E
Security Free WordPress.org

Exploit Scanner

3.2 (40 reviews)
· 8K+ active installs · By Donncha O Caoimh (a11n)
Active Installs
8K+
Rating
3.2 / 5
Version
v1.5.2
Last Updated
Nov 2017
Share

Plugin Review

AI-Researched

What is Exploit Scanner?

Exploit Scanner is a free WordPress plugin designed to search your site for signs of a hack. It scans files on your server, plus your posts and comments database tables, for anything suspicious. The plugin also checks active plugin filenames for unusual patterns. It does not remove anything — it only reports findings for you to review.

Developed by Donncha O Caoimh (a11n), this plugin has been around for 18 years. That makes it one of the oldest security tools in the WordPress repository. Despite its age, it currently has 8K+ active installs. Its rating sits at 3.2/5 from 40 ratings, with 45% 35% one-star reviews. The last update was Nov 28, 2017.

Key Features of Exploit Scanner

  • File system scanning: Searches all website files for suspicious strings, base64 encoded text, and unknown external links.
  • Database scanning: Checks posts and comments tables for injected content or spam you did not create.
  • Active plugin review: Examines your list of active plugins for filenames that look unusual or potentially malicious.
  • Three-tier result levels: Results are labeled Severe, Warning, or Note to help you prioritize what to investigate.
  • Core file hash verification: Includes MD5 and SHA1 hashes for WordPress core files (versions 4.6 through 4.7.5) to detect modified core files.
  • Adjustable memory limit: You can increase PHP memory allocation from the plugin admin page if scans run out of memory.
  • Max file size control: Set a limit on scanned file size to skip large files, with skipped files listed after the scan.
  • False positive guidance: The plugin explains common false positive scenarios and advises caution when interpreting results.

Who Should Use Exploit Scanner?

This plugin suits site owners who want a hands-on wordpress hack scanner. You need some technical comfort — the plugin reports findings but expects you to investigate and remove threats yourself. It works best for small to medium sites where you can manually review flagged files. With 8K+ installs, it appeals to users who prefer a lightweight, no-frills security scan over automated cleanup tools.

If you are wondering how to check if wordpress site is hacked, Exploit Scanner gives you a starting point. It is not a real-time monitor or firewall. Use it as a diagnostic tool when you suspect a breach. The 45% five-star rating suggests many users find it useful for basic checks. The 35% one-star rating likely reflects its age and lack of updates since Nov 28, 2017.

Installation & Setup

Installation follows the standard WordPress plugin process. Download the zip, upload it, and activate from your Plugins page. A new menu item appears under Tools called “Exploit Scanner.” Beginners can run a scan immediately with default settings. Advanced users can adjust memory limits and max file sizes from the plugin admin page to handle larger sites.

Support & Community

Support data shows a concerning picture. Over the last 2 months, the plugin has 0 open threads and 0 resolved threads — a 0% resolution rate. This likely reflects the fact that the plugin has not been updated since Nov 28, 2017. Users seeking help for false positives or scan issues may find no active support.

The rating breakdown tells a divided story. With 45% five-star ratings, many users appreciate its straightforward approach to a wordpress security scan. But 35% one-star ratings indicate significant dissatisfaction. For those seeking the best wordpress security scanner plugin with active maintenance, newer alternatives exist. If you want to scan wordpress files for malware without relying on developer support, Exploit Scanner still works — but proceed with awareness of its dormant status.

Pros & Cons

What's Good
  • With 8K+ active installs, it provides a free, lightweight method to scan WordPress files and database tables for suspicious code and links.
  • It offers three severity levels (Severe, Warning, Note) to help users prioritize potential threats, with Severe matches often indicating strong hack indicators.
  • The plugin includes MD5 and SHA1 hash files for multiple WordPress versions (4.6 through 4.7.5) to verify core file integrity.
  • It explicitly does not remove any files, giving users full control over remediation decisions.
  • 45% of its 40 ratings are 5-star, suggesting it meets the needs of many site owners for basic exploit detection.
Drawbacks
  • 35% of its 40 ratings are 1-star, indicating significant user dissatisfaction, likely due to frequent false positives.
  • It has 0 total support threads and 0 resolved threads, meaning users have no official support channel for issues or questions.
  • The plugin only scans for suspicious patterns but cannot fix or quarantine threats, requiring manual intervention for any findings.

Technical Details

Requires WordPress
3.3+
Tested up to WP
4.7.33
First Released
2008 (18+ years)
Support (last 2 months)
0 threads

Feature Tags

hack hacking scanner security spam

Frequently Asked Questions