Sentryvine — Antivirus & Anti-Phishing Security
Scan WordPress files and published content for malware indicators, core integrity changes, and phishing risks.
Use with caution
Sentryvine works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Sentryvine stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| anti-phishing | #3 |
| antivirus | #12 |
| integrity | >100 |
| malware scanner | >100 |
| security | >100 |
About Sentryvine
From the official readme · v0.1.0Description
Sentryvine provides a conservative, review-first security scan from the WordPress administration area.
The initial release includes:
- Local inspection of executable and redirect-capable files for high-signal malware patterns.
- Detection of executable PHP files in the uploads directory.
- Anti-phishing analysis for deceptive link text, raw IP destinations, embedded URL credentials, Punycode hosts, encoded control characters, dangerous URI schemes, and external password forms.
- Optional WordPress core integrity verification against official checksums.
- Manual scans and daily WP-Cron scans.
- Bounded scan reports with severity, evidence, location, and recommended review actions.
Sentryvine does not automatically delete, edit, or quarantine files or content. Findings are indicators for an administrator to review; they are not proof that a site is compromised. A scan with no findings does not guarantee that a site is safe.
External services
By default, Sentryvine scans locally and does not send site files or content to an external service.
If an administrator enables “Verify WordPress core checksums,” each scan uses WordPress core’s checksum function to contact https://api.wordpress.org/core/checksums/1.0/. The request includes the installed WordPress version and locale so the service can return the matching official file hashes. WordPress HTTP requests may also include the standard WordPress user-agent. No site files, post content, detected URLs, or scan findings are sent.
This service is operated by the WordPress project. See the WordPress.org privacy policy and terms of service.
Installation
- Upload the
sentryvinedirectory to/wp-content/plugins/, or install the release ZIP through Plugins > Add New > Upload Plugin. - Activate Sentryvine through the Plugins screen.
- Open Sentryvine in the WordPress administration menu.
- Review the settings and select “Run scan now.”
Daily scans use WP-Cron and may run later than scheduled on sites with little or no traffic.
Frequently asked questions
Does Sentryvine remove malware automatically?
No. Version 0.1.0 is intentionally review-only. Automatic remediation can damage a site when a heuristic produces a false positive.
Does Sentryvine send my files or content elsewhere?
No. File and content inspection runs locally. The optional core checksum feature contacts only the official WordPress.org checksum service as described above.
Is a clean result proof that my site is secure?
No. Sentryvine detects a defined set of indicators. Use layered controls, reliable backups, updates, least-privilege access, server monitoring, and professional incident response when compromise is suspected.
Changelog
0.1.0
- Initial private MVP.
- Added bounded local file scanning and optional WordPress core checksum verification.
- Added local anti-phishing content analysis.
- Added manual and daily scheduled scans with an administrator dashboard.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Sentryvine alternatives
All anti-phishing plugins →| Rank | Plugin | Active installs |
|---|---|---|
| 1 |
|
<10 |
FAQ
Sentryvine: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 7, 2026
Is Sentryvine free?
Yes. Sentryvine is free to download and use from the official WordPress.org plugin directory.
Is Sentryvine safe to use in 2026?
Sentryvine works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
How many websites use Sentryvine?
Sentryvine is active on <10 WordPress websites and has been downloaded 149 times since it launched in August 2026. It was downloaded 74 times in the last 30 days.
Does Sentryvine work with WordPress 7.1?
Yes. The developer has tested Sentryvine up to WordPress 7.1.3, the latest release. It requires WordPress 6.4 or newer.
What PHP version does Sentryvine need?
Sentryvine requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Sentryvine last updated?
The latest version, 0.1.0, was released on August 26, 2026 (1 month ago).
Who makes Sentryvine?
Sentryvine is developed and maintained by sentryvine.
What are the best alternatives to Sentryvine?
The most popular alternatives to Sentryvine are Holovid® Secure Connect (<10 installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card