The plugin looks in WordPress upload and cache storage for executable PHP or a file that disguises PHP behind a non-executable extension.
WordPress malware scanner with a safer cleanup route.
Scan the site where the files live. Lofts Security Center checks high-risk writable paths locally, shows the evidence behind a finding, and lets an administrator quarantine one eligible file with a restore route.
No FTP. No remote shell. No automatic bulk deletion. The tool does not call a clean result a security guarantee.
Useful signals, not security theater.
When checksums are available, it compares core files with WordPress.org records. A mismatch stays review-only: the right next step is an update or clean reinstall after a backup.
The self-service scanner does not upload site files. The signup shares only the contact details and site address you provide to Lofts.
A safer WordPress malware cleanup order.
“Malware removal” should not mean deleting anything that looks unusual. This tool is deliberately narrow: it gives the WordPress administrator a reviewable, reversible path for a single eligible file.
See Lofts WordPress security care- Install inside WordPress.Upload the plugin ZIP from the admin area. The local safety scan works without a Lofts account, API key, FTP login, or Lofts control-plane connection.
- Read the finding before acting.Confirm the file path, the evidence, and whether it belongs to the site. A suspicious signal is a prompt for review, not proof by itself.
- Quarantine one approved file.For an eligible writable-path finding, the plugin moves the reviewed file into protected local quarantine and changes its extension so it is no longer executable in place.
- Verify, then restore only if needed.Check the site after the local action. If the exact file must return, the plugin verifies the quarantined copy before offering a safe restore path.