1. Malware is “injected” into the code.
  2. Going by just one result is hazardous at best.

We use a multitude of scanners/reports to get “the whole” picture.
Myself I have almost two dozen “primary scanners” in my arsenal. Each one scans for different issues.