Host Says Your Site Has Malware? What to Do Next
By Glenn Lyvers · Updated · 7 min read
When your host emails to say malware was found on your site, it means their automated scanner matched one or more files in your account against known malicious patterns. It is usually right that something is wrong, usually incomplete about how much, and it is a warning with a clock on it: ignore it and many hosts will disable the files, the site, or the whole account. You don’t have to buy the cleanup product attached to the email, but you do have to deal with the infection.
What the notice actually means
Most hosts run a server-side scanner across every account on a schedule. It walks your files, compares them to a signature database, and produces a list: file path, detection name, sometimes a line number. That list is what arrives in your inbox, often with a button to buy a cleanup.
Read it as evidence, not a diagnosis. A signature scanner is good at spotting well-known web shells, mailer scripts and injected code it has seen before. It is weak at custom backdoors, malware stored in the database, and anything obfuscated in a new way. So the list tells you the site is compromised and gives you a starting point. It rarely tells you everything that is there, and it never tells you how the attacker got in.
Which scanner your host is using
| Host | Scanner behind the notice | The upsell you’ll be offered |
|---|---|---|
| GoDaddy | Website Security, powered by Sucuri (GoDaddy owns Sucuri) | A Website Security plan with malware cleanup |
| SiteGround | SG Site Scanner, built with Sucuri | Site Scanner plans; cleanup through their partner |
| Bluehost, HostGator and other Newfold brands | SiteLock (a free SiteLock Lite scan on some plans) | SiteLock premium with removal |
| Hostinger | Malware Scanner in hPanel, powered by Monarx | Automatic removal on eligible plans |
| Many cPanel hosts | ImunifyAV or Imunify360 by CloudLinux | Varies by host; sometimes automatic cleanup |
Product names and plan details change often, so check your host’s current help pages for exact terms. The point of the table is simpler: the notice comes from a commercial scanner, and the offer attached to it is a commercial product.
Should you delete the flagged files?
Sometimes, but not blindly. Flagged files fall into two groups, and they need different handling:
- Files that shouldn’t exist at all — a random-named PHP file in
wp-content/uploads, a web shell in a theme folder, a mailer script in the root. These can go, once you have noted their names and timestamps. The timestamps are useful: they tell you when the break-in happened, which is how you find the entry point (see finding patient zero). My guide to PHP files in the uploads folder covers the most common case. - Legitimate files with code injected into them —
index.php,wp-config.php, a theme’sfunctions.php, a plugin file. Deleting these breaks the site. Replace core and plugin files with clean copies from the official source, and edit out the injection from files that are unique to you.
Some host scanners also quarantine files automatically, renaming them or stripping permissions. If the site went down right after the email, check whether the scanner moved something the site needs.
Can a host scanner be wrong?
Yes, occasionally. Backup plugins that store archives of your own site, security plugins that ship malware signatures, legitimate code that uses eval or base64_decode, and developer tools left on the server can all trip a scanner. If a flagged file is a known plugin file whose contents match the official version exactly, it is probably a false positive — say so to the host and ask them to whitelist it. My checksum verification guide shows how to prove a core or plugin file is unmodified.
But be honest with yourself. In my experience most of these notices are accurate, and “it must be a false positive” is how a small infection becomes a suspended account.
The deadline, and what happens if you miss it
Many notices give a window — sometimes days, sometimes much less — before the host acts. What they do varies: disabling individual files, taking the site offline, blocking outgoing mail, or suspending the entire hosting account, which takes down every site and mailbox on it. That last stage is a different and more urgent problem, covered in hosting account suspended for malware. If you are still at the warning stage, act now and reply to the host with what you are doing; a documented cleanup in progress usually buys time.
If the account holds more than one site, check all of them. Infections move between sites that share an account — see cross-site contamination on shared hosting — and cleaning only the one named in the email is the most common reason the notice comes back a week later.
Tired of hosts that notice malware but won’t fix it?
I clean the site, and if the server is the weak point I can move it somewhere better.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
Should you pay for the host’s cleanup?
It is a legitimate option and some of these services do decent work. Before you click the button, ask what you are buying:
- Does it cover the database, or only files?
- Does anyone find and close the entry point, or just remove what the scanner matched?
- Is it a one-off cleanup or a subscription that renews?
- Do you get a written report of what was found and removed? (Here is what a cleanup report should contain.)
- What happens if it comes back?
If the answers are vague, compare. My malware removal service is a flat $195 per site, done by me personally, including the database, hardening, blacklist mitigation, a written video report and a 60-day malware cleanup guarantee. And whoever you hire, the red flags when hiring malware removal apply.
Stopping the next email
A second notice within weeks means the first cleanup missed something — a backdoor, a malicious scheduled task, a rogue admin user, or a vulnerable plugin still installed. Why sites keep getting reinfected goes through the usual survivors. After cleanup, update everything, remove unused plugins and themes, rotate hosting, database and FTP passwords, and keep off-server backups so you are never dependent on the host’s. Run the free site scanner for a quick outside view. And if your current host is quick to send warnings but slow to help, that is a reasonable moment to move somewhere better.
Common questions
My host says my website has malware. Is it real?
Usually, yes. Host scanners match files against known malware signatures, and most notices point at genuinely malicious or modified files. False positives do happen, typically with backup archives, security plugin signature files or legitimate code that uses functions like eval. Compare flagged plugin and core files against official copies before deciding either way.
Can I just delete the files my host flagged?
Only the ones that should not exist, such as random PHP files in uploads or unknown scripts in the root. Legitimate files with injected code, like index.php or a theme's functions.php, will break the site if deleted and should be replaced with clean copies or edited. Note file names and timestamps first, because they help identify how the attacker got in.
Do I have to buy my host's malware removal service?
No. You can clean the site yourself or hire anyone you trust, as long as the malware is removed before the host's deadline. Before buying the host's product, check whether it covers the database, whether it closes the entry point, whether it is a recurring subscription, and whether you receive a written report.
How long do I have before my host suspends my account?
It depends on the host and the severity. Some give several days, others act within hours if the site is sending spam or attacking other servers. Read the notice for the deadline, reply to confirm you are working on it, and if the account is already suspended follow a suspension-specific recovery process instead.
Why did I get another malware notice after cleaning my site?
Because something survived the first cleanup. Common survivors are backdoors in unexpected folders, malicious scheduled tasks, rogue administrator accounts, infected sibling sites on the same hosting account, and the vulnerable plugin that let the attacker in. A repeat notice is a reinfection signal, not a scanner error.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.