SECURITY FINDING
Disguised malware file (double extension)
What it is
A file was found with two extensions, like image.jpg.php — a classic way to disguise malicious code as a harmless picture or document, since some servers still execute the hidden second extension.
How to fix it
Delete the file if you don't recognize it, and change your passwords if you're unsure how it got there. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.
In depth
Our security scan found a file with two extensions in its name, like image.jpg.php, which is a common trick used to hide malicious code on websites. When a file has this double extension format, a web server may execute it as code (in this case, PHP) even though the first extension suggests it's just a harmless image file. An attacker could use such a file to gain control of your website, steal customer data, or infect visitors with malware. To fix this, log into your WordPress admin area, go to your security plugin's dashboard, find the flagged file in the scan results, and click the option to delete or quarantine it. After removal, change your WordPress admin password and any FTP or hosting account passwords you use to access your website files. If you're uncomfortable doing this yourself, contact your web hosting support team and ask them to locate and remove files with double extensions in your WordPress directory.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.