Threat Scan Plugin
This is a very simple threat scan that looks for things out of place in the content directory as well as the database.
Consider an alternative
Threat Scan Plugin shows warning signs in 2026 — compare the alternatives below before installing. It runs on 400+ sites, is rated 5/5 and was last updated 2 years ago, and scores 34/100 on our health check.
- Small user base (400+ active installs)
- Very few reviews so far
- No update in 2 years
- Only tested up to WordPress 6.6 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Threat Scan Plugin stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| hacked | #28 |
| Malicious code | #68 |
| scan | >100 |
| Threats | #49 |
| virus | #21 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About Threat Scan Plugin
From the official readme · v1.4Description
This is a very simple threat scan that looks for things out of place in the content directory as well as the database.
It searches PHP files for the occurrence of the eval() function, which, although a valuable part of PHP is also the door that hackers use in order to infect systems. The eval() function is avoided by many programmers unless there is a real need. It is sometimes used by hackers to hide their malicious code or to inject future threats into infected systems. If you find a theme or a plugin that uses the eval() function it is safer to delete it and ask the author to provide a new version that does not use this function.
When you scan your system you undoubtedly see the eval used in javascript because it is used in the javascript AJAX and JSON functionality. The appearance of eval in these cases does not mean that there is a possible threat. It just means that you should inspect the code to make sure that it is in a javascript section and not native PHP.
The plugin continues its scan by checking the database tables for javascript or html where it should not be found.
Normally, javascript is common in the post body, but if the script tag is found in a title or a text field where it does not belong it is probably because the script is hiding something, such as a hidden admin user, so that the normal administration pages do not show bad records. The scan looks for this and displays the table and record number where it believes there is something hinky.
The scan continues looking in the database for certain html in places where it does not belong. Recent threats have been putting html into fields in the options table so that users will be sent to malicious sites. The presence of html in options values is suspect and should be checked.
The options table will have things placed there by plugins so it is difficult to tell if scripts, iframes, and other html tags are a threat. They will be reported, but they should be checked before deleting the entries.
This plugin is just a simple scan and does not try to fix any problems. It will show things that may not be threats, but should be checked. If anything shows up you should try to repair the damage or hire someone to do it. I am not a security expert, but a programmer who discovered these types of things in a friend’s blog. After many hours of checking I was able to fix the problem, but a professional could have done it faster and easier, although they would have charged for it.
You probably do not have a backup to your blog, so if this scan shows you are clean; your next step is to install one of the plugins that does regular backups of your system. Next make sure you have the latest WordPress version.
If you think you have problems, the first thing to do is change your user id and password. Next make a backup of the infected system. Any repairs to WordPress might delete important data so you might lose posts, and the backup will help you recover missing posts.
The next step is to install the latest version of WordPress. The new versions usually have fixes for older threats.
You may want to export your WordPress posts, make a new clean installation of WordPress, and then import the old posts.
If this doesn’t work it is time to get a pro involved.
A clean scan does not mean you are safe. Please do Backups and keep your installation up to date!
Support
This plugin is in active development. All feedback is welcome.
If this plugin helps you, you might support my programming by buying
one of my books: https://linktr.ee/keithpgraham
Installation
- Download the plugin.
- Upload the plugin to your wp-content/plugins directory.
- Activate the plugin.
- There are no options. Clicking on the Settings link will perform the scan.
Changelog
1.3
- Updated for newer versions of WordPress 5.7.1 and PHP
1.2
- Updated for newer versions of WordPress 5.4.1 and PHP
1.1
- Updated for newer versions of WordPress and PHP
1.0
- Added more detailed information
- Confirmed compatibility with WordPress 3.5
0.9
- Fix small errors and compatibility with WordPress 3.0
0.8
- First test release
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Threat Scan Plugin alternatives
All hacked plugins →FAQ
Threat Scan Plugin: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 9, 2026
Is Threat Scan Plugin free?
Yes. Threat Scan Plugin is free to download and use from the official WordPress.org plugin directory.
Is Threat Scan Plugin safe to use in 2026?
Threat Scan Plugin shows warning signs in 2026 — compare the alternatives below before installing. It runs on 400+ sites, is rated 5/5 and was last updated 2 years ago, and scores 34/100 on our health check.
How many websites use Threat Scan Plugin?
Threat Scan Plugin is active on 400+ WordPress websites and has been downloaded 29,688 times since it launched in April 2010. It was downloaded 117 times in the last 30 days.
Does Threat Scan Plugin work with WordPress 7.1?
Threat Scan Plugin is officially tested up to WordPress 6.6.10, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
When was Threat Scan Plugin last updated?
The latest version, 1.4, was released on July 14, 2024 (2 years ago).
Who makes Threat Scan Plugin?
Threat Scan Plugin is developed and maintained by Keith P. Graham.
What are the best alternatives to Threat Scan Plugin?
The most popular alternatives to Threat Scan Plugin are Batch REST Guard (100+ installs), Cleverhog Malware Scanner (80+ installs) and Segurium (80+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card