forumNew topic

Hosting provider says our site is clean, but a security scanner flags malware — who do we trust?

BBarış K***Expert
Job title
Corporate IT manager
Joined
Jun 2023
Message
172
#1

We are an immigration law consulting office based in Los Angeles with a five-year-old WordPress-based corporate site. Last week, we ran a routine check using an external web-based website security checker. The scanner flagged a hidden JavaScript redirect and showed the site making requests to suspicious external domains. To make matters worse, two of our clients told us they were redirected to a gambling page when visiting the site on mobile.

We reported the issue to our web hosting provider, whom we pay 400 dollars a year. Their support team ran a server-level virus scan and closed the ticket two hours later saying, 'Your files are clean, there is no malware on the server, the issue might be coming from your local browser.' Yet every time we run the independent security checker, it keeps flagging the exact same redirect code.

If the host says it's clean but an external scanner flags it as malicious, who should we believe? Why isn't the hosting company's scan catching this code, and whose job is it to fix this?

VVildan Ş***Member
Job title
Quality control inspector
Sector
Textile
Organization type
medium-sized business
Joined
Aug 2024
Message
162
Most Helpful#2

Short answer: You should absolutely trust the external website security checker. Standard antivirus tools used by hosting providers only perform static scans against known file signatures on the server; modern redirect malware, on the other hand, is usually stored in the database or dynamically injected into the page under specific user conditions.

Your hosting provider might not be intentionally lying to you; there genuinely may not be a malicious PHP script in your server's file directory. These types of conditional redirects typically exploit plugin vulnerabilities to inject payloads directly into the database's post tables or theme settings options. Worse yet, these scripts stay dormant when a server admin or desktop browser visits, but output malicious JavaScript the moment a visitor arrives via a mobile device or a search engine referral. The host's traditional file-level scanner will never catch this because it doesn't render and parse the compiled page like a browser does.

When it comes to the division of responsibility, the rule is clear: The hosting provider is responsible for securing the operating system, server hardware, and network ports. The website's application layer, WordPress core, installed themes, plugins, and database contents fall entirely on the site owner. Follow these steps to resolve it: 1) Export a database backup and search for the suspicious redirect domain as plain text, 2) Compare your theme source files against clean, original versions line by line, 3) Immediately reset all admin and database credentials.

İİlker B***MemberCommunity member
Joined
Jan 2024
Message
400
#3

This is called a conditional redirect. The attackers serve a clean page to desktop visitors to evade detection, targeting only mobile users. To test it visit the site from your phone on cellular data via a search engine link; you'll see the malware trigger with your own eyes.

TTolga A***MemberCommunity member
Joined
Nov 2023
Message
346
#4

Don't expect application-level cleanup from shared hosting support. As long as the server doesn't crash, they won't touch file contents, and their terms explicitly state that website security is the user's responsibility. You need to get the site professionally cleaned ASAP.

HHavva Ç***Member
Job title
System administrator
Sector
Catering
Organization type
sole proprietorship
Joined
Apr 2023
Message
55
#5

Take a full backup of the site right away. Then install a reputable WordPress security plugin and run a deep database scan. Strip out any foreign script tags and terminate all active user sessions.

FFiliz Ö***Member
Job title
Operations manager
Sector
Seafood
Organization type
8-person team
Joined
Sep 2024
Message
383
#6

curl the site from your terminal while spoofing a mobile user-agent but youll clearly see that hidden redirect js being pushed to the browser your hosting company just didnt wanna bother.

EEmre D***Member
Job title
Marketing manager
Sector
Real estate
Organization type
workshop
Joined
Jan 2025
Message
340
#7

Three-step emergency action plan to diagnose this: 1) Completely remove all unused old themes and plugins from the site, 2) Manually check the configuration file in the WordPress root directory for any foreign code blocks, 3) Log into the search engine indexing console and check whether any security warnings have been flagged.

BBurcu B***MemberCommunity member
Joined
Jan 2025
Message
264
#8

We wasted three weeks on a similar case; we did nothing because the hosting provider said it was clean. In the end, the search engine blacklisted our site with a red warning screen and our organic traffic tanked by 85%. We had to pay an external expert 600 dollars to get it cleaned up.

EErcan B***MemberCommunity member
Joined
Sep 2023
Message
140
#9

We ran into the exact same contradiction on our office site last year. Late at night, the site was redirecting to fake pharmacy sites, but when hosting support opened the ticket in the morning, the site showed up clean. Turns out the malicious code was scheduled to trigger only at night. That's why external checkers give way more honest results.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#10

It's rare to find an explanation this clear. When making a decision, first look at what data you have on hand.

If 2FA is on, a stolen password alone is useless. I'm also curious if anyone does it differently.

SSevimNew member
Job title
Florist
Joined
Nov 2024
Message
26
#11

There's one point I'm curious about... Just because everyone does it doesn't mean it's right.

When we decide without measuring, we always end up in the same place. Good luck with that.

NNazlı E***Member
Job title
Software team lead
Sector
Sports and fitness
Organization type
120-person company
Joined
May 2024
Message
19
#12

Following.

GGizem C***Member
Job title
Purchasing manager
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
May 2023
Message
324
#13

Noted, thanks.

MMelikeExpert
Job title
E-commerce Manager
Organization type
boutique agency
Joined
Sep 2023
Message
178
#14

I'd say don't rush. Don't hesitate to ask; those who don't ask always pay more.

Of course, it varies if your situation is different.

VVolkan U***MemberCommunity member
Joined
Feb 2024
Message
56
#15

I disagree with you on this point. Most incidents start with a leaked password, not a vulnerability.

Correct me if I'm wrong.

BBurcu Ş***Member
Job title
Social media manager
Sector
Media and publishing
Organization type
workshop
Joined
Mar 2025
Message
406
#16

Let me summarize the topic, since several different answers were given. Mistakes made on the website security checker side are usually reversible but expensive.

Your time to detect an issue directly determines its cost. Of course, it varies if your situation is different.

IIrmak B***MemberCommunity member
Joined
Jan 2025
Message
304
#17

I'll try it.

CCansu K***Member
Job title
Accounting clerk
Sector
Paper
Organization type
medium-sized business
Joined
Sep 2024
Message
4
#18

I didn't know that. Most incidents start with a leaked password, not a vulnerability.

That's all, sorry if I went on too long.

IIrmak S***MemberCommunity member
Joined
Feb 2024
Message
381
#19

Thanks for writing this, that's the right way. Don't hesitate to ask; those who don't ask always pay more.

Of course, it varies if your situation is different.

TTuğrulMember
Job title
Solar energy
Joined
Feb 2024
Message
88
#20

I disagree with you on this point. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

If I were you, I'd go this route.

Reply