A monitoring report is a comprehensive document that provides an overview of all changes made to files on your server or in a user's browser. This guide will help you understand each section of the report so you can identify potential security risks and take the right action — even if you're not a technical expert.
What Is a Monitoring Report and Why Does It Matter?
Think of a monitoring report like a security camera log for your website. Just as a security camera records who enters and exits a building, a monitoring report tracks every file that was added, changed, or deleted on your website's server.
Your website is made up of thousands of files — code files, images, stylesheets, and more. When everything is working normally, these files rarely change on their own. But when a hacker gains access or malware infects your site, files start appearing, disappearing, or getting modified without your knowledge. That's exactly what a monitoring report helps you catch.
The report is divided into three primary sections: New Files, Changed Files, and Deleted Files. Each section tells you something different about what happened on your server. Understanding these sections can help you identify potential security risks and take appropriate action — whether that's ignoring a harmless change or calling in experts for immediate malware removal.
Understanding Risk Levels
Before diving into the report sections, it's important to understand the two risk levels you'll see. Every file change in your report is classified as either high-risk or low-risk based on the type of file involved.
High-Risk Changes
Requires Attention
High-risk changes refer to modifications made to files that can be executed on the server or in a user's browser. In simple terms, these are the "brain" files of your website — they contain actual code that tells your website what to do. If a hacker modifies these files, they can make your website do harmful things like steal visitor data, redirect to malicious sites, or send spam.
These files often have extensions such as *.php, *.phtml, *.js, among others. Any unauthorized changes to these files could potentially harm your server, website, or users. When you see high-risk changes in your report, always review them carefully.
File types to watch:.php.phtml.js.html.htaccess — these files contain executable code. If they changed and you didn't make the change, investigate immediately.
Low-Risk Changes
Usually Safe
Low-risk changes, on the other hand, refer to modifications made to files that pose little to no harm to the server, website, or users. These are the "visual" and "data" files — images you upload, design stylesheets, text files, and similar content. Even if someone modifies an image file, it cannot execute harmful code on your server.
These files typically include *.jpg, *.png, *.css, *.txt, and others. In most cases, changes to these files are a result of normal website activity — uploading new images, updating your site's design, or writing new content.
File types generally safe:.jpg.png.gif.css.txt.svg.woff — these are non-executable files. Changes here are usually harmless.
New Files Section
This section lists files that were added to your server since the last scan. New files can appear for perfectly normal reasons — you installed a plugin, uploaded a photo, or your cache system generated temporary files. But new files can also appear because a hacker uploaded malicious scripts. Here's how to tell the difference:
If your report indicates high-risk files in the New Files section, don't panic. Instead, review the files in detail. Here are the most common scenarios:
Safe — Cache files: Files in cache folders with long random filenames, such as /c203d8a151612acf12457e4d67635a95.php or /wp-cache-c203d8a151612acf12457e4d67635a95.php, can be safely ignored. These are automatically generated by your website's cache plugin to make your site load faster. They have long, random names because the system creates them automatically — this is completely normal behavior.
Dangerous — Suspicious filenames: If you see files like dir.php, xml56.php, adminer.php, shell.php, up.php, or similar short, generic names, you should be concerned. These are very likely virus files (also called backdoors or webshells) planted by attackers. They need to be analyzed and removed from the server immediately. Do not open or execute these files — contact our malware removal team instead.
Investigate — New files in plugin folders: New files appearing in folders like /wp-content/plugins/, /components/, /plugins/, etc. — and you didn't install any new plugins or update existing ones — could indicate that a hacker has access to your admin area. This is a serious security concern. These files need to be reviewed by a professional. If you're not sure whether you made the change, it's better to have our experts check.
Dangerous — Mass fake pages: A large number of *.html or *.php files appearing in strange or unfamiliar folders (not part of your CMS) could suggest that someone has uploaded fake pages (also known as SEO spam or doorway pages). Hackers use these to exploit your website's reputation for their own benefit — for example, to promote illegal products or redirect your visitors. These files should be removed immediately, and your website should be scanned for additional infections.
Safe — Upload folder images: If you see low-risk files (images, documents) in folders like /upload/, /tmp/, /media/, etc., you can safely ignore this alert. It's very likely that you or your team simply uploaded images or other non-threatening files through your CMS admin panel.
Changed Files Section
This section shows files that already existed on your server but have been modified since the last scan. File changes are a normal part of running a website — you edit content, update plugins, adjust settings. However, unexpected changes to executable files can indicate a security breach.
If your report shows high-risk files in the Changed Files section, you need to examine what changes were made. Here's what to look for:
Investigate — Theme / template file changes: If you notice changes in template or theme files (like header.php, footer.php, functions.php) and you didn't edit your theme files, this could be a cause for concern. Hackers and malware often inject malicious code into theme files because they run on every page of your site. These changes need to be analyzed and any malicious code must be removed. This type of attack is especially common in WordPress, Joomla, and other popular CMS platforms.
Safe — Plugin or CMS updates: If you recently updated a plugin, theme, or your CMS itself (WordPress, Joomla, Magento, etc.) and received this alert, it's perfectly fine. When you update software, many files get replaced with newer versions — this is a normal and expected part of the update process. You can safely ignore these changes.
Helpful tip: A simple rule of thumb — ask yourself: "Did I (or my developer) make any changes recently?" If the answer is yes, the changes are likely normal. If the answer is no, then the changes may have been made by an attacker and should be investigated. When in doubt, always contact our team.
Deleted Files Section
This section shows which files have been removed from the server since the last scan. While viruses and malware typically don't remove files (they usually add or modify them instead), deleted files can still be a sign of unusual activity.
Files may be deleted for normal reasons — you uninstalled a plugin, removed old images, or your cache system cleaned up expired files. However, in rare cases, an attacker may delete important files to disrupt your website's functionality (for example, deleting a configuration file to make your site crash).
Rule of thumb: If you didn't delete any files yourself and you see unexpected deletions — especially of core CMS files or configuration files — this is unusual and should be analyzed. Report it to us so our team can investigate and ensure your website's integrity is intact.
Quick Reference: What to Do
A simple summary to help you decide what action to take when you see changes in your monitoring report.
You Can Ignore It If…
You recently updated a plugin, theme, or CMS
New files are in cache folders with long random names
Images or media files appeared in upload folders
You or your developer made changes recently
Only low-risk file types were affected (.jpg, .png, .css)
Contact Us Immediately If…
Unknown .php or .js files appeared with short names
Theme files changed but you didn't edit them
New files in plugin folders without your action
Many .html pages in unfamiliar folders (SEO spam)
Core CMS files were deleted unexpectedly
For Subscription Customers
Standard, Premium & Business Subscribers
For users with a Standard, Premium, or Business security subscription, our team analyzes all changes in real-time and fixes any issues if necessary. Therefore, no action is required on your part — our security experts handle everything automatically as part of your enterprise website security package.
You'll receive a monitoring report for your records and transparency. If we detect anything suspicious, we'll fix it proactively and notify you. You can focus on running your business while we take care of your website's advanced web protection.
Common questions about monitoring reports and website security.
How often is a monitoring report generated?
The frequency depends on your security plan. SiteGuarding's monitoring service scans your website files regularly — from daily to real-time, depending on your subscription level. Each scan generates a new report comparing the current state of your files to the previous scan.
I see changes in my report but I didn't do anything. Should I worry?
Not always. Some changes happen automatically — cache files, log updates, scheduled tasks, and automatic CMS updates. However, if you see high-risk files (like .php or .js) that you didn't create or modify, it's best to have them reviewed. Contact our team and we'll analyze the files for you.
What should I do if I find malware in my report?
Don't try to fix it yourself unless you're an experienced developer. Incorrectly deleting files can break your website. Instead, contact SiteGuarding's malware removal team. We'll safely remove the malware, clean up any backdoors, and harden your website against future attacks. If you have an active subscription, our team will handle it automatically.
Can I get alerts on my phone when changes are detected?
Yes! SiteGuarding supports notifications via email and Telegram. You can set up a Telegram bot to receive instant alerts whenever your monitoring report detects suspicious activity. Check our Telegram bot setup guide for step-by-step instructions.
Do I need to do anything if I have a Premium or Business subscription?
No action is required on your part. Our security team monitors all file changes in real-time and handles any issues automatically. The report is sent to you for transparency so you always know what's happening on your server. You can relax knowing your website is under continuous professional security monitoring.
If you received a monitoring report and aren't sure what the changes mean, don't worry — our security experts are here to help. Send us the report and we'll analyze it for free.
Our website uses cookies, which help us to improve our site and enables us to deliver the best possible service and customer experience. See our policyAccept