The WP Cloud malware scan API runs an on-demand signature scan against one site. It helps a host partner’s support or development team locate files that need investigation. It does not clean the site, replace a maintained security product, or provide client-wide scan scheduling and reporting.
This endpoint is currently intended for host partner support and development teams, not for direct use by a partner’s customers or other end users. WP Cloud plans to provide separate malware and vulnerability scanning features for automated, recurring scans. Reserve this endpoint for a one-off investigation.
Review every match before deleting or changing customer files. False positives are possible, especially in custom plugins, themes, and application code. For a confirmed or likely infection, follow your incident response process.
Start a scan
Send a POST request to the Scan Site for Malware endpoint:
curl -H "Auth: ${WP_CLOUD_API_KEY}" -X POST \
"https://atomic-api.wordpress.com/api/v1.0/malware/scan/${WP_CLOUD_SITE}"Code language: JavaScript (javascript)
The default scan:
- writes
~/logs/malware-scanner-results.login the site’s SSH home; - enables standard signature matching;
- enables fuzzy matching;
- leaves experimental signatures disabled; and
- leaves the additional virus scanner disabled.
The log is not web-accessible. It records matched signature names and file paths for the partner team reviewing the result.
A successful request returns a response ticket:
{
"message": "OK",
"data": {
"response_ticket_id": "697101d62363a84200817088867.243054b9b46e78e7.1"
}
}Code language: JSON / JSON with Comments (json)
Optional scan parameters
Most investigations should keep the defaults.
| Parameter | Default | Effect |
|---|---|---|
experimental | false | Enables exploratory signatures that can increase false positives. |
fuzzy-patterns | true | Set to false to disable fuzzy content matching. |
log | true | Set to false to suppress the local log. |
patterns | true | Set to false to skip standard pattern matching. |
virus | false | Enables an additional scanner whose output can be unreliable in the current release. Leave this disabled. |
Pass an option as form data only when the investigation requires it. For example, this disables the local log while keeping the other defaults:
curl -H "Auth: ${WP_CLOUD_API_KEY}" -X POST \
--data "log=false" \
"https://atomic-api.wordpress.com/api/v1.0/malware/scan/${WP_CLOUD_SITE}"Code language: JavaScript (javascript)
Read the result
Use the Get Response Ticket Details endpoint until the ticket reaches a final status. A new job can return Accepted with a null data value. A completed scan reports status: success and a response such as Malware scan completed.
The response ticket confirms whether the scan job ran successfully; it does not mean that the files are clean. Read the result webhook or the local log to determine whether the scanner found candidate files. A failed ticket should be resolved before interpreting an absent or incomplete log as a clean result.
WP Cloud can also send:
response-ticketwebhooks with the ticket ID and final status; andmalware-scanner-resultswebhooks with scan status and result output.
See Webhooks for signature validation. A result event has this general shape:
{
"event": "malware-scanner-results",
"timestamp": 1769013720,
"atomic_site_id": 12345,
"data": {
"status": "success",
"results": "Initiating security scan\nKnown bad scan completed\nStrict scan completed\nFuzzy scan completed\nDone\n",
"signature": {
"signature": "xxxx",
"timestamp": 14981791994327545,
"salt": "xxxx"
}
}
}Code language: JSON / JSON with Comments (json)
The local log identifies phases, signatures, and paths:
Strict pattern based scanning starting up
php_malware_dropper_lumpen [production] htdocs/badware.php
php_hacktool_discord_001 [production] /tmp/badware.php
Strict scan completed
Fuzzy pattern based scanning starting up
Fuzzy scan completed
Done
Inspect the matched file, its source, and whether an official clean copy exists. Do not treat a match as permission to delete a customer’s custom code. If a confirmed malicious sample is not detected by the scanner, preserve it safely for the WP Cloud security team rather than placing it in a public issue or documentation example.