Title: Sentryvine — Antivirus &amp; Anti-Phishing Security
Author: sentryvine
Published: <strong>August 26, 2026</strong>
Last modified: August 26, 2026

---

Search plugins

![](https://ps.w.org/sentryvine/assets/icon-256x256.png?rev=3667864)

# Sentryvine — Antivirus & Anti-Phishing Security

 By [sentryvine](https://profiles.wordpress.org/sentryvine/)

[Download](https://downloads.wordpress.org/plugin/sentryvine.0.1.0.zip)

 * [Details](https://wordpress.org/plugins/sentryvine/#description)
 * [Reviews](https://wordpress.org/plugins/sentryvine/#reviews)
 *  [Installation](https://wordpress.org/plugins/sentryvine/#installation)
 * [Development](https://wordpress.org/plugins/sentryvine/#developers)

 [Support](https://wordpress.org/support/plugin/sentryvine/)

## Description

Sentryvine provides a conservative, review-first security scan from the WordPress
administration area.

The initial release includes:

 * Local inspection of executable and redirect-capable files for high-signal malware
   patterns.
 * Detection of executable PHP files in the uploads directory.
 * Anti-phishing analysis for deceptive link text, raw IP destinations, embedded
   URL credentials, Punycode hosts, encoded control characters, dangerous URI schemes,
   and external password forms.
 * Optional WordPress core integrity verification against official checksums.
 * Manual scans and daily WP-Cron scans.
 * Bounded scan reports with severity, evidence, location, and recommended review
   actions.

Sentryvine does not automatically delete, edit, or quarantine files or content. 
Findings are indicators for an administrator to review; they are not proof that 
a site is compromised. A scan with no findings does not guarantee that a site is
safe.

#### External services

By default, Sentryvine scans locally and does not send site files or content to 
an external service.

If an administrator enables “Verify WordPress core checksums,” each scan uses WordPress
core’s checksum function to contact `https://api.wordpress.org/core/checksums/1.0/`.
The request includes the installed WordPress version and locale so the service can
return the matching official file hashes. WordPress HTTP requests may also include
the standard WordPress user-agent. No site files, post content, detected URLs, or
scan findings are sent.

This service is operated by the WordPress project. See the [WordPress.org privacy policy](https://wordpress.org/about/privacy/)
and [terms of service](https://wordpress.org/about/terms/).

## Installation

 1. Upload the `sentryvine` directory to `/wp-content/plugins/`, or install the release
    ZIP through Plugins > Add New > Upload Plugin.
 2. Activate Sentryvine through the Plugins screen.
 3. Open Sentryvine in the WordPress administration menu.
 4. Review the settings and select “Run scan now.”

Daily scans use WP-Cron and may run later than scheduled on sites with little or
no traffic.

## FAQ

### Does Sentryvine remove malware automatically?

No. Version 0.1.0 is intentionally review-only. Automatic remediation can damage
a site when a heuristic produces a false positive.

### Does Sentryvine send my files or content elsewhere?

No. File and content inspection runs locally. The optional core checksum feature
contacts only the official WordPress.org checksum service as described above.

### Is a clean result proof that my site is secure?

No. Sentryvine detects a defined set of indicators. Use layered controls, reliable
backups, updates, least-privilege access, server monitoring, and professional incident
response when compromise is suspected.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Sentryvine — Antivirus & Anti-Phishing Security” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ sentryvine ](https://profiles.wordpress.org/sentryvine/)

[Translate “Sentryvine — Antivirus & Anti-Phishing Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/sentryvine)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/sentryvine/), check
out the [SVN repository](https://plugins.svn.wordpress.org/sentryvine/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/sentryvine/) by 
[RSS](https://plugins.trac.wordpress.org/log/sentryvine/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.0

 * Initial private MVP.
 * Added bounded local file scanning and optional WordPress core checksum verification.
 * Added local anti-phishing content analysis.
 * Added manual and daily scheduled scans with an administrator dashboard.

## Meta

 *  Version **0.1.0**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [anti-phishing](https://wordpress.org/plugins/tags/anti-phishing/)[antivirus](https://wordpress.org/plugins/tags/antivirus/)
   [integrity](https://wordpress.org/plugins/tags/integrity/)[malware scanner](https://wordpress.org/plugins/tags/malware-scanner/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/sentryvine/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/sentryvine/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/sentryvine/reviews/)

## Contributors

 *   [ sentryvine ](https://profiles.wordpress.org/sentryvine/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/sentryvine/)