Skip to content
How to install

Malware scans

Every site is scanned once a day. A scan holds WordPress and directory plugins to wordpress.org’s published checksums, and looks for known malware in the rest with AMWScan. It can move what it finds into quarantine.

A site's Security tab with its last malware scan, open findings and the quarantine

Each step runs in a throwaway container that sees only the site’s files, read-only, with no network, as the site’s own user. The scan holds WordPress and directory plugins to their checksums, and looks for PHP in uploads and links that lead out of the site. AMWScan’s signatures then read what the checksums could not vouch for.

Scan now on a site’s Security tab, or Scan all sites on Sites → Security, starts a scan. At most three run at once, one per server.

Result Means
Nothing found Every engine finished, and nothing is open.
Findings Something is open.
Incomplete An engine could not read everything or ran out of time or memory, or the checksums could not be fetched. Never shown as clean.
Failed Nothing could be scanned. Three in a row send an alert.
Superseded A restore, a move or an update changed the files meanwhile. It runs again.
Finding Severity
Known malware, WordPress file changed, Unknown file among WordPress’s own, PHP in uploads, Handler trick in uploads, WPL7 file changed High
Plugin file changed, Unknown file in a plugin, Link leaving the site Medium
Suspicious code Low, or medium where AMWScan rates it dangerous
WordPress file missing, Plugin file missing Low
  • Reinstall original downloads WordPress or the plugin again from wordpress.org, at the site’s version, over its files.
  • Put back writes a changed WPL7 file again.
  • Quarantine moves the file out of the site.
  • Ignore hides a finding until its file changes. Resolved says you dealt with it, and a scan reopens it if it is still there.

On a finding, in Settings → Security or a site’s own settings, decides what a scan moves:

  • Report and alert, the default, moves nothing.
  • Quarantine confirmed malware moves known malware found in uploads, or as an unknown file among WordPress’s own or in a directory plugin.
  • Quarantine everything it may also moves other code in uploads and unknown files among WordPress’s own.

Everything else is only reported: changed files of WordPress or a plugin, wp-config.php, the top index.php and .htaccess, mu-plugins, links, and files of themes and premium plugins. Suspicious code never moves or alerts. A scan that would move more than 25 files moves none.

Quarantined files sit beside the site’s folder, where nothing serves them. They travel with the site, are in no backup, and stay until deleted or until Keep quarantined files (days) runs out.

A scan vouches for a file only when its exact hash is in one of these:

  • wordpress.org’s checksums for its WordPress or plugin version, a plugin in a renamed folder included.
  • The panel’s record of the files it writes itself.
  • A checked zip of that plugin in the plugin catalog, at any version.

A file the zip’s check flagged counts only after someone chooses They are the plugin’s own code under Malware check on the Plugins page.

  • A scan reads files, not the database. A backdoor that rewrites its file from there comes back.
  • Premium plugins and themes have no checksums. A backdoor in one is found only if AMWScan knows it.
  • Malware already in a catalog zip when you uploaded it, and unknown to AMWScan, is vouched for on every site that has it.
  • Calls to eval() and the like are not findings on their own. A backdoor that hides behind nothing else is found only if a signature knows its shape.
  • Signatures lag behind new malware. Scripts over 1 MiB are read only at their start and end.