Malware scanner in Modular DS: what it is and how to configure it
The Modular DS malware scanner periodically checks your sites' files and database for malicious, infected or compromised content. This way you catch the problem as soon as it appears, instead of finding out once the damage is already done.
In this article we'll show you how it works and help you get the most out of it.
What the malware scanner does
The scan goes through your site's files (WordPress core, plugins, themes, content and media) and its database tables, and flags anything suspicious or outright malicious.
It's the piece that completes your security alongside Patch & Protect, and the difference between the two is simple. Patch & Protect works on prevention: it applies virtual patches and rules that block vulnerabilities before they can be exploited. The malware scanner works on detection: it warns you when a site may already be compromised.
The scanner is powered by Imunify, a malware detection technology present on millions of domains worldwide.
Basic version and Premium version
Every user gets one free malware scan per month for each site. That's the Basic version, which runs a scheduled monthly scan.
If you need more control, you can activate the Premium version, which is paid and adds the option to:
- Run scheduled daily and weekly scans, on top of the monthly one.
- Run manual on-demand scans at any time.
The Premium version costs €2 per month per site, is billed monthly, and you can cancel it whenever you want.
There's an important detail about billing: charging starts the moment you apply a Premium configuration to a site. Before continuing, you'll see a notice confirming the price, so you can decide with the information in front of you.

To stop paying for a site, remove its Premium configuration and apply a Basic one. As long as a site has a Premium configuration applied, it will keep being charged.
How to access the malware scanner
Go into your Modular DS dashboard and click "Malware scanner", inside the "Security" section of the left-hand menu.
There you'll see the list of all your sites with the following information, for the sites where the scan is active:
- "Frequency": how often the site is scanned (monthly, daily, etc.).
- "Version": whether that site uses the Basic or Premium version.
- "Last analysis": the status of the latest scans, with one colored dot per scan. Hover over a dot to see its status and results.
- "Name": the global configuration applied to the site.

Clicking the three dots on any site gives you quick access to several actions:
- "Scan now": launches an immediate scan (only available in the Premium version).
- "Apply configuration": changes the global configuration assigned to the site.
- "Go to site", "View last analysis" and "Deactivate" the scan for that site.

How to create a global configuration
Just like backups or the uptime monitor, the malware scanner works with global configurations: you define once how you want your sites scanned and apply that configuration to as many as you like.
From the "Global configurations" tab you can see the ones you've already created and create new ones with the "Create global configuration" button.

The first step, "General configuration", brings together the main options:
- "Configuration name": to identify it among the others.
- "Version": choose between "Basic" (monthly scan) and "Premium" (daily, weekly and on-demand scans).
- "Recurrence": how often the scan runs and at what time. In the Basic version only the monthly option is available.
- "Scan options": enabling "Limit scan to WordPress table prefix" makes the scan skip database tables that don't belong to that site.
- "File exclusion": with "Exclude files by extension" you leave the file types you specify out of the scan.

Further down you'll find the "Expert configuration". As the notice itself points out, it's a configuration for advanced profiles only: we recommend not touching it unless you know the capabilities of the server hosting the site well. Here you can adjust the "Maximum number of files" to process per cycle (lowering it helps on slower servers) and the "Maximum file size to scan".

The second step is choosing which sites this configuration applies to. You can also set it as the default so it's automatically applied to new sites you add.
If you selected the "Premium" version, an activation notice with its price will appear when you save. Remember that charging starts as soon as you apply it to a site.
To edit or delete an existing configuration, use the three dots next to it in the "Global configurations" tab.
How to review a site's analyses
There are two ways to reach the result of an analysis from the general view:
- Click the three dots on a site and choose "View last scan".
- Or click directly on the site's name. You'll enter that site's "Malware scanner" section, with the summary of the latest scan, the malware found and the "Scan history". From there, click "View details" on any analysis to open its full information.
The site's section also has the "Scan now" button, which launches an immediate scan. It only works if the site has the Premium version active.

What an analysis shows you
The summary and detail of each analysis include:
- "Infected files", "Malicious files" and "Database threats" detected.
- "Analyzed files": the total number of scanned files.
- "Suspicious files": files pending verification.
- The breakdown by type (core, themes, plugins, content and media) and the table of detected threats with their severity and status.

About "Suspicious files", keep one thing in mind: the scanner may flag a file because of its structure even if it isn't a real threat, so they can be false positives. Even so, it's worth reviewing them to confirm they're legitimate before considering them safe.
In the "Scan history", each scan's status shows how it ended. If you use the Basic version and have already used up your free scan for the month, you'll see the "Quota exceeded" status: the scan doesn't run because you've used up your monthly quota, not because there's a problem with the site.

Related articles
Do you need help with anything else? Email us at help@modulards.com or contact us via the support chat, and we'll be happy to help you.
Updated on: 06/08/2026
Thank you!
