WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by eyesecurity v1.1.0

Compromise Scanner for wp2shell

Read-only forensic scanner for the WordPress core exploit chain CVE-2026-63030 / CVE-2026-60137 (wp2shell). Reports a scored verdict; changes nothing.

Compromise Scanner for wp2shell

The facts

Rating
5★ from 2
Active installs
2k+
Price
Free
Last updated
20 Jul 2026
Added
Jul 2026
Requires WP
5.6
Tested up to
WP 7.0.4
Requires PHP
7.2
Downloads
6,628

Our analysis

AI-assisted

Compromise Scanner for wp2shell is a forensic scanner designed for WordPress sites to detect potential remnants of specific exploits tracked as CVE-2026-63030 and CVE-2026-60137. It inspects the database and plugin directory for indicators left by the exploit, presenting a scored verdict on its admin screen without altering any site data. The plugin is intended for site administrators who want to assess the security of their WordPress installation against these vulnerabilities.

The scanner checks for various artifacts related to the exploits, including suspicious entries in the oembed cache, unusual object-graph artifacts, and traces of deleted administrator accounts. It provides an export feature for generating a report in a zip archive or JSON format, which can be useful for record-keeping or further investigation. However, users should not rely solely on this tool for security assurance and should consider a comprehensive investigation if any indicators are found.

Best for: This plugin is suitable for WordPress site administrators concerned about specific security vulnerabilities.

What it does well

  • Free to use from the WordPress.org directory
  • Designed specifically for detecting wp2shell exploit remnants
  • Provides detailed reports with severity indicators
  • Allows export of findings for further analysis
  • Read-only operation does not alter site data

Where it falls short

  • Matched checks are not definitive proof of a breach
  • Does not fix vulnerabilities or replace core updates
  • Requires manual verification of findings

Verdict

Compromise Scanner for wp2shell is a focused tool for assessing potential security issues related to specific exploits. While it offers valuable insights, it should be used in conjunction with other security measures and professional investigations.

From the developer

eyesecurity's own description of Compromise Scanner for wp2shell, lightly tidied.

Compromise Scanner for wp2shell is a read-only forensic scanner for the WordPress core exploit chain publicly tracked as CVE-2026-63030 (REST batch route confusion) and CVE-2026-60137 (author__not_in SQL injection), widely referred to as wp2shell.

It inspects the database and the plugin directory for artifacts the exploit leaves behind — even when the attacker cleaned up afterwards — and presents a scored verdict on its own admin screen. It does not change anything on your site, and it does not fix the vulnerability. To close the hole, update WordPress core.

What it checks (each weighted by severity):

  • oembed_cache entries that loop back to your own site, that number exactly three, or that were created around the disclosure date (the exploit uses oembed rendering as a write primitive).
  • Object-graph artifacts: posts with implausibly high parent IDs, known proof-of-concept titles/slugs, and customize_changeset entries created since disclosure.
  • Account artifacts: the wp2_ login prefix and @wp2shell.invalid email used by public exploit code, and non-founder administrator accounts created since disclosure.
  • Deleted-admin traces: orphaned user metadata and gaps in the user-ID sequence (create-then-delete).
  • Webshell plugin files or directories matching wp2shell_*.

How it reads: the weighted score maps to No indicators (under 25), Some indicators (25–49), or Multiple indicators (50+). Each check is shown with its severity and detail so you can verify it yourself. Matched checks are not proof of a breach.

Export: the Export report (.zip) button downloads a zip archive for record-keeping or to hand to an investigator. Because the exploit hides its SQL injection and pre-auth admin creation inside a REST batch request body — which web servers do not log — the database artifacts are the primary evidence, so the archive includes the raw rows a human needs to review: the report as JSON and plain text, the relevant oembed_cache, customize_changeset, suspect posts, suspect users (exploit-default logins/emails and new administrators; never password hashes), orphaned usermeta and changed plugin files, plus LOG-COLLECTION-GUIDE.txt listing the server-side logs to gather by hand (the plugin cannot read those itself). If the server lacks the PHP zip extension, a single JSON file with the same data is downloaded instead. The export is generated on the fly and stores nothing on the site.

This is a focused, single-purpose tool. It is best-effort: matched checks are not proof of a breach on their own, and an all-clear result is not a guarantee. Do not act on this quick check alone — verify matched checks with your webmaster, consider a proper investigation (server and access logs, file integrity) if anything is unexplained, and treat reinstalling WordPress as a last resort. It complements, and does not replace, updating core and a professional investigation.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for moving data.

Members

Members

94

The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you rest...

Free 300k+ installs 4.9★ (1,274)
Easy Updates Manager

Manage all your WordPress updates, including individual updates, automatic updates, logs, and loads more. This...

Free 300k+ installs 4.8★ (725)
Redux Framework

Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins....

Free 900k+ installs 4.4★ (273)
PrettyLinks

🌠 Shorten, brand, and track any URL on your own domain. Keep your links — and your data — where they belong....

Free 200k+ installs 4.8★ (1,317)