Linux 软件免费装
Banner图

DevDome Malware Scanner – Virus Scanner & Malware Removal

开发者 devdome
更新时间 2026年9月15日 20:50
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security malware malware scanner backdoor malware removal

下载

1.2.1 1.2.2 1.3.0 1.3.1 1.3.2 1.0.2 1.0.3 1.1.0 1.2.0

详情介绍:

WordPress Malware Scanner & Malware Removal DevDome Malware Scanner is a WordPress malware scanner for detecting malware, backdoors, malicious code, infected files and reinfection risks. Scan WordPress files and database content, quarantine threats, and safely repair trusted files from the dashboard. It combines malware signatures, file integrity checks, code analysis and WordPress-specific security checks to find modified core files, suspicious PHP, database injections, hidden backdoors, rogue administrators, malicious cron jobs and other persistence mechanisms. It does not only find infected files. It also looks for the things that bring the malware back after a cleanup, and it keeps uncertain findings separate from confirmed threats. What It Finds Scan Files and Database The malware scan covers WordPress core, every plugin and theme, the uploads folder, must-use plugins, drop-ins and the configuration files. The database scan looks for script and iframe injections, encoded payloads, SEO spam and hidden links across options, posts, revisions and meta. Administrator accounts are read from the capability values in usermeta, not just role labels, and every WP-Cron event is checked for tasks that can re-download a payload. Every finding says what changed, why it is suspicious, how confident the scanner is, and what to do about it. Every row expands to a detail panel with the facts behind the decision: file size, modified time, plugin and hash for a file; username, email, role and registered date for an account; hook and next run for a scheduled task; the post or option for database content. For a modified core or plugin file, View what changed shows the lines that differ from the official copy. Find Backdoors and Reinfection Risks Removing infected files alone does not clean a site that keeps a rogue admin, a cron beacon or a planted must-use plugin behind. These are tracked on their own Reinfection risks tab with a Neutralize action: an unknown administrator loses its admin rights (the account stays and can be restored under Users), a planted must-use plugin or drop-in moves to quarantine, a suspicious scheduled task is removed. The tab also lists every must-use plugin and drop-in present on the site. A neutralized threat that comes back is reported again as reappeared. Safe Malware Cleanup One click fix closes every back door the plugin can fix safely and reversibly: known malware, executables hidden in uploads, unexpected files in core and high-confidence malicious code are moved to quarantine; modified core and WordPress.org plugin files are repaired by reinstalling the whole package from WordPress.org, with every file that reinstall would change copied to quarantine first. The scan then runs again so the clean verdict is verified, not assumed. A quarantined file is removed from disk and its contents are kept as a compressed, non-executable copy in the plugin's own database table, together with the original path, SHA-256, size and permissions. Nothing executable is ever written anywhere on disk. It can be restored at any time from the Quarantine tab, and the restored file is verified against the recorded hash. Deleting a quarantined file permanently is a separate, explicit action. Threats that need a human stay under Needs your decision with a plain explanation and a link to the right place: theme files (replacing them changes your design), injected database content, new administrator accounts, suspicious cron tasks, configuration files, software with a known security hole. Files WordPress cannot boot without are never moved by the plugin. File Integrity Checking WordPress core files are verified against the official checksums from WordPress.org, including unknown files inside wp-admin and wp-includes. WordPress.org plugins are checked against their official checksums, and WordPress.org themes against the official zip of the installed version: modified, missing and foreign files. Premium and custom plugins and themes are checked against a baseline, with a file change timeline from the second scan on. A modified core or WordPress.org plugin file is repaired by WordPress itself: the WordPress updater reinstalls the same installed version of the whole package (all of WordPress core, or the whole plugin) from WordPress.org, and the result is verified against the official checksum. Because a reinstall touches more than one file, the flagged file is moved to quarantine and every other file the reinstall would overwrite or delete (a file that differs from the official copy, an extra file in the plugin folder) is copied to quarantine first; each can be restored over the official copy from the Quarantine tab. The plugin never writes into core, plugin or theme folders and never edits files surgically; a failed reinstall puts the original back. Severity and Confidence Are Separate Severity is how bad a finding would be (Critical, High, Medium, Low, Info). Confidence is how likely it is malicious. A known-signature match has 100% confidence; a high-entropy blob on its own is only a contributing signal and is never called malware by itself. Low and Info rows are notes, not threats, and never trigger an alert. The Overview shows a protection ring that reflects the worst open finding, the verdict in plain words and how many threats can be fixed with one click. Areas the scan could not fully verify (excluded paths, oversized files, an unreachable checksum source) are listed as coverage gaps and never assumed clean. Scheduled Malware Scans Daily or weekly scans run around 02:00 site time. Scans run in short time-boxed batches (8 seconds by default, adjustable) driven by the open admin page, with a WP-Cron fallback that keeps a scan going after you close the tab. Scans can be paused, resumed and cancelled. One engine failing does not destroy the scan: the failed stage is recorded as a coverage gap and the scan moves on. Works Without a DevDome Account The local scan is complete without an account: integrity checks, code analysis, uploads, configuration, users, cron, database and persistence engines all run on your server. Nothing is sent to DevDome before you connect. A site that never connected runs on its built-in heuristics and says so in the coverage notes. Optional DevDome Account Connecting a free DevDome account adds: Not connected: the file hash check and signature updates stop. Byte-pattern signatures already downloaded to this site keep matching after a disconnect. Advanced Detection Details Simple and Advanced Views The Simple view shows the verdict, the one-click cleanup and Settings. The Advanced view adds Threats with severity filters, search and bulk actions (Quarantine, Replace with official file, Trust this exact content, Ignore, False positive, Reopen), File Changes (last 90 days), Reinfection risks (Neutralize), Quarantine (Restore, Delete permanently, Remove from list) and Scan History. Multisite On a network the scanner is a network administrator tool, because integrity checks, quarantine and repair touch shared core and plugin files. Each site keeps its own scan data; network deactivation clears scheduled scans on every site. AI and Agent Support On WordPress 6.9 and newer, DevDome Malware Scanner registers WordPress Abilities covering the whole plugin: the security verdict with the fix plan, findings with every filter, finding details with evidence, the diff against the official copy, scan start, pause, resume, cancel, progress and history, One click fix, every per-finding action (quarantine, repair, trust, false positive, ignore, acknowledge, reopen, neutralize a rogue administrator, cron task or planted file), restore, delete or forget quarantined copies, the file change and event logs, settings (read and update), the simple or advanced view and the signature download. Compatible AI agents and MCP clients can discover and use these abilities when the site exposes them, for example through the official WordPress MCP Adapter. Every ability runs the same code as the plugin screens under the same administrator capability; a finding action is refused unless it is one the screen offers for that finding, and One click fix, quarantine, repair, neutralize, restore and permanent deletion require an explicit confirm flag from the agent.

安装:

  1. Upload the plugin and activate it.
  2. Open Malware Scanner in the admin menu and press Scan Now.
  3. The first scan verifies integrity and seeds the file baseline; later scans add the change timeline.
  4. Uninstalling removes the plugin's tables, settings and scheduled tasks, including the quarantine table. Restore or delete quarantined files before uninstalling if you still need them.

屏幕截图:

  • Malware and Backdoor Findings: review suspicious files, malicious code and the evidence behind each finding.
  • File Changes: track created, modified, quarantined and repaired WordPress files over time.
  • Reinfection Risks: find rogue admins, malicious cron jobs, must-use plugins and drop-ins.
  • Malware Quarantine: safely quarantine suspicious files and restore them when needed.
  • Scan History: review previous malware scans and detected threats.
  • Settings: optional DevDome account features, vulnerability check, scan limits and excluded paths.

常见问题:

Does the plugin delete files?

No. Threats are moved to quarantine (a compressed, non-executable copy in the plugin's database table; the file itself is removed from disk) and can be restored from the Quarantine tab at any time. The only deletion is the explicit Delete permanently button on a quarantined file. Uninstalling the plugin removes its tables, settings and scheduled tasks, including the quarantine table, so restore or delete quarantined files first if you still need them.

Do I need a DevDome account?

No. Every scanning engine runs on your own server: core, plugin and theme integrity, code analysis, uploads, configuration files, users, cron, database and persistence. Connecting a free account adds the 90,000+ known-malware signatures, the security dashboard and the alert email. Without an account the signature set is never downloaded, so there is no known-malware signature matching; the scanner relies on its heuristics and reports that in the coverage notes. If you connect and later disconnect, the byte-pattern signatures already on this site keep matching, but updates and the file hash check stop.

Can a cleanup break my site?

It is built not to. Files WordPress cannot boot without are never quarantined. A repair reinstalls the whole package (all of WordPress core, or the whole plugin) through the WordPress updater, verified against the official checksum afterwards; the flagged file and every other file the reinstall would change are copied to quarantine first, and if the reinstall fails the original is put back. Theme files, database content, user accounts, cron tasks and configuration files are never changed automatically, with one exception: a theme file that matches a known-malware signature is quarantined (restorable from the Quarantine tab). Anything quarantined can be restored with one click.

Why does the scan list coverage gaps?

Because unscanned is not the same as clean. Excluded paths, files above the deep scan size limit, an unreachable checksum source, a file the previous scan could not finish and a stage that failed are all listed on the Overview, and findings on files that could not be rechecked are kept, not resolved.

Does a scan slow down my site?

Scans run in short batches (8 seconds per request by default, 3 to 25 in Settings) while the admin page is open, and continue through WP-Cron when it is closed. You can pause or cancel at any time. The scan does use PHP time on your server, so lower the batch budget on very constrained shared hosting.

What is the difference between severity and confidence?

Severity is the potential impact (Critical, High, Medium, Low, Info). Confidence is how likely the finding is malicious. A known-signature match has 100% confidence; a high-entropy blob on its own is only a contributing signal and never called malware by itself. Low and Info rows are notes, not threats, and never trigger an alert.

更新日志:

1.3.2 1.3.1 1.3.0 1.2.2 1.2.1 1.2.0 1.1.0 1.0.3 1.0.2 1.0.1 1.0.0