Cleverhog Malware Scanner
Totally free malware scanner with no paid features: find infected files, backdoors, hacked core files, rogue admins and outdated software.
Solid choice
Cleverhog Malware Scanner is a solid plugin choice in 2026, with a few things worth checking first. It runs on 70+ sites, is rated 5/5 and was last updated 2 weeks ago, and scores 70/100 on our health check.
- Actively developed — last update 2 weeks ago
- Small user base (70+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Cleverhog Malware Scanner stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| backdoor | #10 |
| hacked | #14 |
| malware | #17 |
| scanner | #16 |
| security | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About Cleverhog Malware Scanner
From the official readme · v1.7.0Description
Cleverhog Malware Scanner helps you investigate a suspicious or compromised WordPress site from the admin dashboard.
100% free — no paid features
This plugin is totally free. There is no premium version, no “Pro” upgrade, no paid add-ons, no locked features, no license keys, and no per-site fees. Use it on unlimited websites.
Every feature we develop — now and in the future — will be free and available to everyone.
This plugin detects and reports potential security issues. It does not automatically remove malware or guarantee that a site is clean. Always back up your site before changing or deleting files.
What it scans
- Files — Scan of themes, plugins, uploads, wp-content, site-root files, or the full site (with code snippets, file size, and last-modified date). Detects obfuscated backdoors (hex/octal escapes, split strings, strrev/rot13), request-driven code execution, uploader shells, credential stealers, hidden admin creation, search-engine cloaking, known malware families (wp_vcd, lock360, NDSW), PHP hidden in images/icons, malicious
.user.inifiles, and JavaScript injections - Backdoors — Must-use plugins, drop-ins, wp-config, cron jobs, suspicious hooks, and WordPress core integrity (modified core files and unknown files in wp-admin, wp-includes, and the site root, checked against official WordPress.org checksums)
- .htaccess — Discovers
.htaccessfiles site-wide and lists malicious redirects, search-engine referrer redirects, PHP handlers in uploads, images executed as PHP, lock360-style lockdown rules, auto_prepend, cloaking rules, and more - Authentication — XML-RPC, user enumeration, weak salts, file editor, and SSL-related checks
- Database — Open registration with a privileged default role, hidden active plugins, PHP payloads stored in options, injected JavaScript in options and posts
- Administrators — All admin users with registration dates and risk flags, including admin accounts hidden from the Users screen
- Updates — Outdated plugins, themes, and core (medium for major/minor updates, low for patch-only updates)
- Plugin integrity — WordPress.org plugins compared to official checksums, including extra files added to otherwise clean plugins
Features
- Live threat counter during scans
- Results sorted by severity (critical, high, medium, low)
- Last scan results restored when you reopen the dashboard
- Admin menu badge showing critical issue count
- Excludes this plugin’s own files from file scans to reduce false positives
Privacy
This plugin runs entirely on your server. Scans do not send your site files to the plugin author.
When you run a scan, the plugin may contact:
- WordPress.org (
downloads.wordpress.org) — to fetch official plugin checksums for integrity verification - WordPress.org update APIs — to check for available plugin, theme, and core updates (standard WordPress behavior)
No personal data is collected by the plugin author. Scan results are stored in your WordPress database (options and transients) for display in the admin dashboard and are visible to users who can manage the site.
Support
Support is provided through the WordPress.org support forums after publication.
Installation
- Install through Plugins → Add New after this plugin is on WordPress.org, or upload the
cleverhog-malware-scannerfolder to/wp-content/plugins/ - Activate Cleverhog Malware Scanner
- Open Cleverhog Malware Scanner in the admin menu
- Choose scan types and click Start Security Scan
Frequently asked questions
Is there a paid or Pro version?
No. The plugin is completely free with no paid features, upsells, or license keys. Every feature we develop — now and in the future — will be free and available to everyone.
Does this remove malware automatically?
No. It shows what was found with file paths, snippets, and severity so you can investigate. Restore from backup or use professional help for active breaches.
Can it give false positives?
Yes. Legitimate plugins may use patterns that look suspicious (for example base64_decode). Review every critical finding before deleting files.
Does it scan its own plugin files?
No. The scanner excludes its own directory from file scans.
Will large sites timeout?
File scans run in batches via AJAX to reduce PHP timeout issues.
Which plugins can be checksum-verified?
Only plugins hosted on WordPress.org with published checksums for the installed version. Premium or custom plugins are listed as unverified; use the file malware scan on those.
Changelog
Much stronger malware detection (core integrity, obfuscated backdoors, hidden admins, JavaScript injections) and several scanner bug fixes. Run a new scan after upgrading.
1.7.0
- Detection: plugins with pending updates are now malware-scanned and checksum-verified (previously skipped — outdated plugins are the most common infection route)
- Detection: files added to otherwise clean WordPress.org plugins are reported and malware-scanned (previously the whole plugin folder was skipped)
- Detection: WordPress core integrity check against official checksums (modified core files, unknown PHP in wp-admin / wp-includes / site root)
- Detection: quick scans include site-root files (index.php, wp-config.php, dropped loaders)
- Detection: new signatures for obfuscated function names (hex/octal escapes, string splitting, strrev/rot13), request data used as callbacks or shell commands, eval of downloaded code, $GLOBALS obfuscation, uploader shells, include of image/data files, admin-creating backdoors, hidden users, hidden plugins, credential stealers, search-engine cloaking, and wp_vcd/lock360/NDSW markers
- Detection: JavaScript injection scanning (NDSW, encoded script tags, eval of decoded code)
- Detection: PHP hidden in .ico and hidden image files, malicious .user.ini auto_prepend_file, and more executable PHP extensions (.pht, .php3, .php8, …)
- Detection: large files are scanned (start and end) instead of skipped; cache/vendor/test folders inside uploads are no longer skipped
- Detection: .htaccess lock360 rules, images executed as PHP, and search-engine referrer redirects
- Detection: database checks for privileged open registration, hidden active plugins, PHP payloads in any option, and injected JavaScript
- Detection: administrator accounts hidden from the Users screen (pre_user_query) are reported as critical
- Fix: REST API user enumeration check ran as the logged-in admin and always reported a problem; it now checks as a logged-out visitor
- Fix: verified-plugin results were lost between scan batches, so trusted plugins were partly re-scanned
- Fix: the same issue could be listed twice (e.g. must-use plugin found by both backdoor and file scans)
- Fix: fewer false positives — Wordfence/firewall auto_prepend_file, www/non-www and HTTPS redirects, “AddHandler cgi-script” PHP-disable rules, generic filenames (input.php, defaults.php, shell.php) inside plugins/themes, and “require $_GET” in comments
- Security: quarantined files are renamed so they can never execute (including on nginx) and the quarantine folder denies access on Apache 2.2 and 2.4
- Security: on multisite, only network administrators can run scans or view/move files
- Plugin is 100% free with no paid features — stated in the plugin description
1.6.9
- Fix admin JavaScript: file preview (View file) and permission-hardening actions work reliably again
- Quarantined file preview sends quarantine ID for correct path resolution
1.6.8
- Update findings: major/minor bumps are medium severity; patch-only updates are low
- Harden permissions action for world-writable file findings (e.g. core bootstrap files)
- Mobile-friendly stacked layout for the administrator accounts table
- Do not offer delete on inactive parent themes when a child theme is active
1.6.7
- PHPCS/WPCS: prefix dashboard template globals for Plugin Check compliance
1.6.6
- WordPress.org review: all wp-admin includes centralized in Admin_Dependencies with immediate function use
- Path resolution centralized in Wp_Paths (uploads, plugins via WPMG_PLUGIN_FILE, WP_LANG_DIR, core files)
- Checksum API failures cached with a distinct marker (not an empty array)
1.6.5
- Checksum fetch failures use a distinct transient marker so plugins are not marked verified after a failed lookup
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Cleverhog Malware Scanner alternatives
All backdoor plugins →FAQ
Cleverhog Malware Scanner: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 3, 2026
Is Cleverhog Malware Scanner free?
Yes. Cleverhog Malware Scanner is free to download and use from the official WordPress.org plugin directory.
Is Cleverhog Malware Scanner safe to use in 2026?
Cleverhog Malware Scanner is a solid plugin choice in 2026, with a few things worth checking first. It runs on 70+ sites, is rated 5/5 and was last updated 2 weeks ago, and scores 70/100 on our health check.
How many websites use Cleverhog Malware Scanner?
Cleverhog Malware Scanner is active on 70+ WordPress websites and has been downloaded 692 times since it launched in May 2026. It was downloaded 266 times in the last 30 days.
Does Cleverhog Malware Scanner work with WordPress 7.1?
Cleverhog Malware Scanner is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does Cleverhog Malware Scanner need?
Cleverhog Malware Scanner requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Cleverhog Malware Scanner last updated?
The latest version, 1.7.0, was released on September 17, 2026 (2 weeks ago).
Who makes Cleverhog Malware Scanner?
Cleverhog Malware Scanner is developed and maintained by cleverhog.
What are the best alternatives to Cleverhog Malware Scanner?
The most popular alternatives to Cleverhog Malware Scanner are Deep Malware Cleaner (50+ installs), Malroot Security (20+ installs) and Nova Scan Lite (<10 installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card



