Guides/Plugins and tools/Jetpack/Scan your site for security threats

Scan your site for security threats

Last reviewed on December 10, 2025

Our Jetpack Scan tool checks every WordPress.com site daily for dangerous plugins, themes, malware, and other vulnerabilities. This guide explains security scanning and how to view a record of all threats to your site.

About Jetpack Scan

Jetpack Scan, our security tool enabled on all WordPress.com sites, checks the following files on your site automatically each day:

Once weaknesses or malware are spotted, our security team swiftly resolves the issues, updating or reverting files as needed, depending on the problem. 

View Jetpack scan history

This section of the guide applies to sites with our WordPress.com Personal, Premium, Business, and Commerce plans. For free sites, upgrade your plan to access this feature.

On our higher-tier plans, you have access to the scan history, which shows a record of all previous threats identified on your site. To view the scanning history, take the following steps:

  1. Visit your site’s dashboard.
  2. Navigate to Jetpack → Scan.
  3. The Scanner tab will show you when the most recent scan was, with a “Scan now” button to trigger a new scan.
  4. Click the History tab to view a record of all previously active threats on your site.
  5. Scroll through the security threats, where you can expand more details about the threat.
Scanning history.

No action is required for these security threats – Jetpack Scan fixes each threat discovered.

Examples of common threats

Jetpack Scan checks your site for common security threats and vulnerabilities that could put your data or visitors at risk. Below are some examples of what you may see in the scanning history.

Changes to core WordPress files

Jetpack Scan will alert you if any core WordPress files have been changed or deleted. These files should never be modified directly. To customize your site’s functionality, use plugins or themes instead.

If you didn’t make these changes yourself, treat them as suspicious. Replace the affected files with clean versions using SFTP or contact support for help.

Vulnerable plugins

Jetpack Scan detects plugins with known security vulnerabilities and will include a link to learn more about the vulnerability. If a newer version includes a fix, we will update the plugin to patch the threat. You can delete plugins you no longer need on your website.

Other vulnerabilities

Jetpack Scan looks for shells found in files that give attackers access to execute malicious code (malware), delete files, and make changes to your database. Jetpack Scan removes any infected files and replaces them with a clean version from your backup.

Was this guide helpful for you?

Not quite what you're looking for? Get Help!

Copied to clipboard!