Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
14 years of threat data. 1,000,000+ site audits completed.

Free WordPress Malware
Scanner That Checks
Every File

Most scanners only check known plugin files. We scan every single file in your webspace, including hidden backdoors, obfuscated code, and files that don't belong.

No credit cardResults in minutesRemediation steps included

90,000+

Sites protected

1,000,000+

Audits completed

Since 2012

14 years of threat data

Surface-level scanners miss the threats that matter

Most WordPress malware scanners visit your homepage, check for Google blacklist warnings, and call it done. That catches maybe 5% of real threats. The rest are buried in files your visitors never see - deactivated plugins, uploaded scripts, modified core files, and backdoors tucked away in your /wp-content/ directory.

Our scanner connects directly to your server through a lightweight plugin and takes a full snapshot of every file in your webspace. Each file is analysed against our threat intelligence database, built over 14 years and refined across more than a million audits.

  • Scans every file - not just WordPress core or active plugins
  • Detects obfuscated code designed to evade signature-based scanners
  • AI-powered heuristic analysis catches zero-day and novel threats
  • Understands WordPress file structure, flags files that do not belong
  • Instant results with specific file paths and remediation steps

Typical online scanner

  • Checks homepage URL against blacklists
  • Scans public HTML output only
  • Cannot see server-side files
  • Misses 95% of real infections

mySites.guru deep scanner

  • Scans every file on your server
  • Finds threats in inactive plugins and uploads
  • Detects obfuscated and encoded malware
  • Real-time alerts when new threats appear

How the scanner works

Three steps from sign-up to knowing exactly what threats are on your site.

1

Connect your site

Sign up and install our lightweight connector plugin. It takes about two minutes and requires no server access or technical knowledge.

2

Automated deep scan

Our engine takes a complete snapshot of every file in your webspace and runs it through 14 years of threat intelligence and AI-powered analysis.

3

Instant results

Get a full breakdown of every threat found, the exact file path, what it does, and step-by-step remediation instructions to clean it up.

What we detect

Every threat category attackers use against WordPress sites, not just the obvious ones.

Malware and viruses
Known malicious code injections, obfuscated PHP, encoded payloads, and web shells that attackers use to keep access long after the initial breach.
Backdoors
Hidden file uploaders, remote code execution scripts, and authentication bypasses buried in inactive plugins or renamed files your visitors never see.
Phishing pages
Fake login pages, bank clones, and credential harvesting forms injected into your webspace to target your visitors without your knowledge.
Spam injections
Hidden links, pharma hacks, Japanese SEO spam, and keyword stuffing buried in your content or templates, damaging your search rankings.
Cryptominers
Cryptocurrency mining scripts quietly spending your server resources, and your visitors' browsers, to mine coins for somebody else.
SEO spam
Thousands of hidden doorway pages, cloaked content, and redirect chains designed to take your domain authority and send your visitors elsewhere.

Built differently from the start.

Every file in the webspace is read, not sampled: core files, plugins, themes, uploads, and everything that belongs to none of them. A backdoor parked in a deactivated plugin folder, or in a directory no theme has referenced for years, is sitting exactly where it expects nobody to look.

The threat data behind that has been built since 2012 and refined across more than 1,000,000 audits. Roughly 1,500 regex patterns, plus hash lists and filename rules, all of them taken from real compromises found on real sites rather than bought in from a feed.

Signature matching on its own misses anything freshly obfuscated, so the patterns describe what code does rather than only what it looks like: encoded payloads, packed PHP, and the decode-then-execute shape a web shell needs whatever filename it is given. Every match is shown to you with the offending lines highlighted, so you can judge it yourself instead of trusting a score.

Finding it is only half of it. Real-time alerts fire the moment a file changes unexpectedly, an admin logs in, or a plugin is deactivated, so you hear about it before your visitors do.

Common questions

How deep does the WordPress malware scan go?
We scan every single file in your webspace - not just your WordPress core or active plugins. That includes inactive plugins, themes, uploaded media directories, and any files that were left behind by previous attacks. Most scanners only check known plugin files against a signature database. We check everything.
How often does the malware scanner run?
The first scan runs immediately after you connect your site, typically completing within a few minutes. After that, automated scans run on a regular schedule so new threats are detected as soon as they appear. You get alerted in real time when something changes.
Will the scanner slow down my WordPress site?
No. The scanner runs server-side through a lightweight connector plugin. It reads files; it does not modify anything on your site, and it does not run in your visitors' browsers. Your site performance is completely unaffected during and after the scan.
Is it really free?
Yes. The malware scanner, file-level audit, and full diagnostic toolset are included at no cost. No credit card is required and there is no time-limited trial. If you want ongoing monitoring across multiple sites, paid plans are available from £19.99/month.
Does it work with WordPress only, or other CMS too?
mySites.guru fully supports both WordPress and Joomla from a single dashboard. The scan engine understands both CMS architectures, so it knows what files should and should not exist in each, which makes it significantly more accurate than a generic file scanner.

What our users say about security scanning

“I am not a developer nor web designer, I am purely self taught and have many gaps in my knowledge specifically on how to keep sites secure. mySites.guru has allowed me to not only secure my 7 sites and feel confident from potentially hacks but also illustrated areas I was completely unaware of.”
Nick Lucas
Nick LucasCEO at Greata Brands Limited
“mySites.guru has become one of the most valuable tools in my WordPress security toolkit. It helped me identify rogue administrator accounts that would otherwise have gone completely unnoticed and provided insights that standard monitoring tools missed.”
Sven Krumbeck
Sven KrumbeckWeb Development, WortBildTon
“I've been using MySites for years. I would not have a website without it been monitored by Phil. He understanding of security on websites is second to none. Some years ago I got him to help remove malware from a website hosting account, he really is amazing”
Peter L
Peter L

Find out what is hiding in your WordPress site

Over a million scans completed since 2012. Yours takes about two minutes to set up and is completely free.

Scan Your Site Free
No credit cardResults in minutesRemediation steps included

Also supports Joomla. Run a full site security audit →