ImunifyAV scans your hosting account for malware, backdoors and injected code at the server level.
Running a scan
- In cPanel open ImunifyAV under Security.
- Click Start Scanning and choose to scan your full home directory.
- Wait for the scan to finish — this can take several minutes on a large account.
- Review the Malicious tab.
Reading the results
Each detection shows the file path and the signature matched. Common findings are obfuscated PHP in theme files, unknown PHP files inside wp-content/uploads, and modified core files.
Acting on detections
- Core WordPress files — do not edit them; replace with fresh copies from wordpress.org.
- Plugin or theme files — delete the plugin or theme and reinstall it from a legitimate source.
- Unknown PHP in uploads — safe to delete; nothing legitimate puts PHP there.
- Anything you are unsure about — open a ticket before deleting. Removing the wrong file takes the site down.
Always download a backup before deleting anything flagged. False positives do happen, particularly with heavily minified or licence-protected premium plugins.