Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

sys / cleanr engine / 1.45

WordPress malware scanner that never runs the site’s PHP

Cleanr Engine treats every WordPress install as untrusted data. It hashes, classifies, and scores files. It does not include, eval, or launch WP-CLI against the target. FREE Scan is HTTP-only and asks for no credentials.

HTTP check. No passwords. Does not read site files.

How the engine works

  • php never-exec
  • http no-passwords
  • apply required
Untrusted data Reads files. Never a PHP runtime for the target site.
No passwords Public FREE Scan is an unauthenticated HTTP check.
Verified cleanup Copy, SHA-256, then remove. Official replace for core PHP.
Explicit Apply A finding is evidence. Nothing is deleted by a match.

How the engine treats a site

Five steps. Read-only until you check Apply. The target never becomes a PHP runtime.

  1. 01 Bound the tree Path jail. Symlinks that leave the root are skipped.
  2. 02 Read as bytes version.php and headers as text. No include or eval.
  3. 03 Hash and class SHA-256, optional MD5, core / plugin / theme / upload.
  4. 04 Score evidence Integrity, YARA, heuristics. A match does not delete.
  5. 05 Explicit Apply Quarantine, replace, and harden are separate jobs.

Not another plugin on the infected site

Most scanners install next to the problem. Cleanr Engine stays off the WordPress runtime.

On the site

Typical security plugin

  • Runs PHP next to the malware it hunts
  • Can include or eval the target
  • Lives inside wp-content
  • Cleanup can fire without a confirm

Off the site

Cleanr Engine

  • Reads files as untrusted data
  • Never include, eval, or WP-CLI against the target
  • The engine is not installed on WordPress
  • Apply is an explicit checkbox

Untrusted data, not a runtime

The scanner reads files. It never executes PHP from wp-includes, plugins, or uploads. A YARA or heuristic match does not delete anything.

FREE Scan without passwords

The public FREE Scan is an unauthenticated HTTP check. Private, loopback, and credentialed URLs are refused. It is not a filesystem malware scan.

Cleanup you can verify

Malware removal copies, verifies SHA-256, then removes. Core PHP is replaced only from an official tree whose MD5 matches local checksums.

What you can do

One engine. Four surfaces. Scan stays read-only until you check Apply.

Plans

CLEAN is €99 cleanup plus €9.95/month for 11 months. FREE HTTP scan stays free.

HTTP

FREE

HTTP scan, no site credentials.

  • Unauthenticated HTTP check
  • No wp-admin, no filesystem
  • Private URLs refused
Run FREE Scan

Ops

PROTECT

Harden, baseline, monitor.

  • Everything in CLEAN
  • Hardening jobs
  • Baseline and monitor
See details

Fleet

AGENCY

Customers, white-label, WHM import.

  • Customers on CLEAN
  • White-label brand
  • WHM WordPress discovery
For agencies

See plan details. New here? Create a FREE account.

Scan a public WordPress site in seconds

No account required for FREE Scan. No passwords. HTTP surface only.

Run a FREE HTTP scan

Deep dives

Same engine, narrower questions. No malware samples.

FAQ

Does WP Cleanr execute PHP from the WordPress site?

No. Cleanr Engine treats the installation as untrusted data: no include, require, eval, or WP-CLI against the target.

Does FREE Scan find malware in files?

No. FREE Scan is an unauthenticated HTTP surface check. Filesystem malware scanning (hashes, integrity, YARA, heuristics) is the deep scan on CLEAN+.

Is the Connector plugin a scanner?

No. It is HMAC pairing and jailed read. Clean and harden do not run through site PHP; they still require SSH.

Is there billing?

Yes. One product: €99 verified cleanup plus €9.95 per month for 11 remaining months (one year). Paid via Stripe Checkout. FREE stays the HTTP scan.

Can a symlink take the scanner off-site?

No. The walk stays inside the site root. Symlinks are not followed and are not quarantined.

Full FAQ

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.