Luketom Compromise Review

Luketom Compromise Review

Details
View on WordPress

Luketom Compromise Review detects the known August 2026 incident filenames and the contact-page gambling redirect pattern, plus PHP in uploads, multi-signal webshell code, gambling content in posts and administrators outside an explicit allowlist.

Features:

  • One clearly labelled full manual security scan with safe 50,000-file continuation batches until every eligible file has been checked.
  • Daily scheduled quick scan with optional, administrator-enabled email alerts.
  • Lightweight four-hour monitoring for changes to .htaccess, wp-config.php and key WordPress bootstrap files.
  • Protected, fingerprinted recovery copy of the last explicitly approved .htaccess, with a verified pre-restore rollback copy.
  • Evidence-preserving quarantine only after independent confirmation and a fresh matching fingerprint.
  • One-click verified restore for current and legacy quarantine records, with overwrite protection.
  • Targeted .htaccess repair with a verified restorable backup and protection against overwriting newer rules.
  • Reversible removal of individually selected or bulk-selected inactive themes after a fresh eligibility check.
  • Administrator allowlist and WordPress file-editor capability blocking.
  • Configurable same-site URL/path for the page where a known injection was observed and must be verified after cleanup.
  • No automatic administrator deletion and no automatic removal of ambiguous files. A protected, manually confirmed action is available for suspicious administrators.

This plugin cannot protect against a compromised hosting control panel, SFTP account or server-level attacker. Rotate credentials and use hosting-level monitoring as well.

Privacy

Compromise Review does not send telemetry and does not contact luketom or any other third-party service. Important-file monitoring and malware scans run locally. Live-page verification requests only the same-site URL selected by the administrator. Email alerts are disabled on a fresh installation until an administrator enables them and controls the recipient list.

Details

Plugin code:
luketom-compromise-review
Plugin version:
1.18.3
Author:
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-08-28
Rating:
Times rated:
0
incident-response
malware
quarantine
scanner
security