Websites and Tech

Malware Scan

Also called malware scanning, malware removal, website security scan

A check of a website's files, database and pages for malicious code, injected spam links, hidden redirects and other signs of a hack.

Quick facts: Malware Scan

Category
Websites and Tech
Also called
malware scanning, malware removal, website security scan
Level
Intermediate
Affects
Search visibility, browser warnings, customer trust, data protection obligations
Where to see it
Search Console Security Issues report, Google Safe Browsing site status, Sucuri SiteCheck, Wordfence, your host's scanner
In this article4
  1. How a malware scan works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A malware scan is a check of a website for malicious code: scripts that redirect visitors, injected spam links, hidden pages selling counterfeit goods, backdoors that let an attacker back in, and code that steals card details or login data. Scanners compare what they find against known patterns and flag files and database entries that look wrong.

How a malware scan works

There are two kinds, and they see different things. A remote scanner, such as Sucuri SiteCheck, loads your pages from outside like a visitor would. It spots visible symptoms: spam links in the HTML, suspicious scripts, redirects and blocklist warnings. It cannot see inside your server.

A server-side scanner runs on the hosting account or inside the CMS. Wordfence and similar WordPress security plugins, and host tools such as ImunifyAV, read the actual files and often the database. They compare core files against the official versions, look for code patterns attackers commonly use, and flag files that should not exist, such as a PHP file inside an uploads folder.

No scanner catches everything. Well-hidden backdoors can look like ordinary code, and some infections only show to Googlebot or to mobile visitors arriving from search, so a quick look at the homepage on your own laptop proves little.

Why it matters

A hacked site can damage search visibility long before anyone in the business notices. Common attacks create thousands of spam pages on your domain, often in Japanese or selling medicines, which Google then crawls and indexes. Others redirect visitors from search to scam sites while showing you the normal page. Google may list the problem in the Security Issues report in Search Console, label your listings “This site may be hacked”, and Chrome may show a full-page Safe Browsing warning that turns most visitors away.

There is a legal side too. If the hack exposed personal data, such as enquiry form entries or customer accounts, UK GDPR requires you to report it to the ICO within 72 hours of becoming aware, unless it is unlikely to pose a risk to people. A scan result is often the first evidence you have of when an attack started.

Common mistakes

  • Running only a remote scan, seeing “clean” and stopping there.
  • Deleting the infected files but not the backdoor, so the site is reinfected within days.
  • Restoring a backup without updating the outdated plugin or theme that let the attacker in.
  • Leaving the spam URLs to return 200 or redirect to the homepage, so Google keeps them in its index for months.
  • Not changing hosting, database, admin and SFTP passwords after the clean-up.
  • Installing nulled (pirated) premium plugins, a frequent source of hidden malware.

How to act on it

Check the Security Issues report and run a site: search for your domain to see whether strange pages are indexed. Run a server-side scan as well as a remote one. If something is found, take a copy of the infected site for evidence, then clean it or ask your host or a security specialist to. Update everything, remove unused plugins and themes, rotate every password and key, turn on two-factor authentication for admin accounts, and consider a web application firewall.

Once the site is clean, the spam URLs should return 404 or 410, and you can ask Google to review the security issue in Search Console. Finding and clearing out the indexed spam is part of my technical SEO work; the security clean-up itself is best done by a specialist or your host.

Do and do not

Do

  • Run a server-side scan as well as a remote one
  • Check the Security Issues report in Search Console regularly
  • Change every password and key after cleaning a hacked site

Do not

  • Restore an old backup and assume the hole is closed
  • Ignore spam pages in Google just because the homepage looks normal
  • Install nulled premium plugins or themes

Questions people ask about this

How do I know if my website has malware?

Warning signs include strange pages in a site: search, Search Console security alerts, visitors reporting redirects or pop-ups, new admin users you did not create, and a sudden rise in indexed pages. Your host may also suspend the account or email you. A server-side scan is the most reliable check.

Will Google remove my site from search if it is hacked?

Google usually adds warnings rather than removing the whole site, but it may stop showing affected pages and Chrome may block visits. Spam pages can also be indexed under your domain. Once the site is clean, requesting a review in Search Console normally clears warnings within days, although spam URLs can take longer to drop out.

How often should I scan my website?

A daily automated scan from a security plugin or your host suits most small business sites, with a manual review after any major update or new plugin. More frequent checks make sense for shops that take payments. Scanning is only half the job; keeping software updated prevents most infections in the first place.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.