[WordPress] 外掛分享: Nova Scan Lite – Malware Scanner, Backdoor & File Integrity

首頁外掛目錄 › Nova Scan Lite – Malware Scanner, Backdoor & File Integrity
WordPress 外掛 Nova Scan Lite – Malware Scanner, Backdoor & File Integrity 的封面圖片
全新外掛
安裝啟用
尚無評分
9 天前
最後更新
問題解決
WordPress 6.2+ PHP 7.4+ v1.0.9 上架:2026-08-20

內容簡介

Nova Scan Lite 是一款免費且輕量的 WordPress 惡意程式掃描器,能夠檢查網站的 PHP 威脅並驗證 WordPress 核心檔案的完整性,所有操作均在伺服器的管理會話中進行。

【主要功能】
• 掃描 PHP 檔案以檢測後門和網頁外殼
• 驗證 WordPress 核心檔案的官方檢查碼
• 一鍵隔離可疑檔案而不刪除
• 支援大檔案掃描,避免超時
• 提供完整的掃描歷史與嚴重性分類

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.0.9) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Nova Scan Lite – Malware Scanner, Backdoor & File Integrity」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Nova Scan Lite is a free, lightweight malware scanner for WordPress. It checks your site for common PHP threats and verifies WordPress core file integrity — all running locally on your server during an admin session.
What it does

Scans PHP files for backdoors, webshells, and RCE patterns
Verifies WordPress core files against official checksums
Flags modified or unexpected files in wp-admin/ and wp-includes/
One-click quarantine to disable suspicious files without deleting
Chunked scanning (handles thousands of files without timeouts)
Full scan history with severity breakdowns

What it detects

Backdoors & webshells (C99, r57, FilesMan, custom shells)
Remote code execution (eval + base64, preg_replace /e, create_function)
System command execution (system, shell_exec, passthru with user input)
Credential harvesting and wp_users dumps
File system abuse (remote file writes, 0777 chmod, wget/curl droppers)
Obfuscation patterns (long base64, chr/ord chains, hex encoding)
Modified WordPress core files

Privacy
Nova Scan Lite does not transmit any of your site’s content, file data, or user information anywhere. Scans run locally on your server. The only outbound request the plugin makes is to the official WordPress.org checksums API for core file integrity verification (see the “External services” section below).
External services
Nova Scan Lite uses one external service, provided by WordPress.org.
WordPress.org Core Checksums API

What it is and what it is used for: The official WordPress.org API that returns known-good MD5 checksums for every file in a given WordPress core release. Nova Scan Lite uses it to verify that the installed WordPress core files have not been modified by malware or unauthorized users.
What data is sent and when: The request is triggered only when the site administrator clicks the “Check Core Files” button in the admin. The request sends only the currently-installed WordPress version string and the site’s locale (for example version=7.0&locale=en_US). No site URL, no user data, no file contents, and no database information is transmitted.
Terms and privacy: The API is operated by the WordPress Foundation. Its use is governed by the WordPress.org privacy policy (https://wordpress.org/about/privacy/).
Endpoint: https://api.wordpress.org/core/checksums/1.0/

No other outbound requests are made. No tracking, no telemetry, no phone home, no remote assets loaded.
Upgrade to Nova Scan Pro
Nova Scan Pro is also free (included with a free Nova Heaven account). It replaces Lite and adds:

Web Application Firewall with brute-force and XML-RPC protection
Database payload scanner
Vulnerability (CVE) intelligence and virtual patching
Repository integrity check, file modification monitoring, tamper-proof canaries
Mass-reinfection velocity alerts, cron job scanner, rogue admin detection
Obfuscation / encoding detection and behavioral pattern analysis
Security score, threat dashboard, one-click hardening, security headers
Allowlist management, scheduled scans, email alerts
Frontend Shield monitor (cross-domain, catches skimmers and injected scripts)
12-provider cascading email engine so alerts never get stuck on one quota
Signed automatic updates
Multilingual (21 languages)

Learn more at novaheaven.io/novascan.

延伸相關外掛

文章
Filter
Mastodon