Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

11 Sep 2026

PHP in WordPress uploads is a finding, not a delete command

This page does not include malware samples. A match on its own is not an action.

The engine looks at path, extension, and a short content sniff. If a file under uploads looks like PHP, the report gets php_in_uploads. Weight is high because that location is for media.

Nothing is deleted. A later quarantine job can copy, verify SHA-256, and remove, but only with Apply. Hardening can then stop PHP from being served there.

Related: detection landing, removal.

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.