One focused workflow
From bounded input to evidence you can review
- Add the source.Accepted inputs are ZIP, TAR, TAR.GZ, TGZ. The visible limit is 3 files · 128 MB total.
- Confirm the job.Every assigned source number, selected filename and setting stays visible before the confirmed SHA-256 input hash is accepted. Product-specific mappings remain explicit settings rather than guessed roles.
- Process in isolation.A one-job networkless sandbox receives only this job and cannot access accounts, queues, encryption keys or other customer storage.
- Review exact findings.Check a WordPress ZIP or TAR for suspicious PHP patterns, executables in uploads, double extensions, exposed configuration and archive hazards.
- Download the evidence.HTML, suspicious-file and archive-inventory CSV files, static evidence JSON and manifest Every output hash is covered by the coordinator-created manifest.
What this product does not claim
PHP and SQL are never executed. This version performs static risk checks and never claims the backup is malware-free, clean or restorable.