Calvin Akn, a security researcher, published an article looking at WordPress malware scanners. The summary of the article is that malware scanning can be helpful for detecting common malware, but more sophisticated attacks can bypass it and give you a false sense of security. Therefore, you should not rely totally on malware scanning but should have good measures in place for prevention. There are some interesting and clever step by step illustrations of the concepts described in the article.
The research in the article was done in conjunction with GridPane and Thomas J. Raef. Patchstack verified the proof of concepts discussed, as noted in the article.