WordPress connector (server scan)

Server-side integrity and malware checks with the Webforta Connector plugin.

The Webforta Connector is a small WordPress plugin that checks your site from the inside and reports to your dashboard (Website > Server scan). It is read-only and push-only: it never changes your site, and Webforta cannot send it commands.

What it checks

  • Every WordPress core file against the official checksums from WordPress.org: modified, missing and unknown files.
  • PHP files hidden in the uploads folder (WordPress only stores media there).
  • Known malware and backdoor code patterns in wp-content, reported with file and line.
  • PHP files changed in the last 7 days.
  • Pending updates for WordPress, plugins and themes, and the list of administrator accounts.
  • Risky settings: open registration as administrator, errors shown to visitors, a public debug.log, the built-in file editor, readable wp-config.php, an account named "admin".
  • An activity log: logins, failed logins (with IP), new users, role changes, password resets, plugin/theme changes and updates.

Install

  • Open the website in Webforta, go to Server scan and click Set up the WordPress plugin, then Download plugin. The zip already contains this site's key.
  • In WordPress: Plugins > Add New > Upload Plugin, choose the zip, Activate.
  • The first report arrives within a minute or two; full file scans run every 12 hours and activity is sent hourly. You get an email when something new that looks like a compromise appears.

Reports rely on WP-Cron, which runs when your site has visitors. For a site with very little traffic, add a real cron job that requests wp-cron.php every 15 minutes (most hosts offer this in their control panel).