Compromise Scanner for wp2shell
by eyesecurity 5 (2 reviews)

Compromise Scanner for wp2shell

Read-only forensic scanner for the WordPress core exploit chain CVE-2026-63030 / CVE-2026-60137 (wp2shell). Reports a scored verdict; changes nothing.

Compromise Scanner for wp2shell ranks #4,139 among WordPress.org plugins with 3,000+ active installations, is #306 of 4,555 in the Security category, a 5/5 rating from 2 reviews, and was last updated Jul 20, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.5 (Current: 7.1.1)
v1.1.0 Current Version v1.1.0
Updated 2 months ago Last Update on 20 Jul, 2026
Refreshed 9 hours ago Last Refreshed on
#306 of 4,555 in Security Top 5% by installs Downloads -31.4% this week
View on WordPress.org
Rank
#4,139
No change
Active Installs
3K+
+0.6%
KW Avg Position
52.3
0.3 worse
Downloads
7.4K
+22 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (2 reviews)

Next Milestone 4K

Total Progress 79.8%
3K+ 4K+
497
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 202 more installs to reach 4K+

Rank Changes

4,134 4,149 4,163 4,177 4,192 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
4,134 4,149 4,164 4,178 4,193 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Current #4,139
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

10 20 30 40 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
10 20 30 40 50 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
2 reviews
Overall 100%
5
2 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for Compromise Scanner for wp2shell. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners and administrators who want to check whether their site has been compromised by the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137). It performs a read-only forensic scan of the database and plugin directory for artifacts left by the exploit and produces a scored verdict without modifying the site or patching the vulnerability.

  • Read-only forensic scanning
  • Scored compromise verdict
  • Checks oembed_cache artifacts
  • Detects suspicious post/changeset artifacts
  • Flags exploit-pattern admin accounts
  • Finds deleted-admin traces
  • Detects wp2shell webshell files
  • Exports report as zip/JSON

Frequently Asked Questions

Common questions about Compromise Scanner for wp2shell

No. It only reads the database and lists files in the plugin directory. It never creates, edits, or deletes posts, users, options, or files (other than removing itself when you click the self-destruct button).
No. It only detects artifacts. Update WordPress core to a fixed version (6.8.6 / 6.9.5 / 7.0.2 or later) to close the vulnerability. A check is marked "Matched" but I know it is legitimate. That can happen — for example, three recent legitimate embeds, or an administrator you onboarded recently, can match individual checks. The verdict is a weighted score across many indicators; review each detected item against your own records.
It means no known wp2shell artifacts were found. A careful attacker can remove traces, and other attacks leave different evidence, so treat "Clean" as reassuring but not conclusive.

Sign In / Register

You need to sign in or register to use this feature.