Learning Hub · Intermediate · 30 minutes
How to Scan a Site for Malware
Everything you need to confirm a suspicion or verify a clean bill, with the right tools — the steps, the gotcha, and the tip the support desk gives everyone.
The short answer
Goal: confirm a suspicion or verify a clean bill, with the right tools. Time needed: 30 minutes. Difficulty: intermediate.
Below: the exact steps, the classic pitfall, and a pro tip from the support desk. Where our platform automates a step, the guide says so rather than making you do robot work.
Intermediate
Skill level
5
Steps to done
Free
Support included
Tested
On our platform
You don't need to be technical for this — the walkthrough is written for first-timers, tested against our own platform, and honest about which parts are genuinely fiddly versus merely unfamiliar.
One promise before starting: nothing in this guide is irreversible. Where a step could bite, we say so and give the undo.
The shape of the job
Start to finish, you'll read the external symptoms, run the server-level scan, cross-check with application scanners, consult the external verdicts and interpret honestly.
Each stage is a few minutes of focused clicking — the elapsed time mostly depends on how familiar the control panel already feels. The detailed steps are listed further down this page; skim the whole route once before starting.
Read this before you start clicking
Deleting the one found file and declaring victory — malware plants backdoors in multiples precisely so the obvious infection's removal leaves the quiet ones running; cleanup is a process, not a deletion.
Forewarned is genuinely forearmed here — this exact mistake accounts for most of the frustration this topic produces, and it's entirely avoidable once named.
One habit that makes this easier forever
Scan from multiple vantage points when suspicious — server scanner, application checker and external URL scan each see a different layer, and compromises hide from single perspectives.
Small habits like this are the real difference between people who find hosting easy and people who find it stressful — the tools are identical; the workflow isn't.
How HostingAlly makes this easier
Several steps in this guide exist because hosting historically made you do them — on our plans, SSL issues itself, backups run daily without being asked, and one-click installers replace manual setup entirely. What remains is the genuinely-yours part of the task.
And when a step misbehaves anyway, support answers around the clock — with the actual fix, not a knowledge-base link and a shrug. Half our best guides started as patterns in the tickets.

The platform this guide assumes
Tutorials age badly when they're written against imaginary hosting. These are written against ours — the same panel, installer and defaults you'll actually see.
Business email on your own domain is included, not sold back as an add-on.
- Step-by-step, tested as written
- The gotcha flagged before you hit it
- Automation covers the boring steps
- 24/7 support if you get stuck
Why HostingAlly
What you get with every plan
The undo is always named
Where a step could bite, the guide says so and gives the reversal.
No jargon tax
Terms are explained in place or linked to the glossary — nothing assumes you already know.
Help on standby
Stuck at step three at midnight? Support answers around the clock, mid-guide included.
Works as written
Every step tested on our own platform — no 'your host may vary' hand-waving.
Written from real tickets
Our guides come from the support desk — the gotchas are the ones people actually hit.
Automation where it belongs
SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.
Getting Started
How to get going
- 1
Read the external symptoms
Search results showing spam titles, browser warnings, redirect complaints from visitors — outside symptoms often announce what inside scans confirm.
- 2
Run the server-level scan
On protected plans, Imunify360's scanner inspects files below the application — panel-level scanning sees what compromised WordPress code could hide from its own plugins.
- 3
Cross-check with application scanners
A WordPress security plugin's integrity check compares core files against official checksums — modified core files are the smoking gun of compromise.
- 4
Consult the external verdicts
Search Console's security section and URL-scanning services show what the outside world has flagged — blocklist status is part of the diagnosis.
- 5
Interpret honestly
One infected file usually means more — malware installs redundantly; a positive result triggers the full cleanup process, not a single-file deletion.
Included
What's covered on our plans
- One-click installer for WordPress and 400+ apps
- Free domain for the first year on annual plans
- SSH, Git and Composer access on developer-friendly plans
- 24/7 support from real people
- Per-site PHP version selection
- Renewal prices that match signup prices
- DDoS protection at the network level
- 99.9% uptime commitment, monitored around the clock
- Free SSL certificate on every plan, renewed automatically
- No setup fees, ever
FAQ
Your questions, answered
The scanner found nothing but the site acts infected — now what?
Trust the symptoms — check for injected database content (spam links in posts), .htaccess redirects, rogue admin users and recently-modified files. Scanners catch known patterns; hands-on inspection catches the custom ones. Support can help look.
How often should scans run?
Server-level protection scans continuously on covered plans — the manual full-scan ritual is for incidents and quarterly hygiene. Frequency matters less than acting completely on any positive.
What happens if I outgrow my plan?
You upgrade in place — plan changes apply from your client area without migrations or downtime, and our range runs from small shared plans through VPS to dedicated servers, so growth is an account change rather than a new-host project.
Will you move my existing website for free?
Yes — open a ticket with your current host's access details and we handle the whole move: files, databases, email and configuration, verified by you before DNS switches. The old site keeps serving until the new copy takes over, so visitors never see a gap.
Which control panel do you provide?
cPanel — the industry standard, which means every tutorial on the internet matches your screen, your backups restore anywhere cPanel runs, and skills learned here transfer for life. Plesk and DirectAdmin options exist on specific plans for those who prefer them.
Can I host more than one website on a plan?
On the Pro tier and above, yes — multiple sites with their own domains, email and SSL under one account. If the extra sites belong to clients rather than you, reseller hosting gives each one proper isolation instead.
How long does it take to get started?
Minutes — hosting activates on payment, the domain (free for year one on annual plans) connects immediately, and one-click installers put WordPress or 400+ other apps live the same sitting. If you have an existing site, our team migrates it free, usually within 24 hours.
Keep exploring
How to Schedule Server Backups
Automated, offsite, tested — the three words that make backups real — advanced level, one hour of setup.
How to Secure Your Hosting Account
Protect the account that owns every site inside it — beginner level, 30 minutes.
VPS Hosting
KVM virtual servers with root access, DDoS protection and flat pricing.
WordPress Hosting
Managed WordPress with LiteSpeed caching, staging and automatic backups.
Put an ally behind your website.
Fast NVMe hosting, free SSL and migration, and real people on support around the clock — at prices that stay put.
See Hosting Plans