Small. Fearless. Finds What Shouldn't Be There.
Honey Badger is a lightweight scanner that sniffs through your WordPress site for malware, backdoors and tampered files, the vicious little things that hide in a hacked site, and drags them into the daylight in plain English.
- Featherweight plugin
- Read-only, never edits a file
- Daily patrol
- Plain-English reports
Cobras Come in Many Shapes.
A hacked WordPress site rarely looks hacked. The damage hides in files you never open. Honey Badger knows what a clean copy looks like and notices everything that isn't one.
Tampered core files
Every WordPress core file is compared to the official fingerprint for your exact version. One changed byte and it's flagged.
Modified plugins
Plugins from the WordPress.org directory are checked against their official copies, so injected code has nowhere to hide.
Backdoors in uploads
Your uploads folder is for images and documents. Code that can run from there is a classic backdoor, and it gets called out.
Stowaway files
Unknown files sitting inside the WordPress system folders or your site root, where nothing new should ever appear.
Quiet loaders
Must-use plugins and drop-ins load on every page without showing up in the normal plugin list. Honey Badger lists every one.
Missing pieces
Core files that should be there and aren't. Sometimes harmless, sometimes a sign that something has been rearranged.
All Bite. No Bloat.
Most security plugins move in and take over the house. Honey Badger does one job, does it quietly, and stays out of your visitors' way.
Sniff. Spot. Tell.
Sniff
Honey Badger walks your WordPress files and compares each one to the official published copy for the exact version you run.
Spot
Anything changed, added or out of place is sorted by how serious it is. Wherever there's trouble, a little cobra shows up.
Tell
You get a clear report: which file, what's wrong and when it changed. Honey Badger advises. You, or we, decide what happens next.
Send the Badger In.
Run a sample patrol and see what a report looks like.
A Report You Can Actually Talk To.
Security reports are usually written for other security people. Honey Badger has a built-in AI advisor, so you can ask what a finding means and what to do about it.
- Explains each finding in plain English
- Honest about uncertainty. It won't cry wolf, and it won't call a clean scan a guarantee
- Only a summary of the scan is shared with the AI. The contents of your files never leave your server
Questions, Answered.
Will it slow my website down?
No. Scans run in the background in short bursts, once a day or when you press Scan. Nothing is added to the pages your visitors load.
Does Honey Badger remove what it finds?
Not on its own. It is an advisor: it finds and explains, and never edits or deletes a file, which is why it can't break a site. If it turns up a cobra, the Xblu team can clean it up with you.
What exactly does it check?
WordPress core, plugins from the WordPress.org directory, your uploads folder, and the places where hidden loaders live. Premium and custom plugins have no public reference copy, so they are listed as "could not verify" rather than guessed at.
If the scan is clean, is my site safe?
A clean scan is a very good sign, not a guarantee. No scanner can promise that. Honey Badger is one strong layer alongside updates, backups and good passwords.
Does it replace a firewall?
No. A firewall tries to keep trouble out. Honey Badger checks whether anything got in. They do different jobs and work well together.
Are there any usage costs?
Scanning has none. The optional AI advisor uses OpenAI, which bills by usage, so you only pay for the questions you actually ask.
Honey Badger Doesn't Scare Easy.
Worried something is living in your site, or just want someone on patrol? Let's put the badger to work.
Talk to Xblu