BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Exploit Scanner icon
Possibly abandoned Tested up to 4.7.37 #2 in hack

Exploit Scanner

This plugin searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames.

Active installs8K+5K+ tier
Downloads · 30d324▲ +12.5% vs prev. 30d
Rating3.2/540 reviews
Health score37/100At risk
All-time downloads1.1MSince Jun 2008
Support resolved—No recent threads
RequiresWP 3.3PHP any
Downloads · 7d86▼ -5.5% week over week
Our verdict

Consider an alternative

Exploit Scanner shows warning signs in 2026 — compare the alternatives below before installing. It runs on 8K+ sites, is rated 3.2/5 and was last updated 9 years ago, and scores 37/100 on our health check.

  • Mixed reviews — 3.2/5 from 40 ratings
  • No update in 8 years
  • Only tested up to WordPress 4.7 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

61218Jun 28Aug 11Sep 25
Yesterday15
Daily average (1y)8
Peak day25Apr 28, 2026
Last 12 months2.8K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Exploit Scanner stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
hack >100 405 Best hack plugins →
hacking #88 140 Best hacking plugins →
scanner >100 1,321 Best scanner plugins →
security >100 10,000 Best security plugins →
spam >100 3,497 Best spam plugins →

Version adoption

Share of active sites per release.

  • 1.586.3%
  • 1.37.0%
  • 1.45.9%
  • Other0.80%

Rating breakdown

★★★★★★★★★★ 3.2 from 40 reviews

  • 5★45.0%
  • 4★10.0%
  • 3★2.5%
  • 2★7.5%
  • 1★35.0%

About Exploit Scanner

From the official readme · v1.5.2

Description

This plugin searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames.

It does not remove anything. That is left to the user to do.

Latest MD5 hash values for Exploit Scanner:

  • 17e2ccfc834d691bc68cc5c64f9bed89 exploit-scanner.php (1.5.2)
  • 1d5f9d6220fe159cd44cb70a998a1cd7 hashes-4.6.php
  • fbdf61c17f65094c8e331e1e364acf68 hashes-4.6.1.php
  • 477d128d84802e3470cec408424a8de3 hashes-4.7.php
  • d53210f999847fbd6f5a2ecac0ad42f2 hashes-4.7.5.php

Latest SHA1 hash values for Exploit Scanner:

  • 1decc1e47a53d1cab9e8f1ef15b31682198367ee exploit-scanner.php (1.5.2)
  • 5cec64380a2acdc876fd22fbbbbf8c335df1ed3f hashes-4.6.php
  • 99d9e7be23a350f3d1962d0f41e7b4e28c00841e hashes-4.6.1.php
  • 1eeab377a1afc6d776827a063678d2461b29e71d hashes-4.7.php
  • 8c890a6af26bb74e9d17e5d2b21d6be27764da45 hashes-4.7.5.php

See the Exploit Scanner homepage for further information.

Interpreting the Results

It is likely that this scanner will find false positives (i.e. files which do not contain malicious code). However, it is best to err
on the side of caution; if you are unsure then ask in the Support Forums,
download a fresh copy of a plugin, search the Internet for similar situations, et cetera. You should be most concerned if the scanner is:
making matches around unknown external links; finding base64 encoded text in modified core files or the wp-config.php file;
listing extra admin accounts; or finding content in posts which you did not put there.

Understanding the three different result levels:

  • Severe: results that are often strong indicators of a hack (though they are not definitive proof)
  • Warning: these results are more commonly found in innocent circumstances than Severe matches, but they should still be treated with caution
  • Note: lowest priority, showing results that are very commonly used in legitimate code or notifications about events such as skipped files

Help! I think I have been hacked!

Follow the guides from the Codex:

Ensure that you change all of your WordPress related passwords (site, FTP, MySQL, etc.). A regular backup routine
(either manual or plugin powered) is extremely useful; if you ever find that your site has been hacked you can easily restore your site from
a clean backup and fresh set of files and, of course, use a new set of passwords.

Updates

Updates to the plugin will be posted here, to Holy Shmoly! and the WordPress Exploit Scanner page will always link to the newest version.

Other Languages

Unfortunately for people using WordPress versions for other locales some of the file hashes may be incorrect as some strings have to be hardcoded in their translated form. Here are some file hashes for WordPress in other languagues provided separately by other members of the community:

The hash files should only be declaring an array called $filehashes and the majority of the hashes should still be the same.

Installation

  1. Download and unzip the plugin.
  2. Copy the exploit-scanner directory into your plugins folder.
  3. Visit your Plugins page and activate the plugin.
  4. A new menu item called “Exploit Scanner” will be available under the Tools menu.

Changelog

Added hashes for WordPress 4.7.5

1.5.2

  • Added hashes for WordPress 4.7.5

1.5.1

  • WordPress 4.6 hashes
  • WordPress 4.6.1 hashes
  • WordPress 4.7 hashes

1.5

  • WordPress 4.5.3 hashes
  • Move to follow WP versioning system

1.4.12

  • WordPress 4.5.2 hashes

1.4.11

  • WordPress 4.5 hashes
  • WordPress 4.5.1 hashes

1.4.10

  • WordPress 4.4.1 hashes

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Exploit Scanner alternatives

All hack plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 WPScan – WordPress Security Scanner WPScan – WordPress Security Scanner WPScan WordPress Security Scanner - Scans your system for security vulnerabilities listed… by ethicalhack3r 8K+ ★★★★★★★★★★ 3.8 (28) 9 months ago 55
3 WPDoctor Malware Scanner & Vulnerability Checker & IP blocker with Hack monitor Lite WPDoctor Malware Scanner & Vulnerability Checker & IP block… This plug-in can exhaustively scan program files on the site to detect malware and… by WP Doctorワードプレスドクター 600+ ★★★★★★★★★★ No reviews 2 years ago 30
4 WP Guardian WP Guardian An easy way to harden your website's security effectively. by Ciprian Popescu 90+ ★★★★★★★★★★ 5 (1) 2 weeks ago 75
5 Smart Copy Protect Smart Copy Protect Simple and Amazing wordpress copy protect plugin. This plugin will be able to block the… by Sumon Hasan 60+ ★★★★★★★★★★ 4 (4) 7 years ago 29
6 MW WP Hacks MW WP Hacks MW WP Hacks is plugin to help with development in WordPress. by Takashi Kitajima 60+ ★★★★★★★★★★ 4 (2) 12 years ago 29
7 WP-Sentinel WP-Sentinel A wordpress security system plugin which will check every HTTP request against a given set… by evilsocket 60+ ★★★★★★★★★★ 2.6 (5) 15 years ago 27
8 Secure Uploads Secure Uploads This plugin will put blank index.php in every sub-directory of your wp-content/uploads… by njkuiper6 40+ ★★★★★★★★★★ 1 (1) 10 years ago 19
9 WP Smart Security WP Smart Security WP Smart Security is a comprehensive and easy to use WordPress security plugin. It gives… by bulktheme 20+ ★★★★★★★★★★ 5 (1) 11 years ago 31
10 Exploit Scanner for Active Theme Exploit Scanner for Active Theme Detects whether your theme files have fallen victim to malicious hackers. by Tauno Hanni 20+ ★★★★★★★★★★ No reviews 10 years ago 24
11 Hack-Info Hack-Info Ext Security. Monitoring about evil hacking attempts and block IP via htaccess. Our reports… by wpgear 10+ ★★★★★★★★★★ No reviews 4 days ago 66

FAQ

Exploit Scanner: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 26, 2026

Is Exploit Scanner free?

Yes. Exploit Scanner is free to download and use from the official WordPress.org plugin directory.

Is Exploit Scanner safe to use in 2026?

Exploit Scanner shows warning signs in 2026 — compare the alternatives below before installing. It runs on 8K+ sites, is rated 3.2/5 and was last updated 9 years ago, and scores 37/100 on our health check.

How many websites use Exploit Scanner?

Exploit Scanner is active on 8K+ WordPress websites and has been downloaded 1,068,981 times since it launched in June 2008. It was downloaded 324 times in the last 30 days.

Does Exploit Scanner work with WordPress 7.1?

Exploit Scanner is officially tested up to WordPress 4.7.37, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

When was Exploit Scanner last updated?

The latest version, 1.5.2, was released on November 28, 2017 (9 years ago).

Who makes Exploit Scanner?

Exploit Scanner is developed and maintained by Donncha O Caoimh (a11n).

What are the best alternatives to Exploit Scanner?

The most popular alternatives to Exploit Scanner are WPScan (8K+ installs), WPDoctor Malware Scanner &… (600+ installs) and WP Guardian (90+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.