Scan and clean a hacked site with AI
Run a fast triage of your core files, plugins, admin accounts, and key settings, then approve a staged cleanup.
Prerequisites
A connected site and a full backup, since cleanup steps overwrite files and remove accounts.
I think my WordPress site may be hacked. Run a security triage and show me a report before changing anything. Check these and list what you find: verify my WordPress core and plugin files against the official versions and flag anything modified, missing, or added; list every administrator account with its email and creation date so I can spot one I did not add; and read the settings attackers commonly hijack, my site address and home URL, the default role for new users, and whether open registration is on. Do not change anything yet. Give me a plain triage report and a staged cleanup plan. I have a full backup. Once I approve each step, remove the accounts I confirm are rogue, and for any tampered core or plugin files, reinstall clean copies from the official WordPress source or lay out the exact steps for me. Be honest about what you cannot see: if you cannot inspect every file in my uploads or must-use plugins folder, tell me, so I can run a dedicated malware scanner for those.
Already connected to WPVibe?
Skip the copy-paste. Just ask your AI for the “Scan and clean a hacked site with AI” recipe, or describe the task, and WPVibe runs these steps on your own site.
You suspect your site is hacked, or a scanner flagged it, and you do not know where to start. The classic signs are a strange admin you never added, plugin files that changed on their own, a redirect to a site you have never heard of, or open registration you did not turn on. Checking all of that by hand means SSH, checksums, and database queries most owners never touch.
WPVibe runs the checks a first responder would. It verifies your WordPress core and plugin files against the official copies to find anything modified, missing, or added; lists every administrator so a planted account stands out; and reads the settings attackers hijack, your site address, the default role for new users, and whether registration is open. It hands you a plain triage report and a staged cleanup plan, and changes nothing until you approve each step.
Take a full backup before you touch a compromised site, then run the prompt and read the report before approving anything. Once you confirm, WPVibe removes accounts you flag as rogue, and for tampered core or plugin files the plan walks through reinstalling clean copies from the official WordPress source. Know its limits: it checks core, plugins, accounts, and key settings, but it cannot walk every file in your uploads or must-use plugins folder, so if the report shows real compromise, pair it with a dedicated malware scanner or your host’s security team for a full file sweep.
Outcome
A triage report of tampered files, unexpected admins, and hijacked settings, with a staged, approved cleanup plan.