Skip to content

Security

wp-full-site-scan

Scan and recover a hacked WordPress site

Scans a hacked WordPress site across files and database, finds the entry point, cleans copies, restores safely and closes the way back in.

Area
Security
Checked against
WordPress 7.1.2, WP-CLI 2.12.0
Last verified
28 September 2026
Files
SKILL.md, 12 references, 10 scripts

How it works

  1. 1Collect the complete file set, database dump and owner approval.
  2. 2Build a separate workspace with copied files and a throwaway database.
  3. 3Verify official checksums, then scan files, scripts and external hosts.
  4. 4Scan the database for injected content, users, sessions, cron jobs and settings.
  5. 5Build a dated timeline and identify the entry point with stated confidence.
  6. 6Clean files and database together on copies, then verify the clean set.
  7. 7Restore with approval, check the site, harden the entry point and write the report.

Use it when

  • Investigate redirects, spam pages, warnings or unknown administrators.
  • Trace malware that returns after earlier cleanup.
  • Check suspected checkout skimmers, spam mail or phishing files.
  • Recover a site after a host reports malware.

How it stays safe

  • Works on copies and keeps the original files and database unchanged until restore.
  • Reads suspect code as text and avoids running the site's own code.
  • Quarantines removed files with their paths preserved for evidence and rollback.
  • Backs up the live site and gets owner approval before each restore or hardening step.

Install it

Copy the whole wp-full-site-scan folder into your agent's skills folder, not only SKILL.md.

git clone --depth 1 https://github.com/hamzaahmadaslam/agent-skills.git
cp -R agent-skills/wp-full-site-scan "<your agent's skills folder>/"

More skills in the collection

All 11 skills