· updated 2026-10-07
A webshell is a small script that lets someone run commands on the server through a browser. It needs no WordPress login and no FTP — only the file URL.
What it looks like
The simplest version fits on one line and takes a command from a query parameter. More advanced ones include a file browser, a database client and a mail form — a complete control panel.
The filename rarely raises suspicion: wp-cache.php, wp-conf.php, index2.php, or a random string.
Where to look
wp-content/uploadsand its year subfolders;- theme and plugin directories, especially inactive ones;
- the site root, among core files;
- directories beginning with a dot.
A reliable detection method
In the server access logs, look for POST requests to PHP files other than wp-admin, wp-login.php or admin-ajax.php. Webshell use almost always leaves this trace, even if the file itself has already been deleted.
Once a webshell is found, assume the attacker had full access to files and database. That means rotating every credential, auditing every file, and assessing whether personal data was reached — which can trigger a reporting obligation.