Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually....
Search the files and database of your WordPress install for signs that may indicate that it has fallen victim to malicious hackers.
Exploit Scanner is a WordPress plugin that searches your website's files and database for suspicious content. It examines posts, comments, and active plugins for unusual filenames but does not remove any detected items, leaving that task to the user.
This plugin is suitable for users who want to monitor their site for potential security threats. It can help identify possible hacks, although it may also produce false positives, so users should verify results carefully.
Best for: This plugin suits website owners concerned about security and potential hacks.
What it does well
Where it falls short
Exploit Scanner can be a useful tool for monitoring website security, but users should be cautious about interpreting its results and take action based on their findings.
Donncha O Caoimh (a11n)'s own description of Exploit Scanner, lightly tidied.
This plugin searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames.
It does not remove anything. That is left to the user to do.
Latest MD5 hash values for Exploit Scanner:
Latest SHA1 hash values for Exploit Scanner:
See the Exploit Scanner homepage for further information.
It is likely that this scanner will find false positives (i.e. files which do not contain malicious code). However, it is best to err
on the side of caution; if you are unsure then ask in the Support Forums,
download a fresh copy of a plugin, search the Internet for similar situations, et cetera. You should be most concerned if the scanner is:
making matches around unknown external links; finding base64 encoded text in modified core files or the wp-config.php file;
listing extra admin accounts; or finding content in posts which you did not put there.
Understanding the three different result levels:
Follow the guides from the Codex:
Ensure that you change all of your WordPress related passwords (site, FTP, MySQL, etc.). A regular backup routine
(either manual or plugin powered) is extremely useful; if you ever find that your site has been hacked you can easily restore your site from
a clean backup and fresh set of files and, of course, use a new set of passwords.
Other plugins for backups.
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually....
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your...
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your...
All-in-one WordPress backup, migration and staging plugin — schedule automatic backups, restore in one click,...
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta box...
WordPress backup plugin: backups, restore & migration in minutes. Clone or duplicate your site, test updat...