Plugin Author
Eli
(@scheeeli)
Getting a 404 on the scan page in your wp-admin is most likely caused by some other security plugin or malicious software that is intercepting and blocking scan requests.
If this general info does not spark any insight that leads to the solution then please send me a list of plugins that you have installed on your WordPress site, and a screenshot of the 404 error page with the full URL showing, and also the contents of your .htaccess file might be helpful.
If you don’t want to post any of that info on this public forum you can send it to my direct email:
eli AT gotmls DOT net
Ok. Thanks. Will disable Wordfence and try again.
Did not help. Will send you a plugin list.
Plugin Author
Eli
(@scheeeli)
Hi Johan,
Thanks for giving me more time to look at this issue on your site. I was able to narrow it down to the Extended Protection feature of the WAF in your Wordfence settings. Even if you deactivate the Wordfence plugin the WAF is still active if the Extended Protection feature is enabled. I found that you can disable the Extended Protection feature by clicking on “manage WAF” in the firewall setting for Wordfence and that was the only thing that would then allow my plugin to run the Complete Scan on the public_html directory. It’s strange that I could run the scan on other directories but just not on the whole site. Also, I tried to recreate this issue on a few other test sites and was not able to get it to interfere with my scan the way it does on your site. It must have been something to do with the way Wordfence built the firewall rules on your site when it was in the learning phase. Maybe you can get them to help your site relearn it’s firewall rules.