Malware scanning

An independent WordPress malware scanner, with quarantine that's never destructive.

WPFixAgent's malware detection is self-built -- no third-party security vendor or external scanning API is involved. It checks WordPress core files against the official WordPress.org checksum manifest, and reviews plugin/theme/upload files for known-bad signatures and suspicious structural traits like unusual entropy or anomalous modification timing.

Independent

Detection

Official

Checksum manifest

Non-destructive

Quarantine

Never

Auto-deleted

wpfixagent.com/wordpress-malware-scanner

Scan-to-resolution workflow

ScanCore files, plugin/theme files, and uploads are checked for integrity and suspicious content.
Rank by confidenceEach finding is labeled signature (high-confidence match) or heuristic (structural, worth a look before acting).
QuarantineA confirmed finding is moved to protected quarantine, hash-matched to the exact scanned file so nothing else is touched.
RecoverRestore a false positive, delete permanently once confirmed, or reinstall the parent plugin/theme from its official source.
Re-verifyA fresh scan confirms the finding is actually resolved.

Repair playbook

1

Scan

Core files, plugin/theme files, and uploads are checked for integrity and suspicious content.

2

Rank by confidence

Each finding is labeled signature (high-confidence match) or heuristic (structural, worth a look before acting).

3

Quarantine

A confirmed finding is moved to protected quarantine, hash-matched to the exact scanned file so nothing else is touched.

4

Recover

Restore a false positive, delete permanently once confirmed, or reinstall the parent plugin/theme from its official source.

5

Re-verify

A fresh scan confirms the finding is actually resolved.

Core file integrity checks

Every WordPress core file is compared against the checksum manifest for the official WordPress.org release matching your installed version -- missing, modified, or unexpected files are flagged individually.

Signature-based detection

Known-bad patterns -- common obfuscation techniques, files sitting somewhere they never should, backdoor shells -- are matched directly and reported with high confidence.

Structural and heuristic checks

Files without a known signature match can still surface for review based on unusual entropy, polyglot structure, or a modification time that doesn't fit the rest of the plugin or theme they're in.

Non-destructive quarantine

A flagged file is moved into a locked, non-executable directory with a recovery manifest -- never deleted outright. Restore it in one click if a finding turns out to be a false positive.

Reinstall from official source

If the affected file was actually part of a plugin or theme you still have installed, redownloading the current official release from WordPress.org and replacing every file closes the gap that quarantine alone doesn't -- see Core Integrity for how this extends to WordPress itself.

What this scanner does and doesn't claim

Independent detection -- no third-party vendor in the loop

Quarantine is always reversible, never a silent delete

Checksum comparison uses the official WordPress.org manifest

Not a substitute for full incident response after a confirmed compromise

Practical guidance

Go deeper before changing a live site.

Open documentation

Critical errors

How to Fix a WordPress Critical Error Without Making It Worse

Recover from the WordPress critical error screen with a controlled process that protects evidence, creates a restore point, isolates the cause, and verifies the result.

Read guide

Auto repair

WordPress Auto Repair: What Should Be Automated and What Needs Review?

Automation should resolve known, reversible WordPress conditions while risky database, malware, and hosting failures remain review-driven.

Read guide

Backups

Local vs Off-Site WordPress Backups: What a Recovery Plan Needs

Local restore points make repairs fast, while off-site copies protect against hosting and disk failure. A serious recovery plan needs clear roles for both.

Read guide

FAQ

Common questions

Is this scanner powered by a third-party security vendor?

No. Detection logic is built and run entirely by WPFixAgent -- no external malware-scanning API or vendor is involved.

Does quarantine delete the file?

No. The file is disabled and moved to a locked directory with a recovery manifest. Restore or permanently delete it yourself once you've reviewed it.

What if the finding is a false positive?

Restore it from the Quarantine tab in one click -- nothing about the file or the surrounding plugin/theme was altered.

Does this replace a full security audit after a real compromise?

No. For a confirmed, actively-exploited compromise, this scanner is one tool among several a full incident response would use -- it doesn't replace specialist review.

Free 14-day trial · no card required

Give every WordPress site a safer path from incident to verified recovery.

Install the connector, pair with a one-time token, and start monitoring in minutes -- upgrade whenever you're ready.

Start Free Trial