β All tools
PHP Webshell Detector
Scan a PHP file or ZIP project for common webshell indicators and suspicious execution patterns without running the uploaded code.
Free to use
Scan without executing
Upload one PHP/source file or a ZIP project. The scanner reads bounded text only; it never includes, runs, or serves uploaded code.
- Input up to 20 MiB
- ZIP: up to 2,000 entries, 2 MiB per file, and 20 MiB of source read
- Heuristic only: findings need expert review and a clean result is not proof of safety
Findings
Upload a source file or project archive to see findings.