Luketom Compromise Review detects the known August 2026 incident filenames and the contact-page gambling redirect pattern, plus PHP in uploads, multi-signal webshell code, gambling content in posts and administrators outside an explicit allowlist.
Features:
This plugin cannot protect against a compromised hosting control panel, SFTP account or server-level attacker. Rotate credentials and use hosting-level monitoring as well.
Compromise Review does not send telemetry and does not contact luketom or any other third-party service. Important-file monitoring and malware scans run locally. Live-page verification requests only the same-site URL selected by the administrator. Email alerts are disabled on a fresh installation until an administrator enables them and controls the recipient list.