All templates

Automated Sucuri Security Scan Alerts

Every hour, WebRun opens the Sucuri dashboard, checks every monitored site's malware scan result, blocklist status, and firewall activity, archives the full scan report as a file in Google Drive, and posts an immediate Slack alert naming the site and the issue if anything new is found.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Sucuri check malware scans and firewall activity
2 Google Drive archive the scan report
3 Slack alert the team instantly
In short

How do I get alerted the moment Sucuri finds a security issue?

Every hour, WebRun checks Sucuri's malware scan results, blocklist status, and firewall activity for every monitored site. It archives the full scan report to Google Drive and posts an immediate Slack alert naming the site and the exact issue whenever something new turns up, so a security problem gets seen within the hour instead of at the next manual check.

  • A new malware detection reaches the team within the hour, not at the next login
  • Every scan report is archived, giving you a searchable security history
  • The Slack channel stays quiet until there is something real to act on

Built for web agencies · site owners · security operations teams · WordPress administrators

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens my.sucuri.net in a real browser with your saved login - no setup, no API keys.

  2. 1
    Sucuri - check malware scans and firewall activity
    sucuri.net
    WebRun in Sucuri: check malware scans and firewall activity
    WebRun opens Sucuri to check malware scans and firewall activity.
    • Open the Sucuri dashboard and check every monitored site's malware scan result
    • Check blocklist status and firewall block volume for each site
    • Flag anything new since the last check, a fresh detection, a new blocklisting, or an unusual spike in blocked requests

    Done when Every monitored site's scan, blocklist, and firewall status is checked.

  3. 2
    Google Drive - archive the scan report
    drive.google.com
    WebRun in Google Drive: archive the scan report
    WebRun opens Google Drive to archive the scan report.
    • Save the full scan report for each site as a file in the Sucuri folder in Google Drive
    • Name the file with the site and the date so past reports stay easy to find
    • Keep a running archive rather than overwriting the prior report

    Done when This run's scan reports are archived in Google Drive.

  4. 3
    Slack - alert the team instantly
    slack.com
    WebRun in Slack: alert the team instantly
    WebRun opens Slack to alert the team instantly.
    • Post an immediate Slack alert naming the site and exactly what was found
    • Include whether it is a malware detection, a new blocklisting, or a firewall spike
    • Stay quiet when nothing new is found

    Done when Any new finding this run has triggered a Slack alert.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
my.sucuri.net
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Security alert · Slack
OutputWhat each run produces - An immediate Slack alert naming any new security finding, plus an archived scan report per site in Google Drive.
Text + document
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does it clean the malware or remove the blocklisting itself?

No. WebRun only detects and reports. Cleaning infected files and requesting blocklist removal always stays a step your team or Sucuri support performs.

How fast does the team find out about a new detection?

Within the hour it is found, since the Slack alert fires as soon as the scan shows something new rather than waiting for a routine digest.

Does every hourly check post a Slack message?

No. It only posts when something new is found. A clean scan produces no alert, so the channel stays quiet unless there is something to act on.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.