WordPress malware scanner with a safer cleanup route.

Scan the site where the files live. Lofts Security Center checks high-risk writable paths locally, shows the evidence behind a finding, and lets an administrator quarantine one eligible file with a restore route.

No FTP. No remote shell. No automatic bulk deletion. The tool does not call a clean result a security guarantee.

Useful signals, not security theater.

High-risk writable paths

The plugin looks in WordPress upload and cache storage for executable PHP or a file that disguises PHP behind a non-executable extension.

WordPress core integrity

When checksums are available, it compares core files with WordPress.org records. A mismatch stays review-only: the right next step is an update or clean reinstall after a backup.

Evidence stays local

The self-service scanner does not upload site files. The signup shares only the contact details and site address you provide to Lofts.

A safer WordPress malware cleanup order.

“Malware removal” should not mean deleting anything that looks unusual. This tool is deliberately narrow: it gives the WordPress administrator a reviewable, reversible path for a single eligible file.

See Lofts WordPress security care
  1. Install inside WordPress.Upload the plugin ZIP from the admin area. The local safety scan works without a Lofts account, API key, FTP login, or Lofts control-plane connection.
  2. Read the finding before acting.Confirm the file path, the evidence, and whether it belongs to the site. A suspicious signal is a prompt for review, not proof by itself.
  3. Quarantine one approved file.For an eligible writable-path finding, the plugin moves the reviewed file into protected local quarantine and changes its extension so it is no longer executable in place.
  4. Verify, then restore only if needed.Check the site after the local action. If the exact file must return, the plugin verifies the quarantined copy before offering a safe restore path.

Before you run a WordPress malware scan.

Can this WordPress malware scanner remove malware automatically? +
No. Lofts Security Center does not automatically delete files. It flags conservative local evidence, then lets a WordPress administrator quarantine one reviewed eligible file at a time while keeping a restore route.
Does the WordPress malware scanner upload my files? +
No. The self-service scan and quarantine workflow run inside WordPress on the site's own server. The signup form shares contact details and a website address with Lofts, but not site files.
What does the Lofts WordPress malware scanner check? +
It checks high-risk writable upload and cache paths for executable or disguised PHP, and compares available WordPress core files against WordPress.org checksums. A clean result is never a guarantee that a website is secure.
Do I need a Lofts account to use the cleanup tool? +
No. The short signup gives Lofts enough context to support the request and then shows the plugin download. The local scanning and quarantine route does not require a Lofts account or Lofts control-plane connection.