Malware & Threat Detection
Scan your sites for malware, phishing indicators, and blocklist status.
Malware & Threat Detection
LemWatch checks your site against multiple threat intelligence databases to detect malware, phishing attempts, and blocklist presence.
What Gets Scanned
- Malware signatures — Known malicious code patterns in page source
- Phishing indicators — Fake login forms, credential harvesting scripts
- Blocklist status — Whether your domain appears on Google Safe Browsing, PhishTank, or other blocklists
- Suspicious scripts — Cryptocurrency miners, data exfiltration, or obfuscated code
- Iframe injections — Hidden iframes loading malicious content
Severity Levels
Level — Description — Action —
🔴 Critical — Active malware detected or domain blocklisted — Immediate remediation required —
🟠 Warning — Suspicious scripts or potential phishing elements — Investigate and verify —
🟢 Clean — No threats detected — No action needed —
When Scans Run
Malware scans run as part of your regular site checks. The frequency depends on your plan:
- Free — Every 24 hours
- Pro — Every 6 hours
- Agency — Every hour
- Enterprise — Every 15 minutes
What to Do If Malware Is Found
- Don't panic — but act quickly
- Check the details — LemWatch shows exactly what was flagged and where
- Clean the infection — Remove malicious code, update plugins/themes, change passwords
- Re-scan — Run a manual check from LemWatch to verify the fix
- Request review — If blocklisted, submit a review request to Google
- Investigate root cause — Check for compromised credentials, vulnerable plugins, or outdated software