Cleverhog Malware Scanner

Cleverhog Malware Scanner

توسط

Cleverhog Malware Scanner helps you investigate a suspicious or compromised WordPress site from the admin dashboard. It is free and may be used on unlimited websites with no license keys or per-site fees.

This plugin detects and reports potential security issues. It does not automatically remove malware or guarantee that a site is clean. Always back up your site before changing or deleting files.

What it scans

  • Files — Pattern-based scan of themes, plugins, uploads, wp-content, or the full site (with code snippets, file size, and last-modified date)
  • Backdoors — Must-use plugins, drop-ins, wp-config, cron jobs, and suspicious hooks
  • .htaccess — Discovers .htaccess files site-wide and lists suspicious redirects, PHP handlers in uploads, auto_prepend, cloaking rules, and more
  • Authentication — XML-RPC, user enumeration, weak salts, file editor, and SSL-related checks
  • Database — Suspicious autoloaded options and injected post content
  • Administrators — All admin users with registration dates and risk flags
  • Updates — Outdated plugins, themes, and core (medium for major/minor updates, low for patch-only updates)
  • Plugin integrity — WordPress.org plugins compared to official checksums (one summary per plugin)

Features

  • Live threat counter during scans
  • Results sorted by severity (critical, high, medium, low)
  • Last scan results restored when you reopen the dashboard
  • Admin menu badge showing critical issue count
  • Excludes this plugin’s own files from file scans to reduce false positives

Privacy

This plugin runs entirely on your server. Scans do not send your site files to the plugin author.

When you run a scan, the plugin may contact:

  • WordPress.org (downloads.wordpress.org) — to fetch official plugin checksums for integrity verification
  • WordPress.org update APIs — to check for available plugin, theme, and core updates (standard WordPress behavior)

No personal data is collected by the plugin author. Scan results are stored in your WordPress database (options and transients) for display in the admin dashboard and are visible to users who can manage the site.

Support

Support is provided through the WordPress.org support forums after publication.

  1. Install through Plugins Add New after this plugin is on WordPress.org, or upload the cleverhog-malware-scanner folder to /wp-content/plugins/
  2. Activate Cleverhog Malware Scanner
  3. Open Cleverhog Malware Scanner in the admin menu
  4. Choose scan types and click Start Security Scan

سوالات متداول

Does this remove malware automatically?

No. It shows what was found with file paths, snippets, and severity so you can investigate. Restore from backup or use professional help for active breaches.

Can it give false positives?

Yes. Legitimate plugins may use patterns that look suspicious (for example base64_decode). Review every critical finding before deleting files.

Does it scan its own plugin files?

No. The scanner excludes its own directory from file scans.

Will large sites timeout?

File scans run in batches via AJAX to reduce PHP timeout issues.

Which plugins can be checksum-verified?

Only plugins hosted on WordPress.org with published checksums for the installed version. Premium or custom plugins are listed as unverified; use the file malware scan on those.

×
نظری برای این آیتم موجود نیست.
0 0 رای ها
امتیازدهی
اشتراک در
اطلاع از
0 نظرات
قدیمی‌ترین
تازه‌ترین بیشترین رأی
بازخورد (Feedback) های اینلاین
مشاهده همه دیدگاه ها
هیچ نسخه‌ای برای این آیتم موجود نیست.
★★★★★
★★★★★
5.0 /5 (1 نظر)

قیمت:

رایگان

نگارش

آخرین انتشار

21 خرداد 1405

آخرین بروزرسانی

7 روز پیش

نصب های فعال

-

نگارش وردپرس

وردپرس 5.8+

تست شده از نسخه

وردپرس 7.0

نگارش PHP

PHP 7.4+

نسخه ها

0 نسخه