{"id":359742,"date":"2026-08-26T22:33:48","date_gmt":"2026-08-26T22:33:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sentryvine-antivirus-anti-phishing-security\/"},"modified":"2026-08-26T22:33:29","modified_gmt":"2026-08-26T22:33:29","slug":"sentryvine","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/sentryvine\/","author":23555960,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.0","stable_tag":"0.1.0","tested":"7.1","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"Sentryvine \u2014 Antivirus & Anti-Phishing Security","header_author":"Sentryvine","header_description":"Scans WordPress files and published content for malware indicators, integrity changes, and phishing risks.","assets_banners_color":"","last_updated":"2026-08-26 22:33:29","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":39,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"sentryvine","date":"2026-08-26 22:33:29","revision":3667864}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3667864,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3667864,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[145796,1175,173015,55021,600],"plugin_category":[54],"plugin_contributors":[277740],"plugin_business_model":[],"class_list":["post-359742","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-phishing","plugin_tags-antivirus","plugin_tags-integrity","plugin_tags-malware-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-sentryvine","plugin_committers-sentryvine"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sentryvine\/assets\/icon-128x128.png?rev=3667864","icon_2x":"https:\/\/ps.w.org\/sentryvine\/assets\/icon-256x256.png?rev=3667864","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Sentryvine provides a conservative, review-first security scan from the WordPress administration area.<\/p>\n\n<p>The initial release includes:<\/p>\n\n<ul>\n<li>Local inspection of executable and redirect-capable files for high-signal malware patterns.<\/li>\n<li>Detection of executable PHP files in the uploads directory.<\/li>\n<li>Anti-phishing analysis for deceptive link text, raw IP destinations, embedded URL credentials, Punycode hosts, encoded control characters, dangerous URI schemes, and external password forms.<\/li>\n<li>Optional WordPress core integrity verification against official checksums.<\/li>\n<li>Manual scans and daily WP-Cron scans.<\/li>\n<li>Bounded scan reports with severity, evidence, location, and recommended review actions.<\/li>\n<\/ul>\n\n<p>Sentryvine does not automatically delete, edit, or quarantine files or content. Findings are indicators for an administrator to review; they are not proof that a site is compromised. A scan with no findings does not guarantee that a site is safe.<\/p>\n\n<h4>External services<\/h4>\n\n<p>By default, Sentryvine scans locally and does not send site files or content to an external service.<\/p>\n\n<p>If an administrator enables \"Verify WordPress core checksums,\" each scan uses WordPress core's checksum function to contact <code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code>. The request includes the installed WordPress version and locale so the service can return the matching official file hashes. WordPress HTTP requests may also include the standard WordPress user-agent. No site files, post content, detected URLs, or scan findings are sent.<\/p>\n\n<p>This service is operated by the WordPress project. See the <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">WordPress.org privacy policy<\/a> and <a href=\"https:\/\/wordpress.org\/about\/terms\/\">terms of service<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>sentryvine<\/code> directory to <code>\/wp-content\/plugins\/<\/code>, or install the release ZIP through Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate Sentryvine through the Plugins screen.<\/li>\n<li>Open Sentryvine in the WordPress administration menu.<\/li>\n<li>Review the settings and select \"Run scan now.\"<\/li>\n<\/ol>\n\n<p>Daily scans use WP-Cron and may run later than scheduled on sites with little or no traffic.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20sentryvine%20remove%20malware%20automatically%3F\"><h3>Does Sentryvine remove malware automatically?<\/h3><\/dt>\n<dd><p>No. Version 0.1.0 is intentionally review-only. Automatic remediation can damage a site when a heuristic produces a false positive.<\/p><\/dd>\n<dt id=\"does%20sentryvine%20send%20my%20files%20or%20content%20elsewhere%3F\"><h3>Does Sentryvine send my files or content elsewhere?<\/h3><\/dt>\n<dd><p>No. File and content inspection runs locally. The optional core checksum feature contacts only the official WordPress.org checksum service as described above.<\/p><\/dd>\n<dt id=\"is%20a%20clean%20result%20proof%20that%20my%20site%20is%20secure%3F\"><h3>Is a clean result proof that my site is secure?<\/h3><\/dt>\n<dd><p>No. Sentryvine detects a defined set of indicators. Use layered controls, reliable backups, updates, least-privilege access, server monitoring, and professional incident response when compromise is suspected.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial private MVP.<\/li>\n<li>Added bounded local file scanning and optional WordPress core checksum verification.<\/li>\n<li>Added local anti-phishing content analysis.<\/li>\n<li>Added manual and daily scheduled scans with an administrator dashboard.<\/li>\n<\/ul>","raw_excerpt":"Scan WordPress files and published content for malware indicators, core integrity changes, and phishing risks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/359742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=359742"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sentryvine"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=359742"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=359742"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=359742"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=359742"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=359742"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=359742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}