Skip to content

Review suspicious WordPress plugin records

In cPFence v4+, Threat & Malware Detection → Suspicious Plugins shows retained plugin detections and protection actions. Support users need access to the selected server and permission to view history and findings.

  1. Open Suspicious Plugins and choose Local or one secondary server in server scope.
  2. Choose Summary period: Last month, Last week, Last 24 hours or All time.
  3. Search by site, owner or file path. Choose Status and Started since, then Apply filters. Use Clear all to reset the filters.
  4. Review Recent plugin detections. Use Previous and Next, then open Details for the intended file.

The Detected files, Files disabled and Incomplete records cards describe the selected period. Searching the table does not recalculate those period totals.

Select a summary card to filter the records; select it again to clear that card’s filter. Files disabled includes historical disabling records, including incomplete ones.

Suspicious Plugins with period summary, server scope, search, status and date filters, and retained detection rows.

Plugin totals describe the selected period; table filters narrow the retained rows. Identifying values are concealed. Select the image for full size; use browser Back to return.

The Status filter includes No recorded action; a row can show No action admitted. In details, read the recorded action and observation separately.

Status or detail How to read it
Disabled (recorded) A disabling action was recorded; it does not verify the file’s current state.
No action admitted Do not assume a disabling action was admitted or completed.
Incomplete Read the recorded problem; the action did not establish a completed result.
Retained observation / Cleared observation A later observation of the detection, separate from the original protection action.

In Plugin detection details, check the site, owner, server, file and detection time. Compare Recorded action with Observation and Last observation. Read Protection action for recorded ownership/permission changes and any problem.

The recorded-action field may say No action recorded. Retained, Cleared or Ineligible describe observations separately. An ineligible ownership or writable-permissions observation does not establish a successful automatic disable; read its reason.

Plugin detection details with No action recorded, an Ineligible observation and an empty Protection action table.

No automatic disabling action was recorded for this retained observation. Identifying values are concealed; the record does not verify current file state. Select the image for full size; use browser Back to return.

For a Disabled (recorded) detection, compare Original and Recorded action under Ownership, Permissions and Result. Expand Recorded actions to inspect the recorded action history.

Plugin detection details showing recorded permission changes from 0644 to 000, an Applied result and the Recorded actions entry.

A retained disabling action recorded permissions changing from 0644 to 000 and Result Applied. Identifying values are concealed; current file state is not verified. Select the image for full size; use browser Back to return.

Verify the actual file and its purpose before removing software or changing permissions. Keep a backup and investigate the affected site using malware scans and WordPress integrity checks.

This history view is separate from removing blacklisted plugins. For an infected installation, follow clean an infected WordPress site. Keep paths and customer details private when sharing an error with support.