Malware scans
Every site is scanned once a day. A scan holds WordPress and directory plugins to wordpress.org’s published checksums, and looks for known malware in the rest with AMWScan. It can move what it finds into quarantine.

What a scan does
Section titled “What a scan does”Each step runs in a throwaway container that sees only the site’s files, read-only, with no network, as the site’s own user. The scan holds WordPress and directory plugins to their checksums, and looks for PHP in uploads and links that lead out of the site. AMWScan’s signatures then read what the checksums could not vouch for.
Scan now on a site’s Security tab, or Scan all sites on Sites → Security, starts a scan. At most three run at once, one per server.
What a scan says
Section titled “What a scan says”| Result | Means |
|---|---|
| Nothing found | Every engine finished, and nothing is open. |
| Findings | Something is open. |
| Incomplete | An engine could not read everything or ran out of time or memory, or the checksums could not be fetched. Never shown as clean. |
| Failed | Nothing could be scanned. Three in a row send an alert. |
| Superseded | A restore, a move or an update changed the files meanwhile. It runs again. |
| Finding | Severity |
|---|---|
| Known malware, WordPress file changed, Unknown file among WordPress’s own, PHP in uploads, Handler trick in uploads, WPL7 file changed | High |
| Plugin file changed, Unknown file in a plugin, Link leaving the site | Medium |
| Suspicious code | Low, or medium where AMWScan rates it dangerous |
| WordPress file missing, Plugin file missing | Low |
Deal with a finding
Section titled “Deal with a finding”- Reinstall original downloads WordPress or the plugin again from wordpress.org, at the site’s version, over its files.
- Put back writes a changed WPL7 file again.
- Quarantine moves the file out of the site.
- Ignore hides a finding until its file changes. Resolved says you dealt with it, and a scan reopens it if it is still there.
Let scans move files
Section titled “Let scans move files”On a finding, in Settings → Security or a site’s own settings, decides what a scan moves:
- Report and alert, the default, moves nothing.
- Quarantine confirmed malware moves known malware found in uploads, or as an unknown file among WordPress’s own or in a directory plugin.
- Quarantine everything it may also moves other code in uploads and unknown files among WordPress’s own.
Everything else is only reported: changed files of WordPress or a plugin, wp-config.php, the top
index.php and .htaccess, mu-plugins, links, and files of themes and premium plugins.
Suspicious code never moves or alerts. A scan that would move more than 25 files moves none.
Quarantined files sit beside the site’s folder, where nothing serves them. They travel with the site, are in no backup, and stay until deleted or until Keep quarantined files (days) runs out.
What vouches for a file
Section titled “What vouches for a file”A scan vouches for a file only when its exact hash is in one of these:
- wordpress.org’s checksums for its WordPress or plugin version, a plugin in a renamed folder included.
- The panel’s record of the files it writes itself.
- A checked zip of that plugin in the plugin catalog, at any version.
A file the zip’s check flagged counts only after someone chooses They are the plugin’s own code under Malware check on the Plugins page.
Limits
Section titled “Limits”- A scan reads files, not the database. A backdoor that rewrites its file from there comes back.
- Premium plugins and themes have no checksums. A backdoor in one is found only if AMWScan knows it.
- Malware already in a catalog zip when you uploaded it, and unknown to AMWScan, is vouched for on every site that has it.
- Calls to
eval()and the like are not findings on their own. A backdoor that hides behind nothing else is found only if a signature knows its shape. - Signatures lag behind new malware. Scripts over 1 MiB are read only at their start and end.