Mastodon Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

One Security Vendor Flagging Your Website on VirusTotal: What to Do

VirusTotal displays contributor verdicts; it does not own every detection. Learn how to identify the contributor, verify the exact URL, and request the right review.

You scan a website on VirusTotal. Most results are clean, but one security vendor marks it malicious, suspicious, phishing, or malware. A minority verdict can be wrong, stale, or the only product noticing a real problem. The first job is to identify who owns the verdict and test the exact evidence behind it.

VirusTotal is an aggregator, not one antivirus verdict

VirusTotal submits URLs to many security products and blocklists and displays the returned results. Its official contributor documentation explains that false-positive decisions belong to the contributor that produced the verdict.

VirusTotal normally cannot override a result from ESET, Fortinet, Quttera, CRDF, URLhaus, OpenPhish, or another named contributor. The contributing company or project must change its own classification, after which the updated result can propagate to VirusTotal.

Do not use the number of clean results as proof

“One out of many” is not a diagnosis. Vendors use different data, crawl schedules, URL normalization, reputation history, and behavioral models. One engine may inspect a path or signal the others do not. Conversely, one vendor can retain an old or incorrect verdict after the website is clean.

Step 1: save the exact result

Record the submitted URL, scan date, named contributor, verdict text, and details link. Check whether you submitted the canonical HTTPS URL, a redirected HTTP URL, a deep path, a subdomain, or only the homepage. These are not interchangeable.

Step 2: find the contributor’s scope and official route

Open the contributor’s record in the website reputation vendor directory. The directory separates consumer antivirus, phishing feeds, malware URL feeds, website scanners, and enterprise filters. It provides an official lookup or review route where one has been verified and clearly labels systems with no public route.

Step 3: verify the reported URL independently

Investigate more than the visible page. For WordPress, review modified files, database injections, unknown users, scheduled events, active plugins and themes, redirect rules, uploads, cached output, vulnerable components, and third-party scripts. Test from clean sessions and follow every redirect.

If the website had a real incident, describe the verdict as stale after cleanup rather than automatically calling it a false positive. Accurate wording makes a review easier to evaluate.

Step 4: contact the verdict owner

Use the contributor’s official form, support channel, forum, or documented dispute method. A useful request includes:

  • the exact URL and current verdict;
  • the date you verified it;
  • whether a real compromise was found;
  • the corrective work completed;
  • relevant clean behavior or investigation evidence;
  • a request to re-evaluate the contributor’s own classification.

Avoid promising that the site is “100% clean,” accusing the vendor, or sending unrelated screenshots from other scanners as if they overrule the contributor.

Step 5: wait for the owner before judging propagation

After the contributor changes its verdict, VirusTotal and downstream products may update on different schedules. A fresh scan can help confirm propagation, but repeatedly rescanning before the owner changes its database does not resolve the root record.

Special cases

No public false-positive route

Some feeds expose no direct public review workflow. Use the project’s documented contact or support channel if one exists. Do not copy unverified email addresses from old third-party lists.

The contributor name is unfamiliar

VirusTotal’s official URL/domain engine list includes many intelligence projects that are not consumer antivirus brands. The directory includes those contributors as reference records without pretending each has a removal service.

The verdict returns after removal

A returning detection can indicate reinfection, a URL that was missed, a compromised external dependency, or a new reputation signal. Repeat the investigation before filing the same request again.

Get evidence-led WordPress reputation recovery

If you cannot identify the flagged URL, suspect a prior compromise, or need help documenting cleanup, see the WordPress antivirus and blacklist removal service. 3Zero Digital can investigate and submit through the appropriate official route, but cannot guarantee a third-party vendor decision or timetable.

Primary references: VirusTotal API overview, VirusTotal contributors, and VirusTotal URL/domain engine list.

Start with evidence

Give your website a calmer next chapter.

Share the symptoms, warnings, or maintenance concerns. You will receive a focused assessment and a clear recommended next step.

Request a Website Assessment