Malware Scanner & Rescue Center

Find suspicious changes. Inspect the evidence. Recover safely.

Watchdog Security Suite PRO combines local malware scanning, evidence-rich findings, quarantine and repair workflows so administrators can respond without blindly deleting active website files.

Local-first scanningEvidence viewerQuarantine & restore

Rescue analysis console
WDC-SCAN / LOCAL
SCAN ACTIVEEvidence enabled
High-confidence rogue PHP fileSuspicious behavior and risky location produced a strong verdict.
Quarantine
Injected code requires reviewEvidence is available before any repair decision is made.
Review
Core integrity repair availableOfficial WordPress package can be used for controlled replacement.
Repairable
More than one signature

Malware decisions become stronger when several signals agree.

Watchdog does not rely on one filename or one pattern alone. Findings can combine malware signatures, repository differences, dangerous behavior, suspicious locations, obfuscation and other contextual evidence.

File malware scanning

Scan WordPress files for suspicious code patterns, known malware behavior and high-risk characteristics.

  • Local file inspection
  • Severity and confidence classification
  • Safer false-positive handling

Database malware checks

Inspect stored content and configuration areas for known malicious patterns without treating every unusual value as malware.

  • Known-pattern detection
  • Review-first cleanup approach
  • Evidence for safer remediation

WP-Cron inspection

Review scheduled WordPress tasks for suspicious hooks, unexpected execution and persistence behavior.

  • Scheduled-task visibility
  • Persistence-oriented review
  • Context alongside other findings

Repository integrity comparison

Compare supported WordPress core, plugin and theme files against clean official packages where verification is available.

  • Official WordPress core packages
  • WordPress.org plugin and theme comparison
  • Premium and custom code handled cautiously
Evidence before action

Understand why a file was flagged.

Supported findings can expose the information an administrator needs to make a safer decision instead of presenting only a red warning and a delete button.

Detection detailsSignature, category, severity, confidence and recommended action.
Package contextFile path, component information and repository-verification status.
Safe code snippetA limited escaped snippet around the matched pattern with the relevant part highlighted.
Secret-aware presentationLarge, unreadable or sensitive content is not exposed blindly.

Finding evidence

A compact example of the context the Rescue Center can present before a cleanup action.

wp-content/uploads/cache.phpHIGH CONFIDENCE
18  $payload = $_POST['data'] ?? ";
19  if ($payload)
22  // snippet limited and safely escaped
Rescue workflow

Quarantine first. Preserve a path back.

High-confidence rogue files can move into a protected quarantine workflow instead of being permanently deleted from an active site.

Review the finding

Inspect severity, confidence, file location, package context and the available evidence.

Quarantine safely

Move a high-confidence rogue file out of execution while retaining recovery information.

Verify the website

Check site behavior, compare clean sources and decide whether repair or restoration is appropriate.

Restore or remove

Recover the quarantined file when needed or complete removal after review and confirmation.

Evidence-based repair paths

Use the cleanest available source for the type of damage found.

Not every infected file should be handled the same way. Watchdog separates repairable official packages from custom code and injected legitimate files.

Official source

WordPress core repair

Replace damaged or modified core files from an official WordPress package when clean comparison is available.

Controlled restoration rather than arbitrary replacement.

Repository verified

Plugin & theme integrity repair

Compare supported WordPress.org packages and restore clean files where package verification is possible.

Premium and custom components are not assumed to match public packages.

Assisted cleanup

Injected legitimate files

When malware is embedded inside a valid active file, the safer path is evidence-guided review rather than blind deletion.

Preserves functionality and keeps the administrator in control.

Local-first protection

Routine scanning stays on the WordPress site.

Watchdog's current malware workflow is privacy-conscious and local-first. Routine scanning does not require uploading the complete website to a third-party cloud for analysis.

No required full-site cloud upload
Future direction

Optional cloud assistance—not mandatory replication.

A future cloud-assisted layer may allow suspicious hashes, snippets or selected files to be submitted for deeper review. The intended direction is explicit opt-in and limited submission.

Operational record

Cleanup should leave evidence, history and accountability.

Rescue actions connect with the wider Watchdog workflow so administrators can understand what was found, what action was taken and whether a rollback path still exists.

Quarantine VaultProtected storage with restore and controlled deletion options.
Cleanup historyReview previous Rescue Center actions and their outcome.
Finding evidenceInspect confidence, matched behavior and package context.
Rescue reportsPreserve a clearer record of security remediation work.

Scan. Understand. Recover.

Malware response should be evidence-based, reversible and appropriate for a live WordPress site.

Watchdog Security Suite PRO combines local scanning, repository intelligence, evidence panels, quarantine and controlled repair workflows inside one WordPress security suite.