WP Manifestindependent plugin directory
manifest / security / wp-malware-auditor

Malwarix — Malware & Security Scanner

Advanced security auditing plugin for WordPress that detects indicators of compromise (IOCs), flags obfuscated backdoors, audits crons, users, drop-in files, database content, and maintains a tamper-evident audit log with quarantine vault.

by theaashishpathak · github.com/theaashishpathak/wp-malware-auditor · website

★ 1stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/theaashishpathak/wp-malware-auditor/archive/refs/heads/main.zip

🛡️ Malwarix — On-Site Security & Remediation Engine (v1.0.0)

License

Malwarix is an enterprise-grade, 100% free and open-source security auditing and automated backdoor remediation engine for WordPress. Built for system administrators, security auditors, and webmasters, it inspects your actual server filesystem and MySQL database for dormant web shells, obfuscated code payloads, double-extension polyglots, rogue server directives, unauthorized admin accounts, and stealth database injections. All features are fully unlocked with zero paid licenses or cloud subscriptions.


⚡ 9 Integrated Security Workstations

# Workstation Slug Description
1 Dashboard wp-malware-auditor Real-time SVG Security Score gauge, interactive Subsystems Grid with muted state borders, telemetry metrics, and one-click hero scan triggers.
2 Findings wp-malware-auditor-findings Comprehensive threat triage table with multi-select bulk operations (Clean, Quarantine, Delete, Ignore), severity filters, and deep inspection drawer.
3 Workspace wp-malware-auditor-workspace 3-column secure file browser and code inspector with real-time syntax highlighting, file metadata, and one-click remediation actions.
4 Database wp-malware-auditor-database 3-column database forensic explorer with table row searching, serialized payload decoding, structured JSON viewing, and one-click option rollbacks.
5 Baseline wp-malware-auditor-baseline Cryptographic SHA-256 baseline ledger for tracking file changes, approving intentional updates, and detecting stealth tampering.
6 Quarantine wp-malware-auditor-quarantine Secure AES-256 isolation vault with full SHA-256 checksums, metadata tracking, single/bulk restores, and permanent file purges.
7 Audit Logs wp-malware-auditor-logs Cryptographically linked SHA-256 tamper-evident event activity log with export options (CSV/JSON) and structured payload viewer.
8 Settings wp-malware-auditor-settings Modern 2-column configuration workstation with sticky navigation, bento overview cards, iOS-style toggles, and sticky bottom save bar.
9 Help wp-malware-auditor-info Platform documentation, architectural guide, threat classification matrices, and security best practices.

🚀 Key Architectural Highlights & Recent Enhancements

  • 📊 Enterprise Security Scan Execution Monitor:

    • Real-time header progress component with active state badges (● SCANNING, ✓ COMPLETED, ! ATTENTION, × FAILED), dynamic elapsed timer (00:07 elapsed), and layered progress track.
    • Active leading indicator pulse dot communicating real-time engine activity.
    • Interactive 13-module horizontal pipeline tracking execution state across every audit stage.
  • 📑 Security Audit Reconciliation Panel:

    • Complete filesystem and module reconciliation replacing generic stat boxes.
    • 5 Structured Metrics: Project Files (Total Scope), Scanned Files (Audited Code), Skipped Static (Intentionally Excluded), Failed/Unreadable (Integrity Check), and Scan Modules (13/13 Complete).
    • Multi-Segment Coverage Bar: Visualizes audited code vs. static assets vs. errors with verified 100% Reconciled certification.
    • Adaptive Result Banners: Clean audit confirmations and attention banners with direct navigation.
  • 🛡️ Subsystems Status Grid with Muted State Borders:

    • Individual subsystem modules (Core, Plugins, Database, User Security, Filesystem, Drop-ins, Cron, File Perms) featuring subtle, color-coded state borders (#d1fae5 Clean, #fde68a Warning, #fecaca Danger) and interactive direct filtering.
  • 🗄️ Database Forensics & Table Explorer Integration:

    • Interactive Database Check telemetry card computing live database table count (12 Tables) with clean verification and one-click routing to the forensic Database Explorer.
  • 🛡️ 100% Physical Filesystem Reconciliation:

    • Traverses physical disk drives and synchronizes exact file and directory counts matching Windows Explorer and Linux disk properties 1:1.
    • Transparent Skipped Static Assets Breakdown modal explaining why static assets (.css, .png, .woff2, .mo, .txt) are safely bypassed while enforcing the Zero-Executable Barrier (polyglots like shell.php.jpg are never skipped).
  • 🌐 Emergency Quick Action Header Controls:

    • Scan Lock Force-Release: Clears stuck concurrency locks and resets the scan engine to ready.
    • Official Core Restoration: Direct checksum restoration of wp-includes and root files from WordPress.org.
    • Default .htaccess Restoration: Resets root .htaccess to pristine WordPress rewrite rules.

⚡ Comparative Analysis: Why Malwarix?

Capability / Feature 🏆 Malwarix ☁️ Traditional Cloud Scanners 🔍 Basic Signature Scanners
Privacy & Data Residency 100% On-Site (Zero Cloud Leaks) Sends file contents & DB to remote servers On-Site
Double-Extension Protection Full Polyglot Scan (.php.jpg, .php.css) Ignored (skips image/CSS extensions) Ignored
Reinjection Loop Prevention Smart Directive Scrubbing (Leaves clean file markers) Naive unlink() (Triggers instant reinjection) Flags files only (No auto-fix)
Database Audit Depth 100% of Custom & Core MySQL Tables Scans wp_options & wp_posts only No Database Scanning
Action Scheduler Monitoring Audits wp_actionscheduler_actions Ignored Ignored
Cross-Platform Path Engine Windows (C:\) & Linux Native (/) Prone to Windows path colon syntax bugs Basic regex
Core Repair Mechanism SVN Checksum Core Replacement Overwrites entire installation None
Audit Trail Integrity Cryptographic SHA-256 Hash Chain Plain SQL table (Tamperable) Plain text log file
Scanning Overhead 15s Time Budget Guards & Batches Heavy CPU spikes & HTTP timeouts Memory crashes

🧩 Architectural Flow Diagram

flowchart TD
    A[User / Cron Trigger] --> B[Scanner Engine Core]
    B --> C[Module 1: Core SVN Checksums]
    B --> D[Module 2: Obfuscation Heuristics]
    B --> E[Module 3: 100% Database Sweeper]
    B --> F[Module 4: Action Scheduler Monitor]

    C & D & E & F --> G[Findings Collector & Deduplicator]

    G --> H{Threat Type?}
    H -->|Rogue Server Directive| I[Content Analyzer: Directive Scrubbing]
    H -->|Malicious Backdoor File| J[AES-256 Quarantine Vault]
    H -->|Core File Modification| K[Pristine SVN Core Restoration]

    I & J & K --> L[Cryptographic SHA-256 Audit Log]
    L --> M[Real-time Webhook Alert: Slack / SIEM]

🛡️ 13 Auditing Subsystems Overview

Subsystem Module Target Vector Risk Level
🧬 Core Checksum Compares wp-admin & wp-includes against official WordPress.org release manifests. CRITICAL
🔌 Plugin Checksums Validates repository plugins with smart content verification for custom edits. HIGH
🎨 Theme Checksums Audits theme template files against official WordPress.org release hashes. HIGH
💣 Root & Drop-in Files Detects unclaimed drop-in backdoors (wp-content/db.php, advanced-cache.php). CRITICAL
🌐 .htaccess Integrity Audits .htaccess for unauthorized server prepends and stealth redirect rules. HIGH
📂 PHP in Uploads Scans wp-content/uploads/ for executable PHP scripts or subfolder overrides. CRITICAL
🔍 Obfuscated Code Heuristic analyzer detecting encoded execution chains, decompression wrappers, and XOR ciphers. HIGH
⏱️ Timestamp Anomaly Tracks file modification timestamps against baseline SHA-256 snapshots. MEDIUM
🔒 File Permissions Audits world-writable files (0777/0666) and repairs permission modes. MEDIUM
👤 Admin User Audit Scans wp_users for unauthorized administrator accounts & elevated privileges. CRITICAL
⏰ Cron Jobs Audit Inspects WP-Cron schedules for unauthorized cron hooks and payload actions. HIGH
🗄️ Database Sweeper Column-by-column payload sweeper across 100% of custom & core MySQL tables. CRITICAL
🧩 MU-Plugins Integrity Inspects wp-content/mu-plugins/ for mandatory drop-in backdoors. HIGH

⚙️ Settings & Performance Tuning

Configure Malwarix under Malware Auditor → Settings:

  • Automated Audit Frequency: Disabled, Hourly Audit, Twice Daily, Daily (Recommended), Weekly.
  • Double-Extension Polyglot Toggle: Enable or disable scanning of .php.jpg, .php.css files.
  • PHP Memory Allocation: Adjust limits (128M, 256M, 512M, 1024M) to optimize performance for large databases.
  • Execution Time Limits: 15-second time budget limits prevent HTTP timeouts across large codebases.
  • Webhook Integration: Send real-time alert JSON payloads to Slack, Microsoft Teams, Discord, or SIEM endpoints.

📄 License & Open-Source Software

Malwarix is 100% Free & Open-Source Software licensed under the GNU General Public License v2.0 (GPLv2).

  • Zero License Keys Required: All features, scanning engines, and remediation tools are 100% free and fully unlocked.
  • Zero Cloud Subscriptions: Operates entirely on-site without recurring cloud costs or third-party paywalls.

👨‍💻 Maintainer & Community

Crafted & maintained with ❤️ by @theaashishpathak

Contributions, feature requests, and security feedback are welcome via GitHub Issues.