Cleanr Engine 1.45 SHA-256 YARA site PHP: never read-only until Apply

Deep scan

WordPress malware scanner

A deep WordPress malware scanner has to read the filesystem without becoming the site’s PHP interpreter. Cleanr Engine walks the install, hashes files, checks official checksums, matches a YARA subset, and scores heuristics. It never runs the PHP it reads.

FREE HTTP scan Create account

SHA-256 Inventory with a file-size cap. MD5 only when checksums need it.
Integrity Official maps for core, plugins, and themes when present.
YARA + heuristics Subset matcher. PHP in uploads. Unexpected core PHP.
Evidence only A match is a finding. It is not a delete instruction.

What the deep scan actually does

On CLEAN, PROTECT, and AGENCY, a site is connected with the Connector plugin (read-only pull) or SSH. The engine then:

That is the WordPress malware scanner. A match is evidence in the report. It is not a delete instruction.

FREE Scan is a different product surface

The public FREE Scan does not log into WordPress and does not read wp-content. It fetches the URL over HTTP, refuses loopback, RFC1918, link-local, CGNAT, and userinfo in the URL. Use it to see whether a site looks like WordPress and what the HTTP surface exposes. For malware in files, you need the deep scanner.

Integrity beats a single signature

Known-bad hashes help. So do YARA strings. The stronger signal on a stock core file is often modified vs official MD5, or PHP where WordPress should not put PHP (uploads, unexpected core paths). See how the engine treats the site as data.

Related: malware removal, hardening, FAQ.

Start with the HTTP surface

No credentials. Then connect a site on CLEAN+ for filesystem scan.

Run a FREE HTTP scan

Ready to scan

Scan a public WordPress site in seconds

No account. No passwords. HTTP surface only. The engine never executes site PHP.