Review suspicious WordPress plugin records
In cPFence v4+, Threat & Malware Detection → Suspicious Plugins shows retained plugin detections and protection actions. Support users need access to the selected server and permission to view history and findings.
Find a detection
Section titled “Find a detection”- Open Suspicious Plugins and choose Local or one secondary server in server scope.
- Choose Summary period: Last month, Last week, Last 24 hours or All time.
- Search by site, owner or file path. Choose Status and Started since, then Apply filters. Use Clear all to reset the filters.
- Review Recent plugin detections. Use Previous and Next, then open Details for the intended file.
The Detected files, Files disabled and Incomplete records cards describe the selected period. Searching the table does not recalculate those period totals.
Select a summary card to filter the records; select it again to clear that card’s filter. Files disabled includes historical disabling records, including incomplete ones.
Interpret status and actions
Section titled “Interpret status and actions”The Status filter includes No recorded action; a row can show No action admitted. In details, read the recorded action and observation separately.
| Status or detail | How to read it |
|---|---|
| Disabled (recorded) | A disabling action was recorded; it does not verify the file’s current state. |
| No action admitted | Do not assume a disabling action was admitted or completed. |
| Incomplete | Read the recorded problem; the action did not establish a completed result. |
| Retained observation / Cleared observation | A later observation of the detection, separate from the original protection action. |
In Plugin detection details, check the site, owner, server, file and detection time. Compare Recorded action with Observation and Last observation. Read Protection action for recorded ownership/permission changes and any problem.
The recorded-action field may say No action recorded. Retained, Cleared or Ineligible describe observations separately. An ineligible ownership or writable-permissions observation does not establish a successful automatic disable; read its reason.
For a Disabled (recorded) detection, compare Original and Recorded action under Ownership, Permissions and Result. Expand Recorded actions to inspect the recorded action history.
Investigate safely
Section titled “Investigate safely”Verify the actual file and its purpose before removing software or changing permissions. Keep a backup and investigate the affected site using malware scans and WordPress integrity checks.
This history view is separate from removing blacklisted plugins. For an infected installation, follow clean an infected WordPress site. Keep paths and customer details private when sharing an error with support.



