↑ ↓ select, Enter open, Esc close

Find PHP files in the WordPress uploads folder

Adjust the values, the command updates live
user@server
find /var/www/vhosts/example.com/httpdocs/wp-content/uploads -type f \( -iname '*.php' -o -iname '*.phtml' -o -iname '*.php[0-9]' \) -ls

Searches the upload directory of a WordPress installation for PHP files, including extensions like .phtml or .php5. Only media should be stored there, so a PHP file is almost always an injected web shell. The output shows the owner, size and modification date of each match.

Note: Some plugins create harmless index.php files to protect directories. These usually contain only a comment and are quick to check.

Also searched as

  • php files in wp-content uploads
  • find webshell wordpress
  • wordpress hacked find malware

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.