Type something to search...
How to scan a WordPress website for malware?

How to scan a WordPress website for malware?

To scan a WordPress website for malware, start with a free remote scanner such as Sucuri SiteCheck to check what visitors see, then run a server-side scan with a security plugin like Wordfence, MalCare, or Jetpack Protect. For a deeper check, verify core and plugin files with WP-CLI checksums and search the server for suspicious code patterns. Using more than one method matters, because each one catches different kinds of infection.

Malware on a WordPress site can be obvious, like a redirect to a spam page, or completely silent, like a backdoor waiting in the uploads folder. This guide covers the warning signs, the three layers of scanning (remote, plugin, and manual), how to interpret what scanners report, and what to do next if something turns up.

Signs Your WordPress Site May Have Malware

You should scan regularly anyway, but these symptoms mean you should scan right now:

  • Unexpected redirects: Visitors, especially on mobile or from Google, are sent to spam, scam, or adult sites.
  • Search results look wrong: Google shows pages with pharmaceutical, casino, or Japanese-language spam titles for your domain.
  • Browser or Google warnings: Chrome shows a red "Deceptive site ahead" screen, or Search Console reports security issues.
  • Unknown admin users: New administrator accounts appear in Users > All Users.
  • Hosting account suspended: Your host flags malware or unusual outbound email.
  • Slow performance or high CPU: Cryptominers or spam scripts can consume server resources.
  • Modified files you didn't change: Core files, .htaccess, or wp-config.php show recent modification dates.
  • Spam emails from your domain: Your server is sending mail you didn't send.

Some malware only shows itself to certain visitors, such as first-time users, mobile visitors, or search engine crawlers. Not seeing a problem yourself doesn't mean your site is clean.

Before You Scan: Take a Backup

Scanning is read-only, but fixing what you find isn't. Before you start acting on results, take a full backup of your files and database. Even an infected backup is useful for forensic comparison, and it gives you a way back if a cleanup step breaks something. Label it clearly so you never restore it by accident.

Layer 1: Remote (External) Scanning

Remote scanners visit your site like a browser and analyze the output. They don't need access to your server.

Tools to Use

  • Sucuri SiteCheck: Enter your URL at sitecheck.sucuri.net. It checks for known malware, injected spam, suspicious scripts, outdated software, and blocklist status.
  • Google Safe Browsing Site Status: Google's transparency report tool shows whether Google currently flags your site as unsafe.
  • Google Search Console: The Security & Manual Actions > Security issues report tells you whether Google has detected hacked content, malware, or social engineering on your verified property.
  • VirusTotal: Submit your URL to check it against many security vendors' blocklists.

What Remote Scans Can and Can't Do

Remote scanners are fast and require no setup, but they only see public output. They can't detect:

  • Backdoors that don't change page output.
  • Malicious files in directories that aren't linked from your pages.
  • Infected database entries that aren't displayed.
  • Malware that only shows to specific user agents or referrers (though some scanners try to simulate these).

A clean remote scan is reassuring, not conclusive. Always follow it with a server-side scan.

Layer 2: Security Plugin Scanning

Security plugins scan your actual files and database from inside WordPress.

Wordfence

Wordfence's free scanner compares core, plugin, and theme files against the WordPress.org originals, checks for known malware signatures, and looks at the database for malicious content.

  1. Install and activate: Go to Plugins > Add New Plugin, search for Wordfence Security, install, and activate it.
  2. Adjust scan options: Go to Wordfence > Scan > Scan Options and Scheduling. For a thorough first scan, choose High Sensitivity, and enable scanning files outside your WordPress installation if your hosting allows it.
  3. Run the scan: Click Start New Scan and wait. Large sites may take a while.
  4. Review results: Each finding includes a severity level and options such as viewing the file, seeing differences from the original, repairing, or deleting.

MalCare

MalCare runs its scans on its own servers, so it's a good option on limited hosting.

  1. Install MalCare Security from the plugin directory.
  2. Connect your site to the MalCare dashboard when prompted.
  3. Let the initial scan complete. MalCare syncs your site and analyzes it off-site.
  4. Review the report. Automatic cleanup is available on paid plans.

Jetpack Protect

Jetpack Protect scans for known vulnerabilities in your core, plugin, and theme versions for free. Malware scanning and one-click fixes are part of Jetpack's paid security plans. It's useful as a second opinion alongside another scanner.

Other Options

Plugins like Sucuri Security (file integrity monitoring and remote scanning), Solid Security (vulnerability scanning), and Defender can also help. Avoid running several heavy scanners at once, since they can slow your server and flag each other's files.

Layer 3: Manual and Command-Line Checks

Plugins are convenient, but malware authors know how they work. If your plugin scan comes back clean yet symptoms persist, or if you want extra confidence, check things directly. You'll need SSH access, ideally with WP-CLI installed.

Verify Core File Checksums

WordPress publishes checksums for every core file. WP-CLI can compare your files against them:

# Check WordPress core files against official checksums
wp core verify-checksums

# Check plugins from WordPress.org against their official checksums
wp plugin verify-checksums --all

Any file reported as modified or added in core directories deserves attention. Premium plugins not hosted on WordPress.org can't be verified this way, so compare those against a fresh download from the vendor.

Find Recently Modified Files

Malware often changes or creates files. Look for PHP files modified in the last week or two:

# PHP files modified in the last 14 days
find /var/www/example.com/public_html -type f -name "*.php" -mtime -14 -printf "%TY-%Tm-%Td %TH:%TM %p\n" | sort

Attackers sometimes fake modification dates, so this is a helpful hint rather than proof.

Look for PHP Files in Uploads

The wp-content/uploads directory should contain media, not PHP scripts. Any PHP file there is a strong red flag:

find /var/www/example.com/public_html/wp-content/uploads -type f -name "*.php"

Search for Suspicious Code Patterns

Certain functions appear frequently in obfuscated malware. They also appear in legitimate code, so treat matches as leads to investigate, not automatic proof:

cd /var/www/example.com/public_html

grep -rnE --include="*.php" "eval\(|base64_decode\(|gzinflate\(|str_rot13\(|assert\(" wp-content/ | head -50

# Look for very long single lines, typical of obfuscated code
grep -rlE --include="*.php" ".{5000,}" wp-content/

Pay special attention to matches in files with random names, files in unexpected folders, and code at the very top or bottom of otherwise normal files.

Check the Database

Malware frequently hides in the database, especially in posts and options. Using WP-CLI, you can search for injected scripts:

# Search post content for script tags or iframes
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%<script%' OR post_content LIKE '%<iframe%';"

# Check key options that attackers like to change
wp option get siteurl
wp option get home

Replace wp_ with your actual table prefix. Some legitimate content does contain scripts and iframes (like video embeds), so review each result.

Also look for unexpected administrator accounts:

wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Check Critical Files by Hand

Open these files and look for anything unfamiliar:

  • wp-config.php: Look for code that includes other files, long encoded strings, or anything after the "That's all, stop editing!" line besides the standard require.
  • .htaccess: Look for unexpected rewrite rules that redirect based on referrer or user agent.
  • wp-content/mu-plugins/: Must-use plugins load automatically and don't appear in the normal plugin list, which makes them a favorite hiding spot.
  • Theme functions.php and header.php: Look for injected code, especially at the top or bottom.

Server-Level Scanners

If you manage your own server, you can use server-side tools in addition to WordPress-specific ones:

  • ClamAV: An open-source antivirus engine. It catches some web malware, though its WordPress coverage is less specialized.
  • Linux Malware Detect (maldet): Designed for shared hosting environments and web malware. It can use ClamAV as its scanning engine.
  • Imunify360 or ImunifyAV: Commercial and free options often provided by hosts using cPanel or Plesk.

A basic ClamAV scan on Ubuntu or Debian looks like this:

sudo apt update && sudo apt install clamav
sudo systemctl stop clamav-freshclam
sudo freshclam
sudo systemctl start clamav-freshclam
clamscan -r -i /var/www/example.com/public_html

On RHEL-based systems, install ClamAV from the EPEL repository with sudo dnf install clamav clamav-update. Many hosts also offer built-in malware scanning in their control panels, so check there first.

How to Interpret Scan Results

Scanners produce both real findings and false positives. Here's how to triage:

  1. Critical findings first: Known malware signatures, backdoors, and modified core files are high priority.
  2. Check file locations: A suspicious function inside a well-known plugin's main file is often legitimate. The same function in wp-content/uploads/2024/03/cache.php almost certainly isn't.
  3. Compare against originals: Download a fresh copy of the plugin or theme and compare the flagged file.
  4. Note outdated software: Scanners often flag outdated plugins with known vulnerabilities. These aren't malware, but they're likely how an infection got in.
  5. Don't delete blindly: Deleting a file that WordPress or a plugin needs can take your site down. Back up first and understand what a file does before removing it.

What to Do If Malware Is Found

Scanning tells you there's a problem. Fixing it is a separate process that usually involves:

  • Putting the site in maintenance mode.
  • Replacing core, plugin, and theme files with clean copies.
  • Removing backdoors and malicious database entries.
  • Changing all passwords, including database, hosting, SFTP, and WordPress admin passwords.
  • Regenerating the security keys and salts in wp-config.php.
  • Updating everything and fixing the vulnerability that let the attacker in.
  • Requesting a review from Google if your site was flagged.

For a complete walkthrough of that process, see our guide on recovering a hacked WordPress site. If the infection is complex or you're short on time, a professional cleanup service from Sucuri, Wordfence, or MalCare can save a lot of stress.

How Often Should You Scan?

  • Automated daily scans: Most security plugins can scan on a schedule. Daily is a good default for business sites.
  • Weekly manual review: Glance at scan reports and alerts at least once a week.
  • After any incident or unusual behavior: Scan immediately if something looks wrong.
  • After installing new plugins or themes: Especially from sources outside WordPress.org.
  • Monthly external check: Run SiteCheck and review Google Search Console.

FAQ: Scanning WordPress for Malware

Yes. Sucuri SiteCheck offers a free remote scan, Wordfence includes a free server-side scanner, and WP-CLI can verify core and plugin checksums at no cost. Combining them gives good coverage without paying.

Remote scanners only see public output, and some malware hides from certain visitors or lives in files that don't affect pages. Run a server-side scan, verify checksums with WP-CLI, and check the database and mu-plugins folder manually.

No. Legitimate plugins sometimes use these functions. They're worth investigating when they appear in unexpected files, in obfuscated code, or in folders like uploads where PHP shouldn't exist.

A remote scan takes seconds. A plugin scan can take anywhere from a few minutes to over an hour, depending on the number of files, database size, scan sensitivity, and server resources.

Scanning itself doesn't change anything, though heavy scans can temporarily slow down limited hosting. Problems usually come from deleting or repairing files, so always back up before acting on results.

Many hosts do, especially managed WordPress hosts and those using tools like Imunify360. Check your hosting dashboard or ask support, but don't rely on host scanning alone.

Treat it as suspicious. Back up your site, inspect the file's contents, and if it isn't clearly part of a trusted plugin, remove it and investigate how it got there. Also consider blocking PHP execution in uploads.


Conclusion

Scanning a WordPress site for malware works best in layers. A remote scan with Sucuri SiteCheck and a look at Google Search Console tells you what the outside world sees. A server-side scan with Wordfence, MalCare, or a similar plugin digs into your files and database. Manual checks with WP-CLI checksums, find, and grep catch the things automated tools miss.

Make scanning a routine rather than a reaction. Schedule automated scans, review reports weekly, and investigate unusual behavior quickly. If you find malware, back up, clean methodically, fix the entry point, and change your credentials. Regular scanning means problems are caught while they're still small.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper