Title: Reporting a false positive
Last modified: August 30, 2016

---

# Reporting a false positive

 *  Resolved [Gary H](https://wordpress.org/support/users/axe6st/)
 * (@axe6st)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/reporting-a-false-positive/)
 * I literally just updated to wordpress 4.4. Immediately following that I ran a
   word fence scan. It determined that the file /wp-admin/includes/class-pclzip.
   php is not a core file or a plugin file and may include malicious code.
    When
   I checked the file date and time, it is identical to when I updated wordpress
   to version 4.4. Is this file malicious? Should I delete it? or is it a false 
   positive. I am still having issues with new files being added and cleaning them
   out daily. Axe
 * [https://wordpress.org/plugins/wordfence/](https://wordpress.org/plugins/wordfence/)

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Thread Starter [Gary H](https://wordpress.org/support/users/axe6st/)
 * (@axe6st)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/reporting-a-false-positive/#post-6826690)
 * ok, nevermind. When I scanned again it is no longer reporting that file and when
   I updated the other sites they all scan clean. 🙂
 *  Plugin Author [WFMattR](https://wordpress.org/support/users/wfmattr/)
 * (@wfmattr)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/reporting-a-false-positive/#post-6826831)
 * Thanks for posting the follow-up message!
 * For anyone else that comes across this post, if WordPress is updated on your 
   site soon after a new release, and before our scanning server gets a copy of 
   it, the core files will be treated as non-core files and will be scanned for 
   common malware patterns. class-pclzip.php includes code that many suspicious 
   files have, but it uses it in different ways and is normally not malicious.
 * -Matt R

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Reporting a false positive’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 2 replies
 * 2 participants
 * Last reply from: [WFMattR](https://wordpress.org/support/users/wfmattr/)
 * Last activity: [10 years, 8 months ago](https://wordpress.org/support/topic/reporting-a-false-positive/#post-6826831)
 * Status: resolved