Security
wp-full-site-scan
Scan and recover a hacked WordPress site
Scans a hacked WordPress site across files and database, finds the entry point, cleans copies, restores safely and closes the way back in.
- Area
- Security
- Checked against
- WordPress 7.1.2, WP-CLI 2.12.0
- Last verified
- 28 September 2026
- Files
- SKILL.md, 12 references, 10 scripts
How it works
- 1Collect the complete file set, database dump and owner approval.
- 2Build a separate workspace with copied files and a throwaway database.
- 3Verify official checksums, then scan files, scripts and external hosts.
- 4Scan the database for injected content, users, sessions, cron jobs and settings.
- 5Build a dated timeline and identify the entry point with stated confidence.
- 6Clean files and database together on copies, then verify the clean set.
- 7Restore with approval, check the site, harden the entry point and write the report.
Use it when
- Investigate redirects, spam pages, warnings or unknown administrators.
- Trace malware that returns after earlier cleanup.
- Check suspected checkout skimmers, spam mail or phishing files.
- Recover a site after a host reports malware.
How it stays safe
- Works on copies and keeps the original files and database unchanged until restore.
- Reads suspect code as text and avoids running the site's own code.
- Quarantines removed files with their paths preserved for evidence and rollback.
- Backs up the live site and gets owner approval before each restore or hardening step.
Install it
Copy the whole wp-full-site-scan folder into your agent's skills folder, not only SKILL.md.
git clone --depth 1 https://github.com/hamzaahmadaslam/agent-skills.git
cp -R agent-skills/wp-full-site-scan "<your agent's skills folder>/"