We are an immigration law consulting office based in Los Angeles with a five-year-old WordPress-based corporate site. Last week, we ran a routine check using an external web-based website security checker. The scanner flagged a hidden JavaScript redirect and showed the site making requests to suspicious external domains. To make matters worse, two of our clients told us they were redirected to a gambling page when visiting the site on mobile.
We reported the issue to our web hosting provider, whom we pay 400 dollars a year. Their support team ran a server-level virus scan and closed the ticket two hours later saying, 'Your files are clean, there is no malware on the server, the issue might be coming from your local browser.' Yet every time we run the independent security checker, it keeps flagging the exact same redirect code.
If the host says it's clean but an external scanner flags it as malicious, who should we believe? Why isn't the hosting company's scan catching this code, and whose job is it to fix this?