

Malware Scan Overview: threat status, severity counts and safe cleanup actions.
DevDome Malware Scanner checks WordPress files and database content for malicious code, backdoors and suspicious changes. Review the evidence, quarantine eligible infected files and repair eligible WordPress core and official plugin packages from your dashboard. Scanning and cleanup work without an account; an optional DevDome account adds known-malware hash checks against 90,000+ signatures, signature updates and cloud reports.
Use the security scanner for a manual security check or scheduled malware scan. It checks:
The database scan covers options, posts, revisions, post metadata and user metadata. PHP analysis follows code behavior, including request input reaching execution and downloaded content being written to disk.
These anti malware checks support a website security review by showing affected files, evidence and areas that could not be checked.
The optional vulnerability check compares installed WordPress, plugin and theme versions with WPVulnerability records for known vulnerabilities. Enable it in Settings; it is off by default.
This is a version check against published records. It does not test the site by attempting an exploit.
The malware checker reports severity and confidence separately:
A changed file or newly added administrator needs investigation but does not prove an infection. Low and Info findings are review notes.
Each finding shows the affected item, why it was flagged and supporting evidence. For modified core and WordPress.org plugin files, “View what changed” compares the file with the official copy.
Coverage gaps identify checks that were skipped, failed or only partly completed. These include excluded paths, unreadable files, size limits and unavailable official checksums. An unchecked area is never treated as verified clean.
Use the findings and coverage notes as evidence for a WordPress security audit.
WordPress core and WordPress.org plugin files are verified against official WordPress.org checksums. WordPress.org themes are compared with the official package for the installed version.
Premium and custom plugins and themes are tracked against a file baseline. The first scan records the starting state; later scans show changes. The baseline records what was present, not whether it was safe.
For eligible core and plugin findings, repair uses the WordPress updater to reinstall the same installed version from the official WordPress.org package. It replaces the whole package, not just the flagged file.
Before reinstalling, repair stores backup copies in quarantine. Afterwards it checks the resulting package against official checksums. If the reinstall fails, it attempts to restore those backups and reports any remaining recovery work. Repair backups can also be restored from the Quarantine tab.
The malware cleaner offers “One click fix” for eligible file findings through quarantine or official package repair. Eligible findings can include known malware, suspicious executable files in uploads and modified core or plugin files.
Findings requiring review remain under “Needs your decision”. These include suspicious database content, configuration changes, administrator accounts and scheduled tasks. Available actions depend on the finding and the current file.
Quarantine removes a file from disk and keeps a compressed copy in the plugin’s database table. If compression is unavailable, it stores an uncompressed copy. Each record includes the original path, hash, size and permissions.
After using these tools to remove malware, review the cleanup results and scan again to check what remains.
After a hack, removing an infected file may leave behind accounts, tasks or files that allow malware to return. The Reinfection risks tab brings together administrator, scheduled-task, must-use plugin and drop-in findings for review.
Where available, “Neutralize” lets you:
Account roles can be restored under Users. Quarantined files can be restored from Quarantine. Removed scheduled tasks cannot be restored through the plugin.
New administrators and other unexpected additions need your review. Legitimate plugins can also create scheduled tasks, must-use plugins and drop-ins.
Run a scan manually or choose daily or weekly scheduled scans for recurring antimalware checks. Automatic scans are scheduled around 02:00 site time and depend on WordPress cron running.
Scans run in short batches. The open admin page drives progress, with a WP-Cron fallback after you close the tab. You can pause, resume or cancel a scan.
Settings let you adjust batch duration, deep-scan file size limits and excluded paths. Reduced coverage is reported with the results.
Without a DevDome account, you can run file integrity, PHP, uploads, configuration, database, user and scheduled-task checks. Quarantine, eligible official repairs and local scan history are also available.
Official verification still contacts WordPress.org. DevDome’s known-malware hash lookup requires a connected account.
Anonymous detection telemetry is optional and off by default. Reports sent through the reporting buttons are separate actions. The External services section explains what each service receives.
Connecting an account adds:
“Enhanced analysis” is a separate opt-in. It sends short suspicious code fragments and a file-path hint for a second opinion. The plugin attempts to redact secrets before sending them, but redaction cannot cover every secret format.
Disconnecting stops hash lookups and signature updates. Previously downloaded byte-pattern signatures can still match locally.
Simple view shows the verdict, cleanup options and settings. Advanced view adds finding filters, bulk actions, file changes, reinfection risks, quarantine and scan history.
On multisite, the scanner requires network administrator access because file checks and cleanup can affect shared core and plugin files. Each site keeps its own scan data.
On WordPress 6.9 and newer, WordPress Abilities let compatible AI agents read WordPress security findings, control scans, manage settings and use cleanup actions.
MCP clients can access these abilities when the site exposes them through an adapter such as the WordPress MCP Adapter.
Abilities use the same permission checks and action rules as the dashboard. Quarantine, repair, neutralization, restore and permanent deletion require an explicit confirmation flag from the agent.
The plugin talks to the following services:
WordPress.org APIs (api.wordpress.org, downloads.wordpress.org, core.svn.wordpress.org, plugins.svn.wordpress.org): used to fetch official core and plugin checksums, plugin directory status (whether an installed plugin was closed for a security issue), the official zip of each installed WordPress.org theme (downloaded during a scan to verify the theme’s files) and, on explicit repair or comparison actions, official file copies. Only your WordPress version, locale, plugin and theme slugs and their versions are sent. Terms: https://wordpress.org/about/privacy/ Privacy: https://wordpress.org/about/privacy/
DevDome Security API (analytics.devdome.com), only on a site connected to a DevDome account: (a) during each scan, the SHA-256 and MD5 hashes of every scanned file are checked against the DevDome database of 90,000+ known-malware signatures (hashes only, never file contents); (b) after every scan a summary (severity counts, the type, title, site-relative path, status, the names of the checks that fired, the file checksum and size of the top 50 findings of any severity, the total number of open findings, the site’s wp-admin URL for the email button, the PHP version and short-tag setting, the WordPress version, the signature-set version and the plugin version; never file contents) is sent so your DevDome dashboard shows the site’s security status and your account address gets an email when critical or high threats are found; (c) the byte-pattern signature set is delivered and updated through the account and stored on this site; the hash signatures stay on DevDome’s servers and are only ever queried by hash; (d) with the separate “Enhanced analysis” opt-in, short suspicious code fragments and a file-path hint are sent for a second opinion; the plugin attempts to redact common credential and secret patterns before transmission, but no redactor can guarantee that every secret format is removed. Authentication is the site token the DevDome Dashboard provisioned on connect. Nothing is sent before you connect. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy
WPVulnerability API (www.wpvulnerability.net), only when you switch on the vulnerability check in Settings (off by default): during a scan, the slugs and versions of your installed plugins, themes and WordPress core are checked against this free public vulnerability database (EUPL v1.2). Only slugs and version numbers are sent. Terms: https://www.robotstxt.es/legal/ Privacy: https://www.wpvulnerability.com/privacy/
Signature data source (not a service the plugin contacts): the signature set is the Linux Malware Detect database (GPLv2, rfxn.com project), imported and served by DevDome; the plugin never contacts rfxn.com. Project page: https://www.rfxn.com/projects/linux-malware-detect/ License (GPLv2): https://www.gnu.org/licenses/old-licenses/gpl-2.0.html
Plugin catalog (devdome.com): the DevDome Dashboard inside wp-admin fetches the list of DevDome plugins (names, descriptions, logos, links, WordPress.org slugs) from https://devdome.com/wp-plugins/catalog.json at most once every 12 hours, and only after you have connected the site to a DevDome account; a site that is not connected never contacts devdome.com for it. Only the bundled core version is sent in the request; no site or visitor data. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy
Connecting a DevDome account (optional): the DevDome Dashboard offers connecting a free DevDome account. Nothing is sent until you press the Connect button. If you do connect, the shared library sends your site address, a generated site ID and a generated secret site token to analytics.devdome.com/api/plugin/connect/start and /api/plugin/connect/claim to link this site to your account; afterwards it confirms the connection with api.devdome.com/plugin/account at most once every fifteen minutes while you use the dashboard (once an hour after a refusal), and tells api.devdome.com/plugin/disconnect when you disconnect. When you connect from the DevDome Dashboard, whose Connect card states this before you press the button, those account checks also carry the slug and version of each active DevDome plugin on the site plus the bundled DevDome library, WordPress and PHP versions, so your DevDome account can show your sites and their DevDome plugins for support and update notices. Nothing about other plugins, users, email addresses, content or visitors is included. Sites connected before this was introduced, and sites connected from a button that does not show that text, do not send the list. Disconnecting stops the checks and the plugin list. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy
Detection telemetry (analytics.devdome.com), only when you tick “Help improve detection” in Settings (off by default) and only on a site that is NOT connected to a DevDome account (a connected site’s scan report, item 2, already carries the same list): after each completed scan the plugin sends the severity, type, title, site-relative path, status, the names of the checks that fired, the file checksum and size of up to 50 open findings of any severity (most severe first), the total number of open findings, the scan number, the PHP version and short-tag setting, the WordPress version, and the plugin and signature versions, under an anonymous site id (a hash; your site address is never sent). Never file contents, e-mail addresses or absolute server paths. DevDome keeps these lists to tell files flagged on many unrelated sites (allowlist rules) from the same unknown file spreading across sites (new signatures), both delivered through the daily signature update. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy
Scanner reports (devdome.com), only when you click “Report false alarm to DevDome” in the Actions menu of a finding list or “Send scan report to DevDome” on the Overview. The dialog shows the exact text before you send it: your site address, the plugin, WordPress and PHP versions, the signature version, and for each finding its severity, type, title, site-relative path, status, file hash, the plugin it belongs to and the stored evidence lines (secrets redacted, absolute paths removed), plus the note and reply e-mail you type (both optional). Never file contents. The report goes to DevDome support, who use it to fix false alarms and improve detection in the daily signature update. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy
Error reports (devdome.com), only when you press “Report this error” on an error message: the plugin sends the error text, the plugin, WordPress and PHP versions, the screen you were on, the last 20 scanner log lines with secrets removed, your site address and your admin e-mail (so support can reply) to https://devdome.com/api/plugin/error-report. Nothing is sent unless you press the button. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy
The scanner does not require a DevDome account. WordPress.org verification services may still be contacted as described above.
The admin stylesheet assets/devdome-tools-tw.css is compiled with Tailwind CSS 3.4.19 from the shipped source src/tw.css. No package.json or build tooling is included in the distribution (WordPress.org review, September 2026). To reproduce the file with the standalone Tailwind CLI (https://github.com/tailwindlabs/tailwindcss/releases/tag/v3.4.19), run from the plugin folder:
tailwindcss -i ./src/tw.css -o ./assets/devdome-tools-tw.css --minify --content "./admin/**/*.php,./assets/admin.js"
The content globs above are the plugin’s complete Tailwind configuration (no theme extensions, no plugins). assets/admin.js is plain, unminified JavaScript and is edited directly; there is no build step for it. The two inline header icons (bug report, save) are from Lucide (ISC licence).