id => 10850
module => file_change
type => fatal
code => file-scan-aborted
timestamp => 2022-09-16 11:31:56
init_timestamp => 2022-09-16 11:31:40
remote_ip => 2001:41d0:700:4e82::
user_id => [empty string]
url => https://mydomain.com/url?nowprocket=1
memory_current => 27776744
memory_peak => 28530736
data => Array
id => file-change
step => get-files
chunk => plugins
Look at the end of url. There is ?nowprocket=1 , even though I don’t use wp-rocket plugin. What does that mean?
]]>“Modified plugin file: wp-content/plugins/wordpress-seo/wp-seo-main.php”
Was this modification done by Yoast? Should I be concerned?
]]>Wordfence has detected an unexpected file change to W3 cache, is this legitimate?
echo “\ngeneric_plugin reset\n”; has been added to the function below.
if ( isset( $GLOBALS[‘w3tc_blogmap_register_new_item’] ) ) {
echo “\ngeneric_plugin reset\n”;
Thanks
]]>the file is: WordPress core: wp-admin/session_mm_cgi-fcgi4314.sem.
I tried to fix by deleting the file as Wordfence suggested but it does give warning.
I don’t want to leave the file there, that is prime for hackers.
Any help will be appreciated on this issue.
Thank you in advance
]]>I don’t see any plugin files loaded by the browser. But that doesn’t mean the plugin isn’t doing things elsewhere to increase page load time.
Thanks in advance.
]]>url: WP-Cron Scheduled Task
Changed:
wp-content/uploads/sucuri/sucuri-plugindata.php
wp-content/uploads/sucuri/sucuri-auditlogs.php
wp-content/uploads/sucuri/sucuri-failedlogins.php
wp-content/uploads/sucuri/sucuri-oldfailedlogins.php
wp-content/uploads/sucuri/sucuri-settings.php
wp-content/uploads/sucuri/sucuri-auditqueue.php
wp-content/uploads/sucuri/sucuri-sitecheck.php
Removed:
Added:
wp-content/uploads/siteground-optimizer-assets/twentyseventeen-customize-preview.min.js
Does this look like a problem/hack/malware?
Any input is appreciated!