| 开发者 | adnanali32038 |
|---|---|
| 更新时间 | 2026年9月30日 18:29 |
| PHP版本: | 7.2 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
db.php /
advanced-cache.php drop-ins, vapor-* / host-*-bridge mu-plugins, injected
theme functions.php, sc_* options and cron). Deleting a legitimate file is
worse than the malware, so three gates must all pass before anything is removed:
/uploads,
the wp-content/cache staging copy, filenames it is known to plant, and any
file in wp-includes/wp-admin/the web root that the official WordPress
checksum manifest says WordPress does not ship.
A file that IS part of a real plugin, theme or WordPress itself is never
deleted — it is reported instead, because an infected real file needs
reinstalling, not erasing. wp-config.php is never deleted under any
circumstance.functions.php is never modified or deleted: it is reported, so you can
reinstall a clean copy of the theme.
Developers can force report-only behaviour for any path with the
wpss_malware_auto_removable and wpss_malware_protected_paths filters.
Database Audit — the things a file scanner cannot see
A file scanner is blind to a compromise that never writes a file, and that is
not a hypothetical: an SEO-cloaking campaign ran for four months across eight
sites on one hosting account while hourly scans reported clean, because its code
lived in a plugin's database table, its configuration in an option, its spam in
wp_posts, and its administrators were inserted straight into wp_users.
The audit runs alongside the file scan and asks three questions that have exact
answers:
md5(sha1($host)), so the name is different on every
site and no blocklist can list it — but the same name can be computed here and
looked up. There is no false-positive surface at all. Autoloaded 32-hex option
names in general are raised as a warning.WP_User::add_role() assigns a boolean, so WordPress only ever writes
s:13:"administrator";b:1. A row built by hand in SQL writes a string
instead. That single difference found four rogue administrators across those
eight sites and produced no false positives. Duplicate user_login values are
treated the same way — WordPress will not create one.stillward-security folder to /wp-content/plugins/, or install
the ZIP via Plugins → Add New → Upload Plugin.That is the one thing it is built not to do. Only non-breaking hardening is on after activation. Every feature that can change how your site behaves -- the request firewall, Content-Security-Policy, HSTS, the strict MIME whitelist, the custom login URL and XML-RPC blocking -- is off until you turn it on yourself.
Three gates must all pass before anything is removed:
No. It never edits, strips or re-encodes a submitted request. It runs in log-only mode by default and blocks only if you switch it to Block mode.
Only if nothing depends on it. Leave it enabled if you use Jetpack, the WordPress mobile app, or any service that publishes to your site remotely.
One, and only WordPress.org's own API. When the Malware Shield inspects a file in wp-includes, wp-admin or the web root, it asks WordPress's built-in get_core_checksums() for the official checksum manifest of your WordPress version, so it can tell a file WordPress genuinely ships from one an attacker planted. That request goes to api.wordpress.org -- the same endpoint WordPress itself uses for updates -- and carries only your WordPress version number and locale. Nothing about your site, its content or its users is sent. The manifest is cached, and if the request fails the scanner simply reports those files instead of judging them. There is no telemetry, no analytics, no third-party service and no registration. Everything else the plugin records stays in your own database.
Uninstall removes its options, its log and quarantine tables and its scheduled tasks, on every site in a multisite network. Accounts you demoted through the account scanner are deliberately left as they are -- silently restoring an administrator during an uninstall would be dangerous.
s:13:"administrator";b:1. Every
account created by SQL injection on those eight sites wrote a string there
instead, because the row was built by hand. That one difference found four
rogue administrators and zero false positives. Duplicated user_login values —
which WordPress refuses to create — are treated the same way. Softer signals
(no e-mail address, a registration date that contradicts the account's own ID,
never used at all) are reported together as a warning rather than separately
as noise..claude/
configuration. Dot-files and dot-directories are now excluded from the build.sc_% prefix.