Malware detection
Early warning signs, honestly described
Webforta looks for the signs that precede or accompany a compromise - from the outside on every site, and from the inside on WordPress with the free connector plugin. No scanner can prove a site is malware-free, and we never claim one is.
What Webforta detects today
- Exposed secrets and source code (.env, .git, database dumps, config backups) that commonly lead to compromise.
- Unexpected DNS changes that can indicate a hijacked domain.
- Removed or weakened security headers after an unexpected change.
- Insecure resources and forms that let attackers tamper with pages in transit.
- Outdated platform versions advertised publicly.
- Injected-content indicators on your homepage and a sample of linked pages: hidden iframes, cryptominers, obfuscated scripts, hidden spam links and scripts served from raw IP addresses.
- Third-party scripts loaded without integrity checks (the path most card-skimming attacks use).
- Blocklist status with Google Safe Browsing, where the deployment has it configured.
- Cloaked malware: redirects or spam shown only to Google or to visitors arriving from a search, which owners usually never see.
- With the free WordPress connector: every core file checked against official checksums, PHP hidden in uploads, known backdoor code with file and line, recent file changes and a login activity log.
What it does not do (yet)
- Automatic malware removal. Webforta pinpoints infected files; cleaning them is up to you or your developer.
- Server-side scanning for platforms other than WordPress.
- Backups and one-click restore.
These are on the roadmap and will be announced when they are available and tested.
See what your website shows attackers
Start a 14-day trial, verify a domain and run your first scan in about ten minutes. No card required.