forumNew topic

Website security scanner flagged our site as infected — real issue or false positive?

PPerihan K***MemberCommunity member
Joined
May 2023
Message
124
#1

We are a 12-person company based in New Jersey supplying medical consumables to dental clinics. We pull in around $18,000 in monthly revenue, and all our sales run entirely through our website. Yesterday morning, a client called saying their browser threw a security warning while trying to place an order. We ran a free website security scanner right after and got flagged with a "malicious code detected" warning on our homepage.

We don't have an in-house, full-time cybersecurity specialist; our technical maintenance is handled by a freelance developer charging $40 an hour. He did a quick scan through the site's source code and says he couldn't spot anything blatantly out of the ordinary. Google Search Console isn't showing any penalties or blacklists yet, but we're terrified our traffic could get cut off at any second.

Do warnings from these online security scanners usually end up being false positives, or is there likely a stealthy breach on the site? How can we definitively verify and fix this without blowing thousands of dollars?

UUfuk S***Member
Job title
Front office accounting
Sector
Agriculture
Organization type
cooperative
Joined
Jun 2022
Message
74

Doki · Incident response support · 2025

Most Helpful#2

Short answer: Warnings from security scanners are frequently false positives triggered by outdated third-party plugins or tracking snippets, but every alert must still be inspected at the source code level. Instead of panicking and pulling the site down, audit recent file modifications and server requests to confirm whether you're dealing with an actual breach or just an outdated library alert.

Follow these steps to get a clear picture: 1) Inspect your site's source code with a hard refresh (bypass browser cache) and look specifically for recently injected iframes or scripts loaded from unfamiliar external domains. 2) Open the file manager via your hosting control panel and list files modified within the last 48 hours; any unscheduled edits to core system files are an immediate red flag for malware. 3) Filter your server access logs, paying special attention to direct, anomalous requests aimed at upload directories and unauthorized login attempts.

If you confirm malicious code, have your freelance dev restore the site to a known clean, full backup. Right after that, change every admin panel, database, and server credential without delay. If you conclude it's a false positive, temporarily disable the flagged third-party script and submit a re-index/re-evaluation request to the scanner.

KKübra G***Member
Job title
Field sales representative
Sector
Law
Organization type
medium-sized business
Joined
Mar 2024
Message
7
#3

When verifying, don't just load the site from your own desktop browser. Attackers often configure redirects to trigger only for visitors coming from search engine referrers or mobile user agents. Send raw command-line requests to your server using different User-Agent and Referer headers to inspect the raw response body. That makes it way easier to spot obfuscated base64 strings or stealth external injections buried in the code.

KKübra M***MemberCommunity member
Joined
May 2025
Message
62
#4

Definitely don't just take your developer's word for it when they say "I looked and didn't see anything." Modern web attacks don't plaster hacker graphics all over your screen; they inject tiny snippets of JavaScript that run quietly in the background and skim credit card form data. If your dev doesn't specialize in security, it's super easy for them to overlook a single obfuscated line of code tucked inside a file.

HHasan G***Member
Job title
QA Tester
Sector
Printing
Organization type
cooperative
Joined
Mar 2022
Message
8
#5

We had a similar scare last year. An online scanner claimed our site was blacklisted, and we saw cleanup services quoting 800 dollars. When we dug deeper, it turned out the warning was triggered by an expired certificate on our live chat plugin. We paid a developer 40 dollars to update the script and sorted the whole thing out with zero extra costs.

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#6

The very first thing you need to do right now is log into your hosting control panel and download your backups from the past week to your local machine. Even if there is an infection, your developer could lose data while trying to clean it up. Once the backup is safe, update your CMS and all active plugins to their latest stable releases. Most of the time, patching a known vulnerability stops the injection in its tracks.

AAlper C***Expert
Job title
Customer service representative
Sector
Software
Organization type
cooperative
Joined
Dec 2023
Message
74
#7

Exactly which file name or URL does the scanner report flag as malicious? Also, have you installed any new plugins, payment forms, or third-party marketing tracking scripts in the last two weeks? Those details are critical for figuring out whether it's a false positive or an actual breach.

HHatice K***MemberCommunity member
Joined
May 2024
Message
131
#8

Getting an alert from a customer is definitely stressful but dont panic. If Google Search Console isnt showing a red warning yet, your traffic wont tank immediately. Still, change your passwords without delay and comb through the files line by line with your developer. btw if you stay calm its something that can be resolved in half a day.

MMurat Z***Member
Job title
Field sales representative
Sector
Glass
Organization type
chain store
Joined
Jan 2025
Message
27
#9

something similar happened to us the scanner literally mistook our analytics code for malware. don't panic and buy expensive security packages right away but check your server logs if there are no weird requests from foreign ips it's probably just a false alarm.

DDoruk Y***ExpertCommunity member
Joined
Feb 2025
Message
99
#10

To sum up what's been said: without panicking, take a backup, check recently modified files, don't just rely on your developer's surface-level glance and check the server logs, and review external scripts before throwing money at expensive cleanup tools for no reason.

TTolga Y***MemberCommunity member
Joined
Dec 2023
Message
14
#11

Following.

İİbrahim B***Member
Job title
Production planning
Sector
Livestock
Organization type
chain store
Joined
Feb 2024
Message
24

Doki · Log management setup · 2024

#12

Sorry, but this doesn't apply in every case. If permission and scope aren't in writing, don't start that test.

If you post the result here, it will help others too.

OOnur Y***Member
Job title
Product Manager
Sector
Furniture manufacturing
Organization type
two-branch business
Joined
Nov 2024
Message
9

Doki · Log management setup · 2024

#13

My questions are cleared up, thanks.

HHatice A***MemberCommunity member
Joined
Dec 2023
Message
2
#14

Great work. The harder it is to reverse a decision, the slower you should make it.

I'm also curious if anyone does it differently.

MMustafa N***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
40-person manufacturing company
Joined
Jan 2023
Message
324
#15

I'm a small business, let me explain from my side. The real issue isn't the number, but what it's based on.

Don't rely on a single measure; go layer by layer.

KKoray E***Expert
Job title
Software developer
Sector
Packaging
Organization type
chain store
Joined
Sep 2023
Message
25
#16

You're right.

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
#17

Here's how it went for us. An untested backup is not a backup.

If you post the result here, it will help others too.

NNazlı A***Member
Job title
Clinic manager
Sector
Machinery manufacturing
Organization type
medium-sized business
Joined
Dec 2023
Message
353
#18

Could you elaborate on that? I mean when making a decision, first look at what data you have on hand.

Don't rely on a single measure; go layer by layer. tbh if you post the result here, it will help others too.

FFiliz E***Member
Job title
Graphic Designer
Sector
Catering
Organization type
two-branch business
Joined
Aug 2022
Message
200
#19

i went throuhg the same thing two years ago. if permission and scope aren't in writing don't start that test.

of course, it varies if your situation is different.

BBurcu A***VeteranCommunity member
Joined
Apr 2024
Message
360
#20

Let me speak from the other side; I'm on the supplier side. The real issue isn't the number, but what it's based on.

Everything goes well for the first three months; problems arise in the fourth. That's all, sorry if I went on too long.

Reply