Malware detection

Early warning signs, honestly described

Webforta looks for the signs that precede or accompany a compromise - from the outside on every site, and from the inside on WordPress with the free connector plugin. No scanner can prove a site is malware-free, and we never claim one is.

What Webforta detects today

  • Exposed secrets and source code (.env, .git, database dumps, config backups) that commonly lead to compromise.
  • Unexpected DNS changes that can indicate a hijacked domain.
  • Removed or weakened security headers after an unexpected change.
  • Insecure resources and forms that let attackers tamper with pages in transit.
  • Outdated platform versions advertised publicly.
  • Injected-content indicators on your homepage and a sample of linked pages: hidden iframes, cryptominers, obfuscated scripts, hidden spam links and scripts served from raw IP addresses.
  • Third-party scripts loaded without integrity checks (the path most card-skimming attacks use).
  • Blocklist status with Google Safe Browsing, where the deployment has it configured.
  • Cloaked malware: redirects or spam shown only to Google or to visitors arriving from a search, which owners usually never see.
  • With the free WordPress connector: every core file checked against official checksums, PHP hidden in uploads, known backdoor code with file and line, recent file changes and a login activity log.

What it does not do (yet)

  • Automatic malware removal. Webforta pinpoints infected files; cleaning them is up to you or your developer.
  • Server-side scanning for platforms other than WordPress.
  • Backups and one-click restore.

These are on the roadmap and will be announced when they are available and tested.

See what your website shows attackers

Start a 14-day trial, verify a domain and run your first scan in about ten minutes. No card required.