Walkthrough · Intermediate · 30 minutes
How to Scan a Site for Malware
How to settle the question — compromised or clean — with tools that can actually tell, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.
The short answer
The job: settle the question — compromised or clean — with tools that can actually tell. Time to set aside: 30 minutes. Skill needed: intermediate.
Below are the precise steps, the classic stumble, and one tip from the support desk. Wherever the platform already does a step for you, the guide says so rather than handing you a machine's chores.
By the Hosting & Domains team · Reviewed 18 August 2026
Intermediate
Experience required
5
Stages, start to finish
Free
Support included
Proven
On the platform itself
No technical background needed. This walkthrough was written for first-timers, proven on our own hardware, and honest about which parts are genuinely tricky rather than merely unfamiliar.
A promise before step one: nothing here is a one-way door. Any step with teeth is flagged, and the way back is printed beside it.
How the work divides up
Over the whole job, you will start from the outside, let the server do the scanning, check the application's integrity, read the external verdicts and expect more than one infection.
Every stage is a few minutes of unhurried clicking — the total depends mostly on how well you already know the control panel. The detailed instructions are further down; read the whole path once before you begin.
One caution before you click anything
Deleting the one file the scanner flagged and declaring victory. Backdoors are planted in sets precisely so the obvious one dies while the quiet ones live on. Clean-up is a procedure, not a delete key.
Forewarned is genuinely forearmed here. This one mistake accounts for most of the frustration the topic ever causes — and it disappears entirely once somebody points it out.
The habit that keeps this easy for good
When you suspect something, look from several angles at once. The server scanner, the application integrity check and an external URL scan each watch a different layer, and what hides from one is often plain to another.
Habits this small are what separate the people who find hosting effortless from the people who find it draining. The same tools on both sides — a different way of working.
Where this platform takes work off you
Some steps in this guide exist only because hosting traditionally forced them on you. Here the SSL issues itself, the copy is taken daily without being asked, and one-click installers remove the manual setup. What is left is the part that was always genuinely yours.
Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

A quick platform makes for a short guide
Tutorials written against imaginary hosting go stale fast. Ours are written against the real thing: the same panel, installer and defaults waiting in your account.
Order an annual plan and the first year of the name's registration is on us.
- Every step checked exactly as published
- The snag named before it arrives
- The dull steps taken out of your way
- People reachable at any hour you stall
Why Hosting & Domains
Standard on every plan
The dull parts automated
SSL, backups and installs look after themselves here, leaving the guide to cover only what is genuinely yours.
5 steps, nothing padded
Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.
The snag, flagged up front
The classic error for this particular task is named before step one, which is how 30 minutes stays 30 minutes.
Help that keeps your hours, not ours
Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.
Taken from real tickets
These guides came out of the support queue, so every snag flagged is one people genuinely hit.
Every undo written out
Any step that could bite is marked, together with the exact way to wind it back.
Quick Start
Order placed to site online
- 1
Start from the outside
Spammy titles in search listings, browser warnings, visitors mentioning redirects they never asked for. What shows up outside is generally the announcement; the internal scan is the confirmation.
- 2
Let the server do the scanning
On protected plans, Imunify360's scanner inspects the files beneath the application. A panel-level scan sees things that compromised WordPress code can hide from its own plugins.
- 3
Check the application's integrity
Core files get checked against the official checksums by a WordPress security plugin. Little evidence in this field is clearer than a core file that has been altered.
- 4
Read the external verdicts
Search Console's security section and the public URL scanners tell you whether you are on a blocklist. That judgement belongs in the diagnosis rather than in a footnote.
- 5
Expect more than one infection
One infected file nearly always means others. Malware installs itself with redundancy, so a single positive begins a full clean-up rather than a lone deletion.
Built In
Fitted to every plan
- cPanel, which is what most of the industry already runs
- Staging copies for trying a change before it goes live
- WebP image optimisation built in, at no extra charge
- A renewal figure identical to the one you registered at
- 99.9% uptime as the target, watched around the clock
- WordPress Toolkit, with the updates seen to for you
- WordPress and 400+ further applications installed in one click
- Webmail in the browser plus IMAP, POP and SMTP for any client
- PHP versions set per site from the control panel
- Upgrades applied in place, with no migration when you change plan
Frequently Asked
The questions that come up most
Every scan says clean but the site still misbehaves — now what?
Trust the symptoms. Look for injected database content, redirects buried in .htaccess, admin accounts you never created, and recently modified files. Scanners match known signatures; a manual review catches the custom work. Support will dig through it with you.
How often should I scan?
Covered plans run continuous scanning at server level, so the manual deep scan is for incidents plus a quarterly sweep. The cadence matters far less than acting fully on whatever a scan turns up.
Can more than one website run on a single plan?
From the Turbo tier upward, yes — several sites, each with its own name, mailboxes and certificate, inside one account. If the extra sites belong to clients rather than to you, look at reseller hosting instead: it keeps each one properly walled off.
What does round-the-clock support actually cover?
A reply from a person at any hour, covering the practical jobs: setting up a mailbox, a DNS record, a WordPress fault, a restore. Not 'server is up, closing ticket'. Put a hard question to us before you buy — the answer is a fair sample of what follows.
Keep reading
How to Check DNS Propagation
Find out whether the internet has taken up your DNS change, and why some corners have not — beginner level, about 5 minutes.
How to Install a LAMP Stack
Get Linux, Apache, MySQL and PHP serving a real page on your own server — intermediate level, about 45 minutes.
Malware (Glossary)
The full definition, along with the practical consequence nobody bothers to mention.
Node.js Hosting
Run Node.js applications beside your sites, with SSH and Git included.
Business Hosting
Shared hosting carrying the whole developer kit, from SSH through Node.js and Python to PostgreSQL.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Your site has earned better hosting.
Free SSL, a free migration, renewals billed at the original rate, and people on support around the clock. That is the whole of it.
View Node.js Hosting plans