Plugins, uploads, and even “core” can contain whatever an attacker wrote. Cleanr Engine therefore reads files as bytes. Version and plugin headers are parsed as text with a size cap. The walk cannot leave the site root. Symlinks are not followed. A YARA or heuristic match is a row in the report, not a delete.
That is slower than “just run WordPress and see”. It is also the only way the product stays a scanner instead of a second infection path. Related: how it works, deep scan.