This is a very simple threat scan that looks for things out of place in the content directory as well as the database.
As of April 2026, Threat Scan Plugin is a WordPress scan plugin with 400 active installations and a 5/5 rating from 1 reviews. It has been downloaded 29K+ times in total. Requires WordPress 3.0+ and PHP false+. Available on WordPress.org since 2010. Last updated 1 year ago — may have compatibility concerns. Top alternative: Jetpack – WP Security, Backup, Speed, &….
This is a very simple threat scan that looks for things out of place in the content directory as well as the database.
It searches PHP files for the occurrence of the eval() function, which, although a valuable part of PHP is also the door that hackers use in order to infect systems. The eval() function is avoided by many programmers unless there is a real need. It is sometimes used by hackers to hide their malicious code or to inject future threats into infected systems. If you find a theme or a plugin that uses the eval() function it is safer to delete it and ask the author to provide a new version that does not use this function.
When you scan your system you undoubtedly see the eval used in javascript because it is used in the javascript AJAX and JSON functionality. The appearance of…
| WordPress | 3.0+ requiredTested up to 6.6.5 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.