One thing i forgot i add, try to avoid nulled versions of themes and plugins because the chance of malware and hacking sgets increases. As i had the website regarding <website> services and i was using nulled versions of important plugins. because the plugins were necessary. But it got hacked...
Yes, it's possible to check the integrity of Word Press and the malware infection. And cPanel Word Press toolkit automatically checks it. But sometimes it can create a false match because of not verifying and working by the word press Api. And it can be happened when your word press Api is...