Getting started

Everything you need to scan a WordPress site, clean up what Moatline finds, and lock the site down afterwards.

Install

  1. In your dashboard, go to Plugins → Add New and search for “Moatline Malware Scanner”, or upload the plugin zip.
  2. Activate it. A Malware Scanner menu appears in your dashboard.

Requires WordPress 5.0+ and PHP 7.0+. Works on Apache, LiteSpeed and Nginx.

Run a scan

Open Malware Scanner → Scanner and click Run Full Scan. The scan runs in separate steps, so large sites don't hit server time limits:

  • Must-use plugins, plugins and the active theme
  • Drop-ins and wp-login.php
  • Fake image files and payload files used by known malware
  • PHP files in the uploads folder
  • Posts, pages, revisions, Elementor data and widgets
  • The database: malicious options, cron jobs and rogue administrators

You can Pause a scan and Resume it later, even after leaving the page (within 24 hours), or Stop it to start fresh.

Understand the results

Each finding shows its type, how serious it is, where it is and the malware family it matched.

  • Modified plugin file: the file differs from the official WordPress.org release. Reinstall that plugin to replace it with a clean copy.
  • Webshell or PHP in uploads: PHP files never belong in uploads. Delete the file with your host's file manager or FTP.
  • Injected script in a post or widget: click Edit content, switch to the code editor and remove the injected script.
  • False alarm: click Dismiss, or add the path under Settings → Excluded Paths.
Moatline never deletes or changes anything on its own. Every change is a button you click.

After an infection

Removing the malicious code is only half the job. Attackers usually still have a way back in. Once the scan is clean:

  1. Change every administrator password and remove admin users you don't recognise.
  2. On Malware Scanner → Hardening, click Log out everyone and Regenerate security keys & salts.
  3. Revoke application passwords you don't use.
  4. Click Clean DB Now on the dashboard to remove known reinfection cron jobs.
  5. Turn on Lockdown and two-step login (below).
  6. Scan again a day later to make sure nothing came back.
Malware often hides itself from Plugins in wp-admin. If something keeps coming back, check wp-content/plugins and wp-content/mu-plugins with your host's file manager.

Lockdown

Malware Scanner → Lockdown has three switches:

  • Plugin & theme installation lock adds DISALLOW_FILE_MODS to wp-config.php. Nobody can install, update or delete plugins and themes from the dashboard. Unlock it briefly when you need to update.
  • File editor lock adds DISALLOW_FILE_EDIT, turning off the built-in theme and plugin editors. Unlocking the full lock leaves this one as you set it.
  • Block PHP in uploads writes a rule to wp-content/uploads/.htaccess (Apache and LiteSpeed). On Nginx, add the rule shown on the page to your server configuration.

Custom login URL

On Malware Scanner → Login Security, choose a login address such as team-access and turn on login URL hardening. Bookmark the new address before you save.

Logged-out visitors who open /wp-login.php or /wp-admin then see a normal “page not found” page, so the new address isn't revealed. Logged-in users aren't affected. Addresses WordPress already uses, such as “login” and “admin”, can't be chosen.

Two-step login

  1. Go to Users → Profile and find Two-factor login.
  2. Scan the QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, 1Password…).
  3. Enter the 6-digit code and click Update Profile.
  4. Save the 10 backup codes somewhere safe. Each works once.

Once it's on, password logins over XML-RPC are refused for that user, so the code can't be skipped. Apps should use application passwords.

XML-RPC & Jetpack

XML-RPC is an old remote-access door that attackers use to guess passwords and edit posts. On Malware Scanner → Hardening, choose a mode:

  • Allow: no change (the default).
  • Jetpack-safe: only Jetpack's signed requests get through. Pick this if you use Jetpack.
  • Block: XML-RPC is refused completely.

You can also refuse password logins over XML-RPC and turn off system.multicall. If you activate Jetpack while XML-RPC is blocked, Moatline switches to Jetpack-safe mode and tells you. On Apache and LiteSpeed you can add a server rule to .htaccess with one click; it's removed when you click again or deactivate the plugin.

Sessions & security keys

  • Active sessions lists every logged-in session with IP address and browser, including sessions left behind by deleted users.
  • Log out everyone ends every session, including yours.
  • Force password reset for other admins makes other administrators set a new password at their next login.
  • Regenerate security keys & salts replaces the keys and salts in wp-config.php, which signs out every stolen cookie at once.

Locked out?

Add one of these lines to wp-config.php, above the line that says “That's all, stop editing!”, log in, then remove the line again:

// Bring back /wp-login.php if you forgot your custom login address
define( 'NNMS_DISABLE_LOGIN_URL', true );

// Turn off two-step login checks if you lost your phone and backup codes
define( 'NNMS_DISABLE_2FA', true );

If you can't edit wp-config.php, rename the wp-content/plugins/moatline-malware-scanner folder with your host's file manager. That switches the plugin off.

Uninstalling

Deleting the plugin keeps your settings and everyone's two-step login setup, so a reinstall picks up where you left off. To remove everything, tick Delete all plugin data on the Settings page first.

Lockdown lines in wp-config.php and the uploads rule are left in place on purpose, so removing the plugin never quietly weakens a hardened site. Turn them off on the Lockdown page before deleting if you want them gone.

Need help?

Email info@nextnova.tech. If your site is hacked right now, Next Nova Technologies offers hands-on malware cleanup.