Suspicious files in uploads
PHP malware hidden in the uploads folder: how to catch it at once
The uploads folder should hold images and documents. A PHP file in there is almost always a backdoor.
The problem
The most writable folder is also the most attacked.
Vulnerable plugins, upload forms and nulled themes let attackers drop files into the uploads folder. From there a PHP backdoor can take the site back even after a clean-up.
The file often has an innocent name or a double extension, like cache.php or logo.php.jpg.
How it works
A scan that knows where to look.
- 1
First scan
The agent records the state of the site’s files, skipping caches and noisy folders.
- 2
Later scans
Every hour it looks for new or changed files, in short steps.
- 3
Report
A PHP file in uploads or a suspicious double extension triggers a critical alert, and you can view its content from the dashboard.
In detail
What gets flagged.
- PHP files in
wp-content/uploadsand in Joomla media folders - Double extensions such as
.php.jpgor.phtml - New or changed files elsewhere, compared with the previous scan
.htaccess,.user.iniandauto_prepend_file: where malware loads before the CMS- File content viewable from the dashboard, so you can decide without FTP
FAQ
Frequently asked questions
Why is a PHP file in uploads so suspicious?
Because WordPress and Joomla never put executable code there: that folder should only hold media and documents.
Does scanning slow the site down?
No, it runs in steps of a few seconds and skips caches and other plugins’ backups.
Related features
Goes well with
Try it on your clients’ sites.
During the beta we welcome agencies in small groups and set up the first sites together.