Skip to main content

wp-scanner

By Kim Schulz kim@schulz.dk

wp-scanner is a WordPress malware scanner focused on finding backdoors, crypto miners, suspicious loaders, and obfuscated payloads in WordPress file trees.

Warning

Use this tool carefully. Quarantine/delete actions can change or remove files. Always take a backup before remediation.

Features

  • Signature-based malware detection (100+ built-in signatures)
  • Heuristic detection for suspicious WordPress patterns
  • Optional WordPress core verification to skip unchanged official core files
  • Interactive Textual TUI with sortable findings, details modal with source view, filtering, export, and remediation actions
  • Headless mode with JSON/HTML report output
  • Audit logging for remediation actions
  • Restore support from quarantine via audit log

Installation

pip

Install from the current directory:

pip install .

Install with TUI dependencies:

pip install 'wp-scanner[tui]'

For local editable/testing installs from this repository, use:

pip install '.[tui]'

pipx

Install as an isolated CLI app:

pipx install .

Install with TUI dependencies:

pipx install 'wp-scanner[tui]'

For local installs from this repository, use:

pipx install --pip-args='.[tui]' .

If you run without TUI dependencies, the scanner falls back to headless mode automatically.

Quick Start

Run TUI scan:

wp-scanner /path/to/wordpress

Run headless scan:

wp-scanner /path/to/wordpress --no-tui

Common Usage

Headless scan with reports:

wp-scanner /path/to/wordpress --no-tui --report-json ./ --report-html ./

Use custom signatures:

wp-scanner /path/to/wordpress --no-tui --signatures ./custom-signatures.json

Verify against official WordPress core and skip unchanged core files:

wp-scanner /path/to/wordpress --verify-core

Offline core verification (cached core only):

wp-scanner /path/to/wordpress --verify-core --verify-core-offline

Remediation (Headless)

Quarantine infected files:

wp-scanner /path/to/wordpress --no-tui --quarantine --quarantine-dir ./quarantine --yes

Delete infected files:

wp-scanner /path/to/wordpress --no-tui --delete --yes

Restore from quarantine using audit log:

wp-scanner /path/to/wordpress --no-tui --restore --audit-log ./wp-scan-remediation-audit.jsonl --yes

TUI Controls

Main controls:

  • q: quit
  • p: pause/resume scan
  • r: stop/restart scan
  • j / k or arrows: move selection
  • d or enter: open details modal
  • s: toggle sort
  • e: export findings
  • space: select/unselect current finding
  • a: select/unselect all visible findings
  • x: quarantine selected
  • delete: delete selected
  • u: open restore modal

Notes

  • Findings can include false positives. Review critical/high findings first.
  • Core verification and remediation audit logging are intended to reduce unnecessary scanning and improve operational safety.

Metadata

Release files for wp-scanner 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wp-scanner 1.1.0
File Size Uploaded
wp_scanner-1.1.0.tar.gz 39.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wp-scanner 1.1.0
File Interpreter ABI Platform
wp_scanner-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 74.5 kB

Release files / wp_scanner-1.1.0.tar.gz

Download URL wp_scanner-1.1.0.tar.gz
Size 39.7 kB
Tags Source
SHA-256 checksum
How to use checksums
eb6e5229575383e6b77b7b967a4c74e9c629d7ef2c1144a7784df14ea531663c
BLAKE2b-256 checksum
How to use checksums
cf6623fcb35041e36dc7f830d4b8f4cf359c5849e7ae74bbf3d01f84fcf10cef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.2

Release files / wp_scanner-1.1.0-py3-none-any.whl

Download URL wp_scanner-1.1.0-py3-none-any.whl
Size 34.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fbf495487c52af5fa9229a8bf995b645723c14672a69dbd3583e2966494a34ea
BLAKE2b-256 checksum
How to use checksums
6b301c8eba3cf239496223e36616e3de3dfee2a6e6515f9428427e559301d4dc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.2

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page