Free WordPress Malware
Scanner That Checks
Every File
Most scanners only check known plugin files. We scan every single file in your webspace, including hidden backdoors, obfuscated code, and files that don't belong.
90,000+
Sites protected
1,000,000+
Audits completed
Since 2012
14 years of threat data
Surface-level scanners miss the threats that matter
Most WordPress malware scanners visit your homepage, check for Google blacklist warnings, and call it done. That catches maybe 5% of real threats. The rest are buried in files your visitors never see - deactivated plugins, uploaded scripts, modified core files, and backdoors tucked away in your /wp-content/ directory.
Our scanner connects directly to your server through a lightweight plugin and takes a full snapshot of every file in your webspace. Each file is analysed against our threat intelligence database, built over 14 years and refined across more than a million audits.
- Scans every file - not just WordPress core or active plugins
- Detects obfuscated code designed to evade signature-based scanners
- AI-powered heuristic analysis catches zero-day and novel threats
- Understands WordPress file structure, flags files that do not belong
- Instant results with specific file paths and remediation steps
Typical online scanner
- Checks homepage URL against blacklists
- Scans public HTML output only
- Cannot see server-side files
- Misses 95% of real infections
mySites.guru deep scanner
- Scans every file on your server
- Finds threats in inactive plugins and uploads
- Detects obfuscated and encoded malware
- Real-time alerts when new threats appear
How the scanner works
Three steps from sign-up to knowing exactly what threats are on your site.
Connect your site
Sign up and install our lightweight connector plugin. It takes about two minutes and requires no server access or technical knowledge.
Automated deep scan
Our engine takes a complete snapshot of every file in your webspace and runs it through 14 years of threat intelligence and AI-powered analysis.
Instant results
Get a full breakdown of every threat found, the exact file path, what it does, and step-by-step remediation instructions to clean it up.
What we detect
Every threat category attackers use against WordPress sites, not just the obvious ones.
- Malware and viruses
- Known malicious code injections, obfuscated PHP, encoded payloads, and web shells that attackers use to keep access long after the initial breach.
- Backdoors
- Hidden file uploaders, remote code execution scripts, and authentication bypasses buried in inactive plugins or renamed files your visitors never see.
- Phishing pages
- Fake login pages, bank clones, and credential harvesting forms injected into your webspace to target your visitors without your knowledge.
- Spam injections
- Hidden links, pharma hacks, Japanese SEO spam, and keyword stuffing buried in your content or templates, damaging your search rankings.
- Cryptominers
- Cryptocurrency mining scripts quietly spending your server resources, and your visitors' browsers, to mine coins for somebody else.
- SEO spam
- Thousands of hidden doorway pages, cloaked content, and redirect chains designed to take your domain authority and send your visitors elsewhere.
Built differently from the start.
Every file in the webspace is read, not sampled: core files, plugins, themes, uploads, and everything that belongs to none of them. A backdoor parked in a deactivated plugin folder, or in a directory no theme has referenced for years, is sitting exactly where it expects nobody to look.
The threat data behind that has been built since 2012 and refined across more than 1,000,000 audits. Roughly 1,500 regex patterns, plus hash lists and filename rules, all of them taken from real compromises found on real sites rather than bought in from a feed.
Signature matching on its own misses anything freshly obfuscated, so the patterns describe what code does rather than only what it looks like: encoded payloads, packed PHP, and the decode-then-execute shape a web shell needs whatever filename it is given. Every match is shown to you with the offending lines highlighted, so you can judge it yourself instead of trusting a score.
Finding it is only half of it. Real-time alerts fire the moment a file changes unexpectedly, an admin logs in, or a plugin is deactivated, so you hear about it before your visitors do.
Common questions
How deep does the WordPress malware scan go?
How often does the malware scanner run?
Will the scanner slow down my WordPress site?
Is it really free?
Does it work with WordPress only, or other CMS too?
More ways mySites.guru protects your sites
WordPress Site Hacked?
Free security scan for compromised WordPress sites
Joomla Site Hacked?
Free security scan for compromised Joomla sites
Joomla Malware Scanner
The same file-level scanning, for Joomla sites
Vulnerability Scanner
Automatic CVE alerts for plugins and themes
Bulk Updates
Update all plugins across every site at once
Manage Multiple Sites
One dashboard for all your WordPress sites
What our users say about security scanning
“I am not a developer nor web designer, I am purely self taught and have many gaps in my knowledge specifically on how to keep sites secure. mySites.guru has allowed me to not only secure my 7 sites and feel confident from potentially hacks but also illustrated areas I was completely unaware of.”

“mySites.guru has become one of the most valuable tools in my WordPress security toolkit. It helped me identify rogue administrator accounts that would otherwise have gone completely unnoticed and provided insights that standard monitoring tools missed.”

“I've been using MySites for years. I would not have a website without it been monitored by Phil. He understanding of security on websites is second to none. Some years ago I got him to help remove malware from a website hosting account, he really is amazing”

Find out what is hiding in your WordPress site
Over a million scans completed since 2012. Yours takes about two minutes to set up and is completely free.
Scan Your Site FreeAlso supports Joomla. Run a full site security audit →