Loopback, RFC1918, link-local, CGNAT, and URLs with userinfo are refused. You learn whether the HTTP surface looks like WordPress and which headers are missing.
The deep scanner on CLEAN+ walks the install, hashes files, compares checksums, runs a YARA subset, and may read the database. That is the WordPress malware scanner. It needs a connector pull or SSH. It still never executes site PHP.
People search for one phrase and mean both products. The site says which is which so a FREE Scan is not mistaken for a clean bill of the filesystem. See scanner and plans.