Does WP Cleanr execute PHP from the WordPress site?
No. Cleanr Engine treats the installation as untrusted data: no include, require, eval, or WP-CLI against the target.
Does FREE Scan find malware in files?
No. FREE Scan is an unauthenticated HTTP surface check. Filesystem malware scanning (hashes, integrity, YARA, heuristics) is the deep scan on CLEAN+.
Is the Connector plugin a scanner?
No. It is HMAC pairing and jailed read. Clean and harden do not run through site PHP; they still require SSH.
Is there billing?
Yes. One product: €99 verified cleanup plus €9.95 per month for 11 remaining months (one year). Paid via Stripe Checkout. FREE stays the HTTP scan.
Can a symlink take the scanner off-site?
No. The walk stays inside the site root. Symlinks are not followed and are not quarantined.
How do I start?
Run a FREE HTTP scan without an account, or register (password 10+ characters). Deep scan needs CLEAN and a connector or SSH site.
Where is the sitemap?
/sitemap.xml lists public pages in English and Spanish with hreflang.