Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

Cleanup

WordPress malware removal

Cleanup is not the scanner. After a report exists, Cleanr Engine can quarantine files (copy, verify SHA-256, then remove) and replace core, plugin, or theme files from an official tree. A finding never deletes by itself.

Start on FREE See the scanner first

Replace, don’t patch Official tree whose MD5 matches. Not a few lines inside load.php.
Copy, verify, remove No delete until a verified quarantine copy exists.
wp-config stays Never replaced. Users and siteurl/home are not rewritten.
Apply checkbox Without it the job is a dry-run. Connector cannot clean.

Replace beats patching infected core

When an official original is available, WP Cleanr prefers replace over patch. It does not rewrite a few lines inside load.php. It substitutes the file whose MD5 matches local checksums. The official tree cannot be the infected site itself. wp-config.php is never replaced. WordPress users and siteurl/home are not rewritten automatically.

Quarantine is copy-verify-remove

A file is not deleted until a verified copy exists in the quarantine store. Restore is the reverse. Symlinks are not quarantined. Apply requires the dashboard checkbox (or CLI --yes); without it the operation is a dry-run.

Database cleanup is narrow

Optional database work can neutralize high-risk options (empty value, autoload off) or drop autoload on huge options. It does not delete users. Connector and SFTP refuse clean and harden; those stay on SSH.

After cleanup, run a verification scan. Pair with hardening so uploads cannot host PHP again. CLEAN is the plan that includes verified cleanup.

Cleanup needs a report first

Scan the HTTP surface now, then connect the site on CLEAN.

Run a FREE HTTP scan

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.