• Resolved Gary H

    (@axe6st)


    I literally just updated to wordpress 4.4. Immediately following that I ran a word fence scan. It determined that the file /wp-admin/includes/class-pclzip.php is not a core file or a plugin file and may include malicious code.
    When I checked the file date and time, it is identical to when I updated wordpress to version 4.4.
    Is this file malicious? Should I delete it? or is it a false positive.
    I am still having issues with new files being added and cleaning them out daily.
    Axe

    https://wordpress.org/plugins/wordfence/

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter Gary H

    (@axe6st)

    ok, nevermind. When I scanned again it is no longer reporting that file and when I updated the other sites they all scan clean. 🙂

    Plugin Author WFMattR

    (@wfmattr)

    Thanks for posting the follow-up message!

    For anyone else that comes across this post, if WordPress is updated on your site soon after a new release, and before our scanning server gets a copy of it, the core files will be treated as non-core files and will be scanned for common malware patterns. class-pclzip.php includes code that many suspicious files have, but it uses it in different ways and is normally not malicious.

    -Matt R

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Reporting a false positive’ is closed to new replies.