Free Security Tool

WhizzyScan: free Magento 2 and WordPress malware scanner

Free server-side scanner for any Magento 2 or WordPress store. One SSH command checks files and database for webshells, card skimmers and backdoors, checks your version against known CVEs, and gives you a private report. No signup, no account.

$ curl https://shopwhizzy.com/gowiz/external/agent | sh

SSH into any Magento 2 or WordPress install and run it. You'll get a private report link at the end.

How it works

The exact same rule engine we run nightly across our own managed fleet - now available to anyone.

terminal

1. Run one command

SSH into the Magento 2 or WordPress install you want to check and paste the command above - cPanel, Plesk, or a bare server, doesn't matter.

search

2. Auto-detects your root

Checks the current directory, then common locations (public_html, httpdocs, www) - just confirm the detected path.

bug_report

3. Scans files & database

Malware signatures, webshells, and skimmer code on any store, plus a growing list of specific Magento and WordPress core CVEs - and a database scan on Magento stores.

verified

4. Get your report

A private report link prints at the end. Re-run it later and the same report updates in place.

What gets checked

shield_lock

Core platform version

Your Magento version checked against Adobe's security bulletins (plus specific high-risk CVEs verified directly against your code, so a spoofed version number can't hide an unpatched vulnerability), or your WordPress core version checked against known WordPress CVEs.

dns

Database integrity (Magento)

CMS blocks/pages, configuration values, and order address data checked for known malicious patterns, plus a full list of your admin accounts.

code

File system scan

PHP and JavaScript files checked for malware signatures, webshells, and payment-skimmer patterns.

fingerprint

Suspicious uploads

Unexpected executable files in Magento's custom options upload directory - a known sign of a successful PolyShell-style attack - or in WordPress's wp-content/uploads.

Why scan from the server, not just from outside

External scanners only see what your store sends to a browser. That catches skimmers loaded on the checkout page, but misses most of what attackers leave behind. WhizzyScan runs inside the server, so it also finds:

code

Backdoors and webshells

PHP files that are never linked from a page, so no outside scanner can reach them, but that give an attacker full control of the store.

dns

Malicious code in the database

Scripts injected into CMS blocks, pages or configuration values, including ones that only load for some visitors.

fingerprint

Executables in upload folders

Unexpected PHP files where only images and documents belong - a common sign that an attack already succeeded.

shield_lock

Unpatched code behind a spoofed version

A version number can be faked. WhizzyScan verifies specific high-risk Magento CVEs directly in your code.

What to do if WhizzyScan finds something

1. Don't delete files blindly

Removing one backdoor while others remain gives a false sense of safety. Attackers usually leave more than one way back in.

2. Take a snapshot first

Copy the files and database before changing anything, so you keep the evidence of what happened.

3. Rotate every credential

Admin users, database, SSH, API integrations and payment keys - assume all of them are known to the attacker.

4. Close the way in

Most infections start with a missing security patch or a vulnerable extension. Apply the patch or upgrade, or the store will be reinfected.

5. Scan again

Re-run the same command. Your private report updates in place, so you can confirm the store is clean.

Need help? Our Magento team cleans infected stores, applies security patches and hardens the server arrow_forward

Already a ShopWhizzy client?

Your servers are already covered automatically every night - this is for anything outside our managed fleet: a second store, a client's server, or a store you're thinking about migrating to us.

Read the full announcement arrow_forward

Frequently asked questions

Is WhizzyScan really free?

Yes. There is no account, no trial and no payment. The scan and the private report are free.

Which platforms does it support?

Magento 2 and WordPress. On Magento stores it also scans the database.

Does it work on cPanel or Plesk hosting?

Yes. It works on any server where you can open an SSH session in the store folder: cPanel, Plesk or a bare server.

Who can see my report?

Only people who have the private report link printed at the end of the scan.

Can I run it again later?

Yes. Run the same command again and the same report updates in place, so you can compare before and after a cleanup.

Is this the same as a malware removal service?

No. WhizzyScan finds the problem. Cleaning the infection, closing the entry point and hardening the store is a separate service our Magento team can do for you.