[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feGFldueqVbklnM88Dij9yAUiNEu21rDfZPD6VfpOCY4":3,"$fSiOEFnJbdC3BWEMPVNUSTrcUBRQVFD-tuqvNg_grHSM":122,"$fa12Qysv5Am4_8EHXM8yAtuujcboLK-oiVn8ysIJG-cI":127},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":37,"analysis":26,"fingerprints":26},"compatshield-site-auditor","CompatShield WP Site Auditor","0.1.0","CompatShield","https:\u002F\u002Fprofiles.wordpress.org\u002Fcompatshield\u002F","\u003Cp>CompatShield Site Auditor gives WordPress site owners and agencies a full picture of their site’s security posture in one scan. Unlike basic security plugins, it audits every layer — environment, plugins, themes, users, files, and database — and produces a single weighted score out of 100 with a per-category breakdown.\u003C\u002Fp>\n\u003Ch4>What it checks\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Environment & Hardening\u003C\u002Fstrong>\u003Cbr \u002F>\n* PHP version (flags below 8.2)\u003Cbr \u002F>\n* WordPress core version\u003Cbr \u002F>\n* WP_DEBUG exposure\u003Cbr \u002F>\n* XML-RPC enabled\u003Cbr \u002F>\n* wp-config.php file permissions\u003Cbr \u002F>\n* Database table prefix (flags default wp_)\u003Cbr \u002F>\n* Directory listing enabled\u003Cbr \u002F>\n* .htaccess integrity\u003Cbr \u002F>\n* HTTPS enforcement\u003Cbr \u002F>\n* readme.html \u002F license.txt version leakage\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Plugin & Theme Intelligence\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lists all installed plugins (active and inactive)\u003Cbr \u002F>\n* Hits WordPress.org API for last updated date and install count\u003Cbr \u002F>\n* Flags plugins not updated in 6, 12, or 24 months\u003Cbr \u002F>\n* Flags plugins removed from the WordPress.org directory\u003Cbr \u002F>\n* Flags abandoned themes\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User & Access Audit\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lists all administrator accounts\u003Cbr \u002F>\n* Flags the default “admin” username still in use\u003Cbr \u002F>\n* Detects dormant admin accounts (no login in 90+ days)\u003Cbr \u002F>\n* Checks for two-factor authentication plugins\u003Cbr \u002F>\n* Flags non-admin users with elevated capabilities (manage_options, install_plugins, etc.)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity & Backdoor Detection\u003C\u002Fstrong>\u003Cbr \u002F>\n* Hashes WordPress core files against official checksums\u003Cbr \u002F>\n* Flags modified core files\u003Cbr \u002F>\n* Scans theme and plugin files for dangerous PHP patterns: eval(base64_decode), gzinflate, str_rot13, shell_exec, exec, system, preg_replace with \u002Fe modifier\u003Cbr \u002F>\n* Flags PHP files inside \u002Fuploads\u002F directory\u003Cbr \u002F>\n* Flags .git directory exposure\u003Cbr \u002F>\n* Detects suspicious WordPress cron jobs\u003Cbr \u002F>\n* Flags PHP files modified in the last 7 or 30 days\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Database Security\u003C\u002Fstrong>\u003Cbr \u002F>\n* Checks for publicly accessible phpMyAdmin\u003Cbr \u002F>\n* Scans published posts for injected content (hidden links, base64 blobs, external iframes)\u003Cbr \u002F>\n* Scans wp_options autoloaded data for malicious PHP patterns and oversized entries\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Score\u003C\u002Fstrong>\u003Cbr \u002F>\n* Weighted score out of 100 (Environment 25, Plugins 20, Headers 20, Users 15, Database 10, Themes 10)\u003Cbr \u002F>\n* Per-category score breakdown with issue count\u003Cbr \u002F>\n* Historical score tracking with week-over-week change\u003C\u002Fp>\n\u003Ch4>Who is this for?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress site owners who want to know their security posture\u003C\u002Fli>\n\u003Cli>Freelancers and developers managing client sites\u003C\u002Fli>\n\u003Cli>Agencies auditing multiple client sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All of the scanning and reporting features described above are fully\u003Cbr \u002F>\nincluded in this free plugin — nothing here is time-limited or\u003Cbr \u002F>\nfeature-gated. CompatShield may offer separate, optional products in\u003Cbr \u002F>\nthe future (such as a multi-site management dashboard); any such\u003Cbr \u002F>\nproduct would be a distinct, separately-installed plugin or service,\u003Cbr \u002F>\nnot a restriction on this one.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>This plugin makes outbound requests to:\u003Cbr \u002F>\n* \u003Cstrong>WordPress.org API\u003C\u002Fstrong> (api.wordpress.org) — to retrieve plugin and theme metadata\u003Cbr \u002F>\n* \u003Cstrong>Your own site’s URL\u003C\u002Fstrong> — to check phpMyAdmin exposure and security headers\u003C\u002Fp>\n\u003Cp>No data is sent to third-party servers by the free version.\u003C\u002Fp>\n","Comprehensive WordPress security auditor. Scans for vulnerabilities, misconfigurations and threats — scored report with actionable fix steps.",0,91,"2026-06-26T10:10:00.000Z","7.0.2","6.5","7.4",[18,19,20,21,22],"audit","hardening","malware","security","vulnerability","https:\u002F\u002Fcompatshield.com\u002Fcompatshield-site-auditor","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcompatshield-site-auditor.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":25,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"compatshield",2,9000,30,94,"2026-08-24T23:33:09.951Z",[38,52,69,85,99],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":25,"downloaded":46,"rating":11,"num_ratings":11,"last_updated":47,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":48,"homepage":50,"download_link":51,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",477,"2026-05-03T09:18:00.000Z",[18,19,49,21,22],"malware-scanner","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",{"slug":53,"name":54,"version":55,"author":56,"author_profile":57,"description":58,"short_description":59,"active_installs":11,"downloaded":60,"rating":11,"num_ratings":11,"last_updated":61,"tested_up_to":62,"requires_at_least":63,"requires_php":16,"tags":64,"homepage":66,"download_link":67,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":68},"boonrisk-site-security-check-report","BoonRisk – Site Security Check & Report","1.0.2","Boon Band","https:\u002F\u002Fprofiles.wordpress.org\u002Fboonband\u002F","\u003Cp>BoonRisk gives you a \u003Cstrong>clear security and readiness report\u003C\u002Fstrong> for your WordPress site. See exactly what security risks exist, why they matter, and what to do about them — all explained in plain language.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Safe & Read-Only:\u003C\u002Fstrong> This plugin only reads your site configuration. It does not scan files, block traffic, or make any changes to your WordPress installation.\u003C\u002Fp>\n\u003Ch4>What You Get\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Check Report\u003C\u002Fstrong> — See your site’s security status: PHP version, WordPress updates, user settings, HTTPS, and 30+ configuration checks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clear Explanations\u003C\u002Fstrong> — Every finding explains “why this matters” and “what to do about it” in plain language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prioritized Risks\u003C\u002Fstrong> — Top risks ranked by impact so you know what to fix first\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Printable Report\u003C\u002Fstrong> — Professional HTML report you can view, print, or share directly from WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What This Plugin Does NOT Do (100% Safe)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No file scanning\u003C\u002Fstrong> — Does not scan your files or look for malware\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No traffic blocking\u003C\u002Fstrong> — Does not act as a firewall or block visitors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No site changes\u003C\u002Fstrong> — Does not modify settings, files, or database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No active testing\u003C\u002Fstrong> — Does not simulate attacks or run security scans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read-only analysis\u003C\u002Fstrong> — Only reads your configuration, never writes or changes anything\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Is It For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> — Understand your security risks without technical expertise\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers & agencies\u003C\u002Fstrong> — Generate client-ready reports in minutes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> — Quick baseline check before or after deployments\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Teams\u003C\u002Fstrong> — Consistent security reporting across multiple WordPress sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Free Security Check (No Account Required)\u003C\u002Fh4>\n\u003Cp>Run a complete security and readiness check instantly — 100% local, no data sent anywhere:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Overall Risk Level\u003C\u002Fstrong> — Clear Low\u002FMedium\u002FHigh rating with explanation of what it means\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Top Risks First\u003C\u002Fstrong> — See your biggest security issues ranked by impact\u003C\u002Fli>\n\u003Cli>\u003Cstrong>30+ Configuration Checks\u003C\u002Fstrong> — WordPress updates, PHP version, HTTPS, user permissions, backups, 2FA, debug mode, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Plan\u003C\u002Fstrong> — Every issue includes “why it matters” and “how to fix it”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Report\u003C\u002Fstrong> — Printable HTML report you can view in WordPress admin or share with your team\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What you’ll learn:\u003C\u002Fstrong> “Is my site at risk?” and “What should I fix first?”\u003C\u002Fp>\n\u003Cp>\u003Cstrong>100% Private:\u003C\u002Fstrong> All checks run on your server. Nothing is sent externally. No account or email required.\u003C\u002Fp>\n\u003Ch4>Optional: Web Dashboard\u003C\u002Fh4>\n\u003Cp>Connect the plugin to the \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">BoonRisk web dashboard\u003C\u002Fa> for additional capabilities (optional, requires free account):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002Fscanner\u002F\" rel=\"nofollow ugc\">Surface Scan\u003C\u002Fa>\u003C\u002Fstrong> — External scan of your site’s public-facing security headers, SSL configuration, and exposed services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong> — Known CVEs matched to your installed plugins and themes with severity ratings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Continuous Monitoring\u003C\u002Fstrong> — Automatic daily checks with alerts when your security posture changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track Over Time\u003C\u002Fstrong> — See how your site security improves (or changes) month over month\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PDF Reports\u003C\u002Fstrong> — Download professional reports to share with clients or management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> The local security check is fully functional on its own. The web dashboard is completely optional.\u003C\u002Fp>\n\u003Cp>Learn more at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Ch4>Local Assessment (Default)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Local Assessment\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Run Assessment Now\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>View your Security Posture Summary and Top Risks\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>View Full Report\u003C\u002Fstrong> for a printable HTML report\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>All analysis happens on your server. Nothing is sent externally.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Create a free account at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Connect (Optional)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Enter your API key\u003C\u002Fli>\n\u003Cli>Send your assessment to the dashboard for vulnerability intelligence, surface scan, and monitoring\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>External API calls only happen when you explicitly request them.\u003C\u002Fp>\n\u003Ch3>Data Usage\u003C\u002Fh3>\n\u003Ch4>Local Assessment\u003C\u002Fh4>\n\u003Cp>In local mode, \u003Cstrong>no data is sent externally\u003C\u002Fstrong>. All checks run inside WordPress.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Cp>When you send data to the dashboard, the following is transmitted:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP and WordPress versions\u003C\u002Fli>\n\u003Cli>Active plugin and theme names\u002Fversions\u003C\u002Fli>\n\u003Cli>Configuration flags (debug mode, file editor status, etc.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>What you get in return:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Known vulnerability data for your installed plugins and themes\u003C\u002Fli>\n\u003Cli>Surface scan results for public-facing security\u003C\u002Fli>\n\u003Cli>Severity context for identified risks\u003C\u002Fli>\n\u003Cli>Historical trend data and monitoring alerts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What is never collected:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User data or personal information\u003C\u002Fli>\n\u003Cli>Passwords or credentials\u003C\u002Fli>\n\u003Cli>Post\u002Fpage content\u003C\u002Fli>\n\u003Cli>Database contents\u003C\u002Fli>\n\u003Cli>File contents\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Data is sent \u003Cstrong>only when you click\u003C\u002Fstrong> Send to Dashboard or enable automatic daily sync. No personal data is collected.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Read our full privacy policy at https:\u002F\u002Fboonrisk.com\u002Fprivacy\u003C\u002Fp>\n","Security posture report for WordPress — 30+ checks, prioritized risks, and a printable report. Get a clear picture in minutes.",171,"2026-02-16T17:38:00.000Z","6.9.4","5.0",[18,19,21,65,22],"site-health","https:\u002F\u002Fboonrisk.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fboonrisk-site-security-check-report.1.0.2.zip","2026-04-16T10:56:18.058Z",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":11,"downloaded":77,"rating":11,"num_ratings":11,"last_updated":78,"tested_up_to":14,"requires_at_least":79,"requires_php":80,"tags":81,"homepage":83,"download_link":84,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"pura-vida-vulnerability-scanner","Pura Vida Vulnerability Scanner","1.1.0","trgomez","https:\u002F\u002Fprofiles.wordpress.org\u002Ftrgomez\u002F","\u003Cp>Pura Vida Vulnerability Scanner checks everything installed on your site, including plugins, themes and WordPress core, against the \u003Cstrong>Wordfence Intelligence\u003C\u002Fstrong> vulnerability database, audits your site’s security posture, and shows you exactly what is at risk and how to fix it.\u003C\u002Fp>\n\u003Cp>It does not invent findings. It correlates your installed software and configuration against authoritative public sources (Wordfence Intelligence, CVE\u002FMITRE, the WordPress.org update channel) and live checks of your own server.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security overview\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The dashboard opens with an at-a-glance status table covering:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress Version: OK \u002F Warning\u003C\u002Fli>\n\u003Cli>Vulnerable Plugins: OK \u002F Critical \u002F High \u002F Medium\u003C\u002Fli>\n\u003Cli>Missing Headers: Present \u002F Missing \u002F N\u002FA (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy)\u003C\u002Fli>\n\u003Cli>SSL: Valid \u002F Expiring soon \u002F Expired \u002F N\u002FA (certificate expiry)\u003C\u002Fli>\n\u003Cli>DNS: OK \u002F Issues \u002F N\u002FA\u003C\u002Fli>\n\u003Cli>Email Security: SPF and DMARC (DKIM is selector-specific)\u003C\u002Fli>\n\u003Cli>CDN\u002FWAF: Detected \u002F Not detected \u002F N\u002FA\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What it does\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Inventories every installed plugin, theme and the WordPress core version.\u003C\u002Fli>\n\u003Cli>Matches each item and version against a continuously updated vulnerability feed.\u003C\u002Fli>\n\u003Cli>Shows severity (CVSS), the CVE identifier, a description and the recommended fix for every finding.\u003C\u002Fli>\n\u003Cli>Audits your configuration and lists prioritized hardening recommendations (2FA, updates, HTTPS, file editor, and more).\u003C\u002Fli>\n\u003Cli>Optional scheduled scans with email alerts when new critical\u002Fhigh issues appear.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data sources\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence Intelligence Vulnerability Data Feed: free for personal and commercial use; includes CVE (MITRE) and CVSS information.\u003C\u002Fli>\n\u003Cli>CVE (MITRE Corporation): the canonical vulnerability identifiers.\u003C\u002Fli>\n\u003Cli>WordPress.org update channel: available core, plugin and theme updates.\u003C\u002Fli>\n\u003Cli>Live site checks performed by the plugin: HTTP headers, SSL, DNS, SPF\u002FDMARC and CDN\u002FWAF.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This product includes data that may be copyrighted by Defiant Inc. (Wordfence Intelligence) and by the MITRE Corporation (CVE®); their notices are displayed alongside the relevant findings.\u003C\u002Fp>\n\u003Cp>Developed by Pura Vida Design Studio, Open Source Security & Website Tools (https:\u002F\u002Fpuravidadesignstudio.com\u002F).\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to one external service to function: the Wordfence Intelligence Vulnerability Data Feed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wordfence Intelligence Vulnerability Data Feed (Defiant Inc.)\u003C\u002Fstrong>\u003Cbr \u002F>\nThis plugin downloads the public WordPress vulnerability database from Wordfence in order to match it against the plugins, themes and core version installed on your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>What is sent: your Wordfence Intelligence API key (in the request Authorization header) and your site’s URL (in the request User-Agent header), sent to https:\u002F\u002Fwww.wordfence.com\u002F. The list of plugins and themes installed on your site is NOT transmitted; matching is performed locally on your own server.\u003C\u002Fli>\n\u003Cli>When it is sent: when you run a manual scan, and when a scheduled scan runs (about once per day). The downloaded database is cached locally for 24 hours so the service is contacted at most about once per day.\u003C\u002Fli>\n\u003Cli>Service terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin also performs read-only checks against your own site for the Security Overview: a loopback HTTP request to your own home URL (to inspect response headers and detect a CDN\u002FWAF) and DNS lookups for your own domain (to check DNS resolution and SPF\u002FDMARC records). These query your own domain and public DNS only; no data is sent to any third party.\u003C\u002Fp>\n","Scan your plugins, themes and WordPress core against trusted vulnerability databases and get a clear, prioritized security overview.",132,"2026-06-16T17:46:00.000Z","5.6","7.2",[19,20,82,21,22],"scanner","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpura-vida-vulnerability-scanner.1.1.0.zip",{"slug":86,"name":87,"version":88,"author":89,"author_profile":90,"description":91,"short_description":92,"active_installs":11,"downloaded":93,"rating":11,"num_ratings":11,"last_updated":94,"tested_up_to":14,"requires_at_least":95,"requires_php":16,"tags":96,"homepage":97,"download_link":98,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"shieldscope-site-security-scanner","ShieldScope – Site Security Scanner","1.3.1","Dhiren Patel","https:\u002F\u002Fprofiles.wordpress.org\u002Fdhirenpatel22\u002F","\u003Cp>\u003Cstrong>ShieldScope – Site Security Scanner\u003C\u002Fstrong> runs a deep, read-only security audit across your entire WordPress site and produces a clear report of issues grouped by severity: Critical, High, Medium, Low, and Info.\u003C\u002Fp>\n\u003Cp>Most security scanners either freeze your admin panel while they run, or quietly hammer your server in the background. ShieldScope does neither. It runs in small, controlled steps with a built-in speed limit — so your site stays fast and responsive the whole time. If you switch to another browser tab, the scan automatically pauses and picks up exactly where it left off when you return.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Here is what ShieldScope checks:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch4>WordPress Core Health\u003C\u002Fh4>\n\u003Cp>Checks that your WordPress installation is up to date and securely configured. Flags outdated versions, exposed debug settings, insecure table prefixes, and other common setup mistakes that attackers actively look for.\u003C\u002Fp>\n\u003Ch4>Core File Integrity\u003C\u002Fh4>\n\u003Cp>Verifies that every WordPress core file is exactly as it should be by comparing against official WordPress checksums. Flags any modified or unexpected files inside core WordPress folders — a common sign of a hacked or tampered site.\u003C\u002Fp>\n\u003Ch4>User Accounts\u003C\u002Fh4>\n\u003Cp>Reviews all administrator accounts for common weaknesses: a default “admin” username, too many admin accounts, weak or outdated password storage, empty passwords, and accounts whose login name is visible to the public.\u003C\u002Fp>\n\u003Ch4>Files & Folders\u003C\u002Fh4>\n\u003Cp>Scans your site’s file system for risky permissions, sensitive configuration files left publicly accessible, leftover backup files that should never be on a live server, and unexpected files in folders where only media should live.\u003C\u002Fp>\n\u003Ch4>Plugins\u003C\u002Fh4>\n\u003Cp>Flags plugins with pending security updates, plugins that are installed but inactive (a common attack surface), and plugins that appear to have been abandoned by their developers with no recent maintenance.\u003C\u002Fp>\n\u003Ch4>Themes\u003C\u002Fh4>\n\u003Cp>Flags themes with pending updates, extra inactive themes that add unnecessary risk, and checks whether your site has a proper active theme configured.\u003C\u002Fp>\n\u003Ch4>Malicious Code Patterns\u003C\u002Fh4>\n\u003Cp>Scans plugin and theme files for known malware signatures, hidden backdoors, and dangerous code patterns that attackers commonly plant on compromised WordPress sites.\u003C\u002Fp>\n\u003Ch4>SSL & HTTPS\u003C\u002Fh4>\n\u003Cp>Checks that your SSL certificate is valid and not about to expire, that your site uses a modern version of HTTPS encryption, that all pages load securely, and that visitors are always redirected from HTTP to HTTPS automatically.\u003C\u002Fp>\n\u003Ch4>Security Headers\u003C\u002Fh4>\n\u003Cp>Checks that your site sends the right security instructions to visitors’ browsers — protections that help prevent clickjacking, content-type attacks, and referrer leaks. Also checks whether your WordPress version number is being broadcast publicly, which gives attackers a head start.\u003C\u002Fp>\n\u003Ch4>Database Settings\u003C\u002Fh4>\n\u003Cp>Checks database-level security settings: whether open user registration is configured with too many permissions, whether your site URLs are consistent, and whether any administrator accounts were created recently without your knowledge.\u003C\u002Fp>\n\u003Ch4>Injection Vulnerabilities\u003C\u002Fh4>\n\u003Cp>Scans plugin and theme code for common vulnerability patterns including SQL injection, cross-site scripting (XSS), and other code weaknesses that attackers exploit to take control of WordPress sites or steal visitor data.\u003C\u002Fp>\n\u003Ch4>Access Control\u003C\u002Fh4>\n\u003Cp>Tests whether parts of your site that should require a login are actually protected. Looks for username leaks through public author pages, missing brute-force login protection, lack of two-factor authentication, and whether admin pages and API endpoints enforce proper access checks.\u003C\u002Fp>\n\u003Ch4>Server Configuration\u003C\u002Fh4>\n\u003Cp>Checks for server-level security issues: outdated PHP versions that no longer receive security patches, sensitive files accidentally left accessible to the public (such as environment config files or debug logs), and server settings that leak technical information to potential attackers.\u003C\u002Fp>\n\u003Ch4>Server-Side Request Forgery (SSRF)\u003C\u002Fh4>\n\u003Cp>Looks for code patterns in plugins and themes that could allow an attacker to trick your server into making unauthorised requests to other systems — both on the internet and inside your private network.\u003C\u002Fp>\n\u003Ch4>Vulnerable & Outdated Components\u003C\u002Fh4>\n\u003Cp>Checks your database software version, WordPress version, and installed plugins against known vulnerability records and end-of-support dates. Flags anything running on software that no longer receives security patches.\u003C\u002Fp>\n\u003Ch4>Vulnerability Database\u003C\u002Fh4>\n\u003Cp>Cross-references your installed plugins and themes against a known vulnerability database. A free WPScan API key (optional) enables live lookups for every plugin and theme on your site. Without a key, a built-in list of the most commonly exploited plugins is checked automatically — no setup needed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ShieldScope never makes any changes to your site.\u003C\u002Fstrong> It is strictly read-only. It scans, reports, and recommends — nothing else.\u003C\u002Fp>\n\u003Ch3>Third-Party Services\u003C\u002Fh3>\n\u003Cp>This plugin communicates with the following external services \u003Cstrong>only while a scan is actively running\u003C\u002Fstrong>. No data is sent on regular page loads.\u003C\u002Fp>\n\u003Ch4>WordPress.org Core Checksums API\u003C\u002Fh4>\n\u003Cp>During the Core Integrity check, the plugin fetches the official file checksums for your exact WordPress version and locale from the WordPress.org API. The only data sent is your WordPress version number and site locale (for example, en_US). No personal data, usernames, or site URLs are transmitted.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: https:\u002F\u002Fapi.wordpress.org\u002Fcore\u002Fchecksums\u002F1.0\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WPScan Vulnerability Database (optional)\u003C\u002Fh4>\n\u003Cp>If you enter a WPScan API key in Settings, the Vulnerability Database check sends the slug and version number of each installed plugin and theme to wpscan.com to retrieve known vulnerability data. This feature is \u003Cstrong>disabled by default\u003C\u002Fstrong> and requires you to explicitly provide an API key. The free tier allows 25 requests per day; results are cached for 24 hours.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: https:\u002F\u002Fwpscan.com\u002Fapi\u002Fv3\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003Cli>Terms of service: https:\u002F\u002Fwpscan.com\u002Fterms\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Disclaimer\u003C\u002Fh3>\n\u003Cp>ShieldScope uses automated analysis to identify potential security issues. Findings should be reviewed before acting on them — particularly for plugins and themes, where a finding may require verification with the plugin or theme developer.\u003C\u002Fp>\n\u003Cp>This plugin is designed to help website owners identify security risks on their own sites. It does not guarantee detection of every possible vulnerability.\u003C\u002Fp>\n\u003Cp>All scanning is performed locally on your own server. No scan data, site content, or personal information is stored externally or shared with any third party. For questions, please use the support forum.\u003C\u002Fp>\n","A thorough WordPress security scanner that checks your entire site for vulnerabilities and misconfigurations — without slowing it down.",114,"2026-07-01T07:52:00.000Z","5.8",[18,19,20,82,21],"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fshieldscope-site-security-scanner\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshieldscope-site-security-scanner.1.3.1.zip",{"slug":100,"name":101,"version":102,"author":103,"author_profile":104,"description":105,"short_description":106,"active_installs":107,"downloaded":108,"rating":109,"num_ratings":110,"last_updated":111,"tested_up_to":14,"requires_at_least":112,"requires_php":79,"tags":113,"homepage":117,"download_link":118,"security_score":119,"vuln_count":120,"unpatched_count":11,"last_vuln_date":121,"fetched_at":27},"wp-malware-removal","Malcure Malware Shield — Removal, Repair, Monitor","19.9.6","Malcure Web Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcure\u002F","\u003Cp>Is your website acting strangely? Seeing ‘Deceptive Site Ahead’ warnings, Japanese SEO hack, or random redirects? Time to fix and monitor your site with \u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Malcure Malware Shield scans for infections, runs silent scheduled scans, and sends alerts before threats spread — turning one-time cleanup into always-on protection.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Malcure scans files, databases, and user accounts to find malware casual scanners miss — backdoors hidden in images, injections in your database, rogue, hidden admin accounts buried in your tables that don’t show up in the admin area. Then it watches your site with scheduled scans and alerts, so one-time cleanup becomes always-on protection.\u003C\u002Fp>\n\u003Cp>Detection runs against 50,000+ signatures with real-time threat intelligence — the same definitions for every user, free or paid. You see every infection with exact file paths and line numbers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Activate \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Know \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>What Our Users Say\u003C\u002Fh3>\n\u003Cp>Quotes are verbatim from WordPress.org support reviews, except for bracketed edits (for example, competitor names removed).\u003C\u002Fp>\n\u003Ch4>Best by far, better than [competitor name removed] and other giants\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“You can see it is a bunch of geeks that created this, with skill and visual creativity at that. I spent hours trying to find a plugin like this. So many options and such bad results until now. Great job guys. You deserve it. Simple and effective. (Disclaimer to other potential readers: there are many types of hacks\u002Fmalware out there, every scenario is different, but start with the Malcure scan and see how it goes. 9\u002F10 you won’t be disappointed, my guess)” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-by-far-better-than-wordfence-and-other-giants\u002F\" rel=\"ugc\">@dalingzaf\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>The ONLY plugin that scans every file-type…\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“I am a web developer and have tried many malware removal plugins, including popular ones [competitor names removed]. However, none of them detected some unusual files that were actually malware causing regular attacks. Some of these files were in JPG format.” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-only-plugin-that-scans-files-in-real-time-2\u002F\" rel=\"ugc\">@devzeeshanx\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Best Malware Removal Plugin in just few minutes\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“Most security plugins that are free only scan the code, but Malcure Malware Removal Plugin scans the wordpress database and the code files in few minutes. Accurately shows which Database table row is infected and it helps resolve the hacking attempt instantly. Saves a lot of time for the developers. Thank You Team Malcure” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-malware-removal-plugin-in-just-few-minutes\u002F\" rel=\"ugc\">@s3630\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>It’s not just a “teaser”\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“This plugin really found the malware, and removed it. Really for free. Thanks guys, I’m going to donate now!” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fits-not-just-a-teaser\u002F\" rel=\"ugc\">@halucska\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>What Malcure Does\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>File Scan:\u003C\u002Fstrong> Core files, themes, plugins, images, uploads — backdoors, shells, obfuscated code, and malware hidden inside image files and archives.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Scan:\u003C\u002Fstrong> Finds malicious injections, recurring malware, and SEO injection links that other non-thorough scanners never see.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Scan:\u003C\u002Fstrong> Detects rogue admin accounts and compromised metadata, including application passwords that bypass your login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DeepScan™:\u003C\u002Fstrong> Scans every file-type without skipping within resource-limits and hidden files where malware hides.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Verification:\u003C\u002Fstrong> Compares your core, plugin, and theme files against official repository checksums. Tampered files are flagged by severity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Hack Detection:\u003C\u002Fstrong> Catches Japanese Keyword Hack, Pharma Hack, and other SEO hacks in page titles and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks installed plugins and themes against a real-time vulnerability database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Intelligence:\u003C\u002Fstrong> Checksum-based verification reduces false alarms compared to heuristic-only scanners.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>50,000+ Signatures:\u003C\u002Fstrong> Detects known variants — C99, R57, RootShell, and many more — plus unknown threats via behavioral analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Alerts\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scheduled Scans:\u003C\u002Fstrong> Set a cadence — daily, weekly, or monthly. Runs silently in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Weekly Security Pulse Email:\u003C\u002Fstrong> A verdict-first security-critical weekly summary — gives you a heads-up — “All Clear”, “Please Review”, or “Needs Immediate Attention” — delivered to your inbox. Covers scan results, failed logins, privileged activity, file edits, and updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled Scan Results Email:\u003C\u002Fstrong> Email report of scheduled scans — clean or infected. Know immediately when a scheduled scan finishes. Gives you early heads-up if malware found and before it spreads and affects SEO or gets the site blacklisted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Recipients:\u003C\u002Fstrong> Choose who gets notified. Licensee, Registrant and additional CC recipients. Send a test Pulse to verify your mail configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Log:\u003C\u002Fstrong> 100-day forensic record of every security event for root-cause analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Inspector:\u003C\u002Fstrong> See who’s logged in — IP, user-agent, login time, and session expiration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Hardening & Firewall\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Block Path Traversal:\u003C\u002Fstrong> Stops attackers from accessing sensitive system files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block PHP Uploads:\u003C\u002Fstrong> Prevents malicious scripts from being uploaded.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bots from fishing for usernames.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection:\u003C\u002Fstrong> Prevents user data leakage via the WP REST API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Counter:\u003C\u002Fstrong> See how many attacks the firewall has blocked, right on your dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Incident Response\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Session Nuke:\u003C\u002Fstrong> Force-logout every user instantly to kick out intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Salt Shuffler:\u003C\u002Fstrong> One-click rotation of \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5230\" rel=\"nofollow ugc\">security keys (salts)\u003C\u002Fa> to invalidate all browser cookies.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Real-Time Threat Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero-Day:\u003C\u002Fstrong> Threat definitions served in real time via the Malcure Cloud. No days-long delay.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Search Console:\u003C\u002Fstrong> Connect directly to fetch security warnings and blacklist status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> Scans send file checksums and your site’s domain to Malcure servers. No sensitive user data is transmitted. Use of the API is subject to our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=1720\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=3\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight:\u003C\u002Fstrong> Runs only on demand or on schedule. No persistent background processes. No bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Dashboard & Experience\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dashboard Widget:\u003C\u002Fstrong> At-a-glance malware status, attack count, and quick-scan CTA on the WP dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Skins:\u003C\u002Fstrong> Classic and Dark skins to match your workflow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Completion Audio Preferences:\u003C\u002Fstrong> Configure sound-notifications for scans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Diagnostics Page:\u003C\u002Fstrong> Environment diagnostics for troubleshooting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Who This Plugin Is For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and developers\u003C\u002Fstrong> who need fast triage across multiple sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce, membership, and lead-gen sites\u003C\u002Fstrong> where downtime and SEO damage are expensive.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> who want clear results — what was flagged, exactly where.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works (Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Review \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Clean \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Scan\u003C\u002Fstrong> — Open \u003Cstrong>Malcure Scanner\u003C\u002Fstrong> in your Admin Dashboard. Run a scan to check files, database, users, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Review\u003C\u002Fstrong> — Every finding comes with an exact location: file path, line number, or database record. Decide what to repair, delete, or keep.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean & Recover\u003C\u002Fstrong> — Shows every infection so you can clean it yourself. Advanced Edition adds repair tools, file operations, whitelisting, and WP-CLI automation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitor\u003C\u002Fstrong> — Set up scheduled scans. Get email alerts the moment a threat is found.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Is It Free?\u003C\u002Fh4>\n\u003Cp>We believe in 100% transparency.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Professional-grade Detection (Knowledge). You see every infected file and database row (exact file path & line number), so you can clean it yourself for free.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Real-time Threat Intelligence, Scheduled Scans, Weekly Security Pulse email, and Firewall & Hardening.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pro Upgrade:\u003C\u002Fstrong> File Repairs, Deletions, Whitelisting, Advanced Scan Filters, WP-CLI Automation, Auto-Definition Updates, Bulk Client-Servicing Features & Premium Support (Expertise).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>You are never forced to pay to \u003Cem>find\u003C\u002Fem> a hack.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FEbSbxiTOc8k?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Advanced Edition\u003C\u002Fh4>\n\u003Cp>For when detection is not enough — you need to remediate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>1-Click Repairs:\u003C\u002Fstrong> Repair infected files from the official source via Malcure Cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Delete Files:\u003C\u002Fstrong> Remove infected or irreparable files directly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File & DB Whitelisting:\u003C\u002Fstrong> Suppress alarms on specific files and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI Integration:\u003C\u002Fstrong> Full command-line control — async scans, definitions sync, checksum refresh, reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Definition Updates:\u003C\u002Fstrong> Hourly cron keeps definitions current without manual intervention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Scan Filters:\u003C\u002Fstrong> Include or exclude directories, custom regex signatures for database and files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Inspector:\u003C\u002Fstrong> Inspect files inline instead of having to go via s\u002Fftp or ssh or file-managers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Copy Scan Results:\u003C\u002Fstrong> Copy results to clipboard for client reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP Config & Diagnostics:\u003C\u002Fstrong> View full PHP configuration in diagnostics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Factory Reset:\u003C\u002Fstrong> One-click plugin reset.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support:\u003C\u002Fstrong> Direct access to our security analysts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">\u003Cstrong>Get Malcure Advanced Edition\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Expert Malware Removal Service\u003C\u002Fh4>\n\u003Cp>In over your head? Our security analysts will clean your site for you — 100% removal guarantee, same-day service, blacklist removal, and 15-day post-cleanup cover.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">\u003Cstrong>Book Expert Malware Removal\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Ch4>Some files are detected by Malcure Malware Shield as “suspicious”. What gives?\u003C\u002Fh4>\n\u003Cp>Malcure’s DeepScan checks each file for malware. However some files aren’t pure malware but may contain code that is suspicious and could potentially do nasty things. You should carefully review and analyse them to see if they indeed do anything nasty.\u003C\u002Fp>\n\u003Ch4>I can’t get Malcure Malware Shield to work. It hangs \u002F doesn’t complete the scan \u002F breaks for some reason.\u003C\u002Fh4>\n\u003Cp>If you think that the plugin is broken, \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Malcure Malware Shield (or for that matter other plugins) may break on malware affected \u002F broken websites. \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">Malcure Advanced Edition\u003C\u002Fa> integrates with WP CLI and allows you to complete the scan from WP CLI even when the site is blocked by the webhost or when you are unable to login to the website.\u003C\u002Fp>\n\u003Ch4>My site is infected however Malcure Malware Shield doesn’t detect the infection.\u003C\u002Fh4>\n\u003Cp>Malware keeps evolving. If you come across malware that Malcure Malware Shield is not able to identify, you may \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=157\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>The scan gets stuck midway. What should I do?\u003C\u002Fh4>\n\u003Cp>In case of such an event, please file a support request with us and we’ll be more than happy to troubleshoot the issue.\u003C\u002Fp>\n\u003Cp>Please visit \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">this page\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I cleaned my site but it got infected again. What should I do?\u003C\u002Fh4>\n\u003Cp>Malware cleanup is a waste of time and effort unless you find the root cause behind the malware infection and monitor for recurrence. How was someone able to infect your website? Have you plugged in that security hole?\u003C\u002Fp>\n\u003Cp>Please read \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002Fblog\u002Fsecurity\u002Fwhy-do-wordpress-websites-get-hacked\u002F\" rel=\"nofollow ugc\">Why Do Websites Get Hacked\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Google Safe Browsing site status (or some other scanner) still shows my site as infected. What should I do?\u003C\u002Fh4>\n\u003Cp>First make sure you purge your site cache. Second, Google (and other scanners) cache the results for some time. You’ll need to force or refresh the scan. You can also file a request with us to \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">get your site off any blacklists\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I found a suspicious file, what now?\u003C\u002Fh4>\n\u003Cp>If Malcure flags it, it’s likely malicious. You can inspect the file content using our built-in inspector. If you’re unsure, consider our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">Expert Malware Removal Service\u003C\u002Fa>.\u003C\u002Fp>\n","Your WordPress site hacked? Malcure scans files AND database to find and help you remove malware casual scanners miss. Free. No bloat.",10000,662306,90,72,"2026-07-14T03:24:00.000Z","6.2",[114,49,21,115,116],"antivirus","virus","vulnerability-scanner","https:\u002F\u002Fmalcure.com\u002F?p=116","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-malware-removal.19.9.6.zip",96,3,"2025-09-03 00:00:00",{"error":123,"url":124,"statusCode":125,"statusMessage":126,"message":126},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcompatshield-site-auditor\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":11,"versions":128},[]]