Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

High-signal finding

Detect PHP in WordPress uploads

A PHP file under wp-content/uploads is not a theme. Cleanr Engine classifies it as php_in_uploads. That is evidence in the report. The engine does not execute the file. Cleanup still needs Apply on SSH.

Deep scanner Why it is only evidence

Why uploads PHP is a strong signal

WordPress is supposed to store media there. Executable PHP in that tree is unexpected. The scanner sniffs content and extension; it does not run the bytes. A false positive can be marked; the finding stays in the report.

What happens after the finding

Quarantine is copy-verify-remove. Hardening can stop uploads from serving PHP later. Neither step is implied by the match alone. The FREE HTTP scan cannot see uploads files at all.

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.