2 min read Sep 26, 2026

How to Use the Free Website Malware Scanner

Every FimuroHost Cloud Hosting site is scanned for malware daily. Learn how to read the Malware Report in StackCP, clean infected files and scan again.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

FimuroHost Cloud Hosting includes a free malware scanner. It checks every website in your account every day, using a mix of commercial and in-house detection tools, and tells you exactly which files look infected.

If malware is found, PHP mail is switched off for that site automatically. This stops a hacked site from sending spam, which protects your domain's reputation and everyone else's. It switches back on once the site is clean.

View your Malware Report

  1. Log in to your FimuroHost client area at app.fimurohost.com.
  2. Go to Services and select your Cloud Hosting plan.
  3. Click Login to Control Panel / StackCP. StackCP opens for that website, already signed in.
  4. Click the Malware Report icon.
  5. Any infected sites are listed with when the infection was found and how many files are affected.
  6. Click View Report to see the file paths and what was detected.

Tip: turn on Receive Daily Email Alerts? so you hear about new detections straight away.

Understanding the results

ColourMeaning
RedHigh risk. The file is likely malicious and should be cleaned or removed.
YellowInformation only. Lower-risk matches, often in logs, SQL dumps or backup files. Review them, but they are not necessarily harmful.

How to clean an infected site

  1. Take a backup before you change anything.
  2. Replace infected core files with fresh copies. For WordPress, download the same version from wordpress.org and replace only the affected files, or reinstall core from the dashboard.
  3. Delete files you don't need, including unknown PHP files in upload folders.
  4. Remove injected code if it is easy to spot, such as a suspicious line added to the top of a legitimate file.
  5. Remove unused plugins and themes and update everything that remains.
  6. Change your passwords: database, FTP, SSH, and all WordPress admin users. Update the database password in wp-config.php too.
  7. Back in the Malware Report, click Scan Again. When the site comes back clean, PHP mail is re-enabled automatically.

Staying protected

  • Keep WordPress, themes and plugins updated, and only install them from trusted sources.
  • Turn on two-factor authentication for your WordPress admins and your FimuroHost client area.
  • Keep FTP locked when you are not using it.

Need help?

Not sure how to clean an infection? Our support team is happy to take a look. Open a ticket at app.fimurohost.com/submitticket.php or message us on WhatsApp at 01818160926.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer