MB Bluejuice
Security

Webshell: remote control on your server

A single file that gives an attacker the same access as your developer. How to find it.

· updated 2026-10-07

A webshell is a small script that lets someone run commands on the server through a browser. It needs no WordPress login and no FTP — only the file URL.

What it looks like

The simplest version fits on one line and takes a command from a query parameter. More advanced ones include a file browser, a database client and a mail form — a complete control panel.

The filename rarely raises suspicion: wp-cache.php, wp-conf.php, index2.php, or a random string.

Where to look

  • wp-content/uploads and its year subfolders;
  • theme and plugin directories, especially inactive ones;
  • the site root, among core files;
  • directories beginning with a dot.

A reliable detection method

In the server access logs, look for POST requests to PHP files other than wp-admin, wp-login.php or admin-ajax.php. Webshell use almost always leaves this trace, even if the file itself has already been deleted.

Once a webshell is found, assume the attacker had full access to files and database. That means rotating every credential, auditing every file, and assessing whether personal data was reached — which can trigger a reporting obligation.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.