How-to · Intermediate · 30 minutes
How to Scan a Site for Malware
Everything you need to settle the question — infected or clean — with the tools that can actually tell — the steps in order, the snag to watch, and the tip our support desk gives everybody.
Straight answer first
The job: settle the question — infected or clean — with the tools that can actually tell. Time to allow: 30 minutes. Skill needed: intermediate.
Below you get the exact steps, the classic snag, and a tip from the support desk. Where our platform handles a step for you, the guide says so rather than making you do the robot's work.
Written by the Hosting Seller staff · Checked 1 August 2026
Intermediate
Skill needed
5
Stages to finish
Free
Help included
Tested
On our own kit
You do not need to be technical for this. The walkthrough is written for first-timers, tested on our own platform, and honest about which parts are genuinely fiddly and which are merely unfamiliar.
One promise before you start: nothing in this guide is irreversible. Where a step could bite, we say so and give you the undo.
The shape of the work
From start to finish, you will start with what the outside sees, run the scan at server level, check the application's own integrity, see what the outside world has flagged and assume there is more than one.
Each stage is a few minutes of steady clicking — the time it takes depends mostly on how familiar the control panel already feels. The detailed steps sit further down this page; skim the whole route once before you begin.
Read this before the first click
Deleting the one file the scanner found and calling the job done. Backdoors are planted in multiples precisely so that removing the obvious one leaves the quiet ones running. Clean-up is a process, not a deletion.
Forewarned really is forearmed here. This one mistake accounts for most of the frustration the subject produces, and it is entirely avoidable once somebody names it.
One habit that makes this easy for good
When you are suspicious, look from more than one angle. The server scanner, the application's integrity check and an external URL scan each see a different layer, and a compromise that hides from one often shows up plainly in another.
Small habits like this are the real difference between people who find hosting easy and people who find it stressful. The tools are identical; the working method is not.
How our platform shortens this
Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.
And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

The hosting this guide is written against
Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.
Mailboxes on your own domain are part of the plan, never an add-on sold back to you at checkout.
- Step by step, tested exactly as printed
- The snag flagged before you reach it
- The dull steps are already automated
- People on hand at any hour if you stall
Why Hosting Seller
On every plan, as standard
Automation where it belongs
SSL, backups and installs run themselves here, so the guide covers only what is genuinely yours to do.
5 steps, no filler
Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.
The snag, named early
The classic mistake for this exact job is flagged before step one, so 30 minutes stays 30 minutes.
Help on the counter
Stuck on step three at midnight? Support answers at any hour, mid-guide included.
Written from real tickets
Our guides come off the support desk, so the snags flagged here are the ones people genuinely hit.
The undo is always named
Where a step could bite, the guide says so and tells you how to put it back again.
First Steps
From choosing to live
- 1
Start with what the outside sees
Spam titles in search results, browser warnings, visitors reporting redirects they never asked for. Outside symptoms usually announce what an inside scan then confirms.
- 2
Run the scan at server level
On protected plans, Imunify360's scanner reads the files underneath the application. Scanning from the panel sees things that compromised WordPress code can hide from its own plugins.
- 3
Check the application's own integrity
A WordPress security plugin compares core files against the official checksums. A modified core file is about as clear as evidence gets in this line of work.
- 4
See what the outside world has flagged
Search Console's security section and the public URL scanners show whether you have landed on a blocklist. That verdict is part of the diagnosis, not an afterthought.
- 5
Assume there is more than one
A single infected file almost always means several. Malware installs itself redundantly, so one positive result starts a full clean-up rather than a single deletion.
In the Box
Packed with every plan
- A 99.9% uptime commitment, watched by monitoring day and night
- PHP versions picked per site from the panel
- WordPress Toolkit, with updates applied for you
- A domain free for year one when you order annually
- Webmail in the browser plus IMAP, POP and SMTP for your own client
- Nothing added at setup — no joining fee, ever
- Upgrades apply to the account in place, with no move between plans
- Staging copies so changes get tested before they go live
- Site migration done for you by our staff, at no charge
- WebP image optimisation built in and costing nothing
Across the Counter
The questions we get asked most
Scans come back clean but the site still behaves oddly — what next?
Believe the symptoms. Look for injected content in the database, redirects hidden in .htaccess, admin users you did not create, and files changed recently. Scanners match known patterns; hand inspection catches the bespoke ones. Support can look with you.
How often should I be scanning?
Server-level protection scans continuously on covered plans, so the manual full scan is for incidents and a quarterly tidy-up. Frequency matters far less than following through completely on anything a scan does find.
Can one plan hold more than a single website?
From the Pro tier upward, yes — several sites, each with its own domain, mailboxes and certificate, all under one account. If those extra sites belong to clients rather than to you, reseller hosting is the better fit: it gives each one proper separation.
What does round-the-clock support actually stretch to?
People at the counter at every hour, and a scope that takes in the practical work: mailbox setup, DNS records, WordPress trouble, restores. Not 'the server responds, ticket closed'. Ask us something hard before you order — the reply is a fair sample of what you would get afterwards.
Can I test changes somewhere safe first?
Yes — plans with staging let you clone the live site, work on the copy, then push it across when you are satisfied. It is the difference between hoping an update behaves and knowing that it does before any customer meets it.
Where do the servers actually sit?
Our hosting runs from European datacentres with London at the centre, behind server-level caching that keeps cached pages quick for visitors anywhere. For most sites the build of the platform — NVMe disks, LiteSpeed, sensible numbers of accounts per machine — decides the speed far more than the postcode does.
How quickly can I be up and running?
Minutes, not days. The account opens the moment the order clears, the domain — free for year one on annual plans — attaches straight away, and the one-click installer puts WordPress or any of 400+ applications on the page before you leave your chair. Already have a site elsewhere? Hand it over and we move it free, usually inside a day.
Read next
How to Secure Your Hosting Account
Lock down the one account that holds every site you run — beginner level, about 30 minutes.
How to Set Custom Error Pages
Turn a dead end into a signposted page that keeps the visit alive — beginner level, about 30 minutes.
VPS Hosting
KVM virtual servers with root access, DDoS filtering and one flat price.
WordPress Hosting
WordPress looked after for you — LiteSpeed caching, staging copies and daily backups.
Packing up and moving host? Take our checklist.
A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.
Give your website a proper home.
Every plan carries the essentials other hosts ring up as extras — and support that actually replies.
See the plans