Compromise Scanner for wp2shell — WordPress Security Plugin
by eyesecurity · WordPress.org page · Website
Compromise Scanner for wp2shell has 3,000+ active installs on WordPress.org and 6,948 downloads all time. We have tracked it since September 4, 2026; download trends appear after 30 days of data. The last update was on July 20, 2026, tested up to WordPress 7.0.4.
Compromise Scanner for wp2shell at a glance
Is Compromise Scanner for wp2shell well maintained?
Features
The feature list from the plugin's own readme on WordPress.org, trimmed to the essentials.
- oembed_cache entries that loop back to your own site, that number exactly three, or that were created around the disclosure date (the exploit uses oembed…
- Object-graph artifacts: posts with implausibly high parent IDs, known proof-of-concept titles/slugs, and customize_changeset entries created since disclosure
- Account artifacts: the wp2_ login prefix and @wp2shell.invalid email used by public exploit code, and non-founder administrator accounts created since…
- Deleted-admin traces: orphaned user metadata and gaps in the user-ID sequence (create-then-delete)
- Webshell plugin files or directories matching wp2shell_*
Compromise Scanner for wp2shell reviews and ratings
2 reviews on WordPress.org, with the most recent ones as their authors posted them.
2 reviews
- 5★
-
2
- 4★
-
0
- 3★
-
0
- 2★
-
0
- 1★
-
0
-
Thanks for your help
You helped to calm my suspicions
Pavel -
Thank you for this useful plugin!
Provides very useful diagnostics for tracing the recent WP hack
Joe C
Compromise Scanner for wp2shell alternatives
Plugins that solve the same problem, ranked by how closely they overlap with Compromise Scanner for wp2shell.
-
Security Ninja 7,000+ installs · 4.7 -
AntiVirus 30,000+ installs · 4.1 -
IP Geo Block 8,000+ installs · 4.2 -
WPVulnerability 10,000+ installs · 5.0
-
NinjaScanner 30,000+ installs · 4.1
Details
Read-only forensic scanner for the WordPress core exploit chain CVE-2026-63030 / CVE-2026-60137 (wp2shell). Reports a scored verdict; changes nothing.
The full description, screenshots and every review live on the WordPress.org page.
Rankings Compromise Scanner for wp2shell competes in
Tags
- forensics
- malware
- security
- vulnerability
- wp2shell
- Version
- 1.1.0
- Last updated
- Jul 20, 2026
- First published
- Jul 20, 2026
- Requires WordPress
- 5.6
- Tested up to
- 7.0.4
- Requires PHP
- 7.2
- Pricing
- Free on WordPress.org
Compromise Scanner for wp2shell FAQ
What does Compromise Scanner for wp2shell do?
According to its WordPress.org readme, Compromise Scanner for wp2shell offers oembed_cache entries that loop back to your own site, that number exactly three, or that were created around the disclosure date (the exploit uses oembed, Object-graph artifacts: posts with implausibly high parent IDs, known proof-of-concept titles/slugs, and customize_changeset entries created since disclosure, Account artifacts: the wp2_ login prefix and @wp2shell.invalid email used by public exploit code, and non-founder administrator accounts created since, Deleted-admin traces: orphaned user metadata and gaps in the user-ID sequence (create-then-delete) and Webshell plugin files or directories matching wp2shell_*.
How many active installs does Compromise Scanner for wp2shell have?
WordPress.org reports 3,000+ active installs for Compromise Scanner for wp2shell as of September 7, 2026.
Is Compromise Scanner for wp2shell still maintained?
Yes. The last release was on July 20, 2026 and it is tested up to WordPress 7.0.4.
Does Compromise Scanner for wp2shell have good support?
On the WordPress.org forum, 0 of 1 recent support threads for Compromise Scanner for wp2shell are marked resolved. That is the developer's free support; a paid version usually comes with its own channel.
Is Compromise Scanner for wp2shell free?
Compromise Scanner for wp2shell is free to install from WordPress.org. Many plugins also sell a paid version or add-ons.