Skip to content

Identify WordPress sites that need investigation

  1. Configure and test notifications if alerts are needed.
  2. Review integrity monitoring, including Daily or Hourly frequency and trusted site/basename exceptions.

WordPress Settings showing Integrity monitoring, Automatic file action and Integrity schedule

Review the integrity switches and schedule for the intended server. The displayed saved choices do not establish that a site is clean. Select the image to view it full size; use your browser’s Back command to return.
  1. Run an appropriate manual smart/full scan in Threat & Malware Detection to include enabled attached integrity checks. Follow progress and inspect recorded findings; scans can take time.
  2. Review vulnerability findings separately. A vulnerability is not proof of an infection.
  3. Investigate the affected installation and follow Clean an infected site.

For dedicated check history, use WordPress Integrity and Suspicious Plugins. Plugin actions are retained records, not verification of the file’s current state.

Review verified false positives separately in malware and integrity policy. Enable automatic file action only after understanding its quarantine/repair effect and preserving backups. An unavailable alert or clean core checksum does not establish the entire site is clean.

From a root terminal on the server hosting the sites, you can change the recurring integrity frequency to Hourly:

Terminal window
cpfence --set-check-frequency hourly

This changes the configured frequency; it does not start an immediate check or enable monitoring by itself. Use cpfence --set-check-frequency daily to return to Daily. Keep the notification and integrity settings from steps 1–2 in place.

For an immediate check of one actual WordPress installation, cPFence v4+ provides:

Terminal window
cpfence --wp-integrity-scan /var/www/ACCOUNT_ID/public_html

Replace the example path with the intended WordPress root. You can provide more than one installation path, separated by spaces. Review Automatic file action and preserve backups first: enabled automatic action can quarantine unexpected files and repair affected core files. Wait for the final output, then inspect the recorded integrity results; a started check is not a completed result.

For the broader malware check from step 3, use:

Terminal window
cpfence --full-scan

Follow progress with cpfence --scan-status and inspect each finding’s recorded action. Scan time depends on files and available resources. For the separate CSV vulnerability report, use cpfence --vuln-export and the export guide, then continue with the cleaning and false-positive steps above.