Skip to content

Scan WordPress databases for malware

  1. Choose the intended servers and sites. Start with one installation.
  2. Check the separate database-scan exceptions and intended site selection before opening the scan action.
  3. Open Choose action → WP-AutoShield → Database → Scan databases for malware.

WP-AutoShield chooser showing Scan databases for malware under Database

Choose the database scan for the reviewed sites. This entry is not a finding or a successful scan result. Select the image to view it full size; use your browser’s Back command to return.
  1. Review the action and targets, then confirm. Read every site’s final result, including skips. Finished can include failed sites; see Read the outcome.

Inspect the actual findings and review the stored report before remediation. A database finding is separate from filesystem malware. Use database-scan exceptions only for verified false positives.

WordPress Settings showing Database malware scan separately from Database optimization

Database scanning and optimization are separate recurring choices. Saved settings do not show a scan result. Select the image to view it full size; use your browser’s Back command to return.

For a failed connection, follow database connection troubleshooting; a failed scan is not a clean result.

From a root terminal on the server hosting the sites, run:

Terminal window
cpfence --bulk-scan-wp-databases

Review /var/log/cpfenceav/wp-sites-list.txt and the inventory and scan confirmations first. This uses the server’s listed installations, not checked WebUI rows, and applies the configured database-scan exceptions.

Wait for the final per-site output. Review /var/log/cpfenceav/wordpress_db_scan_temp_run.log for the current report and /var/log/cpfenceav/wordpress_db_scan_error.log for failures. Preserve a private copy of a report you need before another run.

Investigate positive findings promptly and back up the database before editing records. Restore core files or remove an affected plugin only when the wider investigation calls for it; these actions do not remove malicious database content themselves. Follow the infected-site cleanup guide for the complete recovery flow. Use the daily scanning policy above when recurring checks are intended.