Scan of website not picking up malware

I have scanned the website because I saw some malware loadm.excelator and others pop up on a gtmetrix ( screenshot included) but when I ran the scan nothing showed up as far the malware and I was wondering how I can use defender or another plugin you offer to reslove this, i already have support access on the site

  • Kasia Swiderska

    Hello David,

    Defender scans your WordPress installation and looks for suspicious files - and by that I mean files that should not be present in WordPress - what you see on those screens are redirects. Those redirects can be done by injecting code into good files (like files of theme or plugin) - they can even be hidden in content of the posts. Defender cannot scan in content of the files - that is why it is not showing you anything.
    You would need first make sure that you have everything updated on your site - best if you can download fresh copy of the plugin and themes and install theme again - but before you do that download them and see if you will find similar code in files to one described here https://blog.sucuri.net/2016/05/wordpress-redirect-hack-test0-default7.html - this will give you knowledge where hack was done.
    Also follow on hardening recommendation in Defender

    Please also see this guide on what to do when site was hacked https://codex.wordpress.org/FAQ_My_site_was_hacked

    Let me know if you have more questions.

    kind regards,
    Kasia

  • Kasia Swiderska

    Hello David,

    I asked developer about your issue and it looks I didn't provide whole answer on how Defender works.
    So - Defender will scan also plugins and themes for known issues. So if there is reported vulnerability Defender will find it.
    Also it scans for base64 code - but it wont find redirects made in clear JS code.
    If your site was hacked and JS code was injected - then Defender can't "see" that code.

    Good news is that we are preparing new scan engine that should be more efficient with finding those suspicious codes so keep an eye on updates of Defender.

    I apologize for any confusion I made here.

    kind regards,
    Kasia