One Security Vendor Flagging Your Website on VirusTotal: What to Do
VirusTotal displays contributor verdicts; it does not own every detection. Learn how to identify the contributor, verify the exact URL, and request the right review.
You scan a website on VirusTotal. Most results are clean, but one security vendor marks it malicious, suspicious, phishing, or malware. A minority verdict can be wrong, stale, or the only product noticing a real problem. The first job is to identify who owns the verdict and test the exact evidence behind it.
VirusTotal is an aggregator, not one antivirus verdict
VirusTotal submits URLs to many security products and blocklists and displays the returned results. Its official contributor documentation explains that false-positive decisions belong to the contributor that produced the verdict.
VirusTotal normally cannot override a result from ESET, Fortinet, Quttera, CRDF, URLhaus, OpenPhish, or another named contributor. The contributing company or project must change its own classification, after which the updated result can propagate to VirusTotal.
Do not use the number of clean results as proof
“One out of many” is not a diagnosis. Vendors use different data, crawl schedules, URL normalization, reputation history, and behavioral models. One engine may inspect a path or signal the others do not. Conversely, one vendor can retain an old or incorrect verdict after the website is clean.
Step 1: save the exact result
Record the submitted URL, scan date, named contributor, verdict text, and details link. Check whether you submitted the canonical HTTPS URL, a redirected HTTP URL, a deep path, a subdomain, or only the homepage. These are not interchangeable.
Step 2: find the contributor’s scope and official route
Open the contributor’s record in the website reputation vendor directory. The directory separates consumer antivirus, phishing feeds, malware URL feeds, website scanners, and enterprise filters. It provides an official lookup or review route where one has been verified and clearly labels systems with no public route.
Step 3: verify the reported URL independently
Investigate more than the visible page. For WordPress, review modified files, database injections, unknown users, scheduled events, active plugins and themes, redirect rules, uploads, cached output, vulnerable components, and third-party scripts. Test from clean sessions and follow every redirect.
If the website had a real incident, describe the verdict as stale after cleanup rather than automatically calling it a false positive. Accurate wording makes a review easier to evaluate.
Step 4: contact the verdict owner
Use the contributor’s official form, support channel, forum, or documented dispute method. A useful request includes:
- the exact URL and current verdict;
- the date you verified it;
- whether a real compromise was found;
- the corrective work completed;
- relevant clean behavior or investigation evidence;
- a request to re-evaluate the contributor’s own classification.
Avoid promising that the site is “100% clean,” accusing the vendor, or sending unrelated screenshots from other scanners as if they overrule the contributor.
Step 5: wait for the owner before judging propagation
After the contributor changes its verdict, VirusTotal and downstream products may update on different schedules. A fresh scan can help confirm propagation, but repeatedly rescanning before the owner changes its database does not resolve the root record.
Special cases
No public false-positive route
Some feeds expose no direct public review workflow. Use the project’s documented contact or support channel if one exists. Do not copy unverified email addresses from old third-party lists.
The contributor name is unfamiliar
VirusTotal’s official URL/domain engine list includes many intelligence projects that are not consumer antivirus brands. The directory includes those contributors as reference records without pretending each has a removal service.
The verdict returns after removal
A returning detection can indicate reinfection, a URL that was missed, a compromised external dependency, or a new reputation signal. Repeat the investigation before filing the same request again.
Get evidence-led WordPress reputation recovery
If you cannot identify the flagged URL, suspect a prior compromise, or need help documenting cleanup, see the WordPress antivirus and blacklist removal service. 3Zero Digital can investigate and submit through the appropriate official route, but cannot guarantee a third-party vendor decision or timetable.
Primary references: VirusTotal API overview, VirusTotal contributors, and VirusTotal URL/domain engine list.