WordPress Security · Forensics

Know exactly what happened to your site.

Armory Security is the toolkit you reach for when a WordPress site is — or might be — compromised. It captures a SHA-256 integrity baseline, verifies core & plugin checksums, hunts web-shells and obfuscated PHP, and audits the attacker’s favourite hiding spots. Read-only and forensics-first: it tells you what happened before you change anything.

Get Premium — $49/yr See features Free core · Premium $49/year
🔍 SHA-256 integrity baseline 🐚 Web-shell hunter 👻 Ghost-admin detection 🧾 Evidence export 🔒 Read-only by default
yoursite.com/wp-admin · Armory Security
# armory scan — file-integrity + web-shell sweep
core checksums ✓ verified (WordPress 6.x, 0 mismatches)
plugin checksums ! 1 modified akismet/akismet.php
web-shell hunt ⚠ 1 finding wp-content/uploads/2026/04/.cache.php
obfuscated eval(base64_decode( … )) · POST-driven
ghost admins ⚠ 1 hidden user “wp-svc” · created 03:14 UTC
rogue routes ✓ none
malicious cron ✓ none
mu-plugins/drop-ins ✓ clean
# baseline saved · evidence bundle ready to export
$

Prove what happened, then fix it

A complete incident-response workflow — not just another scanner that says “you might be infected”.

🧬

File-integrity baseline

A SHA-256 inventory of every file, with diff on demand — see exactly what was added, changed or deleted since you were clean.

Core & plugin checksums

Verify WordPress core and plugin files against official checksums to pinpoint tampered code instantly.

🐚

Web-shell & PHP malware hunter

Signature + heuristic engine that finds web-shells and obfuscated PHP — the eval/base64/POST patterns attackers hide in uploads.

👻

Ghost-admin detection

Surface hidden administrator accounts an attacker quietly added to keep their foothold.

🛣️

Rogue route & cron audit

Audit malicious REST/AJAX routes, scheduled cron events, mu-plugins and drop-ins used for persistence.

📡

C2 / outbound domain extraction

Extract hardcoded command-and-control and outbound domains from suspicious files for your block-list and IOC matching.

👮

Admin-session trust & attack feed

See who is logged in, from which IP and device, with a live attack feed of inbound request signatures.

🛡️

One-click hardening & quarantine

Apply runtime hardening, lock the site down and quarantine suspect files — deliberate, reversible actions you control.

🧾

Timestamped evidence export

Export a timestamped evidence bundle (ZIP/CSV) — a clean record of findings for your report or your host.

Free to find. Premium to respond.

The detection funnel is free forever — baseline, checksums, web-shell hunting, ghost-admin and persistence audits. Premium turns Armory from “what happened?” into “handle it”: continuous monitoring, real-time alerts and court-ready proof.

  • Scheduled baselines & drift alerts
  • Real-time admin-account & session monitoring
  • Indicator-of-compromise (IOC) matching
  • Timestamped evidence bundles & timeline
yoursite.com/wp-admin · License & Plan
# free vs premium
FREE security · core · plugins · shell · polyglot
htaccess · db · mu · runtime · activity
PREMIUM schedule · watch · sentry · feed · sessions
harden · quarantine · bundle · timeline
domains · routes · authhooks · perms · cron
ioc · ai
# upgrade in place from WP Admin → License & Plan
$

From “maybe hacked” to answers

No agents, no cloud upload of your files. Everything runs inside your WordPress.

Install the free scanner

Upload the plugin and activate. The detection funnel works immediately — no key required.

Baseline & scan

Capture a SHA-256 baseline, verify checksums and run the web-shell, ghost-admin and persistence sweeps.

Respond & prove

Quarantine, harden and export a timestamped evidence bundle. Upgrade to premium for monitoring and alerts.

Start free today

The full forensic scanner is free forever. Add Premium response & monitoring for $49/year — upgrade in place from WP Admin any time.

Free
$0 forever
Full detection funnel · all sites
  • SHA-256 integrity baseline & diff
  • Core & plugin checksum verify
  • Web-shell & obfuscated-PHP hunter
  • Ghost-admin, route, cron & mu-plugin audit
  • Evidence export (ZIP/CSV)
Get launch notice
Premium
$49 /year
Response · monitoring · proof · 1 site
  • Everything in Free
  • Scheduled baselines & drift alerts
  • Real-time admin & session monitoring
  • Live attack feed & IOC matching
  • One-click hardening, quarantine & timeline

Secure checkout via Stripe · cancel anytime

Compromised right now and need hands-on help? Ask about specialist incident response →

ROread only

Forensics-first, do-no-harm by default

Armory captures evidence and tells you what happened before you touch anything. Hardening, quarantine and lockdown are explicit, deliberate actions you choose to take — never automatic surprises.

🔒

Runs on your server

Your files are never uploaded to a third party. Analysis happens inside your WordPress.

🧾

Court-ready evidence

Timestamped, exportable findings you can hand to your host or your report.

🧩

Works with your WAF

Complements firewalls like Wordfence — it proves and recovers, not just blocks.

Free to start

The full detection funnel is free. Upgrade for response & monitoring when you’re ready.

Questions, answered

Is Armory Security free?

Yes — the core forensic scanner is free: the SHA-256 integrity baseline, core/plugin checksum verification, web-shell and obfuscated-PHP hunting, ghost-admin detection and the rest of the detection funnel. Premium adds live response, monitoring and proof features.

Will it change or break my site?

No. Armory is forensics-first and read-only by default: it tells you exactly what happened before you change anything. Hardening, quarantine and lockdown are explicit, opt-in actions you trigger yourself.

Can I run it alongside Wordfence or another security plugin?

Yes. Armory is built for the moment a site is — or might be — compromised, complementing a firewall/WAF rather than replacing it. It focuses on proving what changed and recovering evidence, not on blocking traffic.

What does the premium plan add?

Premium unlocks the response and monitoring side: scheduled baselines, real-time admin-account and session monitoring, a live attack feed, one-click hardening, quarantine, indicator-of-compromise matching and timestamped evidence bundles.

How much is premium and how do I buy it?

Premium is $49/year for one site, billed securely through Stripe — cancel anytime. After checkout you get your license key by email instantly; activate it from inside WP Admin under Armory Security → License & Plan.

Be ready before the next compromise.

Capture a clean baseline, know the moment anything changes, and prove what happened. Start free, upgrade to Premium for $49/year when you want monitoring and response.

Get Premium — $49/yr