Stalza

Your first scan

What happens during the first scan and how to read the results.

The first scan does two things at once:

  1. Verifies WordPress core and every WordPress.org plugin against official checksums.
  2. Baselines everything else — themes, premium plugins, uploads — so future scans can tell you what changed.

Because it hashes every file, the first scan takes longer than later ones. It runs in the background in small chunks, so you can leave the page.

Reading results

Each finding shows:

  • Risk — how bad it would be if this is real.
  • Confidence — how sure the detection is. A core file that fails its checksum and matches a malware rule is high confidence; a single generic pattern hit in a theme is low.
  • Why — the specific signals that fired.
  • Recommended action — restore, review, ignore, or quarantine.

Start with anything marked high risk and high confidence.