Members
94The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you rest...
Read-only forensic scanner for the WordPress core exploit chain CVE-2026-63030 / CVE-2026-60137 (wp2shell). Reports a scored verdict; changes nothing.
Compromise Scanner for wp2shell is a forensic scanner designed for WordPress sites to detect potential remnants of specific exploits tracked as CVE-2026-63030 and CVE-2026-60137. It inspects the database and plugin directory for indicators left by the exploit, presenting a scored verdict on its admin screen without altering any site data. The plugin is intended for site administrators who want to assess the security of their WordPress installation against these vulnerabilities.
The scanner checks for various artifacts related to the exploits, including suspicious entries in the oembed cache, unusual object-graph artifacts, and traces of deleted administrator accounts. It provides an export feature for generating a report in a zip archive or JSON format, which can be useful for record-keeping or further investigation. However, users should not rely solely on this tool for security assurance and should consider a comprehensive investigation if any indicators are found.
Best for: This plugin is suitable for WordPress site administrators concerned about specific security vulnerabilities.
What it does well
Where it falls short
Compromise Scanner for wp2shell is a focused tool for assessing potential security issues related to specific exploits. While it offers valuable insights, it should be used in conjunction with other security measures and professional investigations.
eyesecurity's own description of Compromise Scanner for wp2shell, lightly tidied.
Compromise Scanner for wp2shell is a read-only forensic scanner for the WordPress core exploit chain publicly tracked as CVE-2026-63030 (REST batch route confusion) and CVE-2026-60137 (author__not_in SQL injection), widely referred to as wp2shell.
It inspects the database and the plugin directory for artifacts the exploit leaves behind — even when the attacker cleaned up afterwards — and presents a scored verdict on its own admin screen. It does not change anything on your site, and it does not fix the vulnerability. To close the hole, update WordPress core.
What it checks (each weighted by severity):
oembed_cache entries that loop back to your own site, that number exactly three, or that were created around the disclosure date (the exploit uses oembed rendering as a write primitive).customize_changeset entries created since disclosure.wp2_ login prefix and @wp2shell.invalid email used by public exploit code, and non-founder administrator accounts created since disclosure.wp2shell_*.How it reads: the weighted score maps to No indicators (under 25), Some indicators (25–49), or Multiple indicators (50+). Each check is shown with its severity and detail so you can verify it yourself. Matched checks are not proof of a breach.
Export: the Export report (.zip) button downloads a zip archive for record-keeping or to hand to an investigator. Because the exploit hides its SQL injection and pre-auth admin creation inside a REST batch request body — which web servers do not log — the database artifacts are the primary evidence, so the archive includes the raw rows a human needs to review: the report as JSON and plain text, the relevant oembed_cache, customize_changeset, suspect posts, suspect users (exploit-default logins/emails and new administrators; never password hashes), orphaned usermeta and changed plugin files, plus LOG-COLLECTION-GUIDE.txt listing the server-side logs to gather by hand (the plugin cannot read those itself). If the server lacks the PHP zip extension, a single JSON file with the same data is downloaded instead. The export is generated on the fly and stores nothing on the site.
This is a focused, single-purpose tool. It is best-effort: matched checks are not proof of a breach on their own, and an all-clear result is not a guarantee. Do not act on this quick check alone — verify matched checks with your webmaster, consider a proper investigation (server and access logs, file integrity) if anything is unexplained, and treat reinstalling WordPress as a last resort. It complements, and does not replace, updating core and a professional investigation.
Other plugins for moving data.
The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you rest...
Manage all your WordPress updates, including individual updates, automatic updates, logs, and loads more. This...
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins....
🌠 Shorten, brand, and track any URL on your own domain. Keep your links — and your data — where they belong....
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerc...
Easily export or import your WordPress customizer settings!