Certego False Positive & Blacklist Removal

Choose the right next step:

Content reviewed July 13, 2026.

By DrGlenn — USA-based WordPress security specialist· 290+ cleanups across 34 countries· Updated June 22, 2026

Is Certego flagging your website or file?

If Certego is flagging your site or a file — often as URL/domain “malicious”/“malware site” verdicts (Certego Quokka feed) — it is either a real infection or a false positive. Here is how to get it cleared.

Step 1 — Confirm it is really a false positive

Do not request removal while malware is still present, or the flag returns. Check first:

If anything turns up, get it fully cleaned first — deleting the visible malware is not enough if a backdoor remains.

Step 2 — Report the false positive to Certego

Certego (Italy) takes re-evaluation requests via its contact form. Submit here: certego.net/en/contatti

  1. Confirm the flagged URL/domain and the “Certego” verdict on VirusTotal.
  2. Submit via certego.net/en/contatti requesting a re-evaluation, with the URL and evidence the site is clean.
  3. Provide ownership proof and remediation details.
  4. Re-scan once their feed updates.

Good to know: Certego contributes URL/domain intelligence to VirusTotal (engine “Certego”, powered by its Quokka platform) — a website/domain scanner, not a file engine. No public FP email; use the contact form.

Step 3 — If it keeps coming back

A detection that returns after you have been cleared almost always means the infection was never fully removed — usually a backdoor in a theme file, a rogue admin user, or malware in the database. That is exactly what I fix, as a USA-based WordPress security specialist who handles the cleanup and the delistings for you.

Get my site cleaned · See how it works · read my client reviews.

Frequently asked questions

How long does Certego take to clear a false positive? Once the site/file is genuinely clean and you have submitted the request, most are resolved within a few days.

It keeps coming back — why? Because the real infection is still there. A full cleanup stops the loop.

More removal guides: Sophos, Palo Alto Networks (WildFire), TEHTRIS (eGambit) · all vendor guides · full report-link directory.

Evidence to include with a Certego review

Save the Certego or linked-service verdict, affected indicator, timestamp and any correlated vendor results. Describe what was inspected and why the indicator is believed to be clean.

  1. Save the exact detection and affected URL or file hash.
  2. Rule out a real infection and document what was checked or cleaned.
  3. Use the current official route shown above and keep the case number.
  4. Retest after the vendor confirms its review.

Return to the full vendor directory · Need cleanup help?