We are a 12-person company based in New Jersey supplying medical consumables to dental clinics. We pull in around $18,000 in monthly revenue, and all our sales run entirely through our website. Yesterday morning, a client called saying their browser threw a security warning while trying to place an order. We ran a free website security scanner right after and got flagged with a "malicious code detected" warning on our homepage.
We don't have an in-house, full-time cybersecurity specialist; our technical maintenance is handled by a freelance developer charging $40 an hour. He did a quick scan through the site's source code and says he couldn't spot anything blatantly out of the ordinary. Google Search Console isn't showing any penalties or blacklists yet, but we're terrified our traffic could get cut off at any second.
Do warnings from these online security scanners usually end up being false positives, or is there likely a stealthy breach on the site? How can we definitively verify and fix this without blowing thousands of dollars?