Home Forums WoodMart support forum wordpress – File appears to be malicious

wordpress – File appears to be malicious

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #723044

    mehmoodm
    Participant

    Hi Support

    I got the following email from worddefence , please advise what actions needs to be done.

    File appears to be malicious or unsafe: wp-content/plugins/native-image-monitor-f582/app/class-core.php

    thanks

    cheers

    #723090

    Aizaz Imtiaz Awan
    Keymaster
    Xtemos team

    Hello,

    The file mentioned in the warning:

    wp-content/plugins/native-image-monitor-f582/app/class-core.php

    does not belong to the WoodMart theme package. We recommend checking whether the native-image-monitor-f582 plugin was intentionally installed on your website. If you do not recognize this plugin or are not actively using it, we suggest temporarily deactivating it and checking whether the site functions correctly. If the plugin is unused or appears suspicious, you may consider removing it.

    Best Regards

    #723105

    mehmoodm
    Participant

    Thanks Awan sab for the details.

    And also please check the attached files of directory structure, please let us know what is not the woodmart theme directory, we believe there are few which malware produced.

    thanks heaps

    Attachments:
    You must be logged in to view attached files.
    #723119

    Aizaz Imtiaz Awan
    Keymaster
    Xtemos team

    Hello,

    Based on the screenshots, the following folders are not part of the WoodMart theme package and should be reviewed carefully:

    – advanced-resource-helper-f348
    – core-font-analytics-170d
    – core-security-engine-f159
    – Seo-enhancer-7e78

    The native-image-monitor-f582 plugin reported by Wordfence is also not a WoodMart component.

    The following are expected WordPress-related directories:

    – woodmart-core
    – woocommerce
    -elementor
    – contact-form-7
    – rank-math
    – wordfence
    -mailchimp-*
    – wp-smushit
    – wp-optimize
    – all-in-one-wp-migration

    If you do not recognize the suspicious folders or did not intentionally install them, we recommend creating a full backup, running a complete Wordfence scan, and removing or investigating those plugins further.

    Since this concerns website security rather than the theme itself, you may also want to consult your hosting provider for a detailed malware assessment.

    Best Regards

Viewing 4 posts - 1 through 4 (of 4 total)