| 开发者 | devdome |
|---|---|
| 更新时间 | 2026年10月1日 20:37 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
Quarantine removes the file from disk and keeps a non-executable copy in the plugin's database table, compressed when compression is available. You can restore it from the Quarantine tab at any time. Permanent deletion requires the explicit Delete permanently button on a quarantined file. Uninstalling removes the plugin's tables, settings and scheduled tasks, including the quarantine table. Restore or delete quarantined files first if you still need them.
No. Every scanning engine runs on your own server: core, plugin and theme integrity, code analysis, uploads, configuration files, users, cron, database and persistence. Connecting a free account adds the 90,000+ known-malware signatures, the security dashboard and the alert email. Without an account, the signature set is never downloaded, so there is no known-malware signature matching. The scanner relies on its heuristics and reports that in the coverage notes. If you connect and later disconnect, byte-pattern signatures already on the site keep matching, but updates and the file hash check stop.
Cleanup has safeguards to reduce that risk. Files WordPress cannot boot without are never quarantined. A repair reinstalls the whole package, either all of WordPress core or the whole plugin, through the WordPress updater and verifies it against official checksums afterwards. The flagged file and every other file the reinstall would change are copied to quarantine first. If the reinstall fails, repair attempts to put the originals back and reports any remaining recovery work. Theme files, database content, user accounts, cron tasks and configuration files are never changed automatically, with one exception: a theme file matching a known-malware signature is quarantined. Anything quarantined can be restored with one click from the Quarantine tab.
Unscanned areas cannot be called clean. The Overview lists excluded paths, files above the deep scan size limit, unreachable checksum sources, files the previous scan could not finish and stages that failed. Findings on files that could not be rechecked stay open instead of being resolved.
Scans run in short batches while the admin page is open and continue through WP-Cron when it is closed. The default is 8 seconds per request, adjustable from 3 to 25 in Settings. You can pause or cancel at any time. Scanning uses PHP time on your server. Lower the batch budget on very constrained shared hosting.
Severity is potential impact: Critical, High, Medium, Low or Info. Confidence is how likely the finding is malicious. A known-signature match has 100% confidence. A high-entropy blob alone is only a contributing signal and is never called malware by itself. Low and Info rows are notes, not threats, and never trigger an alert.
Run a scan and review its evidence and coverage gaps. The plugin checks for changed files, suspicious PHP, database injections and unexpected administrators or scheduled tasks. A changed file or new administrator alone does not prove the site was hacked. Review eligible cleanup actions, then scan again. The Reinfection risks tab helps you investigate access or files that may remain after cleanup.
Open Malware Scanner in the admin menu and press Scan Now. The virus scanner checks WordPress files and database content using integrity checks and code analysis, with known-malware matching available through the optional account. For virus removal from eligible site files, review the proposed quarantine or official repair action. This scans your WordPress installation; it does not provide continuous protection for your computer or automatically clean every finding.
Its database checks look for injected scripts, hidden iframes, spam and hidden links in options, posts, revisions, post metadata and user metadata. These checks can help investigate a pharma hack, Japanese keyword hack or other SEO spam where the infection leaves those patterns. Suspicious database content needs your review. The plugin does not automatically rewrite affected posts or remove search engine listings.
The scanner checks PHP, database content, wp-config.php, .htaccess and .user.ini for suspicious code or settings that may be involved in a redirect hack. Review the evidence to investigate malicious redirects. Configuration and database findings require a decision. These checks do not guarantee detection of every redirect mechanism.
You can use it to inspect WordPress files for suspicious execution, obfuscated code, backdoor and webshell patterns, and other evidence of compromise. Its optional vulnerability check also compares installed versions with published records. Its exploit scanner role is limited to code inspection and version checks. It does not attempt attacks or provide a penetration test.
It checks for suspicious PHP behavior, hidden code, executable uploads and PHP disguised as images or documents. These checks can identify behavior associated with a PHP trojan, but detection depends on the code and scan coverage. Official file comparisons help identify modified packages. Premium and custom code is tracked against a baseline, which records changes without proving that the original files were safe.