Table of Contents
Every Apex hosting plan includes a built-in Web Application Firewall (WAF) and malware scanning tools to help keep your site safe.
How the Built-In Protection Works #
The WAF continuously filters incoming traffic, blocking common attack patterns like SQL injection attempts, brute-force login attacks, and known malicious bots. Our malware scanner also periodically checks your site's files for suspicious code.
Running a Manual Malware Scan #
- Log in to my.apexmanagedhosting.com and open Your Apex Managed Panel.
- Select the instance you want to scan.
- Navigate to the Security tab.
- Click Run Malware Scan.
- The scan will check your site's core files, themes, and plugins against known malware signatures.
- Most scans complete within a few minutes.
Understanding Your Scan Report #
- Clean Files — files that matched no known threats.
- Flagged Files — files containing code patterns associated with malware or unauthorized changes.
- Outdated Software — plugins, themes, or core files that are out of date.
Each flagged item includes a brief description and its file path.
Removing Flagged Files #
- Click on a flagged file to see more details.
- If the file is a core WordPress, theme, or plugin file that's been altered, choose Restore Original File if available.
- If the flagged file is unfamiliar, select Quarantine or Delete.
- After removing flagged items, run the scan again to confirm your site comes back clean.
After Cleaning Up #
- Update all plugins, themes, and WordPress core to their latest versions.
- Change your WordPress admin passwords, along with your SFTP and Apex account passwords.
- Review user accounts in WordPress and remove any you don't recognize.
Need Help? #
If you need further assistance, contact our support team at [email protected] or start a live chat from any page on apexmanagedhosting.com.
