WP Clinic
Log in Sign up

SECURITY FINDING

Executable PHP file hidden in your uploads folder

What it is

A PHP file was found inside the uploads folder — a location meant only for images and attachments, never executable code. This is one of the most common ways an attacker hides a webshell (a backdoor that runs commands on the site).

How to fix it

Delete the file if you don't recognize it, and make sure PHP files can't be executed inside the uploads folder. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.