Scanner says core files were modified? Open the diff. After wp2shell, that is often leftover access.

How to read it

Malware scanner

Scan for malware

Keep your WordPress site secure by scanning for malware using WP Security Ninja. Follow our guide to start scans, interpret findings, and manage suspicious files.

If you are suspicious you might have malware on your computer the Malware Scanner can help you find out where the infestation is located.

Keep in mind, the malware scanner is very thorough, so there can be files showing up as suspicious that does not have any harmful code, but the file contains a piece of code that looks suspicious.

Be careful to review the results carefully. The malware scan can save you hours of investigating a whole site and narrow down the number of files you need to study.

Go to Security Ninja → Malware Scanner and click the scan button. An overlay shows while the scan runs.

Malware Scanner scan button

This process can take a few seconds or several minutes, depending on the number of plugins you have installed on your website.

The scanning process looks through every folder and every file on your website and comparing them to known malicious scripts or pieces of code.

Once the scan is finished, results appear on the same page with a summary strip and status banner (the page no longer needs a full reload to show findings).

Malware scan results listing suspicious files

The top of the results shows how many suspicious files were found and lists each file in a table with severity and guidance.

Next to each file you can expand the row for matched code samples, open View File in the File Viewer, whitelist, or delete when you are certain the file is malicious.

Some rows are structural findings (suspicious plugin or theme folder layout when wordpress.org checksums are not available). Treat those as review recommended, not automatic malware.

Whitelist a suspicious file

Whitelisting a file means that it will no longer show up in the malware scanner results. It will show up in the list of “whitelisted files” next time you run a scan.

Delete a suspicious file

Deleting a file from an active plugin can be dangerous. Please make sure you are certain that this file contains malicious code before you do. If you delete an important file in a plugin it could prevent the plugin from working properly.

Why was plugin marked as malicious?

The malware scanner goes into each file that it finds and looks for suspicious code. If a particular plugin shows up on the list does not mean that the plugin or theme is infected, just that part of the code matches something that the scanner finds suspicious.

We are always trying to find ways to prevent “false positives”. when regular looking code shows up in the list. We continuously improve the scanner to be more accurate.

Check out our step by step guide on how to clean up after a malware attack.

Video walkthrough

Watch how to run a malware scan with WP Security Ninja.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image