Knowledge base
Scanning a site for malware
Every site is scanned on a schedule. You can also start one yourself the moment you are worried, and that is free.
Sites are scanned on a schedule without you asking. If something is found you are told — you do not have to be watching.
Scanning now, because you are worried
Open the site and use Scan now on the security card. The card moves to scanning and updates itself when the result arrives; you do not need to keep the page open.
Asking for a scan of your own site costs nothing and changes nothing about the site, so if you have any reason to suspect a problem, run one. If a scan is already in progress, asking again simply joins the one already running rather than starting a second.
If something is found
The result names the files. Malware on a WordPress site almost always arrives one of two ways, and both matter more than the clean-up:
- An out-of-date plugin or theme. This is the overwhelming majority. Keeping plugins
- A password that was reused somewhere else. Change it, and turn on two-factor.
updated is the single most effective thing you can do, and the platform can do it for you.
Cleaning up
Restore from a backup taken before the infection wherever you can — it is faster and more complete than removing files one at a time, because a compromise you can see is rarely the only change that was made. Check the restore point is genuinely earlier than the first sign of trouble.
Then apply the updates that let it in, before the site is public again. A site cleaned and left un-updated is re-infected within days, usually by the same automated scan that found it first.
False positives
Occasionally a scanner flags a file that is a legitimate part of a plugin. Tell support and we will exclude it — do not delete a file a plugin needs on the strength of one scanner's opinion.
Still stuck?
Support is included on every plan and answers in your own language.
Contact support → All articles →