SECURITY FINDING
Malware or backdoor signature found in a file
What it is
The scan found code that matches known malware or webshell signatures — code built to give an attacker remote control of the site, hidden inside a file that otherwise looks normal.
How to fix it
Install the WordPress Plugin and run AI Repair — it removes the malicious code automatically, with a backup and automatic rollback if anything goes wrong. If you'd rather act right now without it, delete the file if you don't recognize it, then change every password on the site.
In depth
A malware or backdoor signature means that someone has hidden malicious code inside one of your site's files, essentially creating a hidden door that lets them control your website without your permission. This is serious because an attacker with this kind of access can steal your data, send spam, infect your visitors' computers, display fake content, or hold your site hostage. The good news is that this is fixable, and you have a straightforward path forward. The easiest solution is to install a WordPress security plugin that can automatically detect and remove this malicious code while keeping a backup, so if something goes wrong it can undo the changes. If you want to act immediately without waiting for a plugin, you can manually delete any files you don't recognize as part of your site, and then change all your passwords, your WordPress admin password, and your hosting account password to make sure the attacker can't get back in. Either way, you need to act on this today, not tomorrow.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.