WP-Narcan
For the morning after your WordPress site gets hacked. WP-Narcan rebuilds the site from clean sources into a new folder next to the old one, so you can check everything before you swap it in.
Python · v1.1 · MIT License
$ python wpnarcan.py /var/www/example.comWelcome to WP NarcanAuthor: ReignOfComputerFound valid WordPress installation.Rebuilding into: /var/www/example.com-rebuiltDownloaded WordPress core.Found 3 plugin(s): - akismet - contact-form-7 - woocommerceDownload and install these plugin(s)? (y/n): y [1/3] Downloaded plugin: akismet [2/3] Downloaded plugin: woocommerce [3/3] Downloaded plugin: contact-form-7Found 1 theme(s): - twentytwentyfiveDownload and install these theme(s)? (y/n): y [1/1] Downloaded theme: twentytwentyfiveNo mu-plugins directory found, skipping.No drop-in files found.Scanning uploads directory: /var/www/example.com-rebuilt/wp-content/uploads Deleted: .../uploads/2024/03/wp-cache.php Deleted: .../uploads/2025/11/.htaccessWARNING: Suspicious patterns found in wp-config.php: - base64_decode()The file will still be copied, but review it carefully before use.Copied wp-config.php to rebuilt directory.============================================================RECOVERY SUMMARY============================================================ WordPress Core: Downloaded Plugins: 3/3 downloaded Themes: 1/1 downloaded Uploads: 2 suspicious file(s) removed wp-config.php: 1 WARNING(s) - review carefully!============================================================Take note of any missing items and manually verify files before replacing your server copy.Full log saved to: /var/www/example.com-rebuilt/wpnarcan.logAn example run. Your site will have its own list of plugins.
How It Works
- 01
Checks It's WordPress
Makes sure wp-config.php, wp-content, plugins and themes are where they should be before it touches anything.
- 02
Fresh Core
Downloads the latest WordPress from wordpress.org into a new -rebuilt folder.
- 03
Clean Plugins and Themes
Re-downloads every plugin and theme it finds. For paid ones, point it at a folder of your own zips and it'll use those first.
- 04
mu-plugins and Drop-ins
Copies them across and scans each one for suspicious code, because malware likes to hide in the files WordPress loads automatically.
- 05
Uploads
Copies your uploads and strips out anything that shouldn't be in there: .php, .phtml, .phar, .sh, .htaccess, .user.ini and more.
- 06
wp-config.php and the Report
Checks wp-config.php for eval(), base64_decode() and shell commands, then prints a recovery summary and saves the full log to wpnarcan.log.
Try It Here
The Config Check
One step of a rebuild is reading wp-config.php for things that shouldn't be there. This is that check, with the same 13 patterns the script uses, running in your browser. Paste a config in, or try the dodgy one I made earlier.
What It Won't Do
- It doesn't touch your database. Injected posts and rogue admin users need cleaning up separately.
- It can't download paid plugins or themes unless you give it the zips.
- It won't replace your live site. You do that, after you've checked the rebuild.
- It gives you a clean copy, but it won't tell you how the attacker got in.
Running It
You need Python and a copy of the hacked site's files. The rebuild lands next to the original, in a folder ending in -rebuilt.
# Get the code$ git clone https://github.com/ReignOfComputer/WP-Narcan.git$ cd WP-Narcan# Install the two dependencies$ pip install -r requirements.txt# Point it at the hacked site$ python wpnarcan.py /path/to/hacked-site# Paid plugins? Hand it your zips$ python wpnarcan.py /path/to/hacked-site \$ --local-repo-plugins /path/to/plugin-zips \$ --local-repo-themes /path/to/theme-zipsRather Not Do It Yourself?
I clean up hacked WordPress sites, database included, and harden them afterwards.