Linux 软件免费装
Banner图

DevDome Malware Scanner - WordPress Malware Removal & Security Scanner

开发者 devdome
更新时间 2026年10月1日 20:37
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

malware scanner malware removal security scanner vulnerability scanner malware scan

下载

1.3.0 1.3.1 1.3.2 1.0.2 1.0.3 1.1.0 1.2.0 1.2.2 1.3.5 1.2.1 1.3.4 1.3.7 1.3.8 1.3.9

详情介绍:

DevDome Malware Scanner is a WordPress virus scanner that checks files and database content for malicious code, backdoor and webshell patterns, and suspicious changes. Use it as a hack scanner to investigate signs of compromise, with malware detection findings that show affected items and supporting evidence. For malware removal, the malware cleaner offers quarantine and official package repair for eligible file findings. Review the proposed actions, restore quarantined files when needed, and repair eligible WordPress core and WordPress.org plugin packages from your dashboard. Suspicious database content and configuration changes require your review. Scanning and cleanup work without an account, including file integrity checks against official copies and a baseline for premium or custom code. The optional vulnerability scanner compares installed WordPress, plugin and theme versions with published WPVulnerability records and is off by default. An optional DevDome account adds known-malware hash checks against 90,000+ signatures, signature updates and cloud reports. DevDome Malware Scanner checks WordPress files and database content for malicious code, backdoors and suspicious changes. Review the evidence, quarantine eligible infected files and repair eligible WordPress core and official plugin packages from your dashboard. Scanning and cleanup work without an account; an optional DevDome account adds known-malware hash checks against 90,000+ signatures, signature updates and cloud reports. A security scan of WordPress files and data Use the security scanner for a manual security check or scheduled malware scan. It checks: The database scan covers options, posts, revisions, post metadata and user metadata. PHP analysis follows code behavior, including request input reaching execution and downloaded content being written to disk. These anti malware checks support a website security review by showing affected files, evidence and areas that could not be checked. Optional vulnerability scanner The optional vulnerability check compares installed WordPress, plugin and theme versions with WPVulnerability records for known vulnerabilities. Enable it in Settings; it is off by default. This is a version check against published records. It does not test the site by attempting an exploit. Malware detection and findings you can review The malware checker reports severity and confidence separately: A changed file or newly added administrator needs investigation but does not prove an infection. Low and Info findings are review notes. Each finding shows the affected item, why it was flagged and supporting evidence. For modified core and WordPress.org plugin files, "View what changed" compares the file with the official copy. Coverage gaps identify checks that were skipped, failed or only partly completed. These include excluded paths, unreadable files, size limits and unavailable official checksums. An unchecked area is never treated as verified clean. Use the findings and coverage notes as evidence for a WordPress security audit. File integrity and official repair WordPress core and WordPress.org plugin files are verified against official WordPress.org checksums. WordPress.org themes are compared with the official package for the installed version. Premium and custom plugins and themes are tracked against a file baseline. The first scan records the starting state; later scans show changes. The baseline records what was present, not whether it was safe. For eligible core and plugin findings, repair uses the WordPress updater to reinstall the same installed version from the official WordPress.org package. It replaces the whole package, not just the flagged file. Before reinstalling, repair stores backup copies in quarantine. Afterwards it checks the resulting package against official checksums. If the reinstall fails, it attempts to restore those backups and reports any remaining recovery work. Repair backups can also be restored from the Quarantine tab. Malware removal and reversible quarantine The malware cleaner offers "One click fix" for eligible file findings through quarantine or official package repair. Eligible findings can include known malware, suspicious executable files in uploads and modified core or plugin files. Findings requiring review remain under "Needs your decision". These include suspicious database content, configuration changes, administrator accounts and scheduled tasks. Available actions depend on the finding and the current file. Quarantine removes a file from disk and keeps a compressed copy in the plugin's database table. If compression is unavailable, it stores an uncompressed copy. Each record includes the original path, hash, size and permissions. After using these tools to remove malware, review the cleanup results and scan again to check what remains. Hack cleanup and reinfection risks After a hack, removing an infected file may leave behind accounts, tasks or files that allow malware to return. The Reinfection risks tab brings together administrator, scheduled-task, must-use plugin and drop-in findings for review. Where available, "Neutralize" lets you: Account roles can be restored under Users. Quarantined files can be restored from Quarantine. Removed scheduled tasks cannot be restored through the plugin. New administrators and other unexpected additions need your review. Legitimate plugins can also create scheduled tasks, must-use plugins and drop-ins. Scheduled scans and scan controls Run a scan manually or choose daily or weekly scheduled scans for recurring antimalware checks. Automatic scans are scheduled around 02:00 site time and depend on WordPress cron running. Scans run in short batches. The open admin page drives progress, with a WP-Cron fallback after you close the tab. You can pause, resume or cancel a scan. Settings let you adjust batch duration, deep-scan file size limits and excluded paths. Reduced coverage is reported with the results. Works without an account Without a DevDome account, you can run file integrity, PHP, uploads, configuration, database, user and scheduled-task checks. Quarantine, eligible official repairs and local scan history are also available. Official verification still contacts WordPress.org. DevDome's known-malware hash lookup requires a connected account. Anonymous detection telemetry is optional and off by default. Reports sent through the reporting buttons are separate actions. The External services section explains what each service receives. Optional DevDome account Connecting an account adds: "Enhanced analysis" is a separate opt-in. It sends short suspicious code fragments and a file-path hint for a second opinion. The plugin attempts to redact secrets before sending them, but redaction cannot cover every secret format. Disconnecting stops hash lookups and signature updates. Previously downloaded byte-pattern signatures can still match locally. Dashboard and multisite Simple view shows the verdict, cleanup options and settings. Advanced view adds finding filters, bulk actions, file changes, reinfection risks, quarantine and scan history. On multisite, the scanner requires network administrator access because file checks and cleanup can affect shared core and plugin files. Each site keeps its own scan data. WordPress Abilities and MCP On WordPress 6.9 and newer, WordPress Abilities let compatible AI agents read WordPress security findings, control scans, manage settings and use cleanup actions. MCP clients can access these abilities when the site exposes them through an adapter such as the WordPress MCP Adapter. Abilities use the same permission checks and action rules as the dashboard. Quarantine, repair, neutralization, restore and permanent deletion require an explicit confirmation flag from the agent.

安装:

  1. Upload the plugin and activate it.
  2. Open Malware Scanner in the admin menu and press Scan Now.
  3. The first scan verifies integrity and seeds the file baseline; later scans add the change timeline.
  4. Uninstalling removes the plugin's tables, settings and scheduled tasks, including the quarantine table. Restore or delete quarantined files before uninstalling if you still need them.

屏幕截图:

  • Malware and Backdoor Findings: review suspicious files, malicious code and the evidence behind each finding.
  • File Changes: track created, modified, quarantined and repaired WordPress files over time.
  • Reinfection Risks: find rogue admins, malicious cron jobs, must-use plugins and drop-ins.
  • Malware Quarantine: safely quarantine suspicious files and restore them when needed.
  • Scan History: review previous malware scans and detected threats.
  • Settings: optional DevDome account features, vulnerability check, scan limits and excluded paths.

常见问题:

Does the plugin delete files?

Quarantine removes the file from disk and keeps a non-executable copy in the plugin's database table, compressed when compression is available. You can restore it from the Quarantine tab at any time. Permanent deletion requires the explicit Delete permanently button on a quarantined file. Uninstalling removes the plugin's tables, settings and scheduled tasks, including the quarantine table. Restore or delete quarantined files first if you still need them.

Do I need a DevDome account?

No. Every scanning engine runs on your own server: core, plugin and theme integrity, code analysis, uploads, configuration files, users, cron, database and persistence. Connecting a free account adds the 90,000+ known-malware signatures, the security dashboard and the alert email. Without an account, the signature set is never downloaded, so there is no known-malware signature matching. The scanner relies on its heuristics and reports that in the coverage notes. If you connect and later disconnect, byte-pattern signatures already on the site keep matching, but updates and the file hash check stop.

Can a cleanup break my site?

Cleanup has safeguards to reduce that risk. Files WordPress cannot boot without are never quarantined. A repair reinstalls the whole package, either all of WordPress core or the whole plugin, through the WordPress updater and verifies it against official checksums afterwards. The flagged file and every other file the reinstall would change are copied to quarantine first. If the reinstall fails, repair attempts to put the originals back and reports any remaining recovery work. Theme files, database content, user accounts, cron tasks and configuration files are never changed automatically, with one exception: a theme file matching a known-malware signature is quarantined. Anything quarantined can be restored with one click from the Quarantine tab.

Why does the scan list coverage gaps?

Unscanned areas cannot be called clean. The Overview lists excluded paths, files above the deep scan size limit, unreachable checksum sources, files the previous scan could not finish and stages that failed. Findings on files that could not be rechecked stay open instead of being resolved.

Does a scan slow down my site?

Scans run in short batches while the admin page is open and continue through WP-Cron when it is closed. The default is 8 seconds per request, adjustable from 3 to 25 in Settings. You can pause or cancel at any time. Scanning uses PHP time on your server. Lower the batch budget on very constrained shared hosting.

What is the difference between severity and confidence?

Severity is potential impact: Critical, High, Medium, Low or Info. Confidence is how likely the finding is malicious. A known-signature match has 100% confidence. A high-entropy blob alone is only a contributing signal and is never called malware by itself. Low and Info rows are notes, not threats, and never trigger an alert.

Is my website hacked?

Run a scan and review its evidence and coverage gaps. The plugin checks for changed files, suspicious PHP, database injections and unexpected administrators or scheduled tasks. A changed file or new administrator alone does not prove the site was hacked. Review eligible cleanup actions, then scan again. The Reinfection risks tab helps you investigate access or files that may remain after cleanup.

How do I run a WordPress virus scan?

Open Malware Scanner in the admin menu and press Scan Now. The virus scanner checks WordPress files and database content using integrity checks and code analysis, with known-malware matching available through the optional account. For virus removal from eligible site files, review the proposed quarantine or official repair action. This scans your WordPress installation; it does not provide continuous protection for your computer or automatically clean every finding.

Can it help with a pharma hack, Japanese keyword hack or SEO spam?

Its database checks look for injected scripts, hidden iframes, spam and hidden links in options, posts, revisions, post metadata and user metadata. These checks can help investigate a pharma hack, Japanese keyword hack or other SEO spam where the infection leaves those patterns. Suspicious database content needs your review. The plugin does not automatically rewrite affected posts or remove search engine listings.

Can it find a redirect hack or malicious redirects?

The scanner checks PHP, database content, wp-config.php, .htaccess and .user.ini for suspicious code or settings that may be involved in a redirect hack. Review the evidence to investigate malicious redirects. Configuration and database findings require a decision. These checks do not guarantee detection of every redirect mechanism.

Can I use it as an exploit scanner?

You can use it to inspect WordPress files for suspicious execution, obfuscated code, backdoor and webshell patterns, and other evidence of compromise. Its optional vulnerability check also compares installed versions with published records. Its exploit scanner role is limited to code inspection and version checks. It does not attempt attacks or provide a penetration test.

Can it detect a PHP trojan hidden in a plugin or upload?

It checks for suspicious PHP behavior, hidden code, executable uploads and PHP disguised as images or documents. These checks can identify behavior associated with a PHP trojan, but detection depends on the code and scan coverage. Official file comparisons help identify modified packages. Premium and custom code is tracked against a baseline, which records changes without proving that the original files were safe.

更新日志:

1.3.9 1.3.8 1.3.7 1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.2 1.2.1 1.2.0 1.1.0 1.0.3 1.0.2 1.0.1 1.0.0