Cleverhog Malware Scanner helps you investigate a suspicious or compromised WordPress site from the admin dashboard.
100% free — no paid features
This plugin is totally free. There is no premium version, no “Pro” upgrade, no paid add-ons, no locked features, no license keys, and no per-site fees. Use it on unlimited websites.
Every feature we develop — now and in the future — will be free and available to everyone.
This plugin detects and reports potential security issues. It does not automatically remove malware or guarantee that a site is clean. Always back up your site before changing or deleting files.
What it scans
- Files — Scan of themes, plugins, uploads, wp-content, site-root files, or the full site (with code snippets, file size, and last-modified date). Detects obfuscated backdoors (hex/octal escapes, split strings, strrev/rot13), request-driven code execution, uploader shells, credential stealers, hidden admin creation, search-engine cloaking, known malware families (wp_vcd, lock360, NDSW), PHP hidden in images/icons, malicious
.user.ini files, and JavaScript injections
- Backdoors — Must-use plugins, drop-ins, wp-config, cron jobs, suspicious hooks, and WordPress core integrity (modified core files and unknown files in wp-admin, wp-includes, and the site root, checked against official WordPress.org checksums)
- .htaccess — Discovers
.htaccess files site-wide and lists malicious redirects, search-engine referrer redirects, PHP handlers in uploads, images executed as PHP, lock360-style lockdown rules, auto_prepend, cloaking rules, and more
- Authentication — XML-RPC, user enumeration, weak salts, file editor, and SSL-related checks
- Database — Open registration with a privileged default role, hidden active plugins, PHP payloads stored in options, injected JavaScript in options and posts
- Administrators — All admin users with registration dates and risk flags, including admin accounts hidden from the Users screen
- Updates — Outdated plugins, themes, and core (medium for major/minor updates, low for patch-only updates)
- Plugin integrity — WordPress.org plugins compared to official checksums, including extra files added to otherwise clean plugins
Features
- Live threat counter during scans
- Results sorted by severity (critical, high, medium, low)
- Last scan results restored when you reopen the dashboard
- Admin menu badge showing critical issue count
- Excludes this plugin’s own files from file scans to reduce false positives
Privacy
This plugin runs entirely on your server. Scans do not send your site files to the plugin author.
When you run a scan, the plugin may contact:
- WordPress.org (
downloads.wordpress.org) — to fetch official plugin checksums for integrity verification
- WordPress.org update APIs — to check for available plugin, theme, and core updates (standard WordPress behavior)
No personal data is collected by the plugin author. Scan results are stored in your WordPress database (options and transients) for display in the admin dashboard and are visible to users who can manage the site.
Support
Support is provided through the WordPress.org support forums after publication.