Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

sys / free scan / http-only

FREE WordPress security scan (HTTP)

Unauthenticated HTTP surface check. Not a filesystem malware scan. Private, loopback, and credentialed URLs are refused.

No account. No passwords. HTTP surface only.

WordPress Whether the URL looks like WordPress
HTTP Public HTTP paths and headers
No login No wp-content read

What this scan is not

It does not read wp-content, does not ask for wp-admin, and does not SHA-256 files. That is the deep scanner.

WordPress malware scanner · How it works