Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

Read-only pairing

WP Cleanr Connector

The Connector is a WordPress plugin for pairing and read-only pull. It is not a malware scanner and it does not clean the site.

Create account CLEAN+ required

  1. Add a site in the dashboard (CLEAN+). Default transport is connector.
  2. Download wp-cleanr-connector.zip from the account (authenticated). Install it on the WordPress site.
  3. Paste site id and the secret from the site page (visible until Pair). Pair over HMAC v1.

From 1.4, WordPress auto-updates the plugin from /connector/v1/update.json. Sites still on 1.3 need one manual install of the new zip.

Reads are jailed with realpath under ABSPATH. Files larger than 2 MiB are skipped. Clean and harden still require SSH. GET of the sites API does not return the secret.

Agencies can attach many sites this way. See plans.

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.