Scan themes and plugins for backdoors, spam scripts, crypto miners, webshells, and 30+ malware patterns.
Finds eval(base64_decode), webshells (c99/r57), assert() backdoors, preg_replace /e.
Detects mailer spam, hidden SEO links, pharma hack, Japanese keyword injections.
Finds Coinhive, CryptoLoot, and browser-based cryptocurrency mining scripts.
Flags unsanitized database queries missing $wpdb->prepare() calls.
Detects chmod 777, remote file inclusion, and insecure file write patterns.
Finds document.write with unescape/fromCharCode drive-by download techniques.
Provide the absolute server path to your WordPress theme, plugin, or root.
All PHP, JS, HTML files are scanned against 30+ malware signatures.
Review by severity. Premium: exact line numbers and step-by-step fix guide.