Test safely.
Clean confidently.
A practical guide to assessing any WordPress website, reviewing security and storage findings, running recoverable cleanup actions, and preserving a trustworthy evidence record.
Protect the rollback path first
Create a fresh manual restore point with the hosting provider before installing the plugin or running Cleanup Center. Assessment is read-only; selected cleanup actions can change files, posts, transients, and stored backups.
Everything Monster Cleanup checks
Monster Cleanup combines security evidence, WordPress operations, storage intelligence, public verification, and recoverable response in one site-level assessment.
Files and malware signals
- Chunked, resumable scan of the complete WordPress root
- PHP, JavaScript, and executable-risk inspection
- Hidden PHP, unexpected root PHP, and executables in uploads
- Encoded or obfuscated payloads, remote includes, and execution patterns
- Hidden companion loaders and duplicate suspicious code
- Recent changes and unsafe permissions as supporting evidence
- Multi-indicator risk scoring; weak signals remain warnings
Core and components
- Official WordPress core checksum verification
- Plugin and theme inventory with versions and activation state
- Must-use plugin and WordPress drop-in inventory
- Unreadable executable files and scan errors reduce confidence
- Public CISA KEV catalog schema and freshness health
- Every unavailable intelligence layer is reported separately
WordPress operations
- Administrator-like accounts, roles, and effective capabilities
- Cron hooks, recurrences, intervals, and hashed arguments
- Weekly scheduler health
- Sensitive database-option hashes without exposing values
- Strong-signal spam candidates with live rescoring
- Approved Move to Trash action—never permanent spam deletion
Storage intelligence
- Storage map for uploads, backups, caches, logs, temporary files, plugins, themes, core, and other files
- Largest files and largest database tables
- Monthly storage-cost estimate and backup-copy multiplier
- Confirmed image families from attachment metadata
- Originals, preserved originals, derivatives, missing files, and registered sizes
- Obsolete unregistered image-size candidates
Public verification and evidence
- Configurable public pages and download targets
- Status, content type, redirects, and bounded body hashes
- Before-and-after homepage and target verification
- Explicit scan-confidence and intelligence health
- JSON evidence export
- Incident Graph connecting files, loaders, components, privileged changes, spam timing, recurring files, domains, vulnerability evidence, and public-page drift
- Plain-English incident clusters, timeline, risk scores, relationship confidence, and recommended next actions
- Compact twelve-scan history record
Automation and reporting
- On-demand and weekly background assessments
- Resumable scanning with background continuation
- Optional automatic high-confidence safe scopes
- Backups and image derivatives excluded from unattended cleanup
- Optional weekly email reports
- Explicit recording when report delivery fails
Cleanup Center actions and safeguards
Every scope is independent. Monster Cleanup revalidates evidence immediately before acting, records what changed, checks the public site afterward, and retains a recovery path.
Safety controls on every run
- Administrator approval, selected scopes, and typed
CLEANUPconfirmation - Live path, SHA-256, malware, spam, image-size, and direct-reference revalidation
- Private quarantine outside the public WordPress root with configurable retention
- Before-and-after public verification with automatic rollback if a working homepage fails
- Action ledger, skipped-target evidence, recovery manifests, and one-click Undo
- Undo refuses to overwrite a newer live file; symlinks and unsafe paths are rejected
- WooCommerce is never removed merely because it appears or reappears
Externally signed SHA-256 integrity baseline
The WP-CLI baseline engine creates a canonical site manifest, sends only its digest and non-secret context to an independent signer, and verifies the returned Ed25519 signature locally. The private signing key never belongs inside WordPress.
wp monster-cleanup baseline-create wp monster-cleanup baseline-verify wp monster-cleanup baseline-check –format=json- Every file and directory path
- SHA-256 file hashes
- Ownership and group
- Permissions
- Symlink targets and hashes
- WordPress and component versions
- Active plugins and themes
- MU plugins and drop-ins
- Administrators, roles, and capabilities
- Cron hooks and hashed arguments
- Sensitive option hashes
- Incomplete scans refused for signing
Install and configure version 1.1.0
Start with a controlled installation on your own website. Add only the public pages and downloads that matter to your visitors and operations.
Install or update
Download Monster Cleanup 1.1.0
- Open Plugins → Add New Plugin → Upload Plugin.
- Select
monster-cleanup-1.1.0.zip. - Choose Install Now and approve replacing the installed preview version if prompted.
- Activate Monster Cleanup and open it from the WordPress menu.
Configure the first target
- Add the website’s homepage and each important public URL on its own line.
- Include forms, service pages, checkout pages, or public downloads that should be tested.
- Leave monthly cost per GB at zero unless the real cost is known.
- Use storage multiplier
1for production only, then save.
Run the assessment and review the evidence
Run the assessment
- Choose Run assessment and keep the page open during the first pass.
- If it pauses, reload the page and choose Continue assessment.
- Review Scan coverage, Local security findings, Storage map, Image families, WordPress operations, largest files, and largest database tables.
- Choose Export evidence JSON and retain the file.
Use Cleanup Center
- Review every qualified scope before selecting it.
- Malware, strong spam, safe storage, and expired transients may be preselected when qualified.
- Backup and media actions remain off by default.
- Type
CLEANUP, run the selected cleanup, and approve the browser confirmation. - Review the result, history, and public verification report.
Incomplete means incomplete
An unavailable or failed intelligence layer is never counted as a successful scan. A warning is a review signal—not a malware conviction—and high or critical findings should be investigated before anything is changed.
- The public CISA catalog is retrieved and freshness-checked.
- Strong spam is rescored before it can be moved to Trash.
- Generated-image filename patterns remain candidates until WordPress metadata confirms them.
- WooCommerce will not be removed if it reappears.
Not yet connected
These layers require credentials, signed packages, or server/cloud infrastructure:
- Wordfence Intelligence
- WPScan secondary verification
- Installed-component CISA correlation
- ClamAV and YARA
- Independent baseline signer
- Server-level and account-wide scanning
Planned layers and agency capabilities
These capabilities are part of the product direction, but the current dashboard must continue to label them unavailable until their infrastructure is connected and healthy.
Threat intelligence and unknown threats
- Wordfence Intelligence V3 and WPScan correlation
- Installed-component CISA exploitation priority
- ClamAV, freshclam, YARA, package signatures, and suspicious-domain intelligence
- Advanced entropy, outbound-domain, loader relationship, and cross-site code analysis
- Cloud-enriched root-cause narrative across multiple sites and hosting layers
External proof and prevention
- Dead Monster heartbeat and plugin self-integrity
- Multi-region checks, streamed download hashing, cloaking, DNS, TLS, and uptime evidence
- Tamper-evident Monster Proof receipts
- Firewall and virtual-patching integrations
- 2FA/passkeys, session controls, least privilege, upload protection, headers, and rate limiting
- Email, SMS, Slack, Teams, and webhook alerts
Storage portfolio intelligence
- Multi-site storage dashboard, growth history, budgets, and anomaly alerts
- Theme/plugin ownership of generated image sizes
- Duplicate uploads and modern-format workflows
- Backup recursion, retention, cache, and log-rotation analysis
- Hosting-bill verification and account-level measurement
- Server agent for sibling sites, backups, SSH keys, cron, PHP, and web-server configuration
Agency workflow and simulation
- Staging Cleanup Simulator with pages, forms, downloads, checkout, and visual regression
- Database snapshots, orphan cleanup, and dependency-aware component retirement
- Multi-site groups, policies, bulk assessment, and per-site failure visibility
- Technician roles, approval queues, notes, assignments, and client access
- White-label reports, cleanup proposals, API, webhooks, SSO, and regional retention
Recover, troubleshoot, and preserve
Undo when necessary
Use Undo this run during the recovery-retention window if a retained file or post must be restored. Strong spam is moved to Trash, not permanently deleted, in this build.
If the scan pauses
- Continue the assessment after reloading the plugin page.
- Check the host’s real server cron if built-in WP-Cron is disabled.
- Confirm outbound HTTPS access when official WordPress checksums fail.
- Test a failed public target separately; access controls can block the server.
Preserve the test record
Keep the exported JSON and cleanup history. The first action review should validate skipped targets, quarantined paths, storage calculations, scan duration, and the site’s critical public-page and download results.
Ready to test your WordPress website?
Create a restore point, install Monster Cleanup 1.1.0, and begin with a read-only assessment before approving any cleanup action.