The engine looks at path, extension, and a short content sniff. If a file under uploads looks like PHP, the report gets php_in_uploads. Weight is high because that location is for media.
Nothing is deleted. A later quarantine job can copy, verify SHA-256, and remove, but only with Apply. Hardening can then stop PHP from being served there.
Related: detection landing, removal.