Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Security/Site security/Scan a site for malware

Scan a site for malware

LAST UPDATED

3 months ago

    The WP Cloud malware scan API runs an on-demand signature scan against one site. It helps a host partner’s support or development team locate files that need investigation. It does not clean the site, replace a maintained security product, or provide client-wide scan scheduling and reporting.

    This endpoint is currently intended for host partner support and development teams, not for direct use by a partner’s customers or other end users. WP Cloud plans to provide separate malware and vulnerability scanning features for automated, recurring scans. Reserve this endpoint for a one-off investigation.

    Review every match before deleting or changing customer files. False positives are possible, especially in custom plugins, themes, and application code. For a confirmed or likely infection, follow your incident response process.

    Start a scan

    Send a POST request to the Scan Site for Malware endpoint:

    curl -H "Auth: ${WP_CLOUD_API_KEY}" -X POST \
      "https://atomic-api.wordpress.com/api/v1.0/malware/scan/${WP_CLOUD_SITE}"Code language: JavaScript (javascript)

    The default scan:

    • writes ~/logs/malware-scanner-results.log in the site’s SSH home;
    • enables standard signature matching;
    • enables fuzzy matching;
    • leaves experimental signatures disabled; and
    • leaves the additional virus scanner disabled.

    The log is not web-accessible. It records matched signature names and file paths for the partner team reviewing the result.

    A successful request returns a response ticket:

    {
      "message": "OK",
      "data": {
        "response_ticket_id": "697101d62363a84200817088867.243054b9b46e78e7.1"
      }
    }Code language: JSON / JSON with Comments (json)

    Optional scan parameters

    Most investigations should keep the defaults.

    ParameterDefaultEffect
    experimentalfalseEnables exploratory signatures that can increase false positives.
    fuzzy-patternstrueSet to false to disable fuzzy content matching.
    logtrueSet to false to suppress the local log.
    patternstrueSet to false to skip standard pattern matching.
    virusfalseEnables an additional scanner whose output can be unreliable in the current release. Leave this disabled.

    Pass an option as form data only when the investigation requires it. For example, this disables the local log while keeping the other defaults:

    curl -H "Auth: ${WP_CLOUD_API_KEY}" -X POST \
      --data "log=false" \
      "https://atomic-api.wordpress.com/api/v1.0/malware/scan/${WP_CLOUD_SITE}"Code language: JavaScript (javascript)

    Read the result

    Use the Get Response Ticket Details endpoint until the ticket reaches a final status. A new job can return Accepted with a null data value. A completed scan reports status: success and a response such as Malware scan completed.

    The response ticket confirms whether the scan job ran successfully; it does not mean that the files are clean. Read the result webhook or the local log to determine whether the scanner found candidate files. A failed ticket should be resolved before interpreting an absent or incomplete log as a clean result.

    WP Cloud can also send:

    • response-ticket webhooks with the ticket ID and final status; and
    • malware-scanner-results webhooks with scan status and result output.

    See Webhooks for signature validation. A result event has this general shape:

    {
      "event": "malware-scanner-results",
      "timestamp": 1769013720,
      "atomic_site_id": 12345,
      "data": {
        "status": "success",
        "results": "Initiating security scan\nKnown bad scan completed\nStrict scan completed\nFuzzy scan completed\nDone\n",
        "signature": {
          "signature": "xxxx",
          "timestamp": 14981791994327545,
          "salt": "xxxx"
        }
      }
    }Code language: JSON / JSON with Comments (json)

    The local log identifies phases, signatures, and paths:

    Strict pattern based scanning starting up
    php_malware_dropper_lumpen [production] htdocs/badware.php
    php_hacktool_discord_001 [production] /tmp/badware.php
    Strict scan completed
    Fuzzy pattern based scanning starting up
    Fuzzy scan completed
    Done

    Inspect the matched file, its source, and whether an official clean copy exists. Do not treat a match as permission to delete a customer’s custom code. If a confirmed malicious sample is not detected by the scanner, preserve it safely for the WP Cloud security team rather than placing it in a public issue or documentation example.

    Previous PHP filesystem access permissions
    Next Backups overview

    Related Guides

    • HTTP and security headers

      Understand WP Cloud response-header boundaries and add appropriate application headers with WordPress or custom-redirects.php.

      5 Min.

      READ

    • PHP filesystem access permissions

      Control whether PHP requests can write to a WP Cloud site’s filesystem with the php_fs_permissions…

      1 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications