Malware Scanner
Learn how Hostinger's Malware Scanner automatically checks website files for malicious code, how to read scan results in hPanel, and how to clean infections.
Automatic background scanning of your website files for malicious code, with reporting in hPanel. Included on Web and Cloud hosting plans.
What it scans
All files in
public_htmland subdirectoriesPHP, HTML, JavaScript, shell scripts, and other executable content
Recently modified files (tracked by timestamp)
Upload directories (a common infection vector for WordPress)
The scanner runs in the background — there's no schedule to configure and nothing to trigger manually.
What it looks for
Known malware signatures (backdoors, webshells, SEO-spam injectors, phishing kits)
Obfuscated PHP (
eval(base64_decode(…)), encoded payloads)Suspicious file modifications (e.g., core WordPress files changed outside an update)
Unauthorized admin or cron entries that commonly drop when a site is compromised
View scan results
Open your website dashboard in hPanel.
Click Malware Scanner in the sidebar.
The dashboard shows:
Total discovered malware
How many infected files were found in the most recent scan
Actions taken
Files the scanner removed or cleaned automatically
Status
Clean, infected, or partially cleaned
Recent activity
Detection log over time
If malware is detected
You have three options:
Clean it yourself. Restore the affected files manually — replace WordPress core files from a fresh download, reinstall plugins/themes from official sources, and remove any unfamiliar files in
public_html.Restore from a clean backup with a pre-infection timestamp. See Backups.
Order a paid malware cleanup. A one-time service where Hostinger's security team performs the cleanup for you. Offered for WordPress sites from the Malware Scanner panel in hPanel — availability and current pricing are shown there when you order.
Warning: Before manually deleting a flagged file, verify it's not a legitimate plugin or theme file that was modified. Restore from Backups if you're unsure.
After a confirmed compromise
Restore the site from a clean backup (pre-infection timestamp).
Change all admin, FTP, SSH, and database passwords.
Update WordPress core, all plugins, and all themes.
Review WordPress Security and IP Access Rules.
Rotate any API keys or tokens stored in
wp-config.phpor elsewhere on the server.
Notes
The scan database covers files only — it detects malicious files, not database-level infections (e.g. injected posts or options). For database cleanup, restore from a backup or clean manually.
Scanning runs on the server; it doesn't slow down visitor-facing performance.
Not every theme/plugin modification is malicious — the scanner uses heuristics that occasionally flag legitimate code. Review before deleting.
Last updated: July 22, 2026
Last updated
Was this helpful?