Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

sys / cleanr engine / 1.45

How Cleanr Engine scans WordPress

The site is an object, not a runtime. That decision is the product.

Run a FREE HTTP scan Create account

Five steps, then stop

Timeouts (15m scan, 30m job) and a cancelled context abort the whole scan. A single unreadable file does not.

  1. 01 Bound the tree Path jail. Symlinks that leave the root are skipped.
  2. 02 Read as bytes version.php and headers as text. No include or eval.
  3. 03 Hash and class SHA-256, optional MD5, core / plugin / theme / upload.
  4. 04 Score evidence Integrity, YARA, heuristics. A match does not delete.
  5. 05 Explicit Apply Quarantine, replace, and harden are separate jobs.
  1. Bound the tree. Path traversal and symlinks that leave the root are skipped. Huge files hit max_file_size.
  2. Read as bytes. version.php and plugin headers are parsed as text with a size cap. No include.
  3. Hash and classify. SHA-256, optional MD5, class (core, plugin, theme, upload…).
  4. Score evidence. Integrity, YARA subset, heuristics, persistence, optional DB. False-positive verdicts can be marked; they stay in the report.
  5. Act only with Apply. Quarantine, replace, and harden are separate jobs. Connector cannot apply them.

See scanner and FAQ.

See the HTTP surface first

No account. No passwords. Not a filesystem malware scan.

Run a FREE HTTP scan

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.