Sentryvine — Antivirus & Anti-Phishing Security

Sentryvine — Antivirus & Anti-Phishing Security

Details
View on WordPress

Sentryvine provides a conservative, review-first security scan from the WordPress administration area.

The initial release includes:

  • Local inspection of executable and redirect-capable files for high-signal malware patterns.
  • Detection of executable PHP files in the uploads directory.
  • Anti-phishing analysis for deceptive link text, raw IP destinations, embedded URL credentials, Punycode hosts, encoded control characters, dangerous URI schemes, and external password forms.
  • Optional WordPress core integrity verification against official checksums.
  • Manual scans and daily WP-Cron scans.
  • Bounded scan reports with severity, evidence, location, and recommended review actions.

Sentryvine does not automatically delete, edit, or quarantine files or content. Findings are indicators for an administrator to review; they are not proof that a site is compromised. A scan with no findings does not guarantee that a site is safe.

External services

By default, Sentryvine scans locally and does not send site files or content to an external service.

If an administrator enables “Verify WordPress core checksums,” each scan uses WordPress core’s checksum function to contact https://api.wordpress.org/core/checksums/1.0/. The request includes the installed WordPress version and locale so the service can return the matching official file hashes. WordPress HTTP requests may also include the standard WordPress user-agent. No site files, post content, detected URLs, or scan findings are sent.

This service is operated by the WordPress project. See the WordPress.org privacy policy and terms of service.

Details

Plugin code:
sentryvine
Plugin version:
0.1.0
Author:
Outdated:
No
WP version:
6.4 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-08-26
Rating:
Times rated:
0
anti-phishing
antivirus
integrity
malware-scanner
security