[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpQcTYVtvuLgo_nhxlZirRbZNSRBN7x1DAOIIUd5Fz0E":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"vulnerabilities":27,"developer":28,"crawl_stats":25,"alternatives":36,"analysis":141,"fingerprints":554},"vulntitan","VulnTitan – Malware Scanner, Vulnerability Scanner & Security","2.1.6","Jaroslav Svetlik","https:\u002F\u002Fprofiles.wordpress.org\u002Fjerryscg\u002F","\u003Cp>VulnTitan is a WordPress security plugin focused on malware scanning and removal, vulnerability detection, file integrity monitoring, firewall protection, and comment anti-spam controls.\u003C\u002Fp>\n\u003Cp>Instantly scan your WordPress site for malware infections and known vulnerabilities, review detailed results, and clean or remove malware safely using a guided fix workflow with automatic backups.\u003C\u002Fp>\n\u003Cp>VulnTitan focuses on practical protection: vulnerability detection, malware scanning and removal, file integrity monitoring, firewall protection, comment anti-spam defense, hidden custom login access, and a weekly executive security digest every 7 days.\u003C\u002Fp>\n\u003Ch4>Malware Scanner\u003C\u002Fh4>\n\u003Cp>The WordPress malware scanner inspects your site files for suspicious code patterns and known malicious signatures.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Detect malware infections in core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Review problematic files with contextual code preview\u003C\u002Fli>\n\u003Cli>Safe-fix workflow with automatic backups\u003C\u002Fli>\n\u003Cli>Clear severity indicators and actionable recommendations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Vulnerability Scanner\u003C\u002Fh4>\n\u003Cp>The vulnerability scanner checks your installed WordPress core, plugins, and themes against a real-time vulnerability database powered by the VulnTitan API.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Detect vulnerable plugins and themes\u003C\u002Fli>\n\u003Cli>Identify outdated components with known security risks\u003C\u002Fli>\n\u003Cli>Real-time vulnerability intelligence\u003C\u002Fli>\n\u003Cli>Clear risk explanations and remediation guidance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>File Integrity Scanner\u003C\u002Fh4>\n\u003Cp>Monitor unauthorized file changes and unexpected modifications.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Baseline comparison for WordPress files\u003C\u002Fli>\n\u003Cli>Queue-based processing for performance safety\u003C\u002Fli>\n\u003Cli>Visual status legends for fast review\u003C\u002Fli>\n\u003Cli>Actionable next steps for suspicious changes\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Firewall, Login & Comment Protection\u003C\u002Fh4>\n\u003Cp>VulnTitan includes firewall, WAF, login protection, and comment anti-spam controls to block common attack patterns and protect the WordPress login and comment surfaces.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Early MU-plugin runtime request guards\u003C\u002Fli>\n\u003Cli>SQL injection (SQLi) payload protection\u003C\u002Fli>\n\u003Cli>Command injection detection\u003C\u002Fli>\n\u003Cli>Suspicious path traversal blocking\u003C\u002Fli>\n\u003Cli>Endpoint whitelisting controls\u003C\u002Fli>\n\u003Cli>Login lockout protection against brute-force attacks\u003C\u002Fli>\n\u003Cli>TOTP-based two-factor authentication for selected roles\u003C\u002Fli>\n\u003Cli>Recovery codes and trusted-device support for enrolled accounts\u003C\u002Fli>\n\u003Cli>CAPTCHA protection for login, registration, lost-password, and optional comment forms\u003C\u002Fli>\n\u003Cli>XML-RPC allow, disable, or rate-limit policy controls with IP allowlisting\u003C\u002Fli>\n\u003Cli>Weak-password blocking during profile updates, password resets, and compatible registrations\u003C\u002Fli>\n\u003Cli>Comment Shield with honeypot, submit-time validation, duplicate detection, guest link limits, and IP rate limiting\u003C\u002Fli>\n\u003Cli>Suspicious comments can be held for moderation or blocked immediately\u003C\u002Fli>\n\u003Cli>Configurable custom login slug so administrators can use a private login URL instead of the default \u003Ccode>wp-login.php\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Default \u003Ccode>wp-login.php\u003C\u002Fcode> and guest \u003Ccode>wp-admin\u003C\u002Fcode> access can be hidden behind a \u003Ccode>404\u003C\u002Fcode> response when custom login is enabled\u003C\u002Fli>\n\u003Cli>Weekly executive security report email with 7-day firewall, login abuse, WAF, and comment spam statistics\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security-First Architecture\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Secure storage and cleanup of scan queues and logs\u003C\u002Fli>\n\u003Cli>Hardened backup handling outside \u003Ccode>ABSPATH\u003C\u002Fcode> by default\u003C\u002Fli>\n\u003Cli>Adaptive performance tuning for safe large-site scanning\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WP-CLI Support\u003C\u002Fh4>\n\u003Cp>VulnTitan supports WP-CLI commands for malware, integrity, and vulnerability scans so administrators can run checks from the terminal, scripts, or server automation.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>wp vulntitan scan malware\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp vulntitan scan integrity\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp vulntitan scan vulnerability\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp vulntitan scan all\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Optional flags: \u003Ccode>--scope=plugins\u003C\u002Fcode>, \u003Ccode>--format=json\u003C\u002Fcode>, \u003Ccode>--fail-on-findings\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to an external API at https:\u002F\u002Fvulntitan.com\u002Fapi\u002Fvulnerabilities to fetch up-to-date vulnerability data for WordPress core, plugins, and themes. This data is essential for detecting known vulnerabilities during scan operations.\u003C\u002Fp>\n\u003Cp>When a vulnerability scan is performed, the following data is sent to the VulnTitan API:\u003Cbr \u002F>\n– The slug and version of each plugin\u003Cbr \u002F>\n– The slug and version of each theme\u003Cbr \u002F>\n– The WordPress core version\u003C\u002Fp>\n\u003Cp>This data is transmitted only during scans initiated by the user or by scheduled scan settings. No personal, user-identifying, or sensitive site data is collected, transmitted, or stored.\u003C\u002Fp>\n\u003Cp>The external service is provided and operated by VulnTitan.com.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Terms of Service: https:\u002F\u002Fvulntitan.com\u002Fterms\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fvulntitan.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n","VulnTitan security toolkit for WordPress sites. Detect and remove malware, vulnerable plugins, risky file changes, and comment spam.",0,973,100,1,"2026-03-15T13:17:00.000Z","6.9.4","","7.4",[20,21,22],"malware-removal","malware-scanner","vulnerability-scanner","https:\u002F\u002Fvulntitan.com\u002Fvulntitan\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvulntitan.2.1.6.zip",null,"2026-03-15T15:16:48.613Z",[],{"slug":29,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":31,"avg_security_score":32,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"jerryscg",4,40,96,30,91,"2026-04-03T20:10:25.620Z",[37,58,81,102,123],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":16,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":56,"download_link":57,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"malcare-security","MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall","6.36","malcare","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcare\u002F","\u003Ch3>MALCARE SECURITY SERVICES\u003C\u002Fh3>\n\u003Cp>Security Plugin For WordPress Websites\u003Cbr \u002F>\n★★★★★\u003C\u002Fp>\n\u003Cp>A WordPress security plugin ensures that your website remains completely safe and secure, always. We created \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002F\" rel=\"nofollow ugc\">MalCare Security Plugin\u003C\u002Fa> to help website owners worry less about their site security, achieve peace of mind and focus all their energies on growing their business or website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why you need MalCare Security?\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fj3h0JF0we4o?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Difference Between MalCare Free vs Premium\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F4ja5ix9WDCo?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>Why MalCare is best WordPress security plugin?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fvt-0TrMV-TQ?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>MalCare in 1 Minute – Overview\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FH1XRntW_FeE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003Cbr \u002F>\n\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important Links: \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Ffeatures\u002F\" rel=\"nofollow ugc\">Security Features\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002F\" rel=\"nofollow ugc\">Why Choose MalCare?\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Ftop-wordpress-security-plugins-compared\u002F\" rel=\"nofollow ugc\">Comparisons\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fmalcare-free-premium\u002F\" rel=\"nofollow ugc\">Free vs Paid\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>MalCare is the \u003Cstrong>fastest\u003C\u002Fstrong> malware detection and removal plugin loved by thousands of developers and agencies. With an industry-first \u003Cstrong>automatic one-click malware removal\u003C\u002Fstrong>, your WordPress website is clean before Google blacklists it or your web host takes it down. MalCare has been developed from the ground up after \u003Cstrong>analyzing over 240,000 websites over 2.5+ years\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Its \u003Cstrong>intelligent scanning methodology\u003C\u002Fstrong> will \u003Cstrong>never slow down your WordPress site\u003C\u002Fstrong> and \u003Cstrong>accurately identifies\u003C\u002Fstrong> the most complex malware that typically goes undetected in other popular WordPress security plugins.\u003C\u002Fp>\n\u003Cp>The \u003Cstrong>one-click malware cleaner\u003C\u002Fstrong> offers unlimited automated cleanups while the inbuilt \u003Cstrong>powerful cloud-based firewall\u003C\u002Fstrong> ensures round-the-clock website protection against spam attacks. Moreover, you can \u003Cstrong>block countries\u003C\u002Fstrong> to mitigate hack attacks.\u003C\u002Fp>\n\u003Cp>MalCare comes integrated with a \u003Cstrong>complete website management\u003C\u002Fstrong> module that ensures better WP security and site management to your websites from a single dashboard.\u003C\u002Fp>\n\u003Cp>The WP security plugin \u003Cstrong>notifies you if the WordPress site goes down\u003C\u002Fstrong> so that you can handle the situation before you start losing visitors. Performance Check enables WordPress users to keep an eye on their \u003Cstrong>loading speed\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>MalCare offers a premium \u003Cstrong>White-Label\u003C\u002Fstrong> solution that lets agencies provide better website security to their clients without risking their business. And enables users to \u003Cstrong>generate beautiful reports\u003C\u002Fstrong> for their clients.\u003C\u002Fp>\n\u003Ch3>Why Choose MalCare WordPress Security Plugin?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Ch4>WordPress Malware Scanner\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Cloud Based Deep malware scanner\u003C\u002Fli>\n\u003Cli>Doesn’t Slow down your WordPress site\u003C\u002Fli>\n\u003Cli>Detects malware BEFORE it’s too late\u003C\u002Fli>\n\u003Cli>NO impact on your website\u003C\u002Fli>\n\u003Cli>Finds ALL types of malware, even new & complex ones\u003C\u002Fli>\n\u003Cli>Get Alerts about Security Risks with our WordPress Vulnerability Scanner\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>WordPress Malware Removal\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>View hacked file details\u003C\u002Fli>\n\u003Cli>Cleans your site INSTANTLY, in less than 60 Secs\u003C\u002Fli>\n\u003Cli>Removes ALL traces of malware\u003C\u002Fli>\n\u003Cli>UNLIMITED hack cleanups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>WordPress Website Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Blocks hacker BOTS from attacking login page\u003C\u002Fli>\n\u003Cli>Identifies & blocks MALICIOUS traffic\u003C\u002Fli>\n\u003Cli>Enables users to HARDEN their WordPress sites\u003C\u002Fli>\n\u003Cli>Enables users to block ENTIRE countries\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Easy to Use\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Set up an account in 60 secs\u003C\u002Fli>\n\u003Cli>Configure security once & never look at it again\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Agile & responsive customer support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Why Is MalCare Such a Game-Changer?\u003C\u002Fh3>\n\u003Cp>MalCare offers unparalleled security services. Some services are free and others are paid.\u003C\u002Fp>\n\u003Ch4>MalCare’s FREE Services –\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\n\u003Ch4>Cloud-Based Malware Scanning (Free)\u003C\u002Fh4>\n\u003Cp>MalCare’s Cloud-based Scanning ensures no impact on your website ever. Moreover, it detects Complex Malware missed by other popular security plugins for WordPress.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Web-Application WordPress Firewall (Free)\u003C\u002Fh4>\n\u003Cp>Get Real-Time Protection for your WordPress website against the latest security threats with MalCare’s Smart Firewall. Block hackers & bots before they harm your site.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>CAPTCHA-Based Login Page Protection (Free)\u003C\u002Fh4>\n\u003Cp>Automatically prevent brute force attacks with MalCare’s Smart Captcha-Based Login Page Protection. Round-the-clock protection against malicious traffic.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>MalCare’s PAID Services –\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\n\u003Ch4>Viewing Hacked Files (Paid)\u003C\u002Fh4>\n\u003Cp>View the infected files present on your WordPress website. Learn which themes or plugins or files or folders were infected by hackers.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Industry-First Instant Malware Removal (Paid)\u003C\u002Fh4>\n\u003Cp>Clean your hacked site instantly in less than 60 secs with MalCare’s 1-Click Cleaner. Clean your website before Google blacklists it or your web host takes it down.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>WordPress Recommended Website Hardening (Paid)\u003C\u002Fh4>\n\u003Cp>Easily configure WordPress recommended best security practices with just 1-Click from right within MalCare’s dashboard. No technical knowledge needed.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Geo-blocking (Paid)\u003C\u002Fh4>\n\u003Cp>Restrict access to users based on their geographical location. Easily block all visitors from certain countries to mitigate the risk of being hacked.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Uptime Monitoring (Paid)\u003C\u002Fh4>\n\u003Cp>With MalCare’s Uptime Monitoring keep a steady eye on your WordPress site. It ensures that you are not oblivious to website downtime.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Common Hack Attacks Prevented By MalCare\u003C\u002Fh3>\n\u003Cp>MalCare protects websites against all common hack attacks which includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-brute-force\u002F\" rel=\"nofollow ugc\">Brute force attacks\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fjapanese-keyword-hack\u002F\" rel=\"nofollow ugc\">Japanese keyword hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-hacked-redirect\u002F\" rel=\"nofollow ugc\">WordPress redirect hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwhat-is-pharma-hack-how-to-clean-it\u002F\" rel=\"nofollow ugc\">Pharma hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fseo-spam\u002F\" rel=\"nofollow ugc\">SEO spam hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-theme-hacked\u002F\" rel=\"nofollow ugc\">WordPress theme hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fspam-link-injection-wordpress\u002F\" rel=\"nofollow ugc\">WordPress spam link injections\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Frevslider-exploit\u002F\" rel=\"nofollow ugc\">Revslider hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-timthumb\u002F\" rel=\"nofollow ugc\">TimThumb hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fadminer-php-hack\u002F\" rel=\"nofollow ugc\">Adminer.php hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fcross-site-scripting-xss-attacks-what-how-prevent-them\u002F\" rel=\"nofollow ugc\">XSS or cross-site scripting hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fhow-to-detect-and-remove-wp-vcd-malware-a-step-by-step-guide-and-a-bonus-plugin\u002F\" rel=\"nofollow ugc\">WP-VCD hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fpreventing-sql-injections\u002F\" rel=\"nofollow ugc\">SQL injection hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-malvertising\u002F\" rel=\"nofollow ugc\">WordPress malvertising hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fremove-google-blacklist-warning\u002F\" rel=\"nofollow ugc\">Google Blacklist hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fgoogle-adwords-account-suspended\u002F\" rel=\"nofollow ugc\">Google Adwords hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fsession-hijacking-cookie-stealing\u002F\" rel=\"nofollow ugc\">Cookie stealing & session hijacking\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fhow-to-remove-phishing\u002F\" rel=\"nofollow ugc\">WordPress phishing hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Ffavicon-ico-virus-wordpress\u002F\" rel=\"nofollow ugc\">Favicon.ico virus hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fremoving-wp-feed-php-malware\u002F\" rel=\"nofollow ugc\">WP-Feed.php & WP-Tmp.php\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fhow-to-scan-malware-and-backdoors-of-your-wordpress-site\u002F\" rel=\"nofollow ugc\">Backdoor hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fcoinhive-malware-wordpress\u002F\" rel=\"nofollow ugc\">Coinhive hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fdeface-wordpress\u002F\" rel=\"nofollow ugc\">WordPress deface hack\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>MalCare Free vs. MalCare Premium\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Ch4>Cloud Based Malware Scanner (FREE)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Cloud-Based Malware Scanning \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Deep Malware Scanning – Files & Database \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Website Firewall (FREE)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Web Application Firewall \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Plugin Based Firewall \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Rules update every 7 days \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Login Page Protection \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Bot Protection \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Rules update every 5 mins \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Geo-Blocking \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Website Hardening \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Instant Malware Removal (PAID)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>View Malware Insights \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Instant One-Click Clean Ups \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Automatic Clean-Ups \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Unlimited Clean-Ups \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Personalized Customer Support (Paid)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Support on WordPress forum \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Support via email and chat \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Who Can Benefit From MalCare?\u003C\u002Fh3>\n\u003Cp>MalCare is perfect for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Any WordPress Websites\u003C\u002Fli>\n\u003Cli>Small Business Websites\u003C\u002Fli>\n\u003Cli>Developer Websites\u003C\u002Fli>\n\u003Cli>Web Designing Websites\u003C\u002Fli>\n\u003Cli>eCommerce Stores\u003C\u002Fli>\n\u003Cli>Niche Sites\u003C\u002Fli>\n\u003Cli>Artists & Photographers Sites\u003C\u002Fli>\n\u003Cli>Amateur & Professional Bloggers\u003C\u002Fli>\n\u003Cli>Local Business Sites\u003C\u002Fli>\n\u003Cli>Website for Startups\u003C\u002Fli>\n\u003Cli>Websites Selling Courses\u003C\u002Fli>\n\u003Cli>Influencer Sites\u003C\u002Fli>\n\u003Cli>Web Hosting Companies\u003C\u002Fli>\n\u003Cli>Website Maintenance Services or Agencies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Detailed Setup Step-by-Step Tutorials\u003C\u002Fh3>\n\u003Cp>This WordPress security plugin works in tandem with the \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\" rel=\"nofollow ugc\">MalCare\u003C\u002Fa> servers. MalCare servers do all the heavy processing and will alert you if your site has any security issues.\u003C\u002Fp>\n\u003Cp>Hence a MalCare account is needed to use the plugin. This account can also be used by our other products including \u003Ca href=\"https:\u002F\u002Fblogvault.net\" rel=\"nofollow ugc\">BlogVault\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Fsolutions\u002Farticles\u002F35000055512-how-do-i-set-up-a-malcare-account-\" rel=\"nofollow ugc\">How to Set Up a MalCare Account?\u003C\u002Fa> (Help Doc)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=v8L_DZllk7k&list=\" rel=\"nofollow ugc\">How to Set Up a MalCare Account?\u003C\u002Fa> (Video)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>MalCare Full Security Features List\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Ch4>Cloud Based Malware Scanner\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Daily Scan Frequency\u003C\u002Fli>\n\u003Cli>On-demand Site Scans\u003C\u002Fli>\n\u003Cli>Scan Non-WP Files\u003C\u002Fli>\n\u003Cli>Does not slow down your website ever\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Instant Malware Removal\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>View Hacked Files details\u003C\u002Fli>\n\u003Cli>Instant Automatic Malware Removal\u003C\u002Fli>\n\u003Cli>Removal of Unknown & New Malware\u003C\u002Fli>\n\u003Cli>Unlimited Malware Removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Intelligent Malware Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Web Application Firewall\u003C\u002Fli>\n\u003Cli>IP Whitelisting\u003C\u002Fli>\n\u003Cli>CAPTCHA-based Login Page Protection\u003C\u002Fli>\n\u003Cli>Traffic Logs\u003C\u002Fli>\n\u003Cli>Login Logs\u003C\u002Fli>\n\u003Cli>Geo-Blocking\u003C\u002Fli>\n\u003Cli>Alerts for Suspicious Logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Website Hardening\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Block PHP Execution in Untrusted Folders\u003C\u002Fli>\n\u003Cli>Disable Files Editor\u003C\u002Fli>\n\u003Cli>Block Plugin or Theme Installation\u003C\u002Fli>\n\u003Cli>Change Security Keys\u003C\u002Fli>\n\u003Cli>Reset All Passwords\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Complete Website Management\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Centralized Dashboard\u003C\u002Fli>\n\u003Cli>Plugins & Themes Management & Update\u003C\u002Fli>\n\u003Cli>User Management\u003C\u002Fli>\n\u003Cli>Team Management\u003C\u002Fli>\n\u003Cli>Client Management\u003C\u002Fli>\n\u003Cli>Generate & Schedule Reports\u003C\u002Fli>\n\u003Cli>White-Labeling Solution\u003C\u002Fli>\n\u003Cli>Uptime Monitoring\u003C\u002Fli>\n\u003Cli>Site Speed Monitoring\u003C\u002Fli>\n\u003Cli>Blacklist Alarm\u003C\u002Fli>\n\u003Cli>Slack Integration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Email\u003C\u002Fli>\n\u003Cli>Chat\u003C\u002Fli>\n\u003Cli>Social Media\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Fans Are Raving About Us\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fvisualcomposer.com\u002Fblog\u002Fmalcare-review\u002F\" rel=\"nofollow ugc\">MalCare Review on VisualComposer\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.elegantthemes.com\u002Fblog\u002Fresources\u002Fmalcare-security-and-firewall-the-right-security-plugin-for-your-site\" rel=\"nofollow ugc\">MalCare Review on ElegantThemes\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fblog.weglot.com\u002Fideal-security-solution-malcare-review\u002F\" rel=\"nofollow ugc\">MalCare Review on Weglot\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.wpwhitesecurity.com\u002Fmalcare-wordpress-site-security-service-reviewed\u002F\" rel=\"nofollow ugc\">MalCare Review on WPWhiteSecurity\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=2yNIb4Pc_ig\" rel=\"nofollow ugc\">MalCare Reviews by WordPress Influencer Adam Preiser (Plus Real Malware Removal Demo)\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Connect With Our Team of Security Experts\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002FWordPressForWebCreators\u002F\" rel=\"nofollow ugc\">Join MalCare’s Facebook Community\u003C\u002Fa> – The purpose of the group is to enable Web Creators to gain valuable insights and help from community members which will be valuable to their business. So, if you are a WordPress user & want to keep up with the latest industry news and get help for your business, \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002FWordPressForWebCreators\u002F\" rel=\"nofollow ugc\">join us\u003C\u002Fa>!\u003C\u002Fp>\n\u003Ch3>Don’t Know Where to Getting Started? Start From Here –\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Fsolutions\u002Farticles\u002F35000055512-how-do-i-set-up-a-malcare-account-\" rel=\"nofollow ugc\">How to Setup MalCare Account?\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002FWordPressForWebCreators\u002F\" rel=\"nofollow ugc\">Join MalCare Facebook Group MalCare\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fchannel\u002FUC5oQAXXvndQJuyVrWgMRWqg\" rel=\"nofollow ugc\">MalCare Tutorial Videos\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Fhome\" rel=\"nofollow ugc\">User Help Documentations\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Ffaq\u002F\" rel=\"nofollow ugc\">Frequently Asked Questions\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Ftickets\u002Fnew\" rel=\"nofollow ugc\">Support for MalCare Users\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>MalCare vs. Others\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.codeinwp.com\u002Fblog\u002Fsucuri-vs-wordfence-vs-malcare\u002F\" rel=\"nofollow ugc\">MalCare vs Sucuri vs Wordfence by CodeinWP\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmayor.com\u002Fmalcare-sucuri-wordfence-sitelock-ithemes-security-comparison\u002F\" rel=\"nofollow ugc\">MalCare vs Sucuri vs Wordfence vs SiteLock vs iThemes Security by WPMayor\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.",200000,17387894,86,519,"2026-01-29T13:26:00.000Z","4.0","7.0",[53,20,21,54,55],"firewall","vulnerabilities","wordpress-security","https:\u002F\u002Fwww.malcare.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmalcare-security.6.36.zip",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":68,"num_ratings":69,"last_updated":70,"tested_up_to":16,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":76,"download_link":77,"security_score":78,"vuln_count":79,"unpatched_count":11,"last_vuln_date":80,"fetched_at":26},"quttera-web-malware-scanner","Quttera ThreatSign – Web Malware Scanner for WordPress","4.0.0.3","quttera","https:\u002F\u002Fprofiles.wordpress.org\u002Fquttera\u002F","\u003Cp>Quttera ThreatSign protects your WordPress website with multi-layered security:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Malware Detection:\u003C\u002Fstrong> Powered by Quttera’s AI-driven heuristic engine, the scanner detects malicious PHP, obfuscated JavaScript, hidden iframes, redirects, spam, SEO malware, and credit-card skimmers targeting checkout pages. The plugin performs on-demand scans directly from your WordPress admin and checks your domain against more than 40 global security authorities, including Google, McAfee, Norton, and Yandex. Detection capabilities are continuously enhanced using insights from Quttera’s worldwide threat intelligence network.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Brute Force Protection:\u003C\u002Fstrong> Prevents unauthorized login attempts with IP locking, configurable rate limiting, and environment-aware protection policies. Supports both shared hosting (aggressive locking) and dedicated servers (progressive delays). Includes emergency bypass mechanism for critical situations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Bot Protection:\u003C\u002Fstrong> Layered defense against automated attacks using multi-stage risk evaluation, token-bucket rate limiting, and legitimate bot recognition (Googlebot, Bingbot, etc.). Protects REST API, XML-RPC, and WooCommerce endpoints with endpoint-specific risk scoring.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin User Monitoring:\u003C\u002Fstrong> Real-time detection and alerting for unauthorized admin additions, removals, and role changes with database audit trail and snapshots.\u003C\u002Fp>\n\u003Cp>For complete protection—including automated malware removal, scheduled scanning, WAF, and 24\u002F7 monitoring—you can upgrade to a ThreatSign Website Security plan.\u003C\u002Fp>\n\u003Ch4>Malware Detection Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>One-click on-demand scans from WP admin\u003C\u002Fli>\n\u003Cli>0-day (unknown threat) detection via heuristic & behavioral analysis\u003C\u002Fli>\n\u003Cli>Detection of malicious PHP (backdoors, shells, injections)\u003C\u002Fli>\n\u003Cli>Detection of obfuscated or polymorphic JavaScript\u003C\u002Fli>\n\u003Cli>Identification of malicious iframes, redirects & hidden links\u003C\u002Fli>\n\u003Cli>Detection of spam & SEO malware\u003C\u002Fli>\n\u003Cli>Checkout skimmer detection\u003C\u002Fli>\n\u003Cli>Inspection of WordPress core file integrity\u003C\u002Fli>\n\u003Cli>Detection of alien or unauthorized files in core directories\u003C\u002Fli>\n\u003Cli>External links and outbound reference analysis\u003C\u002Fli>\n\u003Cli>Blacklist checks across 40+ security authorities\u003C\u002Fli>\n\u003Cli>Cloud-based scanning to reduce server resource load\u003C\u002Fli>\n\u003Cli>Detailed investigation reports with severity levels\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Brute Force Protection Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>IP-based locking with configurable thresholds\u003C\u002Fli>\n\u003Cli>Multi-stage failure detection with soft and hard locks\u003C\u002Fli>\n\u003Cli>Environment-aware policies for shared hosting and dedicated servers\u003C\u002Fli>\n\u003Cli>IP whitelist\u002Fblacklist with CIDR notation support\u003C\u002Fli>\n\u003Cli>Emergency bypass mechanism via constant or filter\u003C\u002Fli>\n\u003Cli>User account lockout alerts via email\u003C\u002Fli>\n\u003Cli>Combo-lock (IP + username) detection\u003C\u002Fli>\n\u003Cli>Rate limiting with progressive delays\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Bot Protection Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Multi-stage risk evaluation with heuristic analysis\u003C\u002Fli>\n\u003Cli>Token-bucket rate limiting across multiple lanes (global, REST, XML-RPC, checkout, cart)\u003C\u002Fli>\n\u003Cli>Legitimate bot recognition (Googlebot, Bingbot with elevated rate limits)\u003C\u002Fli>\n\u003Cli>REST API enumeration and authentication protection\u003C\u002Fli>\n\u003Cli>WooCommerce endpoint protection (checkout & cart)\u003C\u002Fli>\n\u003Cli>Configurable operation modes (Observe, Balanced, Aggressive)\u003C\u002Fli>\n\u003Cli>Risk-based challenge mechanisms and exponential backoff\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Admin User Monitoring Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Real-time detection of admin user additions and removals\u003C\u002Fli>\n\u003Cli>Admin role change tracking\u003C\u002Fli>\n\u003Cli>Database snapshot comparison for audit trail\u003C\u002Fli>\n\u003Cli>WP-Cron scheduled checks (1-minute intervals)\u003C\u002Fli>\n\u003Cli>Immediate detection via WordPress hooks\u003C\u002Fli>\n\u003Cli>Email alerts for unauthorized changes\u003C\u002Fli>\n\u003Cli>Comprehensive alarm system integration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you need malware removal assistance, contact us at support@quttera.com or sign up for any\u003Cbr \u002F>\nof our ThreatSign annual plans, which include cleanup & blacklist removal:\u003Cbr \u002F>\nhttps:\u002F\u002Fquttera.com\u002Fanti-malware-website-monitoring-signup\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fquttera.com\" rel=\"nofollow ugc\">Quttera\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Plugin’s other home\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fquttera.com\u002Fwordpress_malware_scanner\" rel=\"nofollow ugc\">WordPress Malware Scanner\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress multi-level security scanner detecting malware, 0-day threats, brute-force attacks, bot attacks, and unauthorized admin changes.",10000,4426011,78,47,"2026-03-12T00:02:00.000Z","3.3.2","7.2",[74,20,21,75,55],"card-skimmer","threat-detection","http:\u002F\u002Fquttera.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fquttera-web-malware-scanner.4.0.0.3.zip",98,3,"2025-08-14 00:00:00",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":66,"downloaded":89,"rating":90,"num_ratings":91,"last_updated":92,"tested_up_to":16,"requires_at_least":93,"requires_php":94,"tags":95,"homepage":99,"download_link":100,"security_score":32,"vuln_count":79,"unpatched_count":11,"last_vuln_date":101,"fetched_at":26},"wp-malware-removal","Malcure Malware Shield — Removal, Repair, Monitor","19.8","Malcure Web Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcure\u002F","\u003Cp>Is your website acting strangely? Seeing ‘Deceptive Site Ahead’ warnings, Japanese spam, SEO spam, or random redirects? Time to fix and monitor your site with \u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch3>Malcure Malware Shield: The Powerful Antivirus\u003C\u002Fh3>\n\u003Cp>Just as your computer requires antivirus, your website demands specialized \u003Cstrong>antivirus-grade protection\u003C\u002Fstrong>. Malcure Malware Shield delivers comprehensive, \u003Cstrong>antivirus-style\u003C\u002Fstrong> detection with advanced signatures to identify viruses, trojans, backdoors, adware, and ransomware. Unlike basic security plugins, it operates with the precision of an antivirus engine, scanning every layer of your site—from core files to the database—to ensure your website remains virus-free and secure.\u003C\u002Fp>\n\u003Ch3>Malware Removal, Hack Repair & SEO Spam Cleanup\u003C\u002Fh3>\n\u003Cp>Malware attacks are evolving. Standard scanners often miss hidden backdoors and database infections. If your current security plugin says “All Clear” but your site is still broken, you need \u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong> is the intelligent, lightweight security solution. We believe security should be simple on the surface but deep under the hood. No complex settings. No bloat. Just activate and scan.\u003C\u002Fp>\n\u003Cp>Lightweight, API-driven scanning runs only on demand or on scheduled scans — no persistent background processes.\u003C\u002Fp>\n\u003Cp>Unlike scanners that delay new malware definitions for days, Malcure delivers real-time threat intelligence to every user so you’re protected against the latest threats as soon as they emerge.\u003C\u002Fp>\n\u003Ch3>What Our Users Say\u003C\u002Fh3>\n\u003Cp>Quotes are verbatim from WordPress.org support reviews, except for bracketed edits (for example, competitor names removed).\u003C\u002Fp>\n\u003Ch4>Best by far, better than [competitor name removed] and other giants\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“You can see it is a bunch of geeks that created this, with skill and visual creativity at that. I spent hours trying to find a plugin like this. So many options and such bad results until now. Great job guys. You deserve it. Simple and effective. (Disclaimer to other potential readers: there are many types of hacks\u002Fmalware out there, every scenario is different, but start with the Malcure scan and see how it goes. 9\u002F10 you won’t be disappointed, my guess)” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-by-far-better-than-wordfence-and-other-giants\u002F\" rel=\"ugc\">@dalingzaf\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>The ONLY plugin that scans files…\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“I am a web developer and have tried many malware removal plugins, including popular ones [competitor names removed]. However, none of them detected some unusual files that were actually malware causing regular attacks. Some of these files were in JPG format.” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-only-plugin-that-scans-files-in-real-time-2\u002F\" rel=\"ugc\">@devzeeshanx\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Best Malware Removal Plugin in just few minutes\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“Most security plugins that are free only scan the code, but Malcure Malware Removal Plugin scans the wordpress database and the code files in few minutes. Accurately shows which Database table row is infected and it helps resolve the hacking attempt instantly. Saves a lot of time for the developers. Thank You Team Malcure” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-malware-removal-plugin-in-just-few-minutes\u002F\" rel=\"ugc\">@s3630\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>It’s not just a “teaser”\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“This plugin really found the malware, and removed it. Really for free. Thanks guys, I’m going to donate now!” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fits-not-just-a-teaser\u002F\" rel=\"ugc\">@halucska\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Malware Removal & Hack Repair\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Checksum Verification:\u003C\u002Fstrong> We verify core, plugin, and theme file integrity against the official repository checksums served by our SaaS API endpoint.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Deep Scan:\u003C\u002Fstrong> If checksums fail, Malcure runs a full scan against malware detection signatures detecting estimated 50,000+ variants.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Inspect & Repair:\u003C\u002Fstrong> Inspect infected database records and files. Assists in cleaning compromised files and database entries.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Spam Specialist:\u003C\u002Fstrong> Detects and removes the notorious “Japanese Keyword Hack” and pharma spam from your files and database, helping restore your Google rankings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Virus Scanner & Threat Detection\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Database Scan:\u003C\u002Fstrong> Scans database tables for malicious injections and spam links.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Scan:\u003C\u002Fstrong> Scans core files, themes, plugins, images, and uploads for backdoors and obfuscated code.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Detection:\u003C\u002Fstrong> Checks your core, plugins, and themes for known security flaws.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DeepScan™ Technology:\u003C\u002Fstrong> Scans backups, archives, images, and hidden files where malware hides.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ultra-High Precision:\u003C\u002Fstrong> Uses intelligent checksum verification (comparing your files to official core\u002Fplugin\u002Ftheme checksums) to dramatically reduce false alarms compared to heuristic-only scanners.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Intelligent Health Monitor\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Always-On Guard:\u003C\u002Fstrong> Continuous monitoring via \u003Cstrong>Scheduled Scans\u003C\u002Fstrong> (daily\u002Fweekly\u002Fmonthly) configurable cadence.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Instant Alerts:\u003C\u002Fstrong> Every time a scheduled scan completes, you get an instant email report telling you if your site is clean or infected.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Log:\u003C\u002Fstrong> Track the events leading up to a malware incident for faster root-cause analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Powered by Malcure API: Real-Time Threat Intelligence\u003C\u002Fh3>\n\u003Cp>Hackers don’t sleep, and neither do we. Malcure Malware Shield connects to our real-time API to fetch the latest threat definitions.\u003C\u002Fp>\n\u003Cp>This plugin relies on the Malcure API to provide real-time threat intelligence and checksum verification.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Data Transmission:\u003C\u002Fstrong> To perform scans, the plugin sends file checksums and your site’s domain to Malcure servers. No sensitive user data is transmitted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms & Privacy:\u003C\u002Fstrong> Use of the API is subject to our \u003Ca href=\"https:\u002F\u002Fwww.malcure.com\u002F?p=1720&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=3&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero-Day Alerts:\u003C\u002Fstrong> Our API serves new threat-intelligence in real-time, ensuring the site is scanned against the latest vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Checksums:\u003C\u002Fstrong> We verify your core files, themes, and plugins against the official repository checksums using our API, ensuring absolute integrity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight:\u003C\u002Fstrong> The scanner only uses minimum resources to keep your server fast and responsive.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Why Keep Malcure Malware Shield Installed?\u003C\u002Fh3>\n\u003Ch4>Reinfection Risk & Continuous Monitoring\u003C\u002Fh4>\n\u003Cp>Malware cleanup is not a one-and-done task. New vulnerabilities and reinfections can appear without warning, so continuous monitoring and scheduled scans help catch issues early—before SEO damage, blacklists, or downtime. You get email notification with the results to rest assured that the site is clean or when immediate action is required.\u003C\u002Fp>\n\u003Cp>Cleaning your site is just step one. Malcure is your anti-malware health monitor.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Continuous Monitoring:\u003C\u002Fstrong> Scheduled scans watch your site for changes so you don’t have to.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Event Log:\u003C\u002Fstrong> See exactly what’s happening on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Early Warning:\u003C\u002Fstrong> Catch new infections before Google blacklists you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recurrence Prevention:\u003C\u002Fstrong> Scheduled scans and integrity checks catch reinfections before they spread.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Bloat:\u003C\u002Fstrong> Designed to run on-demand or as per schedule without slowing down your site.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Who This Plugin Is For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> who want clear, actionable results (what was flagged and where).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies & developers\u003C\u002Fstrong> who need fast triage across multiple sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce \u002F membership \u002F lead-gen sites\u003C\u002Fstrong> where downtime, SEO brand-reputation damage are expensive.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anyone\u003C\u002Fstrong> who wants a scanner that cuts through the noise to focus on \u003Cem>signal\u003C\u002Fem>—real threats with practical remediation paths.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works (Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Review \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Clean \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Scan\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Go to \u003Cstrong>Malcure Scanner\u003C\u002Fstrong> in your Admin Dashboard.\u003C\u002Fli>\n\u003Cli>Run a scan to check your files and database for vulnerabilities, malware, backdoors, suspicious code, and integrity issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Review\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Malcure reports findings with clear locations (file paths \u002F database records) so you can verify what changed and why it was flagged.\u003C\u002Fli>\n\u003Cli>Use the results to decide what should be repaired, deleted, or kept (for example, legitimate custom code).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Clean & Recover\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The free edition helps you identify issues, inspect data and understand what needs fixing.\u003C\u002Fli>\n\u003Cli>The Advanced Edition adds Whitelisting, Advanced Scan Filters, File Operations, WP CLI Automation, Deployment, Bulk Client-Servicing Features, Background Scan & Premium Support (Expertise).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Monitor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Set up scheduled scans to keep your site continuously monitored.\u003C\u002Fli>\n\u003Cli>Get email alerts for new infections or integrity issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Is It Free?\u003C\u002Fh4>\n\u003Cp>We believe in 100% transparency.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Professional-grade Detection (Knowledge). You see every infected file and database row (exact file path & line number), so you can clean it yourself for free.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Real-time Threat Intelligence & Monitoring.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pro Upgrade:\u003C\u002Fstrong> Whitelisting, Advanced Scan Filters, File Operations, WP CLI Automation, Deployment, Bulk Client-Servicing Features, Background Scan & Premium Support (Expertise).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>You are never forced to pay to \u003Cem>find\u003C\u002Fem> a hack.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FEbSbxiTOc8k?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Core Features (Free Forever)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Deep Malware Scan:\u003C\u002Fstrong> Scans core files, themes, plugins, images, and your entire database for vulnerabilities, viruses, trojans, backdoors, and \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=60&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">malicious redirects\u003C\u002Fa>.\n\u003Cul>\n\u003Cli>\u003Cstrong>Files:\u003C\u002Fstrong> Scans core files, themes, plugins, images, and uploads for backdoors, shells including variants like C99, R57, RootShell, dolohan, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx, obfuscated code and many more known and unknown variants.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database:\u003C\u002Fstrong> Scans database tables for malicious injections, recurring malware and spam links.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Spam Detection:\u003C\u002Fstrong> Specifically checks page titles and database records for “Japanese Keyword Hack”, “Pharma Hack” and other SEO spam symptoms.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks your installed plugins and themes against our real-time database of known security vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Intelligent Checksum Verification:\u003C\u002Fstrong> Automatically verifies your core files, themes, and plugins against the official checksums. If a file has been tampered with, we know instantly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Uncompromising Detection:\u003C\u002Fstrong> Detects variants like C99, R57, RootShell, dolohan, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx, obfuscated code and many more known and unknown variants.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Surface Hardening & Firewall:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Cstrong>Block Path Traversal:\u003C\u002Fstrong> Stops attackers from accessing sensitive system files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block PHP Uploads:\u003C\u002Fstrong> Prevents malicious scripts from being uploaded to your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bots from fishing for your username.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection:\u003C\u002Fstrong> Prevents user data leakage via the WP REST API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=1622&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Security Hardening\u003C\u002Fa>:\u003C\u002Fstrong> Learn more about securing your site.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recurrence Watchdog (Background Monitor):\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Cstrong>Set it and forget it:\u003C\u002Fstrong> Malcure runs silently in the background using scheduled scans (configurable cadence) + integrity baseline to monitor changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stay Ahead:\u003C\u002Fstrong> Automatically catch new infections before they spread or damage your SEO rankings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Incident Response Toolkit:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Cstrong>Nuke User Sessions:\u003C\u002Fstrong> Instantly force-logout every user on the site to kick out intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Salt Shuffler:\u003C\u002Fstrong> One-click rotation of \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5230&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">security keys (salts)\u003C\u002Fa> to invalidate all browser cookies.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Forensic Flight Recorder (Event Log):\u003C\u002Fstrong> Track every security event. Know exactly \u003Cem>when\u003C\u002Fem> and \u003Cem>how\u003C\u002Fem> a breach might have occurred with our 100-day event log.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Search Console Integration:\u003C\u002Fstrong> Connect directly to Google to fetch security warnings and blacklist status in real-time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time API Updates:\u003C\u002Fstrong> Connects to the Malcure Cloud to fetch the latest threats and vulnerabilities.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Upgrade to Advanced Edition\u003C\u002Fh4>\n\u003Cp>For mission-critical websites that demand comprehensive protection and recovery tools.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>1-Click Surgical Repair:\u003C\u002Fstrong> Inspect, Delete, or Repair infected files instantly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Whitelisting:\u003C\u002Fstrong> Stop false alarms. Supports files, folders, and \u003Cstrong>Database Records\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI Integration:\u003C\u002Fstrong> Complete command-line control for automated scanning and reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Definition Updates:\u003C\u002Fstrong> Definitions update automatically in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>On-Demand Background Scans:\u003C\u002Fstrong> Trigger deep scans immediately without keeping your browser open.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Scan Filters:\u003C\u002Fstrong> For when you are specifically looking for something in the files or database or want to include, exclude specific files & directories\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Operations:\u003C\u002Fstrong> Critical file operations like deletion.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Client-Servicing Features:\u003C\u002Fstrong> Like copying scan results to generate report for clients.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Background Scan:\u003C\u002Fstrong> For when you want to trigger a scan and forget it. The scan continues and emails you upon completion.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support (Expertise):\u003C\u002Fstrong> When you want to consult or want to exploit advanced features or need help troubleshooting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>High-Priority Support:\u003C\u002Fstrong> Direct access to our security analysts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">\u003Cstrong>Get Malcure Advanced Edition\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Additional Resources for Malware Removal\u003C\u002Fh4>\n\u003Cp>Follow these expert guides to remove malware, recover lost traffic, and restore your online reputation:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=1540&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">A step by step guide to remove the malware\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=13946&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Japanese Keyword Hack: How to Remove SEO Spam\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5728&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">What is the Pharma Hack & How to fix it\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=14143&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">How to Fix Google Ads Disapproved for Malicious Software\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=14477&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">How to Prevent SQL Injection Attacks\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5265&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Live Malware Infection Removal & Analysis\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=7207&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">How to Fix “This Site May Harm Your Computer” Warning\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=60&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Comprehensive Guide to Removing JavaScript Redirect Malware\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5699&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">How to Fix a Blank WP-Admin Page\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=9102&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Malcure WP CLI Integration & Cheatsheet\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=14375&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">How to Prevent Brute Force Attacks\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5230&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">How to Change Salt Keys\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Expert Malware Removal Service\u003C\u002Fh4>\n\u003Cp>In over your head? Our security analysts are on standby. We offer a complete \u003Cstrong>Malware Removal Service\u003C\u002Fstrong> that includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>100% Removal Guarantee:\u003C\u002Fstrong> We guarantee to remove all malware from your website.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Same Day Service:\u003C\u002Fstrong> Fast turnaround time to get your business back online.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manual Inspection:\u003C\u002Fstrong> Our experts manually inspect critical files (htaccess, wp-config, index.php) and your database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blacklist Removal:\u003C\u002Fstrong> We handle the removal of your site from blacklists like Google, Norton, McAfee, etc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Hardening:\u003C\u002Fstrong> We identify the root cause and patch vulnerabilities to prevent future infections.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>15-Day Cover:\u003C\u002Fstrong> Security analysts available 24\u002F7\u002F365 to ensure your site stays clean.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">\u003Cstrong>Book Expert Malware Removal\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Ch4>Some files are detected by Malcure Malware Shield as “suspicious”. What gives?\u003C\u002Fh4>\n\u003Cp>Malcure’s DeepScan checks each file for malware. However some files aren’t pure malware but may contain code that is suspicious and could potentially do nasty things. You should carefully review and analyse them to see if they indeed do anything nasty.\u003C\u002Fp>\n\u003Ch4>I can’t get Malcure Malware Shield to work. It hangs \u002F doesn’t complete the scan \u002F breaks for some reason.\u003C\u002Fh4>\n\u003Cp>If you think that the plugin is broken, \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Malcure Malware Shield (or for that matter other plugins) may break on malware affected \u002F broken websites. \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Malcure Advanced Edition\u003C\u002Fa> integrates with WP CLI and allows you to complete the scan from WP CLI even when the site is blocked by the webhost or when you are unable to login to the website.\u003C\u002Fp>\n\u003Ch4>My site is infected however Malcure Malware Shield doesn’t detect the infection.\u003C\u002Fh4>\n\u003Cp>Malware keeps evolving. If you come across malware that Malcure Malware Shield is not able to identify, you may \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=157&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>The scan gets stuck midway. What should I do?\u003C\u002Fh4>\n\u003Cp>In case of such an event, please file a support request with us and we’ll be more than happy to troubleshoot the issue.\u003C\u002Fp>\n\u003Cp>Please visit \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">this page\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I cleaned my site but it got infected again. What should I do?\u003C\u002Fh4>\n\u003Cp>Malware cleanup is a waste of time and effort unless you find the root cause behind the malware infection and monitor for recurrence. How was someone able to infect your website? Have you plugged in that security hole?\u003C\u002Fp>\n\u003Cp>Please read \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002Fblog\u002Fsecurity\u002Fwhy-do-wordpress-websites-get-hacked\u002F?utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Why Do Websites Get Hacked\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Google Safe Browsing site status (or some other scanner) still shows my site as infected. What should I do?\u003C\u002Fh4>\n\u003Cp>First make sure you purge your site cache. Second, Google (and other scanners) cache the results for some time. You’ll need to force or refresh the scan. You can also file a request with us to \u003Ca href=\"https:\u002F\u002Fwww.malcure.com\u002F?p=107&utm_source=readmefaq&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">get your site off any blacklists\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I found a suspicious file, what now?\u003C\u002Fh4>\n\u003Cp>If Malcure flags it, it’s likely malicious. You can inspect the file content using our built-in inspector. If you’re unsure, consider our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107&utm_source=readme&utm_medium=web&utm_campaign=wpmr\" rel=\"nofollow ugc\">Expert Malware Removal Service\u003C\u002Fa>.\u003C\u002Fp>\n","Fast malware removal & security shield. Fix hacks, stop redirects, clean SEO spam. Real-time threat intelligence. No bloat.",605372,88,69,"2026-02-13T05:45:00.000Z","3.7.4","5.6",[96,21,97,98,22],"antivirus","security","virus","https:\u002F\u002Fmalcure.com\u002F?p=116&utm_source=plugin-header&utm_medium=web&utm_campaign=wpmr","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-malware-removal.19.8.zip","2025-09-03 00:00:00",{"slug":103,"name":104,"version":105,"author":106,"author_profile":107,"description":108,"short_description":109,"active_installs":110,"downloaded":111,"rating":11,"num_ratings":11,"last_updated":112,"tested_up_to":113,"requires_at_least":114,"requires_php":17,"tags":115,"homepage":120,"download_link":121,"security_score":122,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"bravo-security","Bravo WP security Plugin","1.1","Technoyer","https:\u002F\u002Fprofiles.wordpress.org\u002Ftechnoyer\u002F","\u003Cp>Bravo WP Security Plugin, Is a plugin helps you to hide wordpress side by side Bravo wordpress firewall, wordpress antivirus (wordpress malware scanner),wordpress brute force protection, WP config security, wordpress google reCAPTCHA, error logs and more features. You can find more by visiting the next link\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fbravo.technoyer.com\" rel=\"nofollow ugc\">http:\u002F\u002Fbravo.technoyer.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>+35 WordPress Security Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hide WordPress\u003C\u002Fstrong>: Hide version from all scripts and styles call inside the pages source.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide wp-login.php\u003C\u002Fstrong>: Create new login link and a 404 error will appear to the default login link.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide wp-admin\u003C\u002Fstrong>: Only the login link can redirect you to the wp-admin dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prevent Proxy\u003C\u002Fstrong>: wp-admin Dashboard will allow real connections only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allow Custom Connections\u003C\u002Fstrong>: wp-admin Dashboard will allow some whitelist countries or\u002Fand IPs only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Firewall\u003C\u002Fstrong>: ‘Firewall profiles’ is advanced option, You are able to choose High, Medium or Low Level of security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>2-Step Verification\u003C\u002Fstrong>:  You are able to choose from many options when you decide to enable 2-Step Verification. Available options: Two factor authentication, Facebook Verification, Four numbers pin code and Security question.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>reCAPTCHA\u003C\u002Fstrong>: reCAPTCHA is important to save your host resources and your WordPress safe from spam, You can add it to guest comments, login, register or\u002Fand reset password forms.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Housekeeping\u003C\u002Fstrong>: Clean your WordPress, Just delete unused files, comments, revisions, trashes, transient feed or\u002Fand relationships.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Backups\u003C\u002Fstrong>: Manually or Scheduling Database backups, both options are available.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Antivirus\u003C\u002Fstrong>: Malware scanner, PHPMussel scanner, File Change Detection, Google Safe Browsing Checker, DB scanner and Spam Lisiting checker.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto Scan Attachments\u003C\u002Fstrong>: Attachments will be scanned while it is being uploading.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan New Plugins & Themes\u003C\u002Fstrong>: After you activate your new plugin or theme, Bravo will create a new antivirus process to scan the new files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute Force Protection\u003C\u002Fstrong>: The complete security for your and users’ passwords by activating Bravo brute force protection options.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blacklist Usernames\u003C\u002Fstrong>: Prevent some usernames from register or log in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blacklist email provider\u003C\u002Fstrong>: Prevent some email hosting from register like e.g: mail.ru.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Min & Max Usernames Length\u003C\u002Fstrong>: Minimum and Maximum chars for registered usernames.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Moderate New Members\u003C\u002Fstrong>: New members will be need admin approval before they can use their dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accounts Protection\u003C\u002Fstrong>: You are able to define the login method (email only or username only or both as default), No weak passwords, Maximum Login Attempts and Whitelist IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Who is Online (Live Tracker)\u003C\u002Fstrong>: Watch your online visitors and what are they doing?!, You will be able to see all their browsing details and block\u002Funblock Ips.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Inline Visitors Blocking\u003C\u002Fstrong>: Watch your visitors activity using the traffic tracker module and you can block and IP or country when you see unusual activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cronjobs (Events Schedules)\u003C\u002Fstrong>: You have full control to set what is the appropriate time to run your events.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DB Prefix Wizard\u003C\u002Fstrong>: A wizard was designed to change WP database prefix.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Development & Maintenance Mode\u003C\u002Fstrong>: There two modes in order to close your site, Development mode will allow some roles to view site as usual as they know it, but Maintenance mode will close site for all.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bandwidth Saver\u003C\u002Fstrong>: Bravo lets you prevent ‘Hotlinking & iFrames’, Your hosted images will not show at other websites, and your website will be not shown in iframe.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Self Protection\u003C\u002Fstrong>: You can set password and choose some management roles to give them ability to manage Bravo.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Idle Logout\u003C\u002Fstrong>: The plugin will clear the current sessions for logged in users if they hold their accounts without using after (n) seconds, you will choose the duration before forcing them to log in again.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mail Watching\u003C\u002Fstrong>: This tool designed for watching outbound email messages in WordPress. It can help if someone using backdoor in your blog to send spam emails.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Error Pages\u003C\u002Fstrong>: Continuing our efforts to hide WordPress, We designed this tool to use our 404 templates instead of your theme 404 pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Log Watching\u003C\u002Fstrong>: If you set the firewall to ‘High’ and disable WordPress debug, You can watch the error log using or tool.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Pro Version\u003C\u002Fh3>\n\u003Cp>To unlock the Pro features please get the premium version \u003Ca href=\"http:\u002F\u002Fbravo.technoyer.com\u002Fpro.php\" rel=\"nofollow ugc\">click here\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Documentation\u003C\u002Fh3>\n\u003Cp>Full documentation is available \u003Ca href=\"http:\u002F\u002Fbravo.technoyer.com\u002Fwiki\u002Findex\" rel=\"nofollow ugc\">here\u003C\u002Fa>.\u003C\u002Fp>\n","Bravo WP Security Plugin, Is a plugin helps you to hide wordpress side by side Bravo wordpress firewall, wordpress antivirus (wordpress malware scanne &hellip;",10,1898,"2017-12-11T06:22:00.000Z","4.9.29","4.7",[116,117,55,118,119],"best-wordpress-security-plugin","wordpress-malware-removal","wordpress-vulnerability-scanner","wp-security","http:\u002F\u002Fbravo-security.technoyer.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbravo-security.1.1.zip",85,{"slug":124,"name":125,"version":126,"author":127,"author_profile":128,"description":129,"short_description":130,"active_installs":11,"downloaded":131,"rating":11,"num_ratings":11,"last_updated":17,"tested_up_to":16,"requires_at_least":132,"requires_php":133,"tags":134,"homepage":138,"download_link":139,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":140},"content-guard-pro","Content Guard Pro – Database Malware Scanner & Spam Detector","1.0.6","contentguardpro","https:\u002F\u002Fprofiles.wordpress.org\u002Fcontentguardpro\u002F","\u003Cp>Your file scanner says “all clear” — but Google just flagged your site for spam.\u003C\u002Fp>\n\u003Cp>Attackers don’t always hide in files. They inject spam links directly into your Gutenberg blocks, bury SEO poison in postmeta, and hide obfuscated scripts in custom fields. \u003Cstrong>Traditional security plugins don’t scan there. Content Guard Pro does.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Content Guard Pro is a database-first malware scanner that finds hidden threats in your WordPress content — the blind spot in your current security stack.\u003C\u002Fp>\n\u003Ch4>The Gap in Your WordPress Security\u003C\u002Fh4>\n\u003Cp>Most security plugins scan files. That’s essential — but it’s only half the picture.\u003C\u002Fp>\n\u003Cp>Malware and spam increasingly bypass file scanners by injecting directly into your database:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Post content\u003C\u002Fstrong> — Hidden pharma links and casino spam inside nested Gutenberg blocks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom fields (postmeta)\u003C\u002Fstrong> — SEO spam and malicious redirects buried in metadata\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widget areas\u003C\u002Fstrong> — Injected scripts that survive every file scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Options table\u003C\u002Fstrong> — Persistent backdoors and cloaked content\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you’ve ever cleaned a hacked site only to have Google flag it again weeks later, database-resident threats are likely the reason. Content Guard Pro finds them.\u003C\u002Fp>\n\u003Ch4>How Content Guard Pro Protects Your Site\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Find what other security plugins miss.\u003C\u002Fstrong> Content Guard Pro scans your posts, pages, custom post types, and metadata — the places where WordPress actually stores your content.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Know exactly what to fix first.\u003C\u002Fstrong> Every finding gets a confidence score from 0 to 100 and a severity level (Critical, Suspicious, or Review). No guesswork, no alert fatigue.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scan without slowing down your site.\u003C\u002Fstrong> Background batch processing with auto-throttling means scans run smoothly even on shared hosting. Your visitors never notice.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Keep false positives low.\u003C\u002Fstrong> Accessibility-aware detection respects screen reader classes. Configurable allowlists let you whitelist trusted domains and patterns.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Maintain a complete audit trail.\u003C\u002Fstrong> Every scan, every finding, every action — tracked and timestamped for forensics and compliance.\u003C\u002Fp>\n\u003Ch4>What the Malware Scanner Detects\u003C\u002Fh4>\n\u003Cp>Content Guard Pro catches a wide range of database-resident threats:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hidden spam links\u003C\u002Fstrong> — Cloaked content using \u003Ccode>display:none\u003C\u002Fcode>, \u003Ccode>visibility:hidden\u003C\u002Fcode>, \u003Ccode>opacity:0\u003C\u002Fcode>, \u003Ccode>font-size:0\u003C\u002Fcode>, and other CSS tricks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suspicious external resources\u003C\u002Fstrong> — Unknown \u003Ccode>\u003Ciframe>\u003C\u002Fcode> and \u003Ccode>\u003Cscript>\u003C\u002Fcode> tags loading remote content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO spam injections\u003C\u002Fstrong> — Pharma, casino, crypto, and gambling keyword stuffing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>URL shorteners and redirectors\u003C\u002Fstrong> — bit.ly, t.co, cutt.ly, and other redirect services hiding malicious destinations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Obfuscated JavaScript\u003C\u002Fstrong> — \u003Ccode>eval()\u003C\u002Fcode>, \u003Ccode>fromCharCode()\u003C\u002Fcode>, Base64-encoded scripts, and \u003Ccode>data:\u003C\u002Fcode> URIs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Serialized PHP malware\u003C\u002Fstrong> — Threats hidden inside PHP arrays in postmeta, options, and page builder data\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cryptocurrency miners\u003C\u002Fstrong> — Coinhive, CryptoLoot, JSEcoin, and similar scripts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-layer encoded attacks\u003C\u002Fstrong> — Automatically peels back up to 3 layers of obfuscation: Base64 \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> URL encoding \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> ROT13 \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> hex \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> octal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Works Alongside Your Existing Security Plugins\u003C\u002Fh4>\n\u003Cp>Content Guard Pro is designed to \u003Cstrong>complement\u003C\u002Fstrong> file-based security, not replace it.\u003C\u002Fp>\n\u003Cp>Already using Wordfence, Sucuri, iThemes Security, All-In-One Security, or MalCare? Great — those tools protect your files. Content Guard Pro covers the database layer they don’t scan. Together, you get complete WordPress security coverage.\u003C\u002Fp>\n\u003Ch4>Built for WordPress Professionals\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies managing client sites\u003C\u002Fstrong> — Find database threats before clients or Google discover them. Use findings to demonstrate the value of your security retainer.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers and consultants\u003C\u002Fstrong> — Add content-layer scanning to your cleanup and maintenance workflow. Catch what file scanners leave behind.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>E-commerce site owners\u003C\u002Fstrong> — Protect product descriptions and category pages from SEO spam that damages your search rankings and revenue.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security professionals\u003C\u002Fstrong> — Fill the database gap in your security stack with specialized content-layer analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Gutenberg Block Editor Security\u003C\u002Fh4>\n\u003Cp>WordPress stores content as nested blocks — and attackers exploit this. Content Guard Pro includes a recursive Gutenberg block parser that inspects every layer of nested blocks, including reusable blocks and block patterns. It also scans content in the Classic Editor with a dedicated meta box for findings.\u003C\u002Fp>\n\u003Ch4>Serialized Data Inspector\u003C\u002Fh4>\n\u003Cp>Page builders like Elementor, Beaver Builder, and Divi store data as serialized PHP arrays. Content Guard Pro safely unserializes and recursively inspects these structures up to 10 levels deep, detecting malware hidden in keys like \u003Ccode>custom_css\u003C\u002Fcode>, \u003Ccode>custom_js\u003C\u002Fcode>, \u003Ccode>callback\u003C\u002Fcode>, \u003Ccode>raw_html\u003C\u002Fcode>, and more.\u003C\u002Fp>\n\u003Ch4>Performance You Can Trust\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Scans approximately 100 posts in 30–60 seconds on shared hosting\u003C\u002Fli>\n\u003Cli>Auto-throttling prevents timeouts and resource exhaustion\u003C\u002Fli>\n\u003Cli>Resumable scans survive server restarts\u003C\u002Fli>\n\u003Cli>Safe Mode activates automatically for large sites (over 2 million rows)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Developer-Friendly\u003C\u002Fh4>\n\u003Cp>Content Guard Pro provides hooks and filters for customization:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>content_guard_pro_loaded\u003C\u002Fcode> — Plugin initialization\u003C\u002Fli>\n\u003Cli>\u003Ccode>content_guard_pro_finding_saved\u003C\u002Fcode> — After a finding is stored\u003C\u002Fli>\n\u003Cli>\u003Ccode>content_guard_pro_detection_patterns\u003C\u002Fcode> — Modify or add detection rules\u003C\u002Fli>\n\u003Cli>\u003Ccode>content_guard_pro_allowlist_domains\u003C\u002Fcode> — Programmatic domain allowlisting\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>REST API available at \u003Ccode>\u002Fwp-json\u002Fcontent-guard-pro\u002Fv1\u002Ffindings\u003C\u002Fcode> for programmatic access (Premium Agency+ tiers).\u003C\u002Fp>\n\u003Ch4>External Services & Privacy\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>API Connection:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin connects to Content Guard Pro API (api.contentguardpro.com) for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Free tier activation tracking (site URL, WP version, PHP version, plugin version)\u003C\u002Fli>\n\u003Cli>License validation when a paid license key is entered\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What is sent:\u003C\u002Fstrong> Site URL, site name, WordPress version, PHP version, plugin version, and admin email (free tier only). Sent once on activation via asynchronous, non-blocking request.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong> All data sent over HTTPS. No post content or scan data is ever transmitted. All scanning happens locally on your server.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service provider:\u003C\u002Fstrong> Content Guard Pro Team\u003Cbr \u002F>\n\u003Cstrong>Terms:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fcontentguardpro.com\u002Fterms\" rel=\"nofollow ugc\">https:\u002F\u002Fcontentguardpro.com\u002Fterms\u003C\u002Fa>\u003Cbr \u002F>\n\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fcontentguardpro.com\u002Fprivacy\" rel=\"nofollow ugc\">https:\u002F\u002Fcontentguardpro.com\u002Fprivacy\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Documentation & Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Documentation:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fcontentguardpro.com\u002Fdocs\" rel=\"nofollow ugc\">https:\u002F\u002Fcontentguardpro.com\u002Fdocs\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Support Forum:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fcontent-guard-pro\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fcontent-guard-pro\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bug Reports:\u003C\u002Fstrong> WordPress.org support forum\u003C\u002Fli>\n\u003C\u002Ful>\n","Scan your WordPress database for hidden malware, spam links, and SEO injections that file-based security plugins miss. Gutenberg-aware.",233,"6.1","8.0",[135,20,21,136,137],"database-security","security-scanner","spam-detection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontent-guard-pro","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcontent-guard-pro.1.0.6.zip","2026-03-15T10:48:56.248Z",{"attackSurface":142,"codeSignals":382,"taintFlows":521,"riskAssessment":548,"analyzedAt":553},{"hooks":143,"ajaxHandlers":303,"restRoutes":379,"shortcodes":380,"cronEvents":381,"entryPointCount":329,"unprotectedCount":14},[144,150,154,158,162,168,172,176,180,182,187,191,195,198,201,205,207,209,214,218,223,226,227,232,236,239,242,245,248,251,254,256,258,260,263,265,269,272,274,277,280,284,287,291,294,297,299],{"type":145,"name":146,"callback":147,"file":148,"line":149},"action","admin_menu","addAdminMenu","includes\\Admin\\Admin.php",27,{"type":145,"name":151,"callback":152,"file":148,"line":153},"admin_notices","renderApprovalsNotice",28,{"type":145,"name":155,"callback":156,"file":148,"line":157},"admin_enqueue_scripts","enqueueAssets",31,{"type":145,"name":159,"callback":160,"priority":14,"file":161,"line":31},"init","maybeBlockSuspiciousRequest","includes\\MuFirewall\\Runtime.php",{"type":163,"name":164,"callback":165,"priority":166,"file":161,"line":167},"filter","authenticate","maybeBlockLockedLogin",99,42,{"type":145,"name":169,"callback":170,"priority":110,"file":161,"line":171},"wp_login_failed","handleLoginFailed",43,{"type":145,"name":173,"callback":174,"priority":110,"file":161,"line":175},"wp_login","handleLoginSuccess",44,{"type":163,"name":177,"callback":178,"file":179,"line":171},"cron_schedules","registerCronSchedules","includes\\Plugin.php",{"type":163,"name":177,"callback":178,"file":179,"line":181},64,{"type":145,"name":183,"callback":184,"file":185,"line":186},"login_enqueue_scripts","enqueueLoginScripts","includes\\Services\\CaptchaService.php",24,{"type":145,"name":188,"callback":189,"file":185,"line":190},"wp_enqueue_scripts","enqueueFrontendScripts",25,{"type":145,"name":192,"callback":193,"file":185,"line":194},"login_form","renderLoginWidget",26,{"type":145,"name":196,"callback":197,"file":185,"line":149},"register_form","renderRegisterWidget",{"type":145,"name":199,"callback":200,"file":185,"line":153},"lostpassword_form","renderLostPasswordWidget",{"type":145,"name":202,"callback":203,"file":185,"line":204},"comment_form_after_fields","renderCommentWidget",29,{"type":145,"name":206,"callback":203,"file":185,"line":33},"comment_form_logged_in_after",{"type":163,"name":164,"callback":208,"priority":31,"file":185,"line":157},"verifyLoginCaptcha",{"type":163,"name":210,"callback":211,"priority":212,"file":185,"line":213},"registration_errors","verifyRegistrationCaptcha",20,32,{"type":145,"name":215,"callback":216,"priority":110,"file":185,"line":217},"lostpassword_post","verifyLostPasswordCaptcha",33,{"type":163,"name":219,"callback":220,"priority":221,"file":185,"line":222},"pre_comment_approved","verifyCommentCaptcha",8,34,{"type":145,"name":202,"callback":224,"file":225,"line":217},"renderCommentFormFields","includes\\Services\\CommentSpamService.php",{"type":145,"name":206,"callback":224,"file":225,"line":222},{"type":163,"name":228,"callback":229,"priority":230,"file":225,"line":231},"preprocess_comment","captureCommentDecision",9,35,{"type":163,"name":233,"callback":234,"priority":110,"file":225,"line":235},"rest_preprocess_comment","captureRestCommentDecision",36,{"type":163,"name":219,"callback":237,"priority":110,"file":225,"line":238},"applyCommentDecision",37,{"type":145,"name":159,"callback":240,"priority":11,"file":241,"line":149},"interceptRequests","includes\\Services\\LoginAccessService.php",{"type":145,"name":243,"callback":244,"priority":11,"file":241,"line":153},"wp_loaded","maybeRenderCustomLogin",{"type":163,"name":246,"callback":247,"priority":110,"file":241,"line":204},"site_url","filterSiteUrl",{"type":163,"name":249,"callback":250,"priority":110,"file":241,"line":33},"network_site_url","filterNetworkSiteUrl",{"type":163,"name":252,"callback":253,"priority":110,"file":241,"line":157},"login_url","replaceGeneratedLoginUrl",{"type":163,"name":255,"callback":253,"priority":110,"file":241,"line":213},"logout_url",{"type":163,"name":257,"callback":253,"priority":110,"file":241,"line":217},"lostpassword_url",{"type":163,"name":259,"callback":253,"file":241,"line":222},"register_url",{"type":163,"name":261,"callback":262,"file":241,"line":231},"lostpassword_redirect","filterLostPasswordRedirect",{"type":163,"name":264,"callback":253,"priority":110,"file":241,"line":235},"wp_redirect",{"type":163,"name":164,"callback":266,"priority":267,"file":268,"line":222},"maybeStartTwoFactorChallenge",60,"includes\\Services\\LoginSecurityService.php",{"type":145,"name":270,"callback":271,"file":268,"line":231},"login_form_vulntitan_2fa","renderTwoFactorChallenge",{"type":145,"name":155,"callback":273,"file":268,"line":235},"enqueueProfileAssets",{"type":145,"name":275,"callback":276,"file":268,"line":238},"admin_init","enforceTwoFactorEnrollment",{"type":145,"name":151,"callback":278,"file":268,"line":279},"renderEnrollmentNotice",38,{"type":145,"name":281,"callback":282,"file":268,"line":283},"show_user_profile","renderProfileSection",39,{"type":145,"name":285,"callback":286,"file":268,"line":31},"personal_options_update","handlePendingProfileEnrollment",{"type":145,"name":288,"callback":289,"priority":110,"file":268,"line":290},"profile_update","saveProfileSection",41,{"type":145,"name":292,"callback":293,"priority":110,"file":268,"line":167},"user_profile_update_errors","validateProfilePassword",{"type":145,"name":295,"callback":296,"priority":110,"file":268,"line":171},"validate_password_reset","validatePasswordReset",{"type":163,"name":210,"callback":298,"priority":212,"file":268,"line":175},"validateRegistrationPassword",{"type":145,"name":300,"callback":301,"file":302,"line":167},"plugins_loaded","closure","vulntitan.php",[304,310,315,319,322,326,330,334,337,340,343,346,349,352,355,358,361,364,367,370,373,376],{"action":305,"nopriv":306,"callback":307,"hasNonce":306,"hasCapCheck":306,"file":308,"line":309},"vulntitan_vulnerability_scan_item",false,"vulnerabilityScan","includes\\Admin\\Ajax.php",17,{"action":311,"nopriv":306,"callback":312,"hasNonce":313,"hasCapCheck":313,"file":308,"line":314},"vulntitan_vulnerability_rescan_item","vulnerabilityRescan",true,18,{"action":316,"nopriv":306,"callback":317,"hasNonce":313,"hasCapCheck":313,"file":308,"line":318},"vulntitan_vuln_risk_update","vulnRiskUpdate",19,{"action":320,"nopriv":306,"callback":321,"hasNonce":313,"hasCapCheck":313,"file":308,"line":212},"vulntitan_vuln_risk_clear","vulnRiskClear",{"action":323,"nopriv":306,"callback":324,"hasNonce":313,"hasCapCheck":313,"file":308,"line":325},"vulntitan_vuln_risk_audit","vulnRiskAudit",21,{"action":327,"nopriv":306,"callback":328,"hasNonce":313,"hasCapCheck":313,"file":308,"line":329},"vulntitan_malware_scan_init","malwareScanInit",22,{"action":331,"nopriv":306,"callback":332,"hasNonce":313,"hasCapCheck":313,"file":308,"line":333},"vulntitan_malware_scan_file","malwareScanFile",23,{"action":335,"nopriv":306,"callback":336,"hasNonce":313,"hasCapCheck":313,"file":308,"line":186},"vulntitan_malware_scan_batch","malwareScanBatch",{"action":338,"nopriv":306,"callback":339,"hasNonce":313,"hasCapCheck":313,"file":308,"line":190},"vulntitan_malware_fix_finding","malwareFixFinding",{"action":341,"nopriv":306,"callback":342,"hasNonce":313,"hasCapCheck":313,"file":308,"line":194},"vulntitan_integrity_scan_init","integrityScanInit",{"action":344,"nopriv":306,"callback":345,"hasNonce":313,"hasCapCheck":313,"file":308,"line":149},"vulntitan_integrity_scan_file","integrityScanFile",{"action":347,"nopriv":306,"callback":348,"hasNonce":313,"hasCapCheck":313,"file":308,"line":153},"vulntitan_integrity_scan_batch","integrityScanBatch",{"action":350,"nopriv":306,"callback":351,"hasNonce":313,"hasCapCheck":313,"file":308,"line":204},"vulntitan_firewall_get_data","firewallGetData",{"action":353,"nopriv":306,"callback":354,"hasNonce":313,"hasCapCheck":313,"file":308,"line":33},"vulntitan_firewall_save_settings","firewallSaveSettings",{"action":356,"nopriv":306,"callback":357,"hasNonce":313,"hasCapCheck":313,"file":308,"line":157},"vulntitan_firewall_clear_logs","firewallClearLogs",{"action":359,"nopriv":306,"callback":360,"hasNonce":313,"hasCapCheck":313,"file":308,"line":213},"vulntitan_firewall_approve_request","firewallApproveRequest",{"action":362,"nopriv":306,"callback":363,"hasNonce":313,"hasCapCheck":313,"file":308,"line":217},"vulntitan_firewall_dismiss_approval","firewallDismissApproval",{"action":365,"nopriv":306,"callback":366,"hasNonce":313,"hasCapCheck":313,"file":308,"line":222},"vulntitan_firewall_unblock_ip","firewallUnblockIp",{"action":368,"nopriv":306,"callback":369,"hasNonce":313,"hasCapCheck":313,"file":308,"line":231},"vulntitan_firewall_allowlist_ip","firewallAllowlistIp",{"action":371,"nopriv":306,"callback":372,"hasNonce":313,"hasCapCheck":313,"file":308,"line":235},"vulntitan_firewall_get_learning","firewallGetLearning",{"action":374,"nopriv":306,"callback":375,"hasNonce":313,"hasCapCheck":313,"file":308,"line":238},"vulntitan_firewall_apply_learning","firewallApplyLearning",{"action":377,"nopriv":306,"callback":378,"hasNonce":313,"hasCapCheck":313,"file":308,"line":279},"vulntitan_firewall_dismiss_learning","firewallDismissLearning",[],[],[],{"dangerousFunctions":383,"sqlUsage":384,"outputEscaping":400,"fileOperations":325,"externalRequests":79,"nonceChecks":190,"capabilityChecks":204,"bundledLibraries":520},[],{"prepared":31,"raw":30,"locations":385},[386,390,393,397],{"file":387,"line":388,"context":389},"includes\\Services\\FirewallService.php",501,"$wpdb->get_results() with variable interpolation",{"file":387,"line":391,"context":392},999,"$wpdb->query() with variable interpolation",{"file":394,"line":395,"context":396},"includes\\Services\\VulnerabilityRiskService.php",390,"$wpdb->get_var() with variable interpolation",{"file":394,"line":398,"context":399},419,"$wpdb->get_col() with variable interpolation",{"escaped":401,"rawEcho":402,"locations":403},139,57,[404,407,410,412,415,417,419,421,423,425,427,429,431,433,435,437,439,441,443,445,447,449,451,453,455,457,459,461,463,465,467,469,471,473,475,477,478,480,482,484,486,488,490,492,494,496,498,500,502,504,506,508,510,512,514,516,518],{"file":148,"line":405,"context":406},563,"raw output",{"file":408,"line":409,"context":406},"includes\\Admin\\Pages\\Firewall.php",148,{"file":408,"line":411,"context":406},159,{"file":413,"line":414,"context":406},"includes\\Admin\\Pages\\LiveFeed.php",61,{"file":225,"line":416,"context":406},52,{"file":268,"line":418,"context":406},255,{"file":268,"line":420,"context":406},281,{"file":268,"line":422,"context":406},285,{"file":268,"line":424,"context":406},290,{"file":268,"line":426,"context":406},329,{"file":268,"line":428,"context":406},331,{"file":268,"line":430,"context":406},339,{"file":268,"line":432,"context":406},340,{"file":268,"line":434,"context":406},345,{"file":268,"line":436,"context":406},346,{"file":268,"line":438,"context":406},347,{"file":268,"line":440,"context":406},348,{"file":268,"line":442,"context":406},352,{"file":268,"line":444,"context":406},353,{"file":268,"line":446,"context":406},355,{"file":268,"line":448,"context":406},356,{"file":268,"line":450,"context":406},358,{"file":268,"line":452,"context":406},362,{"file":268,"line":454,"context":406},363,{"file":268,"line":456,"context":406},364,{"file":268,"line":458,"context":406},368,{"file":268,"line":460,"context":406},370,{"file":268,"line":462,"context":406},374,{"file":268,"line":464,"context":406},375,{"file":268,"line":466,"context":406},376,{"file":268,"line":468,"context":406},377,{"file":268,"line":470,"context":406},382,{"file":268,"line":472,"context":406},384,{"file":268,"line":474,"context":406},386,{"file":268,"line":476,"context":406},388,{"file":268,"line":395,"context":406},{"file":268,"line":479,"context":406},391,{"file":268,"line":481,"context":406},392,{"file":268,"line":483,"context":406},401,{"file":268,"line":485,"context":406},403,{"file":268,"line":487,"context":406},404,{"file":268,"line":489,"context":406},406,{"file":268,"line":491,"context":406},411,{"file":268,"line":493,"context":406},415,{"file":268,"line":495,"context":406},423,{"file":268,"line":497,"context":406},428,{"file":268,"line":499,"context":406},430,{"file":268,"line":501,"context":406},434,{"file":268,"line":503,"context":406},436,{"file":268,"line":505,"context":406},437,{"file":268,"line":507,"context":406},439,{"file":268,"line":509,"context":406},637,{"file":268,"line":511,"context":406},652,{"file":268,"line":513,"context":406},655,{"file":268,"line":515,"context":406},657,{"file":268,"line":517,"context":406},670,{"file":268,"line":519,"context":406},672,[],[522,540],{"entryPoint":523,"graph":524,"unsanitizedCount":11,"severity":539},"malwareFixFinding (includes\\Admin\\Ajax.php:729)",{"nodes":525,"edges":537},[526,531],{"id":527,"type":528,"label":529,"file":308,"line":530},"n0","source","$_POST (x2)",737,{"id":532,"type":533,"label":534,"file":308,"line":535,"wp_function":536},"n1","sink","file_put_contents() [File Write]",808,"file_put_contents",[538],{"from":527,"to":532,"sanitized":313},"low",{"entryPoint":541,"graph":542,"unsanitizedCount":11,"severity":539},"\u003CAjax> (includes\\Admin\\Ajax.php:0)",{"nodes":543,"edges":546},[544,545],{"id":527,"type":528,"label":529,"file":308,"line":530},{"id":532,"type":533,"label":534,"file":308,"line":535,"wp_function":536},[547],{"from":527,"to":532,"sanitized":313},{"summary":549,"deductions":550},"The \"vulntitan\" v2.1.12 plugin exhibits a generally positive security posture, characterized by robust use of prepared statements for SQL queries and a high percentage of properly escaped outputs. The absence of known CVEs and vulnerability history further suggests a commitment to security by the developers. The static analysis also shows good practices like a significant number of nonce and capability checks, and no indication of critical or high severity taint flows.\n\nHowever, a notable concern arises from the presence of 22 AJAX handlers, with one handler lacking any authentication checks. This unprotected entry point represents a potential avenue for unauthorized actions if an attacker can trigger it. While no dangerous functions were identified and external HTTP requests are limited, the single unprotected AJAX handler is a significant weakness that could be exploited. The file operations count is also moderately high, which warrants careful review in conjunction with the unprotected AJAX handler.\n\nIn conclusion, \"vulntitan\" v2.1.12 has many strengths, particularly in its handling of data and output. The lack of historical vulnerabilities is reassuring. The primary weakness lies in the single unprotected AJAX endpoint, which, despite the plugin's otherwise solid foundation, presents a clear and actionable security risk that needs immediate attention.",[551],{"reason":552,"points":221},"Unprotected AJAX handler","2026-03-17T06:25:13.036Z",{"wat":555,"direct":568},{"assetPaths":556,"generatorPatterns":561,"scriptPaths":562,"versionParams":563},[557,558,559,560],"\u002Fwp-content\u002Fplugins\u002Fvulntitan\u002Fbuild\u002Fcss\u002Fvendors.css","\u002Fwp-content\u002Fplugins\u002Fvulntitan\u002Fbuild\u002Fcss\u002Fmain.css","\u002Fwp-content\u002Fplugins\u002Fvulntitan\u002Fbuild\u002Fjs\u002Fvendors.js","\u002Fwp-content\u002Fplugins\u002Fvulntitan\u002Fbuild\u002Fjs\u002Fmain.js",[],[559,560],[564,565,566,567],"vulntitan\u002Fbuild\u002Fcss\u002Fvendors.css?ver=","vulntitan\u002Fbuild\u002Fcss\u002Fmain.css?ver=","vulntitan\u002Fbuild\u002Fjs\u002Fvendors.js?ver=","vulntitan\u002Fbuild\u002Fjs\u002Fmain.js?ver=",{"cssClasses":569,"htmlComments":591,"htmlAttributes":608,"restEndpoints":613,"jsGlobals":620,"shortcodeOutput":625},[570,571,572,573,574,575,576,577,578,579,580,581,582,583,584,585,586,587,588,589,590],"vulntitan-admin-settings-page","vt-firewall-settings","vt-firewall-logs-table","vt-firewall-rules-list","vt-firewall-settings-section","vt-firewall-setting-row","vt-firewall-input-field","vt-firewall-textarea","vt-firewall-button","vt-firewall-notice","vt-firewall-log-entry","vt-firewall-log-details","vt-firewall-ip-allowlist","vt-firewall-ip-blocklist","vt-firewall-login-protection-settings","vt-firewall-waf-settings","vt-firewall-captcha-settings","vt-firewall-comment-shield-settings","vt-firewall-xmlrpc-settings","vt-firewall-learning-mode-settings","vt-firewall-weekly-summary-settings",[592,593,594,595,596,597,598,599,600,601,602,603,604,605,606,607],"\u003C!-- VulnTitan Firewall Settings -->","\u003C!-- VulnTitan Firewall Logs -->","\u003C!-- VulnTitan Firewall Rules -->","\u003C!-- VulnTitan Firewall Options -->","\u003C!-- VulnTitan Firewall Admin Notice -->","\u003C!-- VulnTitan Firewall Log Entry -->","\u003C!-- VulnTitan Firewall IP Allowlist -->","\u003C!-- VulnTitan Firewall IP Blocklist -->","\u003C!-- VulnTitan Firewall Login Protection -->","\u003C!-- VulnTitan Firewall WAF Settings -->","\u003C!-- VulnTitan Firewall CAPTCHA Settings -->","\u003C!-- VulnTitan Firewall Comment Shield -->","\u003C!-- VulnTitan Firewall XMLRPC Settings -->","\u003C!-- VulnTitan Firewall Learning Mode -->","\u003C!-- VulnTitan Firewall Weekly Summary -->","\u003C!-- VulnTitan Firewall End Settings -->",[609,610,611,612],"data-vulntitan-firewall-settings","data-vt-firewall-log-id","data-vt-firewall-ip","data-vt-firewall-action",[614,615,616,617,618,619],"\u002Fwp-json\u002Fvulntitan\u002Fv1\u002Ffirewall\u002Fsettings","\u002Fwp-json\u002Fvulntitan\u002Fv1\u002Ffirewall\u002Flogs","\u002Fwp-json\u002Fvulntitan\u002Fv1\u002Ffirewall\u002Frules","\u002Fwp-json\u002Fvulntitan\u002Fv1\u002Ffirewall\u002Fallowlist","\u002Fwp-json\u002Fvulntitan\u002Fv1\u002Ffirewall\u002Fblocklist","\u002Fwp-json\u002Fvulntitan\u002Fv1\u002Ffirewall\u002Faction",[621,622,623,624],"vulntitanFirewallSettings","vulntitanFirewallData","vtFirewall","vtFirewallAdmin",[]]