Title: ACH Stored Payload Audit
Author: aiutocomputerhelp
Published: <strong>Октябрь 2, 2026-ж.</strong>
Last modified: Октябрь 2, 2026-ж.

---

Плагиндерди издөө

![](https://ps.w.org/ach-stored-payload-audit/assets/banner-772x250.png?rev=3724369)

![](https://ps.w.org/ach-stored-payload-audit/assets/icon-256x256.png?rev=3724334)

# ACH Stored Payload Audit

 Автору [aiutocomputerhelp](https://profiles.wordpress.org/aiutocomputerhelp/)

[Жүктөө](https://downloads.wordpress.org/plugin/ach-stored-payload-audit.1.2.0.zip)

 * [Кенен маалымат](https://ky.wordpress.org/plugins/ach-stored-payload-audit/#description)
 * [Сын-пикирлер](https://ky.wordpress.org/plugins/ach-stored-payload-audit/#reviews)
 *  [Орнотуу](https://ky.wordpress.org/plugins/ach-stored-payload-audit/#installation)
 * [Development](https://ky.wordpress.org/plugins/ach-stored-payload-audit/#developers)

 [Колдоо](https://wordpress.org/support/plugin/ach-stored-payload-audit/)

## Сүрөттөө

ACH Stored Payload Audit scans existing text fields in database tables belonging
to the current site’s WordPress table prefix. Select all site tables, an entire 
detected table-name group, or individual tables. The scanner looks for potential
stored XSS indicators and common encodings, then shows a table, record identifier,
column, and matched rule. A separate View content action retrieves flagged cell 
text on demand and displays it as plain text, never HTML. For publicly viewable 
WordPress posts, an optional Open page link is supplied with a warning.

WordPress post revisions remain in scope. Findings in revisions are labeled with
their parent post ID (for example, “Revision of post #7”) so a stored historical
copy is not confused with a second distinct attack.

The tool is intended for manual investigation, not automatic malware removal. A 
matched rule is not proof of compromise or script execution. Legitimate posts about
web security and active HTML content can generate false positives. Well-formed, 
benign JSON-LD script blocks and strictly validated WordPress and YouTube oEmbed
cache markup are ignored. YouTube exemptions apply only to normal oEmbed cache entries
with fully validated iframe markup. Unfamiliar or suspicious iframes remain in scope.

The plugin does not block incoming HTTP requests, modify database records, save 
audit reports, or send data to external services. Scan results remain in the current
browser tab. Administrator access (manage_options) and a WordPress AJAX nonce are
required to scan and view flagged text. Scanned database content may contain private
data. Use a trusted administrative browser session and do not share sensitive findings
in public reports.

Only tables with the currently configured site’s table prefix are eligible, not 
arbitrary databases or separately prefixed WordPress installations. Multi-site installations
are audited one site at a time.

### Privacy

The plugin does not transmit data to the developer or third-party services, register
visitors, create its own persistent audit log, or store scan findings on the server.
It retrieves matching database content only when an authorized administrator requests
the View content preview. The WordPress administrator’s browser temporarily holds
the results during the current page session. Avoid sharing screenshots or previews
that contain personal information or secrets.

### Languages

The administration interface is written in English and prepared for translation 
through the ach-stored-payload-audit text domain. A translation template is provided
in languages/; WordPress.org language packs can be used once the plugin is published.

## Скриншоттор

[[

[[

[[

## Орнотуу

 1. Install and activate the plugin.
 2. Navigate to Tools > ACH Payload Audit.
 3. Choose “All tables with this site’s WordPress prefix” or “Choose table groups or
    individual tables”.
 4. For a first scan, use the default 10,000-row limit, or reduce it to 1,000. The 
    unlimited option may be resource-intensive.
 5. Inspect flagged values using View content before visiting a potentially compromised
    public page.

If an unexpected PHP error blocks administration, rename wp-content/plugins/ach-
stored-payload-audit via FTP to disable the plugin.

## FAQ.KG

### Does the plugin delete suspicious content?

No. It only reads database rows and does not write to the database.

### Does a finding prove my site is vulnerable?

No. Every finding requires manual contextual review. A harmless code sample may 
match the same indicators as a malicious injected payload.

### Does the plugin scan every byte of every cell?

No. Only the first 32,768 characters of eligible text fields are scanned. Binary
data and tables using other prefixes are excluded. The results view shows up to 
500 findings, while the total count continues.

### Can the scan affect performance?

Yes. It issues database reads in batches of up to 25 rows per request. On very large
tables, scanning may consume server resources. Prefer a limited first scan and a
database backup.

## Сын-пикирлер

There are no reviews for this plugin.

## Contributors & Developers

“ACH Stored Payload Audit” is open source software. The following people have contributed
to this plugin.

Мүчөлөрү

 *   [ aiutocomputerhelp ](https://profiles.wordpress.org/aiutocomputerhelp/)

[Translate “ACH Stored Payload Audit” into your language.](https://translate.wordpress.org/projects/wp-plugins/ach-stored-payload-audit)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ach-stored-payload-audit/),
check out the [SVN repository](https://plugins.svn.wordpress.org/ach-stored-payload-audit/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/ach-stored-payload-audit/)
by [RSS](https://plugins.trac.wordpress.org/log/ach-stored-payload-audit/?limit=100&mode=stop_on_copy&format=rss).

## Өзгөртүүлөр

#### 1.2.0

 * Prepare administration labels, notices, AJAX messages and JavaScript findings
   for WordPress gettext translations.
 * Keep detection rules and scanner query logic unchanged from 1.1.5.
 * Use a distinct ACHSTPAA prefix for the plugin class, AJAX actions, nonce, JavaScript
   configuration and internal identifiers following Plugins Team feedback.
 * Refine readme and privacy documentation for the WordPress.org submission process.

#### 1.1.5

 * Reduce false positives for strictly validated YouTube iframe embeds in WordPress
   oEmbed cache metadata.
 * Keep unexpected iframe attributes, modified destinations, extra markup and encoded
   XSS indicators visible for review.

#### 1.1.4

 * Reduce false positives for strictly validated same-site WordPress oEmbed cache
   markup in wp_postmeta.
 * Keep suspicious oEmbed records, unknown iframes, other domains, and additional
   encoded XSS indicators visible.

#### 1.1.3

 * Label findings from WordPress post revisions with the parent post ID without 
   excluding historical content or changing finding counts.
 * Show revision context in the plain-text inspection dialog.

#### 1.1.2

 * Document narrowly scoped exceptions for justified read-only SQL metadata and 
   scan queries reported by static analysis. No change to detection rules or scan
   behavior.

#### 1.1.1

 * Harden database queries using WordPress identifier placeholders and validate 
   submitted scan parameters.
 * Document read-only database access for review; add the required WordPress.org
   readme header.

#### 1.1.0

 * Select all current-site tables or choose individual tables and table-name groups.
 * Removed the WP Statistics-specific scan preset; the plugin works with any eligible
   site’s table.
 * Added standard WordPress.org readme metadata.

#### 1.0.2

 * English administration interface and read-only plain-text inspection of flagged
   cells.
 * Optional warning before opening a published, public WordPress page.

#### 1.0.1

 * Reduce false positives for valid, benign Schema.org JSON-LD data.

## Мета

 *  Нуска **1.2.0**
 *  Акыркы жаңыртуу **1 күн мурун**
 *  Активдүү орнотуулар **Fewer than 10**
 *  WordPress нускасы ** 6.2 же андан жогору **
 *  Tested up to **7.1.2**
 *  PHP нускасы ** 7.4 же андан жогору **
 *  Тил
 * [English (US)](https://wordpress.org/plugins/ach-stored-payload-audit/)
 * Тег:
 * [audit](https://ky.wordpress.org/plugins/tags/audit/)[database](https://ky.wordpress.org/plugins/tags/database/)
   [malware](https://ky.wordpress.org/plugins/tags/malware/)[security](https://ky.wordpress.org/plugins/tags/security/)
   [xss](https://ky.wordpress.org/plugins/tags/xss/)
 *  [Advanced View](https://ky.wordpress.org/plugins/ach-stored-payload-audit/advanced/)

## Рейтинг

Азырынча эч кандай сын-пикир жок.

[Your review](https://wordpress.org/support/plugin/ach-stored-payload-audit/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ach-stored-payload-audit/reviews/)

## Мүчөлөрү

 *   [ aiutocomputerhelp ](https://profiles.wordpress.org/aiutocomputerhelp/)

## Колдоо

Комментарийлер барбы? Жардам керекпи?

 [Колдоо форумун көрүү](https://wordpress.org/support/plugin/ach-stored-payload-audit/)