Skip to main content
Agency Program 50% cashback. 10% commissions. Priority support. Built for growing agencies. 50% cashback for agencies Speak to the team Join free
Exploit Scanner icon

Exploit Scanner

v1.5.2
by Donncha O Caoimh (a11n) · 3.2 (40 reviews)

Search the files and database of your WordPress install for signs that may indicate that it has fallen victim to malicious hackers.

10K+ active installs Updated Nov 28, 2017 Tested to 4.7.29
Try Demo Download
Pre-installed Ready in ~10s No card

About Exploit Scanner

This plugin searches your website's files and database for any suspicious activity. It does not remove anything, but it provides a list of potential issues for you to investigate and address. The plugin also provides information on how to interpret the results and what to do if you suspect your site has been hacked.

Frequently asked questions

What does the Exploit Scanner plugin do?
This plugin searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames.
Does the Exploit Scanner plugin remove anything?
No, it does not remove anything. That is left to the user to do.
What are the latest MD5 hash values for Exploit Scanner?
17e2ccfc834d691bc68cc5c64f9bed89exploit-scanner.php (1.5.2), 1d5f9d6220fe159cd44cb70a998a1cd7hashes-4.6.php, fbdf61c17f65094c8e331e1e364acf68hashes-4.6.1.php, 477d128d84802e3470cec408424a8de3hashes-4.7.php, d53210f999847fbd6f5a2ecac0ad42f2hashes-4.7.5.php.
What are the latest SHA1 hash values for Exploit Scanner?
1decc1e47a53d1cab9e8f1ef15b31682198367eeexploit-scanner.php (1.5.2), 5cec64380a2acdc876fd22fbbbbf8c335df1ed3fhashes-4.6.php, 99d9e7be23a350f3d1962d0f41e7b4e28c00841ehashes-4.6.1.php, 1eeab377a1afc6d776827a063678d2461b29e71dhashes-4.7.php, 8c890a6af26bb74e9d17e5d2b21d6be27764da45hashes-4.7.5.php.
How should I interpret the results of the Exploit Scanner?
It is likely that this scanner will find false positives (i.e. files which do not contain malicious code). However, it is best to err on the side of caution; if you are unsure then ask in the Support Forums, download a fresh copy of a plugin, search the Internet for similar situations, et cetera. You should be most concerned if the scanner is making matches around unknown external links; finding base64 encoded text in modified core files or the wp-config.php file; listing extra admin accounts; or finding content in posts which you did not put there.

Changelog

1.5.2

  • Added hashes for WordPress 4.7.5

1.5.1

  • WordPress 4.6 hashes
  • WordPress 4.6.1 hashes
  • WordPress 4.7 hashes

1.5

  • WordPress 4.5.3 hashes
  • Move to follow WP versioning system

1.4.12

  • WordPress 4.5.2 hashes

1.4.11

  • WordPress 4.5 hashes
  • WordPress 4.5.1 hashes

1.4.10

  • WordPress 4.4.1 hashes

1.4.9

  • WordPress 4.4 hashes

1.4.8

  • WordPress 4.3.1 security release hashes
  • Other missing hashes

1.4.7

  • WordPress 4.3 hashes

1.4.6

  • WordPress 4.2.3 hashes
  • WordPress 4.2.4 hashes

1.4.5

  • WordPress 4.2.2 hashes

1.4.4

  • WordPress 3.7.3 hashes
  • WordPress 3.7.4 hashes
  • WordPress 3.7.5 hashes
  • WordPress 3.7.6 hashes
  • WordPress 3.7.7 hashes
  • WordPress 3.8.4 hashes
  • WordPress 3.8.5 hashes
  • WordPress 3.8.6 hashes
  • WordPress 3.8.7 hashes
  • WordPress 3.9.4 hashes
  • WordPress 3.9.5 hashes
  • WordPress 4.0.2 hashes
  • WordPress 4.0.3 hashes
  • WordPress 4.0.4 hashes
  • WordPress 4.1.4 hashes
  • WordPress 4.2.1 hashes

1.4.3

  • WordPress 4.1.3 hashes

1.4.2

  • WordPress 4.2 hashes

1.4.1

  • WordPress 3.9.3, 4.1, 4.1.1 and 4.1.2 hashes

1.4

  • Remove an example link to a hacked site
  • Fixed the eval() check incorrectly matching function names that end in “eval”
  • Fixed some PHP warnings
  • WordPress 3.5.2 hashes
  • WordPress 3.6 and 3.6.1 hashes
  • WordPress 3.7, 3.7.1 and 3.7.2 hashes
  • WordPress 3.8, 3.8.1, 3.8.2 and 3.7.3 hashes
  • WordPress 3.9, 3.9.1 and 3.9.2 hashes
  • WordPress 4.0 and 4.0.1 hashes

1.3.3

  • WordPress 3.5 and 3.5.1 hashes

1.3.2

  • WordPress 3.4.2 hashes

1.3.1

  • WordPress 3.4.1 hashes

1.3

  • Detect unknown files in the wp-admin and wp-includes directories
  • WordPress 3.4 hashes

1.2.1

  • WordPress 3.3.2 hashes

1.2

  • WordPress 3.3.1 hashes
  • Use help tabs introduced in WordPress 3.3
  • Help prevent one cause of hanging scans (MySQL error 1153)

1.1

  • Scan for and fix old, vulnerable TimThumb scripts
  • Detect old export files even if they’re larger than the size limit
  • WordPress 3.3 hashes

1.0.5

  • WordPress 3.2 and 3.2.1 hashes

1.0.4

  • WordPress 3.1.4 hashes
  • Suspicious pattern updates and tweaks

1.0.3

  • Detection of export files left by incomplete imports.
  • WordPress 3.1.3 hashes

1.0.2

  • WordPress 3.0.6 and 3.1.2 hashes

1.0.1

  • WordPress 3.1.1 hashes

1.0

  • Core file diffs
  • WordPress 3.1 hashes
  • Updated suspicious patterns

0.97.6

  • WordPress 3.0.5 hashes

0.97.5

  • WordPress 3.0.4 hashes
  • Dropped wp-content from hashes

0.97.4

  • WordPress 3.0.3 compatibility

0.97.3

  • 3.0.2 compatibility

0.97.2

  • 3.0.1 compatibility

0.97.1

  • PHP 4 compatibility

0.97

  • AJAX paging
  • simplified results system (now only 3 levels)
  • contextual help
  • moved to Tools menu section
  • a number of backend changes

0.96

  • Compatibility for WordPress 3.0

0.95

  • Added “exploits” scan level for obvious hacker exploit code.
  • Stored results for later review.
  • Rearranged layout of results.
  • Paged scanning so plugin scans 50 files at a time to avoid timeout errors.
  • Only show “General Info” to non MU sites (it’s too expensive for large MU sites)

Try other plugins