Complete file index
The bridge file walks every directory recursively and computes a SHA-256 hash per file. File contents never leave your server.
See howEvery file by SHA-256 against the official release. No signatures, no hunches — tampered files and planted backdoors appear in the report with path and line.
Not a signature scanner looking for known malware patterns. A full comparison against the known-good state — which catches malware nobody has seen before.
Any time the question is: is this still the state we shipped?
After an infection, know within minutes which files were touched and which do not belong there at all.
Check every client site on a schedule and show the client evidence of its actual state.
Recurring scans as a fixed part of maintenance, with a report for every run.
Spot compromised instances across your fleet before the server ends up on a blacklist.
Assess an inherited project before you take responsibility for it.
Leave the baggage behind: only verified files move to the new system.
Two packages, no subscription. The scan is free and stays free. The larger package is a one-off €29 — currently nothing, as a launch price.
The full comparison against the original files.
forever — no account, no payment details
A second opinion on everything the scan flagged — and the means to act on it.
one-off — per scan, no recurring cost
If your question is not here, support answers on weekdays within a few hours.
The scan is free forever and needs no account — unlimited domains and runs. The AI analysis is a one-off €29 per scan and is also free at launch. No subscription, no payment details for the scan.
It first identifies whether this is Joomla or WordPress, then reads file paths, sizes and modification dates and computes one SHA-256 hash per file, plus the core version and the list of installed extensions. File contents are never transmitted.
Each file is generated for exactly one domain, carries its own token, expires after 24 hours and only accepts requests from our scan servers. You delete it after the scan; we keep reminding you until it is gone.
Joomla 3.9 to 6.x and WordPress 5.x to 6.x, on PHP 7.4 to 8.5. For extensions and plugins the rule is: anything whose original package is still publicly obtainable in the installed version can be verified — for WordPress and the official directory that is almost always the case.
Only when you approve a finding individually. By default the scan is strictly read-only, and every affected file is backed up before anything is written.
Your own changes show up as deviations, because their hash differs from the official package — that is the price of comparing against a known-good state instead of hunting for signatures. The report classifies every file rather than merely flagging it, and the AI analysis separates heuristic false alarms from real findings. A permanent exception list carried across scans does not exist yet.
Domain, file paths, hashes, metadata and your reports. No file contents, no database contents, no credentials. Deleting a project takes its data with it.
The scan costs nothing and needs no account.
All you need is the URL and FTP access.