Every site you host with us is scanned for malware automatically every night, whatever its type – WordPress, Joomla, Drupal, PrestaShop, OpenCart, Grav, MediaWiki, PHP or static HTML. The results are on each site’s Malware scan tab, in plain words: what was found, why it matters and what to do.
💡 Official files are never reported
Before anything is shown to you, each flagged file is compared with the official published copy of WordPress, its plugins and themes, Joomla or Drupal. A file that is byte-for-byte identical to the official one is cleared automatically – so an update or a stock plugin file no longer raises a false alarm.
What the scan checks
- Core files: whether the files of your CMS are the official ones for its version, and whether anything extra has been dropped into its system folders.
- Hidden or disguised code: patterns that malware uses to hide itself (obfuscated code, back doors that hide a plugin or an administrator, and similar).
- Known malware: every changed file, and every file of each site once a week, is checked against large, regularly updated open-source malware signature databases.
- Programs running from your files: a program started from inside a site’s folder (for example a crypto-miner) is stopped at once.
Reading the Malware scan tab
Open your site, then Malware scan in the left menu. A green box means nothing was found. A red box lists each file that needs your attention, what kind of problem it is, when it was first found, and the buttons to deal with it.
A file marked Being checked by our team matched a broad rule that also matches some harmless files; a person checks it before anything happens, and you have nothing to do.
What to do when something is found
- Quarantine the file. It is moved aside, so the site stops loading it at once. Nothing is deleted: the file is kept safely and Restore puts it back exactly as it was.
- Repair core files (WordPress, Joomla, Drupal) puts back the official files of the same version. Your content, plugins, themes, uploads and settings are not touched.
- Change the passwords of the site’s administrators, and update or remove plugins and themes you no longer use – that is how malware usually gets in.
- Press Scan again to check the site straight away instead of waiting for the night scan. It usually takes one to five minutes.
If a core file was changed by you on purpose, press This is my change and it will not be reported again. Not sure a file is harmful? Press Ask support to check – we look at the file for you and reply by e-mail.
When a site is paused
To protect its visitors and the other sites on the server, a site whose malware is still there 7 days after it was first found is paused. The tab shows the date. A paused site opens again automatically once the files are cleaned (or quarantined) and the next scan finds nothing – press Scan again to speed that up.
What we never do
- We never delete your files automatically.
- We never show the contents of your files to anyone outside our support team.
- We never clear a finding because of its file name alone – only when its content is identical to the official copy, or after a person has checked it.
