Online FTP scanner didn't find anything - result "clear". I think that "bad code" could be injected to my site using "bad http links" to my site - sql injection vulnerability. Thanks to Piru, who sent me some examples how to inject code to my site, I fixed them. But it seems that some vulnerabilities are not fixed, I will try to check it. But I think that the site "as it is" is safe to use, maybe there is still some sql injection vulnerability using "bad http link", but these links are not part of my site.