wp-scanner
By Kim Schulz kim@schulz.dk
wp-scanner is a WordPress malware scanner focused on finding backdoors, crypto miners, suspicious loaders, and obfuscated payloads in WordPress file trees.
Warning
Use this tool carefully. Quarantine/delete actions can change or remove files. Always take a backup before remediation.
Features
- Signature-based malware detection (100+ built-in signatures)
- Heuristic detection for suspicious WordPress patterns
- Optional WordPress core verification to skip unchanged official core files
- Interactive Textual TUI with sortable findings, details modal with source view, filtering, export, and remediation actions
- Headless mode with JSON/HTML report output
- Audit logging for remediation actions
- Restore support from quarantine via audit log
Installation
pip
Install from the current directory:
pip install .
Install with TUI dependencies:
pip install 'wp-scanner[tui]'
For local editable/testing installs from this repository, use:
pip install '.[tui]'
pipx
Install as an isolated CLI app:
pipx install .
Install with TUI dependencies:
pipx install 'wp-scanner[tui]'
For local installs from this repository, use:
pipx install --pip-args='.[tui]' .
If you run without TUI dependencies, the scanner falls back to headless mode automatically.
Quick Start
Run TUI scan:
wp-scanner /path/to/wordpress
Run headless scan:
wp-scanner /path/to/wordpress --no-tui
Common Usage
Headless scan with reports:
wp-scanner /path/to/wordpress --no-tui --report-json ./ --report-html ./
Use custom signatures:
wp-scanner /path/to/wordpress --no-tui --signatures ./custom-signatures.json
Verify against official WordPress core and skip unchanged core files:
wp-scanner /path/to/wordpress --verify-core
Offline core verification (cached core only):
wp-scanner /path/to/wordpress --verify-core --verify-core-offline
Remediation (Headless)
Quarantine infected files:
wp-scanner /path/to/wordpress --no-tui --quarantine --quarantine-dir ./quarantine --yes
Delete infected files:
wp-scanner /path/to/wordpress --no-tui --delete --yes
Restore from quarantine using audit log:
wp-scanner /path/to/wordpress --no-tui --restore --audit-log ./wp-scan-remediation-audit.jsonl --yes
TUI Controls
Main controls:
q: quitp: pause/resume scanr: stop/restart scanj/kor arrows: move selectiondorenter: open details modals: toggle sorte: export findingsspace: select/unselect current findinga: select/unselect all visible findingsx: quarantine selecteddelete: delete selectedu: open restore modal
Notes
- Findings can include false positives. Review critical/high findings first.
- Core verification and remediation audit logging are intended to reduce unnecessary scanning and improve operational safety.
Metadata
Release files for wp-scanner 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| wp_scanner-1.1.0.tar.gz | 39.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| wp_scanner-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 74.5 kB
Release files / wp_scanner-1.1.0.tar.gz
| Download URL | wp_scanner-1.1.0.tar.gz |
|---|---|
| Size | 39.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
eb6e5229575383e6b77b7b967a4c74e9c629d7ef2c1144a7784df14ea531663c
|
|
BLAKE2b-256 checksum How to use checksums |
cf6623fcb35041e36dc7f830d4b8f4cf359c5849e7ae74bbf3d01f84fcf10cef
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.2
|
Release files / wp_scanner-1.1.0-py3-none-any.whl
| Download URL | wp_scanner-1.1.0-py3-none-any.whl |
|---|---|
| Size | 34.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fbf495487c52af5fa9229a8bf995b645723c14672a69dbd3583e2966494a34ea
|
|
BLAKE2b-256 checksum How to use checksums |
6b301c8eba3cf239496223e36616e3de3dfee2a6e6515f9428427e559301d4dc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.2
|