Title: ZIP Archive Scanner
Author: bPlugins
Published: <strong>July 20, 2026</strong>
Last modified: July 21, 2026

---

Search plugins

![](https://ps.w.org/b-zip-archive-scanner/assets/banner-772x250.png?rev=3615196)

![](https://ps.w.org/b-zip-archive-scanner/assets/icon.svg?rev=3614971)

# ZIP Archive Scanner

 By [bPlugins](https://profiles.wordpress.org/bplugins/)

[Download](https://downloads.wordpress.org/plugin/b-zip-archive-scanner.1.1.6.zip)

 * [Details](https://wordpress.org/plugins/b-zip-archive-scanner/#description)
 * [Reviews](https://wordpress.org/plugins/b-zip-archive-scanner/#reviews)
 * [Development](https://wordpress.org/plugins/b-zip-archive-scanner/#developers)

 [Support](https://wordpress.org/support/plugin/b-zip-archive-scanner/)

## Description

Old backups, migration exports, and duplicate plugin bundles pile up on every WordPress
site — and a full-site archive sitting in a public folder can expose your database
credentials to anyone who guesses its URL.

ZIP Archive Scanner walks your **entire WordPress file system** (not just uploads)
and gives you a clean report of every ZIP archive it finds:

 * **Full file system scan** — batched and timeout-safe, works on huge sites and
   slow shared hosting.
 * **Risk assessment** — archives in the web root or with backup-like names (`backup.
   zip`, `wp.zip`, `db.zip`…) are flagged high risk.
 * **Review everything** — file name, location, size, and last-modified date in 
   a sortable, searchable table.
 * **One-click cleanup** — delete an archive right from the dashboard, or copy its
   public URL to verify exposure.

### Plugin Overview

### How to Use – Step-by-Step Guide

### Development & Source Code

The plugin’s admin dashboard is a React app compiled with @wordpress/scripts. The
complete, uncompiled source is included in this plugin under the `src/` directory,
together with `webpack.config.js` and `package.json`.

To build from source:

 1. The dashboard uses the shared open-source component library `bpl-tools` (GPL): 
    https://github.com/bPlugins/bpl-tools — clone it as a sibling directory of this
    plugin (i.e. `wp-content/plugins/bpl-tools`).
 2. Inside the plugin directory run `npm install`.
 3. Run `npm run build` — the compiled files are written to `build/`.

## Screenshots

[⌊Scan report — every archive with its location, size, and risk badge, plus CSV/
Markdown export, bulk delete, and one-click actions. High-risk archives in the web
root are flagged instantly.⌉⌊Scan report — every archive with its location, size,
and risk badge, plus CSV/Markdown export, bulk delete, and one-click actions. High-
risk archives in the web root are flagged instantly.⌉[

Scan report — every archive with its location, size, and risk badge, plus CSV/Markdown
export, bulk delete, and one-click actions. High-risk archives in the web root are
flagged instantly.

[⌊Welcome screen — quick start guide, risk-level explanations, and release notes.⌉⌊
Welcome screen — quick start guide, risk-level explanations, and release notes.⌉[

Welcome screen — quick start guide, risk-level explanations, and release notes.

[⌊First run — one click starts a full, timeout-safe scan of your entire file system.⌉⌊
First run — one click starts a full, timeout-safe scan of your entire file system
.⌉[

First run — one click starts a full, timeout-safe scan of your entire file system.

## FAQ

### Does it scan inside the ZIP files?

No. ZIP Archive Scanner locates archive files on disk so you can review and remove
them. It never extracts or modifies archives.

### Will the scan slow down or time out my site?

No. The scan runs in small time-boxed batches over the REST API, so it works within
normal PHP execution limits even on very large installs.

### Can I scan for other archive types?

Developers can extend the scanned extension list with the `bzas_scanned_extensions`
filter.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ZIP Archive Scanner” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ bPlugins ](https://profiles.wordpress.org/bplugins/)
 *   [ Abu Hayat ](https://profiles.wordpress.org/abuhayat/)

[Translate “ZIP Archive Scanner” into your language.](https://translate.wordpress.org/projects/wp-plugins/b-zip-archive-scanner)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/b-zip-archive-scanner/),
check out the [SVN repository](https://plugins.svn.wordpress.org/b-zip-archive-scanner/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/b-zip-archive-scanner/)
by [RSS](https://plugins.trac.wordpress.org/log/b-zip-archive-scanner/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.6

 * Fix: archives behind symlinked folders (e.g. symlinked uploads directories on
   managed hosting) are now scanned, with loop protection

#### 1.1.5

 * Fix: fatal error when activating while another copy (free/premium) of the plugin
   is installed — now hands over gracefully via Freemius

#### 1.1.4

 * Maintenance release — ships the Freemius SDK 2.13.4 update on all channels

#### 1.1.3

 * Docs: added overview and step-by-step video guides to the plugin page

#### 1.1.6

 * Fix: archives behind symlinked folders (e.g. symlinked uploads directories on
   managed hosting) are now scanned, with loop protection

#### 1.1.5

 * Fix: fatal error when activating while another copy (free/premium) of the plugin
   is installed — now hands over gracefully via Freemius

#### 1.1.4

 * Maintenance release — ships the Freemius SDK 2.13.4 update on all channels

#### 1.1.3

 * Update Freemius SDK to 2.13.4

#### 1.1.2

 * Branding: display name is now “ZIP Archive Scanner”

#### 1.1.1

 * Fix: Pricing and Feature Comparison pages showed blank while live plan data is
   unavailable — they now show a friendly fallback

#### 1.1.0

 * New (Pro): Save Result — save scan reports as named snapshots and review them
   anytime (up to 20)
 * New: Pricing and feature comparison pages in the dashboard

#### 1.0.1

 * Fix: scan state storage on very large sites — the folder queue is now compressed
   and stored packet-safe, so scans no longer fail on hosts with a low MySQL max_allowed_packet

#### 1.0.0

 * Initial release

## Meta

 *  Version **1.1.6**
 *  Last updated **18 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.0.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [backup](https://wordpress.org/plugins/tags/backup/)[cleanup](https://wordpress.org/plugins/tags/cleanup/)
   [disk space](https://wordpress.org/plugins/tags/disk-space/)[security](https://wordpress.org/plugins/tags/security/)
   [zip](https://wordpress.org/plugins/tags/zip/)
 *  [Advanced View](https://wordpress.org/plugins/b-zip-archive-scanner/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/b-zip-archive-scanner/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/b-zip-archive-scanner/reviews/)

## Contributors

 *   [ bPlugins ](https://profiles.wordpress.org/bplugins/)
 *   [ Abu Hayat ](https://profiles.wordpress.org/abuhayat/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/b-zip-archive-scanner/)