{"id":342682,"date":"2026-07-28T15:43:18","date_gmt":"2026-07-28T15:43:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/eh-clinic-by-teraserver\/"},"modified":"2026-07-28T15:42:54","modified_gmt":"2026-07-28T15:42:54","slug":"teraserver-clinic","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/teraserver-clinic\/","author":23531863,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.6.3","stable_tag":"0.6.3","tested":"7.0.2","requires":"5.8","requires_php":"7.2","requires_plugins":null,"header_name":"TeraServer Clinic Scan & Repair Kit","header_author":"TeraServer Clinic","header_description":"Keeps your WordPress updated and monitored. Connects to your TeraServer Clinic account.","assets_banners_color":"22446f","last_updated":"2026-07-28 15:42:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/wpclinic.ai","rating":0,"author_block_rating":0,"active_installs":0,"downloads":30,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.6.3":{"tag":"0.6.3","author":"famelhaut","date":"2026-07-28 15:42:54"}},"upgrade_notice":{"0.4.64":"<p>Cleanup fixes: quarantine list refresh, failures shown correctly, DB cleanup free on all\nplans, Nginx quarantine-exposure warning.<\/p>","0.4.63":"<p>Auto-updates, cleanup, and local backups are now free on all plans; minor compliance fixes.<\/p>","0.4.61":"<p>First WordPress.org submission build.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3626145,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3626145,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3626145,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3626145,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.6.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3626145,"resolution":"1","location":"assets","locale":"","width":1119,"height":863},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3626145,"resolution":"2","location":"assets","locale":"","width":1119,"height":863},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3626145,"resolution":"3","location":"assets","locale":"","width":1119,"height":863},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3626145,"resolution":"4","location":"assets","locale":"","width":1119,"height":863}},"screenshots":{"1":"Dashboard overview: plan, auto-update status, autoscan cadence, site health, and last scan result.","2":"Cleanup: finds files, folders and database junk that nothing on your site references anymore, and moves them to a reversible quarantine (nothing is ever deleted outright).","3":"Alerts \/ findings list with severity and file\/location detail.","4":"Harden: one-click, reversible WordPress security hardening (headers, XML-RPC, user enumeration, and more)."}},"plugin_section":[],"plugin_tags":[151,1184,6464,600,2550],"plugin_category":[54,59],"plugin_contributors":[273623],"plugin_business_model":[],"class_list":["post-342682","plugin","type-plugin","status-publish","hentry","plugin_tags-backup","plugin_tags-malware","plugin_tags-scanner","plugin_tags-security","plugin_tags-updates","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-famelhaut","plugin_committers-famelhaut"],"banners":{"banner":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/banner-772x250.png?rev=3626145","banner_2x":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/banner-1544x500.png?rev=3626145","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/icon-128x128.png?rev=3626145","icon_2x":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/icon-256x256.png?rev=3626145","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/screenshot-1.png?rev=3626145","caption":"Dashboard overview: plan, auto-update status, autoscan cadence, site health, and last scan result."},{"src":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/screenshot-2.png?rev=3626145","caption":"Cleanup: finds files, folders and database junk that nothing on your site references anymore, and moves them to a reversible quarantine (nothing is ever deleted outright)."},{"src":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/screenshot-3.png?rev=3626145","caption":"Alerts \/ findings list with severity and file\/location detail."},{"src":"https:\/\/ps.w.org\/teraserver-clinic\/assets\/screenshot-4.png?rev=3626145","caption":"Harden: one-click, reversible WordPress security hardening (headers, XML-RPC, user enumeration, and more)."}],"raw_content":"<!--section=description-->\n<p>TeraServer Clinic is the on-site agent for the TeraServer Clinic service (wpclinic.ai). It connects your\nWordPress installation to a TeraServer Clinic account and, depending on your plan, scans for\nmalicious code, keeps WordPress core\/plugins\/themes updated, backs up your files, and\napplies AI-assisted cleanup when a threat is found.<\/p>\n\n<p>The <strong>free scan works standalone<\/strong> with just a connection token \u2014 no payment required.\nPaid plans add faster\/scheduled autoscan, automatic updates, off-site backups, AI-assisted\nrepair of infected files, and monitoring across more sites.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Malware scan<\/strong>: walks <code>wp-content<\/code> (uploads first) looking for PHP dropped in the\nuploads folder, double file extensions, known webshell\/backdoor signatures, obfuscated\n  eval() calls, and cryptomining scripts. Also checks the database for recently created\nadministrator accounts and posts\/options containing injected\/obfuscated code.<\/li>\n<li><strong>Security hardening<\/strong>: one-click, reversible fixes for common misconfigurations\n(missing security headers, XML-RPC exposure, user enumeration, exposed readme\/info\nfiles, file editor access, directory listing) plus a built-in login-URL cloak.<\/li>\n<li><strong>Automatic updates<\/strong> (paid plans): keeps plugins, themes and WordPress core current,\neach update guarded by an automatic backup, a post-update health check, and a rollback\nif anything breaks. A manual scan\/update can also be triggered from the dashboard.<\/li>\n<li><strong>Autoscan<\/strong>: periodic scanning (daily or weekly depending on plan) via WordPress cron.<\/li>\n<li><strong>Backups<\/strong> (paid plans): a small \"repair set\" backup before any automated fix, an\non-demand full-site backup, and an opt-in weekly full backup \u2014 all stored off-site on\nTeraServer Clinic's backup storage, not on your own hosting.<\/li>\n<li><strong>PHP compatibility report<\/strong>: analyzes the plugins and themes actually in use to\nrecommend the highest PHP version your site can safely run.<\/li>\n<li><strong>AI-assisted cleanup<\/strong> (paid plans): when malware is found, a proposed fix is generated\noff-site and applied through the plugin's own audited code \u2014 never as a remote shell \u2014\nalways preceded by a backup and followed by a health check with automatic rollback if\nanything breaks.<\/li>\n<\/ul>\n\n<p>This WordPress.org edition receives its own updates exclusively through the WordPress.org\nplugin directory, like any other listed plugin \u2014 it does not use a custom update\nmechanism for itself.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin is a thin client: on its own, without a connection, it does nothing. To do\nanything useful it must be connected \u2014 via a one-time connection token generated in your\nTeraServer Clinic account \u2014 to the TeraServer Clinic service, using an API key issued to your site. No\ndata described below is sent anywhere until you complete that connection step, which\nitself shows this same disclosure and links to the Terms and Privacy Policy before you\nsubmit a token.<\/p>\n\n<p>Once connected, this plugin communicates with the TeraServer Clinic backend for the following,\neach described with what is sent and when:<\/p>\n\n<ul>\n<li><strong>Connecting\/licensing.<\/strong> When you paste a connection token, the plugin sends your\nsite's home URL and the plugin version to exchange that token for a per-site API key\nand your plan's entitlements. This happens once at connection time, and again if you\nmove the site to a different TeraServer Clinic account.<\/li>\n<li><strong>Periodic sync.<\/strong> Roughly twice daily (WordPress cron) and right after connecting, the\nplugin sends your site URL, WordPress version, PHP version, plugin version, the current\nlogin URL, and a full inventory of installed plugins\/themes (name, version,\nactive\/inactive, available updates) so the service can tell you what needs attention\nand, on plans that include it, apply updates.<\/li>\n<li><strong>Scan reports.<\/strong> After every scan (free tier included), the plugin sends the list of\nfindings \u2014 file paths\/locations, finding type, and severity\/detail text, not full file\ncontents \u2014 so they show up in your TeraServer Clinic dashboard and can trigger email alerts.<\/li>\n<li><strong>Malware-signature confirmation.<\/strong> During any scan (free tier included), if a small,\nbounded set of files (at most 25 files, 1 MB each) already matches a local\nsuspicious-pattern check, the plugin sends the <strong>full contents of just those flagged\nfiles<\/strong> to the TeraServer Clinic service for a second, server-side confirmation pass. Files that\ndon't match a local pattern first are never sent this way.<\/li>\n<li><strong>Off-site backups (paid plans).<\/strong> Manual and scheduled full-site backups, and the\nsmall \"repair set\" backup taken automatically before any destructive action (delete,\nrepair, update), are uploaded as a zip to TeraServer Clinic's backup storage, kept for a limited\nretention window so a site can be restored.<\/li>\n<li><strong>AI-assisted repair (paid plans).<\/strong> When you request a fix for detected malware, the\n<strong>full contents of the specific flagged file(s)<\/strong> (never your whole site) are sent to\nthe TeraServer Clinic service, which returns a proposed cleaned version. That content is used\nonly to produce the fix and is not retained afterwards. The plugin applies the returned\npatch itself, using its own code \u2014 the fix is never executed as a remote script \u2014 and\nalways backs up first and rolls back automatically if a post-fix health check fails.<\/li>\n<li><strong>Admin email breach check.<\/strong> On a connected site, the plugin sends your WordPress\nadmin email address to the TeraServer Clinic service, which checks it against known public data\nbreaches and returns whether\/how many breaches matched (not the breach data itself).<\/li>\n<li><strong>Plugin\/theme alternative &amp; compatibility suggestions.<\/strong> The plugin sends the slugs and\nversions of installed plugins\/themes so the service can suggest actively-maintained\nalternatives or flag PHP\/WordPress compatibility issues \u2014 no file contents are sent for\nthis.<\/li>\n<\/ul>\n\n<p>Separately, and independent of the TeraServer Clinic connection above:<\/p>\n\n<ul>\n<li><strong>Cloudflare Turnstile (opt-in, your own keys).<\/strong> If you choose to turn on the optional\ncaptcha\/bot-protection feature on the Security tab, you paste your own free Cloudflare\nTurnstile sitekey and secret key (obtained directly from Cloudflare, not from TeraServer Clinic).\nFrom then on, the login\/comment\/registration pages you enabled it for load Cloudflare's\nTurnstile script (challenges.cloudflare.com), and each submission's response token is sent\nto Cloudflare's siteverify endpoint for validation. No data goes to TeraServer Clinic for this\nfeature \u2014 only to Cloudflare, using your own account. See Cloudflare's Privacy Policy\n(https:\/\/www.cloudflare.com\/privacypolicy\/) for their handling of this data. If left off\n(the default), no data is ever sent to Cloudflare.<\/li>\n<\/ul>\n\n<p>All of the above only happens after you connect the plugin with a valid API key; a\ndisconnected\/inactive install sends nothing. See the TeraServer Clinic Terms of Service\n(https:\/\/wpclinic.ai\/legal\/terminos) and Privacy Policy\n(https:\/\/wpclinic.ai\/legal\/privacidad) for the full data-handling and retention terms.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/teraserver-clinic<\/code>, or install it through the\nWordPress plugin screen directly.<\/li>\n<li>Activate the plugin through the \"Plugins\" screen in WordPress.<\/li>\n<li>Go to the new \"TeraServer Clinic\" menu item in your WordPress admin.<\/li>\n<li>Create (or sign in to) a TeraServer Clinic account at wpclinic.ai, go to your account's Plugin\npage, and copy the connection token.<\/li>\n<li>Paste the token into the \"Connect your site\" form and submit.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20plugin%20free%3F\"><h3>Is this plugin free?<\/h3><\/dt>\n<dd><p>The plugin itself is free and licensed under the GPL. What it can do on your site\ndepends on your TeraServer Clinic account plan: some features (autoscan cadence, auto-update,\noff-site backups, AI-assisted cleanup) are limited to paid plans; a scan is available on\nthe free tier.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20account%3F\"><h3>Do I need an account?<\/h3><\/dt>\n<dd><p>Yes. The plugin requires a TeraServer Clinic account and a connection token to do anything \u2014\nwithout a valid connection, it stays inert and sends no data anywhere.<\/p><\/dd>\n<dt id=\"what%20data%20does%20it%20send%2C%20and%20where%3F\"><h3>What data does it send, and where?<\/h3><\/dt>\n<dd><p>See \"External services\" above for the itemized list. In short: once connected, site\nidentity\/version\/inventory and scan-finding metadata are always sent to the TeraServer Clinic\nservice; full file contents are only sent for a bounded, already-flagged set of\nsuspicious files (signature confirmation, on any tier) or for paid backup\/AI-cleanup\nfeatures, and are not retained beyond producing that backup or fix.<\/p><\/dd>\n<dt id=\"what%20runs%20on%20teraserver%20clinic%27s%20server%20versus%20on%20my%20site%3F\"><h3>What runs on TeraServer Clinic's server versus on my site?<\/h3><\/dt>\n<dd><p>Scanning for malware, running WordPress\/plugin\/theme updates, and building backups all\nrun locally on your own site (this plugin does the work). The TeraServer Clinic server keeps\ntrack of your entitlements\/plan, stores scan history and off-site backups, confirms\nsuspicious files against its own signature database, and \u2014 for AI-assisted cleanup \u2014\nanalyzes a flagged file and returns a proposed patch, which this plugin then applies\nlocally using its own audited code (never a remote shell).<\/p><\/dd>\n<dt id=\"how%20does%20this%20plugin%20update%20itself%3F\"><h3>How does this plugin update itself?<\/h3><\/dt>\n<dd><p>This WordPress.org edition updates exactly like any other plugin listed on\nWordPress.org \u2014 through the WordPress.org plugin directory, using WordPress's normal\nupdate mechanism. It does not check any other server for its own updates.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.4.72<\/h4>\n\n<ul>\n<li>Fixed: the \"PHP still executes in uploads\" fix instructions now detect your actual web\nserver (Apache, nginx, LiteSpeed, or OpenLiteSpeed) and control panel instead of assuming\nnginx and Plesk \u2014 OpenLiteSpeed (common with CyberPanel) does not read .htaccess at all and\nneeds a different fix, which is now shown.<\/li>\n<li>Added: the Dashboard now always shows your detected web server (with version, when your\nserver discloses it) and control panel, even when there is no problem to report.<\/li>\n<\/ul>\n\n<h4>0.4.70<\/h4>\n\n<ul>\n<li>Cleanup: fixed a memory exhaustion that could stall restoring a large quarantined database\nitem \u2014 restore now streams the snapshot row-by-row instead of loading it all at once.<\/li>\n<\/ul>\n\n<h4>0.4.64<\/h4>\n\n<ul>\n<li>Cleanup: fixed the quarantine list not refreshing after an action, and failures now show\nas failures instead of a false \"Done\".<\/li>\n<li>Cleanup: database cleanup no longer requires a paid off-site backup \u2014 it works on all\nplans using a local, reversible snapshot.<\/li>\n<li>Cleanup: warns if the quarantine folder is reachable from the internet on Nginx.<\/li>\n<\/ul>\n\n<h4>0.4.63<\/h4>\n\n<ul>\n<li>Auto-updates, cleanup, and local backups are now free on all plans.<\/li>\n<li>Consistent plugin naming throughout the admin UI.<\/li>\n<li>Assets\/scripts are now properly enqueued, and plugin writes moved to the uploads directory.<\/li>\n<\/ul>\n\n<h4>0.4.62<\/h4>\n\n<ul>\n<li>Fixed the Cleanup tab not opening when clicked (it fell back to the Dashboard).<\/li>\n<\/ul>\n\n<h4>0.4.61<\/h4>\n\n<ul>\n<li>WordPress.org submission build: the self-hosted update mechanism (used only by the\ndirect-download edition of this plugin) is fully disabled in this edition; updates for\nthis edition come only from the WordPress.org plugin directory.<\/li>\n<li>Added an in-plugin external-services disclosure notice on the Dashboard tab, and this\nreadme's \"External services\" section.<\/li>\n<\/ul>","raw_excerpt":"Scans for malware, keeps core\/plugins\/themes updated, and backs up your site \u2014 connected to your free or paid TeraServer Clinic account.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/342682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=342682"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/famelhaut"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=342682"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=342682"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=342682"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=342682"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=342682"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=342682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}