I installed the plugin to see if it could prevent injection, however, this day the file:
/wp-includes/js/jquery/ui.tabs.js
was injected at the top with a reference to a NEW php file inserted
and it did not report any of them. After I deleted the php file.... it DID report the deletion.
So........ uhm.... does it exclude ui.tabs.js somehow?