Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

ACH Stored Payload Audit Wordpress Plugin - Rating, Reviews, Demo & Download

ACH Stored Payload Audit Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

ACH Stored Payload Audit scans existing text fields in database tables belonging to the current site’s WordPress table prefix. Select all site tables, an entire detected table-name group, or individual tables. The scanner looks for potential stored XSS indicators and common encodings, then shows a table, record identifier, column, and matched rule. A separate View content action retrieves flagged cell text on demand and displays it as plain text, never HTML. For publicly viewable WordPress posts, an optional Open page link is supplied with a warning.

WordPress post revisions remain in scope. Findings in revisions are labeled with their parent post ID (for example, “Revision of post #7”) so a stored historical copy is not confused with a second distinct attack.

The tool is intended for manual investigation, not automatic malware removal. A matched rule is not proof of compromise or script execution. Legitimate posts about web security and active HTML content can generate false positives. Well-formed, benign JSON-LD script blocks and strictly validated WordPress and YouTube oEmbed cache markup are ignored. YouTube exemptions apply only to normal oEmbed cache entries with fully validated iframe markup. Unfamiliar or suspicious iframes remain in scope.

The plugin does not block incoming HTTP requests, modify database records, save audit reports, or send data to external services. Scan results remain in the current browser tab. Administrator access (manage_options) and a WordPress AJAX nonce are required to scan and view flagged text. Scanned database content may contain private data. Use a trusted administrative browser session and do not share sensitive findings in public reports.

Only tables with the currently configured site’s table prefix are eligible, not arbitrary databases or separately prefixed WordPress installations. Multi-site installations are audited one site at a time.

Privacy

The plugin does not transmit data to the developer or third-party services, register visitors, create its own persistent audit log, or store scan findings on the server. It retrieves matching database content only when an authorized administrator requests the View content preview. The WordPress administrator’s browser temporarily holds the results during the current page session. Avoid sharing screenshots or previews that contain personal information or secrets.

Languages

The administration interface is written in English and prepared for translation through the ach-stored-payload-audit text domain. A translation template is provided in languages/; WordPress.org language packs can be used once the plugin is published.

Screenshots

No screenshots provided


Reviews & Comments