Host Says Your Site Has Malware? What to Do Next

By · Updated · 7 min read

When your host emails to say malware was found on your site, it means their automated scanner matched one or more files in your account against known malicious patterns. It is usually right that something is wrong, usually incomplete about how much, and it is a warning with a clock on it: ignore it and many hosts will disable the files, the site, or the whole account. You don’t have to buy the cleanup product attached to the email, but you do have to deal with the infection.

What the notice actually means

Most hosts run a server-side scanner across every account on a schedule. It walks your files, compares them to a signature database, and produces a list: file path, detection name, sometimes a line number. That list is what arrives in your inbox, often with a button to buy a cleanup.

Read it as evidence, not a diagnosis. A signature scanner is good at spotting well-known web shells, mailer scripts and injected code it has seen before. It is weak at custom backdoors, malware stored in the database, and anything obfuscated in a new way. So the list tells you the site is compromised and gives you a starting point. It rarely tells you everything that is there, and it never tells you how the attacker got in.

Which scanner your host is using

HostScanner behind the noticeThe upsell you’ll be offered
GoDaddyWebsite Security, powered by Sucuri (GoDaddy owns Sucuri)A Website Security plan with malware cleanup
SiteGroundSG Site Scanner, built with SucuriSite Scanner plans; cleanup through their partner
Bluehost, HostGator and other Newfold brandsSiteLock (a free SiteLock Lite scan on some plans)SiteLock premium with removal
HostingerMalware Scanner in hPanel, powered by MonarxAutomatic removal on eligible plans
Many cPanel hostsImunifyAV or Imunify360 by CloudLinuxVaries by host; sometimes automatic cleanup

Product names and plan details change often, so check your host’s current help pages for exact terms. The point of the table is simpler: the notice comes from a commercial scanner, and the offer attached to it is a commercial product.

Should you delete the flagged files?

Sometimes, but not blindly. Flagged files fall into two groups, and they need different handling:

  • Files that shouldn’t exist at all — a random-named PHP file in wp-content/uploads, a web shell in a theme folder, a mailer script in the root. These can go, once you have noted their names and timestamps. The timestamps are useful: they tell you when the break-in happened, which is how you find the entry point (see finding patient zero). My guide to PHP files in the uploads folder covers the most common case.
  • Legitimate files with code injected into them — index.php, wp-config.php, a theme’s functions.php, a plugin file. Deleting these breaks the site. Replace core and plugin files with clean copies from the official source, and edit out the injection from files that are unique to you.

Some host scanners also quarantine files automatically, renaming them or stripping permissions. If the site went down right after the email, check whether the scanner moved something the site needs.

Can a host scanner be wrong?

Yes, occasionally. Backup plugins that store archives of your own site, security plugins that ship malware signatures, legitimate code that uses eval or base64_decode, and developer tools left on the server can all trip a scanner. If a flagged file is a known plugin file whose contents match the official version exactly, it is probably a false positive — say so to the host and ask them to whitelist it. My checksum verification guide shows how to prove a core or plugin file is unmodified.

But be honest with yourself. In my experience most of these notices are accurate, and “it must be a false positive” is how a small infection becomes a suspended account.

The deadline, and what happens if you miss it

Many notices give a window — sometimes days, sometimes much less — before the host acts. What they do varies: disabling individual files, taking the site offline, blocking outgoing mail, or suspending the entire hosting account, which takes down every site and mailbox on it. That last stage is a different and more urgent problem, covered in hosting account suspended for malware. If you are still at the warning stage, act now and reply to the host with what you are doing; a documented cleanup in progress usually buys time.

If the account holds more than one site, check all of them. Infections move between sites that share an account — see cross-site contamination on shared hosting — and cleaning only the one named in the email is the most common reason the notice comes back a week later.

Should you pay for the host’s cleanup?

It is a legitimate option and some of these services do decent work. Before you click the button, ask what you are buying:

  • Does it cover the database, or only files?
  • Does anyone find and close the entry point, or just remove what the scanner matched?
  • Is it a one-off cleanup or a subscription that renews?
  • Do you get a written report of what was found and removed? (Here is what a cleanup report should contain.)
  • What happens if it comes back?

If the answers are vague, compare. My malware removal service is a flat $195 per site, done by me personally, including the database, hardening, blacklist mitigation, a written video report and a 60-day malware cleanup guarantee. And whoever you hire, the red flags when hiring malware removal apply.

Stopping the next email

A second notice within weeks means the first cleanup missed something — a backdoor, a malicious scheduled task, a rogue admin user, or a vulnerable plugin still installed. Why sites keep getting reinfected goes through the usual survivors. After cleanup, update everything, remove unused plugins and themes, rotate hosting, database and FTP passwords, and keep off-server backups so you are never dependent on the host’s. Run the free site scanner for a quick outside view. And if your current host is quick to send warnings but slow to help, that is a reasonable moment to move somewhere better.

Common questions

My host says my website has malware. Is it real?

Usually, yes. Host scanners match files against known malware signatures, and most notices point at genuinely malicious or modified files. False positives do happen, typically with backup archives, security plugin signature files or legitimate code that uses functions like eval. Compare flagged plugin and core files against official copies before deciding either way.

Can I just delete the files my host flagged?

Only the ones that should not exist, such as random PHP files in uploads or unknown scripts in the root. Legitimate files with injected code, like index.php or a theme's functions.php, will break the site if deleted and should be replaced with clean copies or edited. Note file names and timestamps first, because they help identify how the attacker got in.

Do I have to buy my host's malware removal service?

No. You can clean the site yourself or hire anyone you trust, as long as the malware is removed before the host's deadline. Before buying the host's product, check whether it covers the database, whether it closes the entry point, whether it is a recurring subscription, and whether you receive a written report.

How long do I have before my host suspends my account?

It depends on the host and the severity. Some give several days, others act within hours if the site is sending spam or attacking other servers. Read the notice for the deadline, reply to confirm you are working on it, and if the account is already suspended follow a suspension-specific recovery process instead.

Why did I get another malware notice after cleaning my site?

Because something survived the first cleanup. Common survivors are backdoors in unexpected folders, malicious scheduled tasks, rogue administrator accounts, infected sibling sites on the same hosting account, and the vulnerable plugin that let the attacker in. A repeat notice is a reinfection signal, not a scanner error.