more can I do?
 *  Thread Starter [VickeyWilliams](https://wordpress.org/support/users/vickeywilliams/)
 * (@vickeywilliams)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/#post-6512156)
 * Sorry you all got hit with this redirect. Such a pain to get rid of it. I forgot
   to upgrade WordPress etc. on one site on my account and it ended up infecting
   all 6 sites. It’s been 2 weeks now and I may have solved the problem.
 * I did the following after deleting the obvious js code in the header.php file.
 * 1. Updated everything wordpress/themes/plugins
    2. Changed passwords and user
   names, ON EVERYTHING!!! I don’t use admin as a user name any longer. 3. Got rid
   of all plugins and themes I wasn’t using. Though I like to keep one default wordpress
   theme, but it needs to be updated also. 4. Installed Wordfence, it did discover
   some code with a “GLOBAL” line in it on other pages, not sure it was related 
   but I deleted those files and any files Wordfence called out. That line was in
   a contact form plugin and older themes if I recall. Sorry didn’t keep that line
   of code. 5. I also started logging in from another browser thinking Safari may
   have been a problem. 6. I did sign up for Sitelock through my host and elected
   to go for the version that fixes problems. I set this up on one account.
 * I monitor my sites with wordfence now and have Sitelock on the main one.
 * Free from this hack now for a week, keeping my fingers crossed that it’s gone.
 * You may want to review this link I found helpful.
 * [https://www.malwareremovalservice.com/wordpress-header-php-var-a1aqapkrv02vrg-injection/](https://www.malwareremovalservice.com/wordpress-header-php-var-a1aqapkrv02vrg-injection/)
 *  Plugin Author [WFMattR](https://wordpress.org/support/users/wfmattr/)
 * (@wfmattr)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/#post-6512159)
 * VickeyWilliams: Thanks for the details on how you fixed your site! I’ve heard
   of a couple other people who had similar issues on their sites, where there were
   multiple sites on the same hosting account, and an outdated WordPress installation
   or outdated plugin on one of the other sites affected all of them.
 * DebraCuming & 007dutchy: Have you tried following the guide for cleaning hacked
   sites yet? It is a long process, but there are deeper Wordfence scans as part
   of the process that can clean up additional files not found in the regular scans:
   
   [How do I clean my hacked site using Wordfence?](http://docs.wordfence.com/en/How_do_I_clean_my_hacked_site_using_Wordfence%3F)
 * I think the forum mods closed the other thread because there were too many people
   on it, and the forum rules ask to have each person’s issue as a separate topic.(
   Sorry, plugin authors aren’t able to re-open them or change the rules, even in
   cases like this.)
 * As Vickey mentioned, if you do have other sites on your hosting account, make
   sure those are all updated as well. Even if you have other non-WordPress sites,
   if they’re outdated, those could be a problem too. If Wordfence finds any new
   files in the deeper scans, they might not all be malicious — you can send them
   to us if you are unsure if a file is bad or not.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Wordfence not seeing javascript hack’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 5 replies
 * 4 participants
 * Last reply from: [WFMattR](https://wordpress.org/support/users/wfmattr/)
 * Last activity: [10 years, 8 months ago](https://wordpress.org/support/topic/wordfence-not-seeing-javascript-hack/#post-6512159)
 * Status: resolved