Aegisify company logo
Malware Scan2026-08-12T13:26:24+00:00
Aegisify Shield — Malware Security

WordPress Malware Scanner: Find Suspicious Behavior, Understand the Evidence, Control the Response

Aegisify Shield 7.4.5 uses context-aware, behavior-correlated malware analysis to identify suspicious execution patterns, disguised PHP, droppers, persistence behavior, and related indicators while giving administrators confidence, rule evidence, scan profiles, incremental checks, quarantine controls, and incident correlation.

Malware detection gets weaker when every dangerous-looking function becomes an alert.Modern WordPress plugins legitimately use encoding, filesystem, network, and execution-adjacent functions. Aegisify looks for correlated behavior so administrators can focus on stronger evidence instead of raw keyword matches.
1AnalyzeBehavior + context
2PrioritizeConfidence + severity
3ContainReview + quarantine
Malware Response Flow

From Suspicious File to Incident Context

The scanner is designed to preserve administrator judgment while making stronger malware signals easier to investigate.

Click a stage

01ScopeSelect scan targets
Choose supported WordPress locations including plugins, must-use plugins, themes, uploads, wp-admin, wp-includes, optional WordPress root, and approved custom directories where available.
02AnalyzeCorrelate behavior
The malware engine separates comments, strings, and executable PHP, then correlates request input, decoders, execution sinks, payload writes, file location, and persistence behavior.
03ExplainRules + confidence
Findings include risk level, confidence, matched rule identifiers, engine context, and human-readable reasons so the result can be reviewed rather than treated as a black box.
04RespondSafe, close, quarantine
Administrators can review a result, bind a Mark Safe decision to the exact file hash, close a finding, or quarantine when the configured handling mode permits it.
05CorrelateAttack Story
Attack Story can place malware findings into a timeline with related file-monitor, login, and activity events, then expose an incident report for broader review.
Major Malware Engine Improvements

7.4.5 Uses Context Instead of Noisy Raw-Keyword Matching

The current malware engine is materially different from the older public description.

Behavior Correlation

Execution Chains, Droppers, and Web-Shell Signals

Aegisify correlates request-controlled input with execution behavior, dynamic callables, decoder-to-execution chains, payload writes, web-shell capability markers, and persistence patterns. This reduces the chance that a legitimate isolated function name is treated as malware without supporting context.

Disguised Payloads

PHP Where PHP Should Not Be

The engine looks for PHP hidden inside uploads and non-PHP files, including image-backed payload patterns and suspicious executable content in locations that normally store media or generated assets.

Large-File Safety

Bounded Analysis Without Ignoring Appended Payloads

The scanner performs complete analysis through bounded file sizes and uses targeted PHP windows plus head-and-tail inspection for larger files. This allows it to look for malicious code appended near the end of a large file without loading unbounded content into memory.

Evidence Quality

Confidence, Rule IDs, and Scan Errors

Findings can carry confidence, matched rule identifiers, engine version, and plain-language reasons. Unreadable or unresolved files are accounted for instead of silently being treated as clean, which makes the scan result more honest and operationally useful.

Operational Malware Controls

Scan Deeper Without Making Every Response Automatic

Aegisify separates detection sensitivity from response handling so teams can tune coverage without giving up change control.

Profiles

Conservative, Balanced, and Aggressive

Conservative lowers sensitivity when false-positive reduction is the priority. Balanced is the recommended default. Aggressive lowers the detection threshold for deeper scrutiny and may report more suspicious files that require human review.

Scheduled Coverage

Background Malware Scans

Scheduled Scans keep malware review operating even when administrators are not logged in. This reduces dependence on manual reminders and supports a recurring security cadence appropriate to the site’s change rate and business importance.

Incremental Detection

Focus on Files That Actually Changed

Incremental Quick Scan uses file-monitor candidates and hashes to examine changed files without repeatedly scanning the entire installation. Unreadable candidates can be retried with bounded backoff, and pending work remains visible as partial rather than being misrepresented as complete.

Core Validation

WordPress Core Checksum Review

Administrators can run a separate WordPress core integrity check using official checksum data for the installed package context. This complements heuristic malware analysis by answering a different question: whether core files match the expected WordPress distribution.

Safer Finding Handling

Decisions Stay Bound to the Evidence

A “safe” decision should not become permanent permission for a file path that changes later. In the current implementation, Mark Safe exemptions are tied to the file’s exact SHA-256. If the file changes, the hash no longer matches and the file becomes eligible for malware review again.

Quarantine is also deliberately controlled. When selected and permitted by the configured handling mode, Aegisify stores the quarantined payload using a non-executable name in a protected quarantine area, applies access-deny controls, and places a harmless placeholder at the original path. Quarantine can still affect site functionality, so it should be used with backups, recovery access, and validation.

Human review remains important: heuristic malware scanning can produce false positives, and even a high-confidence result should be evaluated in the context of the file, plugin, deployment history, and site behavior before destructive remediation.
Malware Intelligence Dashboard

See Coverage and Threat Signals Before Opening Individual Findings

1Scan Profile CoverageShows enabled scan targets and the active profile context.
2Latest Suspect RatioCompares suspect files with clean files from the latest scan.
3Findings by SeveritySeparates High, Medium, and Low findings for faster prioritization.
4Attack Story SignalsGroups leading malware behavior signals into a more readable investigation view.
Attack Story

Understand What Happened Around a Malware Finding

A file detection is only one point in time. Attack Story correlates recent malware incidents with surrounding Activity Log, File Monitor, and Login Guard events. That can expose whether a suspicious file appeared after an unusual login, whether other files changed in the same window, and whether the finding was followed by quarantine or another response action.

The incident timeline is designed to shorten the first stage of investigation: identify the suspicious file, review related events, determine what else changed, and preserve a report for remediation or post-incident review. Supported incident reports can be opened for HTML/PDF-oriented export workflows.

This is especially useful after an update, suspected credential compromise, or reinfection event because the administrator can compare detection timing with the surrounding operational changes instead of reviewing the malware result in isolation.

Security posture improvement: correlation turns malware scanning from a list of files into an incident workflow. Teams can move faster from “what was detected?” to “what else happened around it?”
Build a Repeatable Malware Routine

Start With a Baseline Scan, Then Keep Watching Change

Run a reviewed malware and core-checksum baseline, tune the scan profile, then use scheduled and incremental scanning to maintain visibility as WordPress changes.

Malware Scan FAQ

Common Questions

Does a malware finding prove a file is malicious?

No. The scanner provides heuristic evidence, confidence, rules, and reasons to support human review. Findings should be validated before destructive action.

What happens when I mark a file safe?

The current implementation binds the safe decision to the file’s SHA-256. If the file changes later, the previous hash exemption no longer matches the modified file.

Does Aegisify replace hosting antivirus or a WAF?

No. Shield provides WordPress-side malware and incident context and is designed to complement secure hosting, a WAF where appropriate, backups, updates, least privilege, and incident response.

Detect Behavior. Review Evidence. Control Response.

Make Malware Detection Actionable

Aegisify Shield helps WordPress teams identify stronger malware signals, investigate the surrounding activity, and apply controlled response actions with clearer evidence.