How to scan a WordPress site for malware, with 8 scanners compared
To scan a WordPress site for malware, combine a free remote scan, a scanner plugin, a checksum check of core and plugin files and a look at Google's Safe Browsing status, because each one sees what the others miss. WPCentrify, a hosted WordPress management platform for anyone responsible for more than one WordPress site, does this for every site with built-in WordPress security monitoring.

The short answer
Scan a WordPress site for malware from outside and from inside: run a free remote scan such as Sucuri SiteCheck, check Google's Safe Browsing status, run a full scan with a scanner plugin, and compare core and plugin files with WordPress.org using WP-CLI. No single scan sees everything, so use at least two kinds.
- Run a free remote scan.
- Check Google's view of the site.
- Back up the site first.
- Run a full scan with a scanner plugin.
- Verify core and plugin files.
- Check the places scanners miss.
- Act on confirmed findings only.
Quick picks: Wordfence for a free scan inside WordPress, Sucuri SiteCheck for a free check from outside, MalCare or Jetpack Scan for scans on the vendor's servers, and WPCentrify (our product) for many sites at once.
What is the difference between a malware scan and a vulnerability scan?
A malware scan looks for harmful code already on your site, while a vulnerability scan looks for software with a known security hole an attacker could use to get in. You need both, plus two checks that often get mixed up with them:
- Malware scan: reads files, the database, posts and comments for backdoors, injected scripts, spam links and malicious redirects.
- Vulnerability scan: compares your WordPress, plugin and theme versions with lists of known holes. WPScan's own FAQ is plain about the limit: it "does not determine whether a site has been compromised".
- File integrity check: compares core and plugin files with the official WordPress.org copies using checksums. A changed file is not always malware, but it deserves a look.
- Blocklist check: asks whether Google or other services already flag the site as dangerous.
Known holes are a common way in, and almost all of them are in plugins. Patchstack's State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025: 91 percent in plugins, 9 percent in themes and only 6 in WordPress core. Our page on WordPress vulnerability scanning covers that side.
Signs your WordPress site may have malware
The clearest sign is a warning from somebody else. The WordPress.org guide to hacked sites lists several of these as indicators of compromise, and any of them is a reason to scan today:
- Google or a browser warns people away, or search results show pages you never wrote.
- Your host suspends the site or flags it for distributing malware.
- Visitors' antivirus blocks the site, or it is reported for sending spam.
- Visitors are redirected to other sites, sometimes only on phones or from Google.
- Administrator accounts appear that nobody on your team created.
- Files change when nobody updated anything, or PHP files appear in wp-content/uploads.
Some infections show no signs at all, because backdoors are built to stay quiet. Scheduled scans catch what symptoms do not.
How to scan a WordPress site for malware, step by step
Work from the outside in: start with checks that need no access to the site, then scan from inside, then confirm what you find.
- Run a free remote scan. Enter the site address in Sucuri SiteCheck or VirusTotal to check the public pages for injected code, spam links and blocklisting.
- Check Google's view of the site. Look the domain up in Google's Safe Browsing site status tool and, if the site is verified, in the Search Console Security Issues report.
- Back up the site first. Copy the files and database before you change anything, even if the site is infected, so you can compare files and undo mistakes.
- Run a full scan with a scanner plugin. Install one scanner, such as Wordfence, MalCare or Jetpack Scan, and run a full scan of files, the database, posts and comments.
- Verify core and plugin files. With WP-CLI on the server, run
wp core verify-checksumsandwp plugin verify-checksums --allto list files that differ from WordPress.org. - Check the places scanners miss. Look for unknown administrators, PHP files in wp-content/uploads and recent changes to .htaccess, wp-config.php and your theme.
- Act on confirmed findings only. Review each result before deleting anything, then contain the problem, clean the site and close the way in.
Remote scans and Google's status
A remote scanner visits your site the way a browser does. Sucuri SiteCheck checks for known malware, blocklisting, errors and out-of-date software, and VirusTotal runs a URL past over 70 antivirus scanners and blocklisting services. A clean result does not mean a clean server, and VirusTotal shares its reports with the public VirusTotal community, so never submit private links.
Google's Safe Browsing site status shows whether Google currently warns people away from the site. If the site is verified in Google Search Console, its Security Issues report lists hacked content, malware and unwanted software, or social engineering, and it is where you request a review after cleaning, which Google says can take several days or weeks.
Verify files with WP-CLI
With SSH access and WP-CLI, two built-in commands compare your files with WordPress.org's checksums. The core command avoids loading WordPress while it checks, which matters when WordPress itself may be compromised.
# Check WordPress core files
wp core verify-checksums
# Check plugins from WordPress.org
wp plugin verify-checksums --all
A clean install answers "Success: WordPress installation verifies against checksums." Anything else is listed file by file. If it flags files you cannot explain, the WP-CLI documentation suggests passing the --locale and --version values shown on your Updates screen.
Wordfence users who suspect an infection should switch to its High Sensitivity scan and turn on the options that compare plugin and theme files with WordPress.org, which the Standard scan leaves off.
The places scanners miss
- Users: remove any administrator nobody can explain.
- Uploads: wp-content/uploads should hold media, not PHP files.
- Key files: check .htaccess, wp-config.php and your theme's functions.php, header.php and footer.php for code you did not add. WordPress.org singles out .htaccess and those theme files as common targets.
- Recent changes: see what changed, who changed it and when, which a WordPress audit log makes quick.
- Your computer: WordPress.org also advises a malware scan of the computers you log in from.
What a WordPress malware scanner cannot see
No single scanner sees everything, and each kind has a predictable blind spot that tells you which second check to add:
- Remote scanners see only public pages. Sucuri says its remote scanner "will not detect anything on the server-side".
- Scanner plugins run inside the site they check, so an attacker with administrator or file access can switch them off or change what they report.
- Free signatures lag. Wordfence's free version gets new malware signatures 30 days after Premium customers.
- Checksum checks cover WordPress core and WordPress.org plugins only. WP-CLI has no checksum command for themes, and premium plugins, uploads and the database are not covered.
- Vulnerability scanners find known holes, not infections, and Google's status only reflects what Google has found so far.
That is why the WordPress.org guide recommends both remote and application scanners: "No one solution is the best approach, but together you improve your odds greatly."
Best WordPress malware scanners at a glance
The best WordPress malware scanner depends on where you want the scan to run: inside WordPress, on the vendor's servers or from outside the site. We compared eight scanners on what they check, where the scan runs, what the free version includes and what the cheapest paid plan costs, using each vendor's own pages and WordPress.org, checked on 10 October 2026. Our comparison methodology explains how we research and correct pages like this. WPCentrify is our product, so it is listed first and described as plainly as the rest.
| Tool | Free version | What it scans | Where it runs | Paid from |
|---|---|---|---|---|
| WPCentrify | Free during early access | Each site, for signs of a hack, known holes and risky sign-ins | Inside and outside each site, daily | Announced at launch |
| Wordfence | Yes; signatures 30 days behind Premium | Files, posts, comments, known vulnerabilities | Inside WordPress, on your server | $149 USD a year |
| Sucuri | SiteCheck and a free plugin | Public pages (SiteCheck); file changes (plugin) | Outside the site; plugin inside | $229 a year, cleanup included |
| MalCare | Weekly scans, no removal | Files and the database | MalCare's servers | $99 a year |
| Jetpack Scan | Vulnerability checks only | Plugins, themes, uploads, selected root files | Jetpack's servers, daily | $9.95 a month, billed yearly |
| Defender | Yes; lists differ by page | Core and plugin files vs WordPress.org | Inside WordPress | $50 a year |
| Kadence Security | Yes (Basic) | Known vulnerabilities, Google blocklist, file changes | Inside WordPress | Kadence Pro or Elite bundle |
| WPScan | Free CLI; API 25 calls a day, non-commercial | Known vulnerabilities, exposed files; not malware | Outside the site | Quote for commercial use |
All facts from each vendor's own pages and WordPress.org, checked 10 October 2026. Prices are the lowest paid plan shown for one site, exclude tax and change often. Disclosure: WPCentrify is our product, and we do not use affiliate links.
The 8 best WordPress malware scanners, one by one
1. WPCentrify: best for many WordPress sites
Sentinel is the security monitoring built into WPCentrify. (Disclosure: WPCentrify is our product.) Every connected site is checked every day from inside and outside, and gets a plain-English verdict and a security score out of 100. Only urgent problems are emailed. When a site is hacked, its security page becomes a recovery plan that shows what happened and points to the last backup from before it started. It works alongside your existing security plugin.
Good for: anyone who looks after several WordPress sites. Watch out for: it is detection, not a firewall or a malware removal service, and alerts are by email for now. It is free during early access, with prices announced at launch.
2. Wordfence: best free scanner inside WordPress
Wordfence Security has more than 5 million active installations (updated 30 September 2026, tested up to WordPress 7.1.3). It scans core, theme and plugin files for malware, backdoors, SEO spam, malicious redirects and code injections, compares them with the WordPress.org repository, and checks posts and comments for dangerous URLs. The free version gets new malware signatures 30 days after Premium and runs a full scan every 72 hours, plus a daily quick scan. Premium, $149 USD per year, adds real-time signatures and blocklist checks, and Wordfence Central shows many sites in one view for free.
Good for: a capable free scanner on one site. Watch out for: scans use your own server's resources.
3. Sucuri: best free check from outside the site
Sucuri SiteCheck is a free remote scanner for known malware, blocklisting, website errors, out-of-date software and malicious code on public pages, with no access to the site needed. The free Sucuri Security plugin (more than 600,000 active installations, updated 9 September 2026, tested up to 7.1.3) adds file integrity monitoring, remote malware scanning and blocklist monitoring. Malware removal comes with the paid Sucuri Platform, from $229 a year for one site, with scans every 12 hours.
Good for: a fast first check, and cleanup included in the price. Watch out for: SiteCheck cannot see the server.
4. MalCare: best for scans that do not load your server
MalCare's plugin hands the heavy processing to MalCare's servers and needs a MalCare account. The free scan covers files and the database (more than 100,000 active installations, updated 17 September 2026, tested up to 7.1.3), but the free plan scans weekly and, in MalCare's words, "Free finds malware but doesn't remove it." Paid plans are billed yearly: Protect, $99 a year for one site, scans every 24 hours without cleanup, and Repair, $299, adds cleanup.
Good for: small hosting plans. Watch out for: weekly free scans, and cleanup only on Repair or Fortify.
5. Jetpack Scan: best if you already use Jetpack
Jetpack Scan runs daily, and on demand, on Jetpack's own servers, so results are there even when the site is down. It checks plugins, must-use plugins, themes, uploads and selected root and wp-content files for known vulnerabilities and suspicious changes, with one-click fixes for most issues. The free Jetpack Protect plugin (more than 100,000 active installations, updated 12 August 2026, tested up to 7.0.7) checks vulnerabilities only. Scan is listed at $9.95 a month, billed yearly, with 50 percent off the first year when we checked.
Good for: sites already on Jetpack. Watch out for: no multisite support, and an infection from before Scan was active may need extra cleanup.
6. Defender: best for WPMU DEV users
Defender, from WPMU DEV, has more than 80,000 active installations (updated 29 September 2026, tested up to 7.1.3). It compares core files and plugins with the WordPress.org repository and flags changes, added files and abandoned plugins. Its WordPress.org page lists vulnerability and suspicious code checks as free, but WPMU DEV's pricing page lists them, with scheduled malware scanning, under Defender Pro, from $50 a year for one site.
Good for: WPMU DEV users, since Pro reports through the Hub. Watch out for: the two feature lists disagree, so test what you get.
7. Kadence Security: best for vulnerability and blocklist checks
Kadence Security, formerly Solid Security and iThemes Security, has more than 700,000 active installations (updated 30 September 2026, tested up to 7.1.3). Its Site Scan checks WordPress, plugins and themes for known vulnerabilities four times a day on the free Basic version or hourly on Pro, and uses the Google Safe Browsing API to warn you if Google has found malware. File change detection logs changed files. Pro comes with Kadence's Pro and Elite bundles.
Good for: login security plus vulnerability checks. Watch out for: its Site Scan is not described as a file malware scan, so pair it with one.
8. WPScan: best for vulnerability checks from the command line
WPScan is a vulnerability scanner, not a malware scanner: it does not determine whether a site has been compromised. Its free command-line scanner looks at a site from outside, as an attacker would, and reports plugins and themes with known holes, exposed wp-config.php backups, database dumps and usernames anyone can list. Its API is free for non-commercial use up to 25 calls a day; commercial use needs a paid license. The WPScan plugin is no longer actively supported for non-enterprise customers.
Good for: developers comfortable in a terminal. Watch out for: it will not find malware.
What to do if a scan finds malware
Confirm the finding before you delete anything, because scanners raise false positives and a wrong deletion can take a site down. Then work in this order:
- Read the finding. A file you or your developer edited on purpose also shows as changed, so compare it with a clean copy.
- Keep a copy of the infected site, as evidence and as a fallback.
- Contain it. Change passwords for wp-admin, hosting, SFTP and the database, and remove unknown administrators.
- Clean or restore. Replace infected files with fresh copies, or restore a backup from before the infection, which WordPress backups stored off the server make faster.
- Close the way in. Update or remove the plugin that let the attacker in; our guide to WordPress plugin management covers audits. On many sites, WPCentrify's safe WordPress updates roll a plugin or theme back automatically if an update causes a PHP fatal error, a server error or a visual break.
Our guide to what to do when a WordPress site is hacked covers each step in detail.
How often should you scan a WordPress site?
Scan automatically at least once a day, and run a full manual scan whenever something looks wrong or after you install a new plugin or theme. Attackers move fast: Patchstack's 2026 report puts the weighted median time to first exploit at 5 hours, and says 46 percent of vulnerabilities had no fix from the developer in time for public disclosure.
Wordfence recommends a scan every 24 hours for most sites, or at least weekly on servers with limited resources, and WPScan suggests a complete scan weekly with high-priority scans nightly.
How to scan many WordPress sites at once
Use one dashboard that brings every site's results together, because scanning forty sites one at a time does not survive a busy month. Wordfence Central is free for unlimited sites, Defender Pro reports through WPMU DEV's Hub, and MalCare includes a dashboard for many sites.
WPCentrify takes a different angle. (Disclosure: WPCentrify is our product.) Every connected site is checked every day from inside and outside and gets a plain-English verdict and a security score out of 100, so "which of my sites need me today?" has one answer on one screen. Plugins with known holes are matched across every site with WordPress vulnerability monitoring, and security sits in the same WordPress website management platform as updates, backups and the WordPress activity log.
In the WPCentrify account we use ourselves, 18 WordPress sites sit on one screen, and on 10 October 2026 it showed 11 updates waiting for review: the kind of backlog that becomes a security hole when nobody sees it. For the wider picture, read about WordPress security for multiple sites and our guide to WordPress site monitoring.
Sources
- Wordfence pricing, scan documentation, scan scheduling and the Wordfence plugin page
- Sucuri SiteCheck, Sucuri Platform plans and the Sucuri Security plugin page
- MalCare pricing and the MalCare plugin page
- Jetpack Scan and the Jetpack Protect plugin page
- Defender Pro and the Defender plugin page
- Kadence Security plugin page and Kadence add-ons
- WPScan pricing and FAQ and the WPScan plugin page
- State of WordPress Security in 2026, Patchstack, and the Patchstack plugin page
- How VirusTotal works
- Google Safe Browsing site status and the Security Issues report help page
- wp core verify-checksums and wp plugin verify-checksums, WP-CLI documentation
- FAQ My site was hacked, WordPress.org documentation
All sources checked on 10 October 2026.
Questions about scanning WordPress for malware
Run a free remote scan such as Sucuri SiteCheck and check Google's Safe Browsing site status, then install a free scanner plugin such as Wordfence and run a full scan. If you have WP-CLI, wp core verify-checksums compares your core files with WordPress.org at no cost.
For a free scanner inside WordPress, Wordfence, with more than 5 million active installations. For a free check from outside the site, Sucuri SiteCheck. For scans on the vendor's servers, MalCare or Jetpack Scan. For many sites at once, WPCentrify, our own product, gives each site a plain-English verdict and a security score.
No. A remote scanner only sees what a browser receives, and Sucuri says its remote scanner will not detect anything on the server side. Use it as a quick first check, then scan the files from inside WordPress or on the server.
A malware scan looks for harmful code that is already on the site. A vulnerability scan looks for plugins, themes or WordPress versions with known security holes. A site can pass a vulnerability scan while it is already infected, so run both.
At least once a day automatically, plus a full manual scan whenever something looks wrong or after you install new plugins. Wordfence recommends scanning every 24 hours, or at least once a week on servers with limited resources.
Yes. Sucuri SiteCheck, VirusTotal and Google's Safe Browsing site status need nothing installed, and WP-CLI can verify core and WordPress.org plugin files on the server. None of these reads the database, so add a scanner plugin if you suspect an infection.
A scan that runs on your own server uses its resources while it runs, which small hosting plans can notice. Wordfence offers a Limited Scan type for restricted hosts, while MalCare and Jetpack Scan do the heavy work on their own servers.
Do not delete files straight away. Check whether the change was made on purpose, keep a copy of the site, change every password, then clean the site or restore a backup from before the infection and update whatever let the attacker in.
Use a dashboard that collects every site's results, such as Wordfence Central or WPMU DEV's Hub with Defender Pro. WPCentrify, our own product, checks every connected site every day from inside and outside and shows each site's verdict and security score in one view.
Related reading
WordPress site hacked
What to do first when a scan confirms the worst: contain, assess, clean up and prevent the next one.
Read the guideVulnerability scanning
Which of your sites run a plugin or theme with a known hole, and the version that fixes it.
See the featureSecurity for multiple sites
How to see security risk across every WordPress site you look after, and patch what matters first.
Read moreMore on this topic: how to track user activity with an audit log and vulnerability monitoring across a portfolio.
Check every WordPress site you manage, every day
WPCentrify checks each site from inside and outside, gives it a plain-English verdict and a security score out of 100, and emails you only when something is urgent.
Free during early access. No credit card required.