WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Malware scanner

File Viewer

Preview files from Core Scanner and Malware Scanner results safely in the WordPress admin. Search, logs, diffs, and common images.

When Core Scanner or Malware Scanner flags a file, open it in the built-in File Viewer instead of downloading it over FTP or editing blindly.

The viewer runs only in the WordPress admin. Files are validated before display. They are not executed on your site.

Where to open files

From scan results, use View File on a row. From Core Scanner you can also use View differences (diff) for modified core files. Malware Scanner uses the same viewer layout.

Supported file types

Text and code (up to 5 MB, truncated after 10,000 lines for very large logs):

PHP, JavaScript, CSS, HTML, XML, JSON, Markdown, YAML, INI, SQL, plain text, and common log names such as debug.log, error_log, and rotated variants like error_log.1.

Images (verified before display):

PNG, JPG, JPEG, GIF, WebP, and ICO.

SVG is not supported in the viewer (SVG can contain executable content).

If a text or log file exceeds the size limit, the viewer shows a truncated preview instead of failing silently.

Security notes

  • Only administrators with access to Security Ninja can open files through the viewer.
  • Paths must stay inside your WordPress installation. The viewer rejects paths outside the install root.
  • Use Restore or Delete from Core Scanner when you have confirmed a core file change. Use Malware Scanner actions when you have confirmed malicious code.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image