I raised a ticket with Wordfence and sent them the infected index.php.
I did a test and Wordfence did pick it elsewhere (because of difference with repository files), just not, it seems, in index.php...
↧
scottmliddell on "[Plugin: Wordfence Security] Site doing porn redirect but clean scan"
↧