Extensions
Scanning Joomla PHP files for malware and backdoors
Scan Malware is a paid Joomla extension from JoomSAFE that checks PHP files for code associated with malware, web shells and backdoors.
Malware checks become relevant when a Joomla site has been hacked, inherits an uncertain deployment, or needs a way to investigate unexplained redirects, resource use or unauthorised access. Joomla core provides updates, user and permission management, and the normal tools for maintaining the CMS; it does not include a general-purpose scanner that inspects installed PHP files for malicious code. A template override is also the wrong tool for this job: overrides change output, not server-side file contents.
Site owners commonly use host-level malware scanning, inspect files manually, restore from a known-clean backup, or install a security extension. According to the listing, Scan Malware goes beyond Joomla core by examining PHP files for suspicious patterns and threats associated with infected Joomla installations. The page does not explain its detection method, whether it can quarantine or remove files, or how it handles false positives.
This is aimed at administrators, agencies and incident-response teams responsible for Joomla sites where file integrity needs checking. A small, newly deployed site with trusted hosting scans and a clean, controlled deployment may have little reason to add it.
The Directory lists it in Scan Malware under Access & Security as a paid download, licensed GPLv2 or later. It says Joomla 4, 5 and 6 are supported, but gives no price. The listing shows no reviews and provides no broader developer track record beyond the JoomSAFE name. Before buying, check scan coverage, cleanup and quarantine features, resource use, exclusions, update and support terms, backup requirements, and the handling of false positives. The page mentions the Joomla Update System, a demo and documentation, but does not provide enough detail here to assess them.
Listed on the Joomla Extensions Directory.