Security

Malware scanning of the websites with ClamAV, the Linux Malware Detect signatures and MagicHost's PHP checks. Malware files are moved to the quarantine and infected WordPress core files are replaced with the genuine ones automatically; code found inside normal files is only reported.

Malware detected by the scanner.

Files the scanner skips while they stay the same.

General

Adds the free web malware signatures of Linux Malware Detect to ClamAV (about 6 MB of memory), updated automatically.
Free ClamAV signatures for malware, phishing pages and web shells, updated every 6 hours. Sanesecurity files are checked with its GPG key; spam signatures are not used, because ClamAV also checks the mail.

Background scanning

On this day all the files are scanned.

Cleanup

Every file written into a website (FTP, SFTP, File Manager, uploads through the website itself) is checked the moment it is saved. Malware files such as web shells go to the quarantine at once; normal files with malicious code inside are only reported.
Malware files go to the quarantine and infected WordPress core files are replaced with the genuine ones. Normal files with malicious code inside are only reported.
days