Get a free website with any plan

See how
TROUBLESHOOTING

Scanning your website for malware

Last updated

IN SHORT

Imunify360 scans every Flashcloud hosting account automatically on a schedule and flags suspicious files. You can also run an on-demand scan anytime from cPanel's Imunify360 tool, or use a WordPress plugin like Wordfence for site-specific threats. No setup is needed. It runs in the background by default.

If you think your site is hacked or just want to confirm it isn't, multiple options for malware scanning are available — server-side automatic, on-demand, and via security plugins.

Server-side automatic scanning (us)

We run Imunify360 on every hosting server. It scans accounts on a schedule and flags suspicious files.

If we detect malware on your account:

  • We email you with the file paths and the type of threat.
  • The portal shows a security notice.
  • For active threats (malware actively serving from your site), we may quarantine specific files immediately.

You don't have to do anything to enable this — it's running in the background.

On-demand scan via cPanel

For an immediate scan:

  1. Open cPanel from your hosting service.
  2. Look for Imunify360 tool or Imunify360 under Security.
  3. Click Start scan.

Scanning takes a few minutes for typical accounts. Results show:

  • Files detected as malware.
  • Suspicious patterns (not necessarily malware but worth reviewing).
  • Recommended actions (delete, clean, ignore).

For each detected file, options:

  • Clean — Imunify360 attempts to remove the malicious code while keeping the file.
  • Delete — remove the file entirely.
  • Ignore — mark as a false positive (don't flag again).

Clean works for some types of infection (injected JavaScript, modified WordPress core files). For wholesale-malicious files (PHP backdoors, web shells), delete is the right action.

WordPress-specific scanning

If you're running WordPress, plugin-based scanners are more thorough for WordPress-specific threats:

Wordfence

  • Free and paid tiers.
  • Comprehensive scan: file integrity (compares your WordPress files to known-good versions), malware signatures, suspicious patterns, vulnerable plugins.
  • Scheduled and on-demand.
  • Results show specifically what's wrong and how to fix.

To install: wp-admin → Plugins → Add New → search "wordfence" → Install → Activate.

Run a full scan from wp-admin → Wordfence → Scan. Initial scan takes 5–30 minutes depending on site size.

Sucuri

  • Subscription-based (no free tier comparable to Wordfence's).
  • Off-site scanner — runs from Sucuri's infrastructure, looks at your site like an external visitor.
  • Catches some things server-side scanners miss (cloaked malware that only shows to specific user agents).

MalCare

  • Combination of WordPress plugin + cloud-based scanner.
  • Auto-cleanup options.
  • Less popular than Wordfence but specialized in clean-after-detection.

For most sites, Wordfence is the right choice. Free tier covers detection; paid adds real-time protection and faster updates.

Online malware scanners (free)

For a quick external check:

These are external scanners; they only see what your site serves publicly. Useful as a sanity check, not as comprehensive as server-side or WordPress-plugin scans.

What to do if malware is found

Once a scan flags something:

  1. Don't panic — most infections are cleanable.
  2. Take a snapshot before changes (preserves evidence).
  3. Identify the entry point:
    • Outdated plugin/theme with known exploit (most common).
    • Weak admin password that was brute-forced.
    • Compromised FTP credentials that were used to upload malware.
  4. Clean or delete the malware — using the scanner's tools.
  5. Restore from a known-clean backup if cleanup is uncertain.
  6. Update everything — WordPress core, all plugins, all themes.
  7. Change all passwords — admin, FTP, hosting, database.
  8. Audit users — make sure no unauthorized admin accounts were created.

For more detailed incident response, see What to do if my website is hacked.

Preventing future infections

Most infections come from:

  • Outdated plugins or themes — patch promptly.
  • Weak passwords — strong, unique, two-factor.
  • Vulnerable themes from random sources — only install themes from reputable sources.
  • Compromised FTP credentials — use strong passwords or SSH keys; restrict FTP IPs if possible.

The best malware scan is the one you don't need to run because the site stays clean.

Power-user note

For continuous monitoring of file changes (catching new infections as they happen), tools like:

  • WordPress's Wordfence "Live Traffic" — shows requests in real time.
  • Tripwire-like file integrity monitoring — alerts on any file change.
  • fail2ban on a VPS — auto-bans IPs based on log patterns.

For high-stakes sites, multiple layers of protection (firewall + WAF + scanner + monitoring) is the right level. Most sites are fine with the default protection plus good update hygiene.

Common questions

How do I know if my site has malware?

Check for a security notice in your hosting portal or an email from us with file paths and threat type. You can also run an on-demand scan from cPanel's Imunify360 tool (listed under Security) to confirm.

Will Flashcloud tell me if malware is found on my account?

Yes. If Imunify360 detects malware, we email you the file paths and threat type, and the portal shows a security notice. For active threats serving malware, we may quarantine the affected files immediately.

Should I clean or delete an infected file?

Clean works for injected JavaScript or modified WordPress core files, since it removes the malicious code while keeping the file. For PHP backdoors or web shells, delete the file entirely.

What's the best malware scanner for WordPress?

Wordfence is the right choice for most sites. Its free tier covers detection with file integrity checks, malware signatures, and vulnerable plugin alerts; the paid tier adds real-time protection and faster updates.

What do I do after malware is found on my site?

Don't panic, most infections are cleanable. Take a snapshot before making changes, identify the entry point, clean or delete the malware, update everything, and change all your passwords.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.