Free Security Tool
WhizzyScan: free Magento 2 and WordPress malware scanner
Free server-side scanner for any Magento 2 or WordPress store. One SSH command checks files and database for webshells, card skimmers and backdoors, checks your version against known CVEs, and gives you a private report. No signup, no account.
$ curl https://shopwhizzy.com/gowiz/external/agent | sh
SSH into any Magento 2 or WordPress install and run it. You'll get a private report link at the end.
How it works
The exact same rule engine we run nightly across our own managed fleet - now available to anyone.
1. Run one command
SSH into the Magento 2 or WordPress install you want to check and paste the command above - cPanel, Plesk, or a bare server, doesn't matter.
2. Auto-detects your root
Checks the current directory, then common locations (public_html, httpdocs, www) - just confirm the detected path.
3. Scans files & database
Malware signatures, webshells, and skimmer code on any store, plus a growing list of specific Magento and WordPress core CVEs - and a database scan on Magento stores.
4. Get your report
A private report link prints at the end. Re-run it later and the same report updates in place.
What gets checked
Core platform version
Your Magento version checked against Adobe's security bulletins (plus specific high-risk CVEs verified directly against your code, so a spoofed version number can't hide an unpatched vulnerability), or your WordPress core version checked against known WordPress CVEs.
Database integrity (Magento)
CMS blocks/pages, configuration values, and order address data checked for known malicious patterns, plus a full list of your admin accounts.
File system scan
PHP and JavaScript files checked for malware signatures, webshells, and payment-skimmer patterns.
Suspicious uploads
Unexpected executable files in Magento's custom options upload directory - a known sign of a successful PolyShell-style attack - or in WordPress's wp-content/uploads.
Why scan from the server, not just from outside
External scanners only see what your store sends to a browser. That catches skimmers loaded on the checkout page, but misses most of what attackers leave behind. WhizzyScan runs inside the server, so it also finds:
Backdoors and webshells
PHP files that are never linked from a page, so no outside scanner can reach them, but that give an attacker full control of the store.
Malicious code in the database
Scripts injected into CMS blocks, pages or configuration values, including ones that only load for some visitors.
Executables in upload folders
Unexpected PHP files where only images and documents belong - a common sign that an attack already succeeded.
Unpatched code behind a spoofed version
A version number can be faked. WhizzyScan verifies specific high-risk Magento CVEs directly in your code.
What to do if WhizzyScan finds something
1. Don't delete files blindly
Removing one backdoor while others remain gives a false sense of safety. Attackers usually leave more than one way back in.
2. Take a snapshot first
Copy the files and database before changing anything, so you keep the evidence of what happened.
3. Rotate every credential
Admin users, database, SSH, API integrations and payment keys - assume all of them are known to the attacker.
4. Close the way in
Most infections start with a missing security patch or a vulnerable extension. Apply the patch or upgrade, or the store will be reinfected.
5. Scan again
Re-run the same command. Your private report updates in place, so you can confirm the store is clean.
Need help? Our Magento team cleans infected stores, applies security patches and hardens the serverAlready a ShopWhizzy client?
Your servers are already covered automatically every night - this is for anything outside our managed fleet: a second store, a client's server, or a store you're thinking about migrating to us.
Read the full announcementFrequently asked questions
Is WhizzyScan really free?
Yes. There is no account, no trial and no payment. The scan and the private report are free.
Which platforms does it support?
Magento 2 and WordPress. On Magento stores it also scans the database.
Does it work on cPanel or Plesk hosting?
Yes. It works on any server where you can open an SSH session in the store folder: cPanel, Plesk or a bare server.
Who can see my report?
Only people who have the private report link printed at the end of the scan.
Can I run it again later?
Yes. Run the same command again and the same report updates in place, so you can compare before and after a cleanup.
Is this the same as a malware removal service?
No. WhizzyScan finds the problem. Cleaning the infection, closing the entry point and hardening the store is a separate service our Magento team can do for you.