On the site
Typical security plugin
- Runs PHP next to the malware it hunts
- Can include or eval the target
- Lives inside wp-content
- Cleanup can fire without a confirm
sys / cleanr engine / 1.45
Cleanr Engine treats every WordPress install as untrusted data. It hashes, classifies, and scores files. It does not include, eval, or launch WP-CLI against the target. FREE Scan is HTTP-only and asks for no credentials.
HTTP check. No passwords. Does not read site files.
Five steps. Read-only until you check Apply. The target never becomes a PHP runtime.
Most scanners install next to the problem. Cleanr Engine stays off the WordPress runtime.
On the site
Off the site
The scanner reads files. It never executes PHP from wp-includes, plugins, or uploads. A YARA or heuristic match does not delete anything.
The public FREE Scan is an unauthenticated HTTP check. Private, loopback, and credentialed URLs are refused. It is not a filesystem malware scan.
Malware removal copies, verifies SHA-256, then removes. Core PHP is replaced only from an official tree whose MD5 matches local checksums.
One engine. Four surfaces. Scan stays read-only until you check Apply.
SHA-256, integrity checksums, YARA subset, heuristics, database and persistence. Deep scan on CLEAN+.
Quarantine, official replace, optional database neutralization. Apply is an explicit checkbox.
Uploads, wp-config, permissions. Does not delete plugins or xmlrpc.php. Independent of clean.
Customers, white-label, WHM discovery. Connector plugin is read-only pairing, not a scanner.
CLEAN is €99 cleanup plus €9.95/month for 11 months. FREE HTTP scan stays free.
HTTP
HTTP scan, no site credentials.
Recommended
Deep scan and verified cleanup via connector or SSH.
Ops
Harden, baseline, monitor.
Fleet
Customers, white-label, WHM import.
See plan details. New here? Create a FREE account.
No account required for FREE Scan. No passwords. HTTP surface only.
Same engine, narrower questions. No malware samples.
No. Cleanr Engine treats the installation as untrusted data: no include, require, eval, or WP-CLI against the target.
No. FREE Scan is an unauthenticated HTTP surface check. Filesystem malware scanning (hashes, integrity, YARA, heuristics) is the deep scan on CLEAN+.
No. It is HMAC pairing and jailed read. Clean and harden do not run through site PHP; they still require SSH.
Yes. One product: €99 verified cleanup plus €9.95 per month for 11 remaining months (one year). Paid via Stripe Checkout. FREE stays the HTTP scan.
No. The walk stays inside the site root. Symlinks are not followed and are not quarantined.
Ready to scan
No account. No passwords. HTTP surface only. The engine never executes site PHP.