WoluTools

WordPress Backup Static Risk Scanner

WordPress Backup Static Risk Scanner Online: inspect a WordPress backup without restoring or running it.

Turn an offline backup into a static suspicious-file worklist before restoration.

START HEREChoose documentsZIP, TAR, TAR.GZ, TGZ
Maximum
3 files · 128 MB total
File handling
Draft 2 hours · encrypted result 24 hours
FREE3 jobs a dayFiles up to 10 MB
PROUp to 200 jobs a day€12.99/month or €89.99/year
See plans

Larger files need Pro. Failed jobs are never counted.

  • Prepared example is free
  • 3 free jobs a day
  • Cancel anytime
EXAMPLE RESULTSample data
Files · 14,205
7
2
14,205
Archive hazards · 2
Seven static file risks need manual investigationHTML, suspicious-file and archive-inventory CSV files, static evidence JSON and manifest
Files
14,205
Suspicious
7
Archive hazards
2
Formats, limits & file handling
Works with
ZIP, TAR, TAR.GZ, TGZ
Limit
3 files · 128 MB total
You receive
HTML, suspicious-file and archive-inventory CSV files, static evidence JSON and manifest
File handling
Draft 2 hours · encrypted result 24 hours

Turn an offline backup into a static suspicious-file worklist before restoration.

THREE CLEAR STEPS

From your documents to a usable result.

  1. 01
    Add your input

    Limits and supported formats are visible before you begin.

  2. 02
    Review the result

    Check the preview, findings or artwork before you download.

  3. 03
    Download

    Use your free job, plan or credits. Failed jobs are never counted.

Prepared result preview

See the decision before sharing a real file.

Turn an offline backup into a static suspicious-file worklist before restoration. This prepared example uses fictional data and the same evidence structure as the server export.

✓
Nothing is uploadedPublic demo only

WordPress recovery

Seven static file risks need manual investigation

PHP and SQL are never executed. This version performs static risk checks and never claims the backup is malware-free, clean or restorable.

Actual prepared coverage: Static archive and PHP-pattern analysis only · no malware-clean claim

  • UrgentExecutable PHP in uploadswp-content/uploads/2026/08/cache.php
  • UrgentObfuscated execution patternwp-content/plugins/helper/load.php · eval(base64_decode(...))
  • ImportantDouble extensionwp-content/uploads/invoice.pdf.php
Files
14,205
Suspicious
7
Archive hazards
2
Show the verified package

HTML, suspicious-file and archive-inventory CSV files, static evidence JSON and manifest

Engine wordpress-backup-scanner-v1 · rules wordpress-signatures-2026-08-30

One focused workflow

From bounded input to evidence you can review

  1. Add the source.Accepted inputs are ZIP, TAR, TAR.GZ, TGZ. The visible limit is 3 files · 128 MB total.
  2. Confirm the job.Every assigned source number, selected filename and setting stays visible before the confirmed SHA-256 input hash is accepted. Product-specific mappings remain explicit settings rather than guessed roles.
  3. Process in isolation.A one-job networkless sandbox receives only this job and cannot access accounts, queues, encryption keys or other customer storage.
  4. Review exact findings.Check a WordPress ZIP or TAR for suspicious PHP patterns, executables in uploads, double extensions, exposed configuration and archive hazards.
  5. Download the evidence.HTML, suspicious-file and archive-inventory CSV files, static evidence JSON and manifest Every output hash is covered by the coordinator-created manifest.

What this product does not claim

PHP and SQL are never executed. This version performs static risk checks and never claims the backup is malware-free, clean or restorable.

Clear answers

WordPress Backup Static Risk Scanner FAQ

Which backup formats can I upload?

ZIP, TAR, TAR.GZ and TGZ, up to three files and 128 MB in total. Archives are expanded inside fixed limits of 10,000 entries and 1 GB of expanded content.

Does the scanner restore or run the backup?

No. PHP and SQL files are read as text. Nothing is executed and no database is imported, so a hostile backup cannot act during the check.

What does a finding look like?

Each finding names the archive path and the reason, for example an executable PHP file under wp-content/uploads or an eval with base64_decode inside a plugin folder.

Is a quiet report proof that the site is not infected?

No. This is a static pattern check against a pinned rule set, not antivirus. Content patterns are read from the first 4 MB of each file, so a silent report means nothing matched within that budget.

What is in the download?

An HTML report, a suspicious-file CSV, an archive inventory CSV, the static evidence JSON and a manifest covering every output hash.

Available now

Inspect a WordPress backup without restoring or running it.

Inspect the fictional result now. Your own files run here without an account: 3 free jobs a day, or up to 200 a day with Pro.