COMPROMISE SCANNER FOR WP2SHELL

Compromise Scanner for wp2shell translation compatibility with REEID Translate — evidence review.

Official plugin evidence describes what Compromise Scanner for wp2shell does, but does not yet establish specific visitor-facing content values that REEID should translate.

Visit Compromise Scanner for wp2shell ↗

AWAITING VERIFICATION

Translation scope is not yet established.

Plugin capabilities can be documented without treating structure, behavior, configuration or feature availability as translatable content.

AWAITING VERIFICATION
This integration has not yet been manually verified by REEID.

TRANSLATION SCOPE
No specific visitor-facing content values are currently approved for translation scope.

PLUGIN EVIDENCE
Plugin capabilities and distinctive features are documented separately from REEID translation support.

PRACTICAL WORKFLOW

Translation workflow

01 · Review official plugin evidence
Document factual capabilities, content models and relevant plugin behavior from the available evidence.

02 · Identify concrete visitor-facing values
Look for explicit labels, titles, descriptions, messages, placeholders or other human-readable content values.

03 · Approve translation scope
Only evidence-backed visitor-facing values become supported translation scope for the integration record.

04 · Test confirmed integration behavior
Validate approved content and plugin behavior before publishing compatibility claims.

PLUGIN INTELLIGENCE

What the official plugin evidence shows

Plugin capabilities

  • Read-only forensic scanning focused on the wp2shell exploit chain (CVE-2026-63030 and CVE-2026-60137) by inspecting WordPress database artifacts and the plugin directory for exploit-related traces.
  • Computes a weighted, scored verdict and categorizes results into indicator levels (No indicators <25, Some indicators 25–49, Multiple indicators 50+) with per-check severity details shown on its admin screen.
  • Detects specific artifact types including oEmbed cache entries with loopback/quantity/timing patterns, object-graph anomalies (e.g., implausible parent IDs, known PoC titles/slugs, customize_changeset entries since disclosure), account artifacts (wp2_ login prefix, @wp2shell.invalid email, and non-founder admin accounts created since disclosure), and deleted-admin traces (orphaned usermeta and gaps in user-ID sequence).
  • Detects webshell plugin files/directories matching the wp2shell_* naming pattern.
  • Provides an “Export report (.zip)” function that downloads a zip archive containing the report (JSON and plain text) plus raw relevant database rows (e.g., oembed_cache, customize_changeset, suspect posts/users, orphaned usermeta) and a LOG-COLLECTION-GUIDE.txt describing server-side logs to gather manually; if PHP zip extension is unavailable, downloads a single JSON file instead.
  • Includes a self-removal workflow: the plugin can be deactivated and deleted via a “Remove this plugin” action on the scan screen; the plugin’s described behavior is not to create/edit/delete site content other than removing itself when requested.

Distinctive features
Read-only forensic scanning focused on the wp2shell exploit chain (CVE-2026-63030 and CVE-2026-60137) by inspecting WordPress database artifacts and the plugin directory for exploit-related traces. Computes a weighted, scored verdict and categorizes results into indicator levels (No indicators <25, Some indicators 25–49, Multiple indicators 50+) with per-check severity details shown on its admin screen. Detects specific artifact types including oEmbed cache entries with loopback/quantity/timing patterns, object-graph anomalies (e.g., implausible parent IDs, known PoC titles/slugs, customize_changeset entries since disclosure), account artifacts (wp2_ login prefix, @wp2shell.invalid email, and non-founder admin accounts created since disclosure), and deleted-admin traces (orphaned usermeta and gaps in user-ID sequence). Detects webshell plugin files/directories matching the wp2shell_* naming pattern. Provides an “Export report (.zip)” function that downloads a zip archive containing the report (JSON and plain text) plus raw relevant database rows (e.g., oembed_cache, customize_changeset, suspect posts/users, orphaned usermeta) and a LOG-COLLECTION-GUIDE.txt describing server-side logs to gather manually; if PHP zip extension is unavailable, downloads a single JSON file instead. Includes a self-removal workflow: the plugin can be deactivated and deleted via a “Remove this plugin” action on the scan screen; the plugin’s described behavior is not to create/edit/delete site content other than removing itself when requested.

Dynamic content
Dynamic or runtime content behavior remains limited to what is explicitly documented in the official plugin evidence.

SEO and metadata
SEO and metadata behavior is documented only where it is explicitly established by official plugin information.

URLs and navigation
URL and navigation behavior remains outside translation scope unless explicitly represented by the integration category.

Forms and commerce
Forms and commerce behavior is limited to factual capabilities documented for this plugin.

CONTENT BOUNDARY

Keep plugin capabilities separate from translation scope.

Current evidence documents what Compromise Scanner for wp2shell does, but no specific visitor-facing content values have been approved as translation scope.

Structure, configuration, logic, integrations and runtime behavior are not translation claims.

LIMITATIONS & QA

Verification notes

  • This integration is documented for compatibility context. Visitor-facing translation scope is not listed for this category.

COMMON QUESTIONS

Compromise Scanner for wp2shell and REEID Translate FAQ.

Does the current evidence establish translation scope for Compromise Scanner for wp2shell?

No specific visitor-facing content values are currently approved as translation scope for this integration.

What does the plugin intelligence section describe?

It summarizes factual plugin capabilities and distinctive features separately from REEID translation-support claims.

What is required before translation scope is published?

Concrete visitor-facing content values must be supported by evidence, approved for the integration record and tested as appropriate.

RELATED GUIDES

Continue through the compatibility library.

INTEGRATION EVIDENCE

Explore REEID Translate for multilingual WordPress workflows.

REEID separates factual plugin intelligence from evidence-backed translation scope.

No specific visitor-facing content values are currently approved for this integration.

Shopping Cart
Scroll to Top