AGENCY can discover WordPress installs on a cPanel server through WHM. The token stays in a file. wp-config.php is not read. Private and loopback hosts are refused. Import creates SSH or SFTP sites; scanning is the same job queue as any other site.
WHM discovery lists accounts and WordPress paths. It does not become a malware scanner running as root on every user. After import, Cleanr Engine scans through SSH or the connector (read-only). Clean and harden still need SSH.
Ready to scan
Scan a public WordPress site in seconds
No account. No passwords. HTTP surface only. The engine never executes site PHP.