The scan runs on your server, read-only. It writes nothing, moves nothing, deletes nothing. In the end, it tells you whether the site is infected, and keeps you a report — whether you buy anything or not.
How it goes
analyse.php and kshield-analyse.zip, at the root of your site. Nothing to unzip: it is the only technical step.Why a sign-up
Because a detection tool handed out without any control also serves those who write backdoors: they would test their own code on it until it slips through the net. The validation code is sent to a real address, and the number of scans is limited.
It is also why the report names the dangerous files and says what they do, but never how they were spotted.