Website malware check
Check the warning first, then protect evidence before changing the site
A browser warning, unexpected redirect, unfamiliar page or Search Console security alert can indicate a compromised website. Do not rely on one public scanner alone. Check Google Search Console, scan the hosting account and review recent changes before deciding what must be restored or removed.
How can I check whether my website has malware?
- 1Check Search Console
Open the Security issues report. Google lists detected hacked content, malware, harmful downloads or deceptive pages and may show sample URLs.
- 2Note what visitors see
Record the exact warning, affected URL and time. Do not enter passwords or payment details on a page you believe is compromised.
- 3Check unfamiliar changes
Look for new administrators, plugins, themes, files, scheduled tasks, redirects and DNS changes that you did not make.
- 4Scan the hosting account
Use the security and malware tools available in Plesk. A clean public URL scan does not prove every private file is safe.
What can UKC shared hosting customers check?
Imunify
Review malware findings in Plesk. If a file is flagged, identify the affected application and take a backup before making manual changes.
WordPress Toolkit
Check WordPress security status, administrators, installed components and available updates. Remove extensions you no longer use.
Files and logs
Compare modification times with the incident. Logs can help identify suspicious requests, but they should not be treated as a complete investigation.
Backups
Plesk Backup Manager can restore your own account backups. UKC also keeps daily server-side backups and can handle restore requests.
What should I do if malware is found?
- 1Limit further damage
Change hosting, CMS, database and administrator passwords from a clean device. Remove unknown users and secure access.
- 2Clean or restore
Replace compromised files with a known-good copy, update the application and remove abandoned components. Ask for specialist help if you are unsure.
- 3Test the complete site
Check forms, downloads, mobile pages, redirects and search results. A scanner may only sample part of the website.
- 4Request Google’s review
When the cause and all affected content are fixed, request a security review through Search Console if a Google warning remains.
How do I reduce the chance of reinfection?
Keep the CMS, themes and plugins current.
Use unique passwords and multi-factor authentication where available.
Delete software and accounts you no longer need.
Keep tested backups outside the live website.
Review security alerts and account changes regularly.
Need a second pair of eyes?
Tell us the warning, affected address and when it began
UKC Support can help identify the appropriate hosting and recovery route.