Free malware scanner for Joomla and WordPress. File by file.

Every file by SHA-256 against the official release. No signatures, no hunches — tampered files and planted backdoors appear in the report with path and line.

What the scan gives you

Not a signature scanner looking for known malware patterns. A full comparison against the known-good state — which catches malware nobody has seen before.

  • Complete file index

    The bridge file walks every directory recursively and computes a SHA-256 hash per file. File contents never leave your server.

    See how
  • Compared to the original

    We pull your core version and every detected extension from the official source, hash the clean files, and compare them pair by pair.

    See how
  • Version and extensions

    Core version plus every component, module, plugin and template installed afterwards, with its version — read straight from the instance.

    See how
  • Foreign files surfaced

    Files that appear in no original package stand out immediately. That is exactly where uploaded shells and backdoors live.

    See how
  • Report and cleanup

    Every finding with its path, risk class and classification. Isolate or restore the original — only once you approve it, and everything stays recoverable.

    See how

Where malwarebuster is used

Any time the question is: is this still the state we shipped?

Hack response

After an infection, know within minutes which files were touched and which do not belong there at all.

Agencies

Check every client site on a schedule and show the client evidence of its actual state.

Maintenance plans

Recurring scans as a fixed part of maintenance, with a report for every run.

Hosting

Spot compromised instances across your fleet before the server ends up on a blacklist.

Handover and audit

Assess an inherited project before you take responsibility for it.

Migration

Leave the baggage behind: only verified files move to the new system.

Pricing

Two packages, no subscription. The scan is free and stays free. The larger package is a one-off €29 — currently nothing, as a launch price.

Scan

The full comparison against the original files.

free

forever — no account, no payment details

  • As many websites and as many checks as you like
  • Every file compared against the vendor’s original
  • Extensions, templates and language packs too — WordPress and Joomla
  • Finds files that have no business being there
  • Also searches the code for 33 suspicious patterns
  • Warns about extensions with known security holes
  • A report saying where and how serious it is

AI analysis and cleanup

A second opinion on everything the scan flagged — and the means to act on it.

freeinstead of €29

one-off — per scan, no recurring cost

  • Everything in Scan
  • An AI reads every flagged file on its own
  • Explains in plain words what the file does
  • Tells real findings from false alarms
  • Take a suspicious file out of service, or put the original back
  • Every step confirmed separately and reversible
  • Report in German and English

Frequently asked questions

If your question is not here, support answers on weekdays within a few hours.

What does it cost?

The scan is free forever and needs no account — unlimited domains and runs. The AI analysis is a one-off €29 per scan and is also free at launch. No subscription, no payment details for the scan.

What does the PHP file I upload actually do?

It first identifies whether this is Joomla or WordPress, then reads file paths, sizes and modification dates and computes one SHA-256 hash per file, plus the core version and the list of installed extensions. File contents are never transmitted.

Isn't the bridge file a risk in itself?

Each file is generated for exactly one domain, carries its own token, expires after 24 hours and only accepts requests from our scan servers. You delete it after the scan; we keep reminding you until it is gone.

Which versions are supported?

Joomla 3.9 to 6.x and WordPress 5.x to 6.x, on PHP 7.4 to 8.5. For extensions and plugins the rule is: anything whose original package is still publicly obtainable in the installed version can be verified — for WordPress and the official directory that is almost always the case.

Does malwarebuster modify files on my server?

Only when you approve a finding individually. By default the scan is strictly read-only, and every affected file is backed up before anything is written.

What about my own customisations?

Your own changes show up as deviations, because their hash differs from the official package — that is the price of comparing against a known-good state instead of hunting for signatures. The report classifies every file rather than merely flagging it, and the AI analysis separates heuristic false alarms from real findings. A permanent exception list carried across scans does not exist yet.

What do you store about my site?

Domain, file paths, hashes, metadata and your reports. No file contents, no database contents, no credentials. Deleting a project takes its data with it.

Check your first installation

The scan costs nothing and needs no account. All you need is the URL and FTP access.