Sentryvine provides a conservative, review-first security scan from the WordPress administration area.
The initial release includes:
Sentryvine does not automatically delete, edit, or quarantine files or content. Findings are indicators for an administrator to review; they are not proof that a site is compromised. A scan with no findings does not guarantee that a site is safe.
By default, Sentryvine scans locally and does not send site files or content to an external service.
If an administrator enables “Verify WordPress core checksums,” each scan uses WordPress core’s checksum function to contact https://api.wordpress.org/core/checksums/1.0/. The request includes the installed WordPress version and locale so the service can return the matching official file hashes. WordPress HTTP requests may also include the standard WordPress user-agent. No site files, post content, detected URLs, or scan findings are sent.
This service is operated by the WordPress project. See the WordPress.org privacy policy and terms of service.