I don’t have to worry about my site
I don’t have to worry about my site being hacked anymore. SiteLock just handles it in the background.
Automated malware scanner that doesn’t slow down your website.
Continuous scanning checks across every layer of your site — so threats are found and removed before your visitors ever notice.
Continuously scans your website files, database, and public pages — with automated removal when malicious code is detected. Threats are stopped before they spread.
Identifies application vulnerabilities, SQL injection risks, and cross-site scripting risks while also monitoring your email reputation. Every angle of your site's credibility is covered.
Collects what was found on every scan, with exportable results and full scan history — so you always know what happened and when.
I don’t have to worry about my site being hacked anymore. SiteLock just handles it in the background.
We were blacklisted once before we had SiteLock. Never again — now any issue gets caught and cleaned up immediately.
Knowing the scan runs automatically every day means I can focus on running my business, not worrying about security.
| File‑Level Malware Scanning & Removal | |
|---|---|
| Catch hidden malware in your website files automatically | Your site files are checked around the clock, so malicious scripts or tampered core files are found and flagged before they can cause serious damage. |
| Remove malware infections in the same pass | When malicious code is detected, it is removed during the same scan, targeting only the infected code so the rest of your site keeps running normally. |
| Know exactly what was scanned, flagged, and fixed every time | Every scan categorizes flagged items as malicious, suspicious, or requiring expert review, so you always know what was checked and what changed. |
| Get expert review on suspicious files | Grey-area files that cannot be clearly labelled clean or malicious are escalated to SiteLock’s research team and flagged separately, so nothing risky gets quietly ignored. |
| Find specific issues without wading through logs | Searchable, filterable results let you jump straight to a specific file or issue type in seconds instead of scrolling through long reports. |
| Keep a full history of every clean‑up | Your malware scan history shows what was found, what was fixed, and when, giving you a complete audit trail without any extra work. |
| Always know when your website was last scanned | “Last scanned” and “next scan” timestamps, plus on‑demand scanning, mean you can see your coverage at a glance and run a fresh check any time you need one. |
| SMART Database Scan — Database Malware Detection & Removal | |
|---|---|
| Catch malware hidden in your database | Scans your CMS databases for injected code, spam content, and anomalies—places many security tools never look—so hidden threats do not linger out of sight. |
| Clean database attacks without touching SQL | When malicious content is found, it is removed automatically so you do not have to export tables, write queries, or edit database entries by hand. |
| Run deep database checks on demand | You can trigger a database scan any time—such as after content changes or plugin installs—so you are not locked to the regular schedule when something feels off. |
| Get protected fast on WordPress and Joomla | For WordPress and Joomla, SiteLock auto‑detects your database credentials and confirms the connection, so protection can start without manual configuration. |
| Undo database cleanup with one click | If a cleanup ever causes an unexpected issue, you can roll the database back to its pre‑scan state, so automated fixes never feel irreversible. |
| Webpage Scan — External Page Scanning | |
|---|---|
| Spot malware visitors and Google could see | Scans your live pages from the outside in to catch injected content, malicious redirects, and website defacement using intelligence from sources like Google Safe Browsing and other threat feeds. |
| Email Reputation Scan — Spam & Blacklist Monitoring | |
|---|---|
| Avoid surprise listings on spam blacklists | Checks your domain against major spam databases so a hacked website does not quietly damage your email deliverability or customer trust. |
| Get alerted the moment your reputation changes | Monitors your domain continuously and alerts you as soon as a blacklist listing appears, giving you time to fix issues before customers notice. |
| Vulnerability Scan — Application & Code‑Level Testing | |
|---|---|
| Find data‑stealing SQL injection risks early | Probes your forms, URLs, and queries the way an attacker would, so SQL Injection vulnerabilities are surfaced and can be fixed before data is exposed. |
| Protect visitors from hidden XSS attacks | Identifies Cross‑Site Scripting (XSS) weaknesses that could let attackers run malicious code in your visitors’ browsers and flags them for remediation. |
| Know which plugins and themes put you at risk | Scans your CMS core, installed plugins, and active themes for known issues and tells you what is vulnerable, how serious it is, and what to do next. |
| SSL Monitor — Certificate Health Monitoring | |
|---|---|
| Prevent browser warnings that drive visitors away | Verifies that your SSL/TLS certificate is valid and active, so customers do not see browser security warnings when they land on your site. |
| Get alerts before your SSL certificate expires | Tracks certificate expiration dates and alerts you well before the date, helping you renew in time and avoid browser warnings, broken padlocks, or ranking penalties. |
| Scan Results, Alerts & Reporting | |
|---|---|
| See all website security scans in one place | File, database, webpage, email reputation, vulnerability, and SSL scans all appear in a single dashboard view with their current status and last scan time. |
| Act at the speed of the threat | Immediate alerts let you know as soon as any scan finds an issue, so you do not have to log in or wait for a digest before responding. |
| Know what security issues to fix first with Site Health | Every scan feeds into your Site Health score and Prioritized Security Action Queue, giving you a clear, ranked list of next actions instead of raw results. |
| What we scan | Scan type | Frequency | How |
|---|---|---|---|
| Website files | SMART File Scan | Daily + on demand | Internal scan of all site files via FTP/SFTP |
| Database | SMART Database Scan | Daily + on demand | Internal database scan via hosting credentials |
| Public pages | Webpage Scan | Daily | External scan of publicly visible pages as a browser would see them |
| Email reputation | Email Reputation Scan | Continuous | Checks domain against known spam databases |
| Application layer | Vulnerability Scan | Scheduled | SQL Injection and XSS testing on inputs, URLs, and queries; application version checks |
| SSL certificate | SSL Monitor | Continuous | Validates SSL certificate status and monitors for expiry |
Your Site Health score combines all scan results into one clear website security health status — and the Prioritized Security Action Queue tells you exactly what to fix next.
No. SiteLock scans run on SiteLock’s own infrastructure, not your server. SMART File Scan connects via FTP/SFTP and processes files remotely — your hosting environment carries none of the processing load. Most sites see no measurable performance impact, even during a full scan run.
Malware Detection is the scanning layer — it continuously monitors your files, database, public pages, email reputation, vulnerabilities, and SSL, and removes malware automatically when found. Malware Removal is SiteLock’s dedicated remediation service, adding deeper cleanup capabilities including backdoor removal, expert-assisted cleanup, and post-cleanup Site Health confirmation. If your site is already infected or you want the full cleanup guarantee, see our Malware Removal solution.
SiteLock uses two complementary methods. SMART File Scan connects to your server via FTP/SFTP and scans from the inside out — covering every file in your server directory, including files no external tool or browser can see. The Webpage Scan runs from the outside in, checking what a visitor or search engine would actually see. Together, they cover both the server-level and public-facing attack surface that a single-method scanner would miss.
Many WordPress security plugins operate at the application layer — inside WordPress itself. They may be limited to files and database tables that WordPress has access to, and some scans run on your server, consuming hosting resources.
SiteLock’s free WordPress plugin is different. It adds lightweight hardening, login security, Site Health visibility, and cloud-based security checks without placing the scanning load on your server.
When you connect an eligible SiteLock plan to our WordPress plugin, SMART File Scan connects at the server level via FTP/SFTP, reaching files outside the WordPress directory that plugins cannot see — including backdoors, injected scripts, and server-level files. Because scanning is performed off-server, it minimizes the impact on your website’s hosting performance.
It depends on what was found. When malware is detected in your files or database, it is removed automatically in the same scan pass. When a vulnerability is identified, it is flagged in your Prioritized Security Action Queue with a severity rating and a direct link to act. SSL issues and email reputation changes trigger immediate alerts. Every finding updates your Site Health score in real time — so you always have a single, current view of your site’s security status.
Reach us by chat in the lower-right corner.
SiteLock scans every layer of your website — files, database, public pages, email reputation, application vulnerabilities, and SSL — continuously, without slowing your site. When malware is found, it’s removed automatically. When vulnerabilities appear, you’re notified immediately. All backed by continuous monitoring and expert support.