Title: AMWScan Antimalware Scanner Lite
Author: Marco Cesarato
Published: <strong>September 4, 2026</strong>
Last modified: September 11, 2026

---

Search plugins

![](https://ps.w.org/amwscan/assets/banner-772x250.png?rev=3680934)

![](https://ps.w.org/amwscan/assets/icon-256x256.png?rev=3681213)

# AMWScan Antimalware Scanner Lite

 By [Marco Cesarato](https://profiles.wordpress.org/marcocesarato1/)

[Download](https://downloads.wordpress.org/plugin/amwscan.0.5.9.zip)

 * [Details](https://es-hn.wordpress.org/plugins/amwscan/#description)
 * [Reviews](https://es-hn.wordpress.org/plugins/amwscan/#reviews)
 *  [Installation](https://es-hn.wordpress.org/plugins/amwscan/#installation)
 * [Development](https://es-hn.wordpress.org/plugins/amwscan/#developers)

 [Support](https://wordpress.org/support/plugin/amwscan/)

## Description

Protect your WordPress site with the free AMWScan PHP antimalware engine, managed
from a clear administrator-only workspace. AMWScan Antimalware Scanner Lite checks
uploads before WordPress accepts them, runs deep scans on demand or on schedule,
and turns each finding into a report you can review and act on.

#### Block threats at upload

Upload protection is enabled by default. It scans media and plugin or theme ZIP 
packages before WordPress accepts them. Detected files and uploads that cannot be
scanned completely are blocked, and their reports are retained for review. ZIP inspection
requires the PHP ZIP extension; administrators can disable upload protection under
Antimalware > Settings > Scan policy.

#### Scan on your schedule

 * Choose manual scans or precisely scheduled background scans.
 * Follow live checked-file progress, scan rate, and estimated time remaining.
 * Resume interrupted scans instead of starting over.
 * Move from Signatures, with the lowest alert volume, through Functions, Lite, 
   and Exploits to Full for the broadest coverage.
 * Receive security finding alerts and see recent activity in the WordPress dashboard
   widget.
 * See unresolved security findings in the administrator toolbar and open reports
   with one click.
 * Monitor incoming WordPress requests against a curated local indicator file and
   review matches without automatically blocking visitors.
 * Browse local folders or connect to read-only FTP/FTPS sources.

#### See the whole security picture

AMWScan organizes canonical findings so you can distinguish malware from other security
risks without sorting through duplicate results.

 * Detect suspicious code and signatures under Malware detections, shown once and
   collapsed until you open them.
 * Review integrity, vulnerability, and reputation checks together under Security
   findings.
 * Use lifecycle exceptions to manage known findings without losing their history.
 * Opt in to bounded ZIP content scanning under Antimalware > Settings > Scope and
   limits. Archives that exceed the safety limits are reported as incomplete coverage.

#### Review and remediate with confidence

Responsive reports make findings easy to filter and inspect across desktop and mobile
screens. Report-only scanning is enabled by default, so a scan does not change files
unless you choose a remediation action.

From the dashboard, review scan history, manage the whitelist and quarantine, create
backups, and apply supported automatic fixes. Eligible installed-plugin files open
in WordPress’s native plugin editor. File-changing actions require explicit confirmation.
Responsibility and backup warnings appear when automatic actions are enabled or 
saved and before report remediation or quarantine deletion. Lite can quarantine 
files and permanently delete them after confirmation, but it cannot restore them.

#### Built for WordPress administration

Only administrators with the `manage_options` capability can access AMWScan. The
About page lists installed plugin and engine versions alongside documentation, support,
contribution guidance, licensing, and project credits.

The plugin follows the WordPress site language. It includes bundled Italian, German,
French, Spanish, Russian, Chinese, Japanese, Hindi, and Arabic translations, with
English as the source and fallback. WordPress uses a matching WordPress.org language
pack when available, then the bundled catalog. Arabic and other right-to-left locales
receive a mirrored admin layout while file paths and hashes remain left-to-right.

#### Optional AI finding review and external services

GenAI finding review is disabled by default. When an administrator enables it, AMWScan
sends a bounded detected-code excerpt to the selected service for an advisory malware,
false-positive, or uncertain verdict. AI results never trigger file changes automatically.

The recommended WordPress AI option is shown only when the WordPress AI Client is
available. Install the canonical plugin from https://wordpress.org/plugins/ai/. 
It uses connector credentials, model preferences, fallback, and approval configured
under Settings > Connectors (`wp-admin/options-connectors.php`). Manage AI plugin
features under Settings > AI (`wp-admin/options-general.php?page=ai-wp-admin`). 
The applicable connector provider’s terms and privacy policy govern those requests.

Direct integrations are also available and send excerpts to the selected provider
only after an administrator supplies credentials and enables review:

 * OpenAI API: https://openai.com/policies/terms-of-use and https://openai.com/policies/
   privacy-policy
 * Anthropic API: https://www.anthropic.com/legal/commercial-terms and https://www.
   anthropic.com/legal/privacy
 * Google Gemini API: https://ai.google.dev/gemini-api/terms and https://policies.
   google.com/privacy

#### Lite and Full editions

AMWScan Antimalware Scanner Lite is packaged independently for WordPress.org without
backend editor services, editor routes, or quarantined-file restoration code. The
shared frontend bundle cannot enable these absent server features. Install only 
one AMWScan edition at a time.

The built-in diff editor and quarantined-file restoration are available only in 
the Full GitHub edition.

#### Interested in development?

Follow development, report issues, contribute, and download the Full edition on 
GitHub: https://github.com/marcocesarato/PHP-Antimalware-Scanner

Open Antimalware > About after installation to explore the plugin and its project
resources.

## Screenshots

[⌊Detailed scan report with severity filters, expanded security findings, malware
detections, evidence, and remediation controls.⌉⌊Detailed scan report with severity
filters, expanded security findings, malware detections, evidence, and remediation
controls.⌉[

Detailed scan report with severity filters, expanded security findings, malware 
detections, evidence, and remediation controls.

[⌊Dashboard with daily manual and scheduled scan activity, scanner policy, security
metrics, and recent reports.⌉⌊Dashboard with daily manual and scheduled scan activity,
scanner policy, security metrics, and recent reports.⌉[

Dashboard with daily manual and scheduled scan activity, scanner policy, security
metrics, and recent reports.

[⌊Report history with scan dates, durations, file counts, and detection totals.⌉⌊
Report history with scan dates, durations, file counts, and detection totals.⌉[

Report history with scan dates, durations, file counts, and detection totals.

[⌊Quarantine manager with isolated-file metadata and permanent deletion controls.⌉⌊
Quarantine manager with isolated-file metadata and permanent deletion controls.⌉[

Quarantine manager with isolated-file metadata and permanent deletion controls.

[⌊Whitelist manager with reviewed matches and removal controls.⌉⌊Whitelist manager
with reviewed matches and removal controls.⌉[

Whitelist manager with reviewed matches and removal controls.

[⌊Fully expanded settings for scan policy, AI review, alerts, traffic protection,
definitions, scope, and private storage.⌉⌊Fully expanded settings for scan policy,
AI review, alerts, traffic protection, definitions, scope, and private storage.⌉[

Fully expanded settings for scan policy, AI review, alerts, traffic protection, 
definitions, scope, and private storage.

[⌊About page with version details, project resources, documentation, and support
links.⌉⌊About page with version details, project resources, documentation, and support
links.⌉[

About page with version details, project resources, documentation, and support links.

[⌊Traffic console with seven-day metrics, filters, privacy-reduced request evidence,
and CSV export.⌉⌊Traffic console with seven-day metrics, filters, privacy-reduced
request evidence, and CSV export.⌉[

Traffic console with seven-day metrics, filters, privacy-reduced request evidence,
and CSV export.

[⌊WordPress dashboard widget with scanner health, the latest result, traffic matches,
report access, and scan controls.⌉⌊WordPress dashboard widget with scanner health,
the latest result, traffic matches, report access, and scan controls.⌉[

WordPress dashboard widget with scanner health, the latest result, traffic matches,
report access, and scan controls.

## Installation

 1. For a source checkout, run `composer install --no-dev --optimize-autoloader`, `
    npm ci`, and `npm run build` in the plugin directory using Node.js 22.
 2. Upload the release ZIP contents, including `vendor`, `includes`, and `build`, to`/
    wp-content/plugins/amwscan`. Do not upload `node_modules` or frontend `src` files.
 3. Activate AMWScan Antimalware Scanner Lite in WordPress.
 4. Open Antimalware > Settings, verify the scan and storage paths, then run a report-
    only scan.

## FAQ

### Why is a queued scan not starting immediately?

WordPress cron runs when the site receives requests. Configure a system cron that
runs `wp cron event run --due-now` when exact timing is required.

### How does upload protection work?

Scan and block malicious WordPress uploads is enabled by default under Antimalware
> Settings > Scan policy. The plugin scans temporary media, plugin, and theme uploads
in report-only mode before WordPress stores or installs them. Malware detections
and incomplete scans block the upload. Plugin and theme ZIP inspection requires 
the PHP ZIP extension.

### How do email alerts work?

Enable alerts under Antimalware > Settings > Email alerts. The plugin uses `wp_mail`
when a completed scan contains unresolved security findings. With no custom recipients,
alerts go to the WordPress administrator. Add up to 20 custom recipients to send
alerts only to those addresses and exclude the administrator. Messages include scan
counts and a protected report link, but no local paths or matched code.

### Does AMWScan require the WordPress AI plugin?

No. AMWScan works without it. When the WordPress AI Client is available, AMWScan
progressively adds the recommended configured-connectors option and read-only abilities
for scan status and finding summaries. Direct AI providers remain optional advanced
alternatives.

### How does traffic detection work?

Enable request monitoring under Antimalware > Settings > Traffic detection. Built-
in heuristics detect conservative traversal, sensitive-file, exploit-path, scanner
user-agent, and unexpected-method probes. An optional curated local indicator file
enriches detection with IP addresses, CIDR ranges, domains, URLs, paths, and explicit
ua: fragments. Plain-text lists and CSV files with trail, info, and reference columns
are supported. Files are limited to 10 MB and 100,000 records. AMWScan does not 
bundle or automatically download indicator data; ensure your data license permits
local use.

This passive monitor checks only requests that reach WordPress. It does not inspect
DNS, TLS, arbitrary ports, static-file traffic, rejected connections, or outbound
traffic, and it never blocks visitors. Query strings are discarded, source addresses
are reduced to network prefixes, duplicate detections are suppressed for five minutes,
and the latest 200 detections appear in the dashboard and Traffic console. The console
provides seven-day severity and category summaries, filters, and a defanged CSV 
export.

### Where are reports, definitions, and quarantined files stored?

By default in an `amwscan-data` directory beside the web document root and outside
the scanned tree. If that parent is not writable, the plugin uses a protected, site-
scoped directory under WordPress’s temporary root. The host can clear temporary 
storage or discard it with a container, so configure persistent external paths before
relying on quarantine, backups, or retained reports. Each scan checks definition
metadata and downloads changed data; a failed update keeps the last verified cache.
Enable Use cached or embedded definitions without updating under Antimalware > Settings
> Engine and storage to prevent update requests.

### Does the plugin scan its own files?

No. The active AMWScan plugin directory and its private data directory are always
excluded from scans.

### How do I scan an FTP server?

Enable the PHP FTP extension, select FTP server under Antimalware > Settings, and
enter a credential-free `ftps://host/path` URL. Set `AMWSCAN_FTP_PASSWORD` in the
WordPress PHP process environment when authentication requires a password. Use FTPS
for authenticated scans because plain FTP is unencrypted. Remote scans are read-
only, and passwords are never stored in WordPress.

### Does uninstall delete security data?

No. Reports, logs, backups, quarantined files, and the whitelist are preserved. 
WordPress options and scheduled events are removed.

### How can I contribute a detection?

Open a report finding and select Report finding. The plugin opens a public GitHub
issue draft from legacy matches or canonical malware file signatures, containing
signature names, detection types, scanner versions, and the file SHA-256 only. It
excludes local paths and matched code. Do not attach executable malware to a public
issue; maintainers can arrange a private transfer if they need the sample.

### How can I contribute a translation?

Use the WordPress.org translation project for reviewed locale packs. The source 
template is `languages/amwscan.pot`.

## Reviews

![](https://secure.gravatar.com/avatar/b741fcc5d91580e569c8f9f0248ef173e620e51a85168c7315d0db8765180382?
s=60&d=retro&r=g)

### 󠀁[Almost Two Days Checking 16595 files](https://wordpress.org/support/topic/almost-two-days-checking-16595-files/)󠁿

 [iitcwebdesign](https://profiles.wordpress.org/iitcwebdesign/) September 8, 2026

I have been to many Antimalware plugins, almost all of them, however AMWScan solely
have an option to run a complete scan while you are not connected to your site and
wait like other plugins.Added to that it’s an open source plugin so the opportunity
seems perfect to me. to try this one. However, after 2 days with a VPS from a reputable
host , it still has checked almost 60% of my 16000 files, what a waste of time and
efforts, I will uninstall it now and return to the others, this plugin wasn’t ready
yet, my best wishes to the team though.Regards

 [ Read all 0 reviews ](https://wordpress.org/support/plugin/amwscan/reviews/)

## Contributors & Developers

“AMWScan Antimalware Scanner Lite” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ Marco Cesarato ](https://profiles.wordpress.org/marcocesarato1/)

“AMWScan Antimalware Scanner Lite” has been translated into 1 locale. Thank you 
to [the translators](https://translate.wordpress.org/projects/wp-plugins/amwscan/contributors)
for their contributions.

[Translate “AMWScan Antimalware Scanner Lite” into your language.](https://translate.wordpress.org/projects/wp-plugins/amwscan)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/amwscan/), check out
the [SVN repository](https://plugins.svn.wordpress.org/amwscan/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/amwscan/) by [RSS](https://plugins.trac.wordpress.org/log/amwscan/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.5.9

 * See the GitHub release notes for this version.

#### 0.5.8

 * See the GitHub release notes for this version.

#### 0.5.7

 * See the GitHub release notes for this version.

#### 0.5.6

 * See the GitHub release notes for this version.

#### 0.5.5

 * See the GitHub release notes for this version.

#### 0.5.4

 * See the GitHub release notes for this version.

#### 0.5.3

 * See the GitHub release notes for this version.

#### 0.5.2

 * See the GitHub release notes for this version.

#### 0.5.1

 * See the GitHub release notes for this version.

#### 0.5.0

 * Complete the React migration for dashboard and widget, report history and detail,
   settings, traffic, quarantine, whitelist, About, and the Full-edition editor.
 * Replace classic views and legacy scripts with the shared admin application and
   lazy-loaded feature chunks. No classic fallback remains.
 * Retain nonce-protected downloads, REST permission checks, file-hash validation,
   and confirmation requirements.
 * Remove editor and quarantine-restoration backend code and routes from Lite while
   retaining trusted missing-core-file restoration.
 * Include translation strings from all lazy frontend features and keep development
   source and tools outside release ZIPs.

#### 0.4.3

 * See the GitHub release notes for this version.

#### 0.4.2

 * See the GitHub release notes for this version.

#### 0.4.1

 * See the GitHub release notes for this version.

#### 0.4.0

 * See the GitHub release notes for this version.

#### 0.3.3

 * See the GitHub release notes for this version.

#### 0.3.2

 * See the GitHub release notes for this version.

#### 0.3.1

 * See the GitHub release notes for this version.

#### 0.3.0

 * See the GitHub release notes for this version.

#### 0.2.7

 * See the GitHub release notes for this version.

#### 0.2.6

 * See the GitHub release notes for this version.

#### 0.2.5

 * See the GitHub release notes for this version.

#### 0.2.4

 * See the GitHub release notes for this version.

#### 0.2.3

 * See the GitHub release notes for this version.

#### 0.2.2

 * Rename the plugin to AMWScan Antimalware Scanner.
 * Remove browser code editing and quarantined-file restoration for WordPress.org
   directory compliance.
 * Pass all WordPress Plugin Check categories without errors or warnings.

#### 0.2.1

 * Follow the WordPress site language and remove the plugin-specific language override.
 * Improve the WordPress admin experience with clearer navigation, responsive reports,
   collapsible settings, and initially collapsed malware detections.

#### 0.2.0

 * See the GitHub release notes for this version.

#### 0.1.1

 * Add upload scanning and configurable archive scanning safeguards.

#### 0.1.0

 * Initial free plugin with scheduled background scans, live scan status, CLI-equivalent
   settings, report exploration, browser editing, automatic fixes, whitelist management,
   and protected remediation actions.

## Meta

 *  Version **0.5.9**
 *  Last updated **13 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.3 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 *  Languages
 * [English (US)](https://wordpress.org/plugins/amwscan/) and [Russian](https://ru.wordpress.org/plugins/amwscan/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/amwscan)
 * Tags
 * [antimalware](https://es-hn.wordpress.org/plugins/tags/antimalware/)[antivirus](https://es-hn.wordpress.org/plugins/tags/antivirus/)
   [malware](https://es-hn.wordpress.org/plugins/tags/malware/)[scanner](https://es-hn.wordpress.org/plugins/tags/scanner/)
   [security](https://es-hn.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://es-hn.wordpress.org/plugins/amwscan/advanced/)

## Ratings

 1 out of 5 stars.

 *  [  0 5-star reviews     ](https://wordpress.org/support/plugin/amwscan/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/amwscan/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/amwscan/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/amwscan/reviews/?filter=2)
 *  [  1 1-star review     ](https://wordpress.org/support/plugin/amwscan/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/amwscan/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/amwscan/reviews/)

## Contributors

 *   [ Marco Cesarato ](https://profiles.wordpress.org/marcocesarato1/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/amwscan/)