Direct plugin download · no signup
Inspect WordPress files without sending them to this portfolio
The scanner runs inside WordPress and helps identify suspicious file patterns for review. It is a diagnostic aid, cannot confirm that a site is clean, and is not a substitute for a secure backup.
Back up the site and database before installing security or cleanup software. Review findings carefully; suspicious code patterns can also appear in legitimate plugins or custom work.
Use responsibly
A scanner narrows the investigation.
It should produce a review queue, not an automatic instruction to delete files.
- 01Create a recoverable backup
Confirm that files and the database can be restored before any cleanup begins.
- 02Run the scan locally
Keep the evidence on the WordPress installation rather than uploading site files here.
- 03Review context
Compare flagged code with plugin sources, recent changes, and server logs where available.
- 04Repair and harden
Replace compromised files safely, update access, close the entry point, and monitor recurrence.