Exploit Scanner
Plugin Review
AI-ResearchedWhat is Exploit Scanner?
Exploit Scanner is a free WordPress plugin designed to search your site for signs of a hack. It scans files on your server, plus your posts and comments database tables, for anything suspicious. The plugin also checks active plugin filenames for unusual patterns. It does not remove anything — it only reports findings for you to review.
Developed by Donncha O Caoimh (a11n), this plugin has been around for 18 years. That makes it one of the oldest security tools in the WordPress repository. Despite its age, it currently has 8K+ active installs. Its rating sits at 3.2/5 from 40 ratings, with 45% 35% one-star reviews. The last update was Nov 28, 2017.
Key Features of Exploit Scanner
- File system scanning: Searches all website files for suspicious strings, base64 encoded text, and unknown external links.
- Database scanning: Checks posts and comments tables for injected content or spam you did not create.
- Active plugin review: Examines your list of active plugins for filenames that look unusual or potentially malicious.
- Three-tier result levels: Results are labeled Severe, Warning, or Note to help you prioritize what to investigate.
- Core file hash verification: Includes MD5 and SHA1 hashes for WordPress core files (versions 4.6 through 4.7.5) to detect modified core files.
- Adjustable memory limit: You can increase PHP memory allocation from the plugin admin page if scans run out of memory.
- Max file size control: Set a limit on scanned file size to skip large files, with skipped files listed after the scan.
- False positive guidance: The plugin explains common false positive scenarios and advises caution when interpreting results.
Who Should Use Exploit Scanner?
This plugin suits site owners who want a hands-on wordpress hack scanner. You need some technical comfort — the plugin reports findings but expects you to investigate and remove threats yourself. It works best for small to medium sites where you can manually review flagged files. With 8K+ installs, it appeals to users who prefer a lightweight, no-frills security scan over automated cleanup tools.
If you are wondering how to check if wordpress site is hacked, Exploit Scanner gives you a starting point. It is not a real-time monitor or firewall. Use it as a diagnostic tool when you suspect a breach. The 45% five-star rating suggests many users find it useful for basic checks. The 35% one-star rating likely reflects its age and lack of updates since Nov 28, 2017.
Installation & Setup
Installation follows the standard WordPress plugin process. Download the zip, upload it, and activate from your Plugins page. A new menu item appears under Tools called “Exploit Scanner.” Beginners can run a scan immediately with default settings. Advanced users can adjust memory limits and max file sizes from the plugin admin page to handle larger sites.
Support & Community
Support data shows a concerning picture. Over the last 2 months, the plugin has 0 open threads and 0 resolved threads — a 0% resolution rate. This likely reflects the fact that the plugin has not been updated since Nov 28, 2017. Users seeking help for false positives or scan issues may find no active support.
The rating breakdown tells a divided story. With 45% five-star ratings, many users appreciate its straightforward approach to a wordpress security scan. But 35% one-star ratings indicate significant dissatisfaction. For those seeking the best wordpress security scanner plugin with active maintenance, newer alternatives exist. If you want to scan wordpress files for malware without relying on developer support, Exploit Scanner still works — but proceed with awareness of its dormant status.
Pros & Cons
- With 8K+ active installs, it provides a free, lightweight method to scan WordPress files and database tables for suspicious code and links.
- It offers three severity levels (Severe, Warning, Note) to help users prioritize potential threats, with Severe matches often indicating strong hack indicators.
- The plugin includes MD5 and SHA1 hash files for multiple WordPress versions (4.6 through 4.7.5) to verify core file integrity.
- It explicitly does not remove any files, giving users full control over remediation decisions.
- 45% of its 40 ratings are 5-star, suggesting it meets the needs of many site owners for basic exploit detection.
- 35% of its 40 ratings are 1-star, indicating significant user dissatisfaction, likely due to frequent false positives.
- It has 0 total support threads and 0 resolved threads, meaning users have no official support channel for issues or questions.
- The plugin only scans for suspicious patterns but cannot fix or quarantine threats, requiring manual intervention for any findings.
Technical Details
- Requires WordPress
- 3.3+
- Tested up to WP
- 4.7.33
- First Released
- 2008 (18+ years)
- Support (last 2 months)
- 0 threads
Feature Tags
Frequently Asked Questions
Yes, Exploit Scanner is completely free and available on WordPress.org. It was first released in 2008 and is currently at version 1.5.2.
Exploit Scanner has 8K+ active installs and is rated 3.2/5 based on 40 ratings. It has been available since 2008.
Exploit Scanner requires WordPress 3.3 or higher and has been tested up to WordPress 4.7.33. It was last updated on Nov 28, 2017.
Exploit Scanner was last updated on Nov 28, 2017 and is currently at version 1.5.2. It has 0 support threads in the last 2 months, indicating limited recent maintenance activity.
The plugin facts do not specify a required PHP version, but it works with WordPress 3.3+ and was tested up to WordPress 4.7.33. You may need to allocate at least 128MB of memory for scanning.
Support threads for Exploit Scanner show 0 total and 0 resolved in the last 2 months. The plugin's author recommends asking in the Support Forums or searching online if you find suspicious results.
Exploit Scanner is suitable for beginners who are cautious, as it only scans and reports suspicious files without removing anything. However, it may produce false positives, so you should be comfortable interpreting results or seeking help in the Support Forums.
The plugin scans your website files, posts and comments tables, and active plugins for suspicious content like base64 encoded text or unknown external links. It does not remove anything and lets you decide what to do with flagged items.