Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

11 Sep 2026

FREE HTTP scan vs WordPress filesystem malware scan

The public FREE Scan fetches a URL. No passwords. No wp-content. The deep scanner is a different product.

Loopback, RFC1918, link-local, CGNAT, and URLs with userinfo are refused. You learn whether the HTTP surface looks like WordPress and which headers are missing.

The deep scanner on CLEAN+ walks the install, hashes files, compares checksums, runs a YARA subset, and may read the database. That is the WordPress malware scanner. It needs a connector pull or SSH. It still never executes site PHP.

People search for one phrase and mean both products. The site says which is which so a FREE Scan is not mistaken for a clean bill of the filesystem. See scanner and plans.

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.