
內容簡介
Deep Malware Cleaner 是一款輕量級的深度惡意程式掃描器,專為 WordPress 設計。它能徹底掃描 wp-content 目錄,檢查核心檔案的完整性,並偵測後門、注入的網站腳本及重定向攻擊,確保網站安全。
【主要功能】
• 深度清理掃描,檢查 PHP 和常見的客戶端格式
• 預安裝上傳防護,阻止惡意檔案上傳
• 資料庫掃描,檢查隱藏的腳本和有效載荷
• 核心完整性檢查,確保檔案未被篡改
• 快速警報與行動工具,應對即時攻擊
外掛標籤
開發者團隊
原文外掛簡介
Deep Malware Cleaner is a lightweight deep malware scanner built for WordPress. It performs a thorough deep cleanup scan of your wp-content directory, verifies your WordPress core files against the official checksums, detects backdoors, finds injected site scripts, flags redirect hacks, and scans your database for hidden payloads — all from your WordPress admin dashboard, with no external service, no subscription, and no scan data ever leaving your server.
Whether you’re dealing with a live attack, a hidden backdoor, or a redirect hack silently sending visitors to malicious sites, Deep Malware Cleaner gives you the tools to scan, alert, and act — fast.
Finding the infected file is only half the job. Deep Malware Cleaner also surfaces the things attackers leave behind so a cleaned site stays clean: the second administrator account, the scheduled event that re-downloads the payload, and the uploads directory that will happily execute the next webshell.
Core Capabilities
Deep Cleanup Scan
Walks your entire wp-content directory, inspecting PHP files plus the client-side formats most often used to deliver malware — JavaScript, HTML, SVG, and .htaccess — for known signatures, obfuscated code, and injected payloads. Results are sorted by severity so the worst threats surface first.
Pre-Install Upload Guard
Scans plugins, themes, and risky media uploads (.php, .svg, .html, .js, .htaccess) in their temporary directory before WordPress moves them into place. If malware is detected the install or upload is aborted and an error is shown — stopping a compromised package before it ever touches your site. Can be toggled in Settings.
Database Scanner
Inspects the most-targeted database tables — options, posts, comments, and post meta — for injected scripts, hidden iframes, and encoded payloads, using keyset pagination and a time budget so it stays safe on a live site.
Core Integrity Check
Hashes every file of your WordPress installation and compares it against the official checksums published by WordPress.org, so a patched wp-login.php or a webshell hidden inside wp-includes cannot pass as a core file. Findings are split into modified, unknown, and missing.
Recently Modified Files
Lists every PHP file changed in the last 1–30 days, newest first. After a break-in the attacker’s files are usually the newest ones on the site, which makes this the fastest way to spot an intrusion the signature rules have not seen before.
Admin User Audit
Reviews every administrator account for the patterns that give away an attacker-created login — added recently, an email on an unrelated domain, no display name, or a machine-generated username. Read-only: no account is ever changed or removed for you.
Cron Job Audit
Lists every WordPress scheduled event and flags the ones no active code listens for, or whose hook name looks obfuscated. If a site keeps getting reinfected after a clean-up, a hidden cron event is the usual reason.
Uploads Directory Protection
Blocks PHP execution in wp-content/uploads with one click. Nothing you upload to WordPress is ever a PHP file, so denying PHP outright turns a webshell dropped through a vulnerable plugin into a file the attacker cannot run. Reversible at any time.
Backdoor Fixer
Detects PHP backdoors uploaded through vulnerable plugins or themes — including webshells, remote-execution scripts, and hidden PHP files inside the uploads folder where no PHP should ever exist.
Site Script Cleaner
Identifies injected JavaScript and malicious
