Skip to Content
Free · Open Source · MIT License

WP-Narcan

For the morning after your WordPress site gets hacked. WP-Narcan rebuilds the site from clean sources into a new folder next to the old one, so you can check everything before you swap it in.

Python · v1.1 · MIT License

wpnarcan.py
$ python wpnarcan.py /var/www/example.comWelcome to WP NarcanAuthor: ReignOfComputerFound valid WordPress installation.Rebuilding into: /var/www/example.com-rebuiltDownloaded WordPress core.Found 3 plugin(s):  - akismet  - contact-form-7  - woocommerceDownload and install these plugin(s)? (y/n): y  [1/3] Downloaded plugin: akismet  [2/3] Downloaded plugin: woocommerce  [3/3] Downloaded plugin: contact-form-7Found 1 theme(s):  - twentytwentyfiveDownload and install these theme(s)? (y/n): y  [1/1] Downloaded theme: twentytwentyfiveNo mu-plugins directory found, skipping.No drop-in files found.Scanning uploads directory: /var/www/example.com-rebuilt/wp-content/uploads  Deleted: .../uploads/2024/03/wp-cache.php  Deleted: .../uploads/2025/11/.htaccessWARNING: Suspicious patterns found in wp-config.php:  - base64_decode()The file will still be copied, but review it carefully before use.Copied wp-config.php to rebuilt directory.============================================================RECOVERY SUMMARY============================================================  WordPress Core: Downloaded  Plugins: 3/3 downloaded  Themes: 1/1 downloaded  Uploads: 2 suspicious file(s) removed  wp-config.php: 1 WARNING(s) - review carefully!============================================================Take note of any missing items and manually verify files before replacing your server copy.Full log saved to: /var/www/example.com-rebuilt/wpnarcan.log

An example run. Your site will have its own list of plugins.

How It Works

  1. 01

    Checks It's WordPress

    Makes sure wp-config.php, wp-content, plugins and themes are where they should be before it touches anything.

  2. 02

    Fresh Core

    Downloads the latest WordPress from wordpress.org into a new -rebuilt folder.

  3. 03

    Clean Plugins and Themes

    Re-downloads every plugin and theme it finds. For paid ones, point it at a folder of your own zips and it'll use those first.

  4. 04

    mu-plugins and Drop-ins

    Copies them across and scans each one for suspicious code, because malware likes to hide in the files WordPress loads automatically.

  5. 05

    Uploads

    Copies your uploads and strips out anything that shouldn't be in there: .php, .phtml, .phar, .sh, .htaccess, .user.ini and more.

  6. 06

    wp-config.php and the Report

    Checks wp-config.php for eval(), base64_decode() and shell commands, then prints a recovery summary and saves the full log to wpnarcan.log.

Try It Here

The Config Check

One step of a rebuild is reading wp-config.php for things that shouldn't be there. This is that check, with the same 13 patterns the script uses, running in your browser. Paste a config in, or try the dodgy one I made earlier.

Runs on this page · Nothing Is Sent

What It Won't Do

  • It doesn't touch your database. Injected posts and rogue admin users need cleaning up separately.
  • It can't download paid plugins or themes unless you give it the zips.
  • It won't replace your live site. You do that, after you've checked the rebuild.
  • It gives you a clean copy, but it won't tell you how the attacker got in.

Running It

You need Python and a copy of the hacked site's files. The rebuild lands next to the original, in a folder ending in -rebuilt.

# Get the code$ git clone https://github.com/ReignOfComputer/WP-Narcan.git$ cd WP-Narcan# Install the two dependencies$ pip install -r requirements.txt# Point it at the hacked site$ python wpnarcan.py /path/to/hacked-site# Paid plugins? Hand it your zips$ python wpnarcan.py /path/to/hacked-site \$     --local-repo-plugins /path/to/plugin-zips \$     --local-repo-themes /path/to/theme-zips

Rather Not Do It Yourself?

I clean up hacked WordPress sites, database included, and harden them afterwards.