Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

11 Sep 2026

The WP Cleanr Connector is not a malware scanner

The plugin exists so CLEAN+ can pull files without storing a shell password. It does not scan or clean.

Pairing uses HMAC. Reads are jailed with realpath under ABSPATH. Files larger than 2 MiB are skipped. The secret stays on the site page until Pair succeeds.

It does not hash the site, run YARA, or clean anything. Clean and harden are refused on connector and SFTP; they need SSH. Calling it a “security plugin” in the WordPress sense would be a lie.

Download is from the authenticated account, not the public sitemap. See connector and agencies.

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.