Skip to content

Website malware monitoring that tells you before your visitors find out.

Uptimia scans your site against Google's Web Risk database and alerts you the moment it's flagged for malware, phishing or unwanted software.

30-day free trial No credit card Nothing to install
Threat types
3
Rescan when flagged
60min
Checkpoints
171+
Countries covered
70+

The day the site was flagged

An injection sat on a forgotten legacy subdomain, serving perfectly normal pages to everyone in the office. The scheduled scan matched it at 14:32.

14:32 legacy.caldmont.com comes back flaggedThe scheduled scan now matches a Google Web Risk MALWARE threat reputation: at risk
14:37 Your team hears it from UptimiaSlack, email, SMS — before most visitors meet Google's red warning reputation: at risk
16:10 You (or your host) remove the injectionUptimia keeps scanning on schedule — no manual re-checking reputation: at risk
next scan Auto-resolved when cleanThe next clean scan closes the incident — recovery notice tells the team reputation: intact
hoursnot weeks
Cleaned the same day.next scan
An infection that sits for weeks costs rankings, browser warnings and trust. This one lived a few hours — flagged, cleaned and confirmed clean without you re-checking anything.
heard from Uptimia, not a customercleaned in hoursclosed itself when cleanmalware · deceptive pages · unwanted software
And without the scanner? Nothing tells you your site is serving malware — it looks normal from your own browser. The first sign is the red "Deceptive site ahead" screen — shown to your visitors, not to you. red screen

What website malware monitoring catches

Every scan checks your URL against Google's Web Risk database for three kinds of threat — in a single request.

Injected scripts & drive-bysPlanted on your pages after a hack
Trojans & backdoorsInvisible to you, not to Google
Phishing & fake loginsBuilt to steal passwords and cards
Deceptive warningsPages that trick your visitors
3 threat types one Web Risk request, every scan
Adware & hijackersInstalls nobody consented to
Deceptive downloadsButtons that install something else
One request to Google Web Risk checks all three threat types on every scanMALWARE, SOCIAL_ENGINEERING, UNWANTED_SOFTWARE — malware detection, not a DNS blacklist lookup and not antivirus. not antivirus

Detection, alerting and history

Detection

Know the moment you're flagged

Uptimia scans your URL against Google's Web Risk database on a schedule you set — malware, phishing and unwanted software in a single request. A match opens an incident right away.

  • Google Web Risk intelligence — the same threat data behind Chrome's Safe Browsing warnings
  • Three threat types every scan — malware, social engineering, unwanted software
  • A skipped scan is not a clean scan — if Web Risk can't be reached the check is retried, never logged as a pass
Free tool: check a URL against Google Safe Browsing
🦠MalwareMALWARE · matchedTHREAT
🎣Social engineeringSOCIAL_ENGINEERINGclean
📦Unwanted softwareUNWANTED_SOFTWAREclean
3threats
one request
Incident opened14:32 UTC
legacy.caldmont.com flagged for malware — the same Web Risk data behind Chrome's Safe Browsing warnings.
MALWAREalert → your channels
Web Risk unreachable? The scan is skipped and retried — never recorded as a clean result. no false all-clear
Alerting

Alerts reach your existing channels

The alert goes out through the same channels as the rest of your monitoring — no separate security console. You decide how long Uptimia waits before paging anyone, from immediately up to half an hour.

  • 12 alert channels, one contact list — email, SMS, Slack, PagerDuty, WhatsApp, Telegram, Discord, Teams and more
  • Your alert delay — hold a detected threat for up to 30 minutes before it pages anyone
  • Recovery notice — you're told once the site scans clean again, on by default; one toggle turns it off
Every channel your team already watches
Flaggedpaged 14:37
legacy.caldmont.com · MALWARE via Google Web Risk at 14:32. Paged once your delay has elapsed.
your delay: 0–30 mindefault 5
Slack — #ops-alerts
Uptimia 14:37
⚠ Flagged — legacy.caldmont.com · malware, via Google Web Risk
SMS
UPTIMIA: legacy.caldmont.com
flagged MALWARE (Web Risk).
Also delivered to
EmailPagerDutyWhatsAppTelegramDiscordTeamsMattermost+ 3 more
Recovery notice — you're told the moment the site scans clean again; one toggle turns it off. on by default
Incident history

A timestamped record of every infection

Every detection is stored as an incident — start, threat type and duration until the site scanned clean. The Incidents tab lists them per monitor, with a full scan log alongside.

  • Start & end time and threat type on every incident — ready for a post-mortem or a client report
  • Incidents tab and Logs tab — clean and flagged scans badged at a glance
  • Auto-resolved — the first clean scan after an infection closes the incident for you
Page the next person until someone acknowledges
MALWAREIncident — legacy.caldmont.com
Jul 17 · 14:32 UTC → Jul 18 · 14:30 UTC
24 hflag → clean
3incidents · 90 d
closedby first clean scan
Logs — Jul 17 · 14:32
scan #212  daily cadence
THREAT · MALWARE matched
incident opened
Logs — Jul 18 · 14:30
scan #213  daily cadence
clean · no threats found
incident closed
+ 88 more scans in the log
every scan kept — clean and flagged badged at a glance
Start, end, threat type and duration — every incident drops straight into a post-mortem or a client report. on record
Setup & cadence

A cadence per site

Scan a busy storefront hourly, a brochure site weekly — any cadence from every hour to every seven days, default once a day. A monitor takes a name and a URL; nothing to install.

  • Scan every 1 hour to every 7 days — default once a day
  • One monitor watches one URL — add a monitor per page or subdomain you care about
  • No agent, plugin or extension — checks run externally against Web Risk
Watch the same URL for downtime too
Nothing to installname + URL
Scans run from our side against Google Web Risk — no agent, no plugin, no extension. Each monitor keeps its own clock.
a namea URLthat's the whole setup
1h
shop.caldmont.com
busy storefront · scanned hourly
every 1 h
1d
www.caldmont.com
the default · once a day
default
7d
brochure.caldmont.co
rarely changes · weekly is plenty
every 7 d
One monitor watches one URL — add a monitor per page or subdomain you care about, each with its own cadence. 1 URL each

How website malware monitoring works

From signup to a live scan in under a minute — nothing to install, scans run from our side.

Step 120 seconds

Enter your URL

Add a monitor with a name and URL — no script, plugin or DNS change.

Website URL
https://caldmont.com
Reachable · ready to scan against Google Web Risk
Monitor name
Caldmont — storefront
Step 220 seconds

Pick your schedule & alerts

Choose how often to scan — hourly to weekly — and which channels get the alert. Defaults: once a day, page you 5 minutes after a threat.

Scan frequency
1 h6 hOnce a day7 d
Alert via
EmailSlackSMS+ PagerDuty, WhatsApp…
CancelStart scanning →
Step 3automatic

Uptimia scans on schedule

Each scan checks your URL against Google Web Risk for all three threat types. A match opens an incident and alerts your team; the next clean scan closes it.

#ops-alerts
Uptimia 14:37
⚠ Flagged — legacy.caldmont.com
MALWAREvia Google Web Risk14:32 UTC
Also sent to EmailSMSPagerDuty

Add the URL once.Hear it from us, not from a customer.

Every scan, every threat type, every alert channel — free for 30 days, and none of it is a paid add-on.

Start your free 30-day trial
30 days free no credit card cancel anytime

Also included

Every monitor type in one account

Malware monitors sit beside your uptime, SSL, domain, speed and heartbeat monitors — same contacts, groups and reports.

legacy.caldmont.comMALWARE www.caldmont.comUPTIME api.caldmont.comSSL

Monitor groups

Group monitors by client or site and roll their status up together.

Caldmont · 6 monitors · 1 flagged

Scheduled reports

Your monitors' status in a report, branded with your logo and colors.

DailyWeeklyMonthly

Free Blacklist Checker

Run a one-off check of any domain against 23 DNS blacklists plus Google Safe Browsing — a fast first look before continuous monitoring. A different job: blacklist monitoring watches DNSBLs; malware monitoring watches Google Web Risk.

23 DNSBLs + Safe Browsing · ✓ not listed

Recovery notices

On by default — you're told the moment your site scans clean again.

clean · incident closed · notice sent

Nothing to install

Cloud-based scans — no agent, plugin or code on your site.

name + URL · that's the setup

Alerts where your team already works

Malware alerts use the same contacts and channels as everything else you monitor with Uptimia.

On-call & escalation
Direct

12 channels, one contact list — set it once, every monitor type uses it.

Browse the full integrations directory
14:32 · malware detected — legacy.caldmont.com · via Google Web Risk
#ops-alertsSlack
⚠ Flagged — legacy.caldmont.com
MALWAREvia Google Web Risk
+371 ··· 4082SMS
Uptimia: MALWARE detected on legacy.caldmont.com via Google Web Risk at 14:32 UTC.
InboxEmail
⚠ Malware flagged — legacy.caldmont.com
Google Web Risk matched a MALWARE threat at 14:32 UTC · review the incident and scan history…
ProductionPagerDuty
TRIGGEREDMalware — legacy.caldmont.com
assigned to on-call · via Uptimia integration

What is website malware monitoring?

Website malware monitoring is an automated service that repeatedly checks a website's URL against a threat-intelligence database — such as Google's Web Risk — to detect malware, phishing and unwanted software. When a page is flagged, you're alerted immediately — act before visitors see a browser warning.

While the site is clean

How does website malware monitoring work?

Uptimia
scans on schedule
Google Web Risk · daily
Your URL
clean · no threats

Each scan checks your URL against Google Web Risk for all three threat types in a single request — every result, clean or flagged, is logged.

When a scan is flagged

Flagged, then alert

Your URL
SOCIAL_ENGINEERING match
flagged
Uptimia
opens the incident

phishing match at 09:10 → incident opens, alerts go out; the next clean scan closes it

The cadence

How often should you scan for malware?

It depends on how often the site changes and how much traffic is at stake — scan a busy storefront hourly, a static brochure site weekly. Uptimia offers every hour to every seven days, default once a day.

The other reputation list: DNSBLs
Scan intervalBest for
Every 1 hourHigh-traffic sites & active campaigns
Every 6 hoursBusy, frequently-updated sites
Once a dayMost websites — the default
Every 2–3 daysSlow-changing sites
Every 7 daysArchives & rarely-updated pages

Website malware monitoring FAQ

01What is website malware monitoring?+
An automated service that repeatedly checks your website's URL against a threat-intelligence database and alerts you if it's flagged for malware, phishing or unwanted software. Uptimia uses Google's Web Risk database and scans on the schedule you choose — so you find out before your visitors do. It's also called a website virus scanner or virus monitoring.
02How does Uptimia detect malware?+
Each scan sends your URL to Google's Web Risk API and checks three threat types in one request: malware, social engineering (phishing) and unwanted software — the same threat intelligence behind Chrome's Safe Browsing warnings. It's not a DNS blacklist aggregation and not an on-server antivirus scan.
03How often does Uptimia scan my site?+
You choose — from once an hour to once every seven days, default once a day. Uptimia then scans your website for malware automatically on that schedule; it isn't continuous — the fastest cadence is hourly.
04Does Uptimia remove malware from my site?+
No. Uptimia detects and alerts — it doesn't clean the infection or patch your CMS. You (or your host) remove the malware; the next clean scan closes the incident automatically, with a recovery notice unless you've turned those off.
05Does it scan my whole website?+
Each monitor watches one URL, not a whole-site crawl. To cover several pages or subdomains, add a monitor per URL — all sharing the same contacts, groups and dashboard.
06How will I be alerted if my site is infected?+
The website-hacked alert arrives through the same 12 channels as the rest of your monitoring: email, SMS, Slack, Microsoft Teams, Discord, Mattermost, Telegram, WhatsApp, PagerDuty, Twilio, webhooks and Atlassian Statuspage. You set how long Uptimia holds the alert before paging — up to 30 minutes, default 5.
07What happens when my site is clean again?+
The first clean scan after an infection automatically resolves the incident, and Uptimia sends a recovery notice to the same channels (on by default) — no re-checking by hand.
08Do I need to install anything?+
No. There's no agent, plugin or extension — nothing goes on your server, CMS or visitors' devices. A monitor takes a name and a URL; scans run externally against Google Web Risk.
09Is this the same as blacklist monitoring?+
No. Malware monitoring checks your URL against Google Web Risk for malware, phishing and unwanted software. Blacklist monitoring watches whether your domain or mail-server IPs land on DNS blacklists (DNSBLs) that hurt email deliverability. For a one-off look, the free Blacklist Checker tests 23 DNSBLs plus Google Safe Browsing.
10Can Uptimia get my site removed from Google's warning screen?+
No. Clearing a Safe Browsing warning is Google's process, handled after you've removed the malware and requested a review. Uptimia's job is to tell you the moment your site is flagged, and confirm when it scans clean again.
11If I scan weekly, do I wait a week for the all-clear?+
No. Once a monitor is in an incident it re-scans every hour, whatever cadence you set for normal operation. A site you scan weekly is re-checked hourly from the moment it's flagged, so the incident closes within the hour of your fix — then the monitor drops back to its weekly schedule.
12Which plans include malware monitoring?+
Every paid plan — it ships alongside uptime, SSL, DNS and transaction monitoring, never as a paid add-on, and plans differ only in how many URLs you can watch (from 1 on Basic up to 100). The free 30-day trial includes it in full (50 monitors, no credit card); after the trial, malware monitors pause until you're on a plan that includes them, while free-plan uptime monitoring keeps running.

Know before your visitors do.

Enter a URL — and be the first to know if malware, phishing or unwanted software lands on your site.

30-day free trial No credit card Nothing to install EU-hosted, GDPR-ready
Malware monitoring lives in the same account as your uptime, SSL and speed monitors — one login, one dashboard.