Honey Badger™ · The lightweight WordPress scanner from Xblu

Small. Fearless. Finds What Shouldn't Be There.

Honey Badger is a lightweight scanner that sniffs through your WordPress site for malware, backdoors and tampered files, the vicious little things that hide in a hacked site, and drags them into the daylight in plain English.

  • Featherweight plugin
  • Read-only, never edits a file
  • Daily patrol
  • Plain-English reports
Patrol in progress
WordPress coreVerified
PluginsVerified
Uploads folder1 cobra
What it hunts

Cobras Come in Many Shapes.

A hacked WordPress site rarely looks hacked. The damage hides in files you never open. Honey Badger knows what a clean copy looks like and notices everything that isn't one.

Tampered core files

Every WordPress core file is compared to the official fingerprint for your exact version. One changed byte and it's flagged.

Modified plugins

Plugins from the WordPress.org directory are checked against their official copies, so injected code has nowhere to hide.

Backdoors in uploads

Your uploads folder is for images and documents. Code that can run from there is a classic backdoor, and it gets called out.

Stowaway files

Unknown files sitting inside the WordPress system folders or your site root, where nothing new should ever appear.

Quiet loaders

Must-use plugins and drop-ins load on every page without showing up in the normal plugin list. Honey Badger lists every one.

Missing pieces

Core files that should be there and aren't. Sometimes harmless, sometimes a sign that something has been rearranged.

Lightweight on purpose

All Bite. No Bloat.

Most security plugins move in and take over the house. Honey Badger does one job, does it quietly, and stays out of your visitors' way.

0files changed. It only reads, so it can't break your site.
15 secbursts. Scans run in short background steps, not one long grind.
Dailypatrol while you sleep, with an email only when something new turns up.
Nogiant signature database to download, store and keep updated.
How it works

Sniff. Spot. Tell.

Sniff

Honey Badger walks your WordPress files and compares each one to the official published copy for the exact version you run.

Spot

Anything changed, added or out of place is sorted by how serious it is. Wherever there's trouble, a little cobra shows up.

Tell

You get a clear report: which file, what's wrong and when it changed. Honey Badger advises. You, or we, decide what happens next.

Try it

Send the Badger In.

Run a sample patrol and see what a report looks like.

Honey BadgerLive demo · sample data
0Files checked
0Core files verified
0Plugins verified
0Cobras found
Ready when you are.
Ask Honey Badger

A Report You Can Actually Talk To.

Security reports are usually written for other security people. Honey Badger has a built-in AI advisor, so you can ask what a finding means and what to do about it.

  • Explains each finding in plain English
  • Honest about uncertainty. It won't cry wolf, and it won't call a clean scan a guarantee
  • Only a summary of the scan is shared with the AI. The contents of your files never leave your server
There's a PHP file in my uploads folder. Is that bad?
It deserves a close look. Uploads is meant for images and documents, so code that can run from there is a common sign of a backdoor. Take a backup first, then check when the file appeared and whether a plugin you trust put it there.
It showed up last Tuesday. Nobody on our team added it.
Then treat it as suspicious. Here's a safe order to handle it...
Straight answers

Questions, Answered.

Will it slow my website down?

No. Scans run in the background in short bursts, once a day or when you press Scan. Nothing is added to the pages your visitors load.

Does Honey Badger remove what it finds?

Not on its own. It is an advisor: it finds and explains, and never edits or deletes a file, which is why it can't break a site. If it turns up a cobra, the Xblu team can clean it up with you.

What exactly does it check?

WordPress core, plugins from the WordPress.org directory, your uploads folder, and the places where hidden loaders live. Premium and custom plugins have no public reference copy, so they are listed as "could not verify" rather than guessed at.

If the scan is clean, is my site safe?

A clean scan is a very good sign, not a guarantee. No scanner can promise that. Honey Badger is one strong layer alongside updates, backups and good passwords.

Does it replace a firewall?

No. A firewall tries to keep trouble out. Honey Badger checks whether anything got in. They do different jobs and work well together.

Are there any usage costs?

Scanning has none. The optional AI advisor uses OpenAI, which bills by usage, so you only pay for the questions you actually ask.

Honey Badger Doesn't Scare Easy.

Worried something is living in your site, or just want someone on patrol? Let's put the badger to work.

Talk to Xblu