Search by

devdome / devdome-malware-scanner

devdome88

Free WordPress malware scanner, virus scanner and malware removal. Backdoor detection, quarantine, trusted repair. Free alternative to Wordfence, Sucuri and MalCare.

Package info

github.com/DevDomeFamily/devdome-malware-scanner

Homepage

Type:wordpress-plugin

pkg:composer/devdome/devdome-malware-scanner

Statistics

Installs: 0

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

1.3.5 2026-09-23 11:01 UTC

This package is auto-updated.

Last update: 2026-09-24 22:37:32 UTC


README

WordPress Plugin Version Active Installs Rating Tested WP License GPL-2.0+

Scan for backdoor and webshell patterns. Review findings, quarantine files and repair eligible WordPress core and official plugin packages. This free WordPress malware scanner checks files, database content and reinfection risks without an account. Use it as a virus scanner for a manual virus scan or scheduled antimalware checks.

The free alternative to Wordfence, Sucuri and MalCare for scanning and removing malware in WordPress.

DevDome Malware Scanner, free WordPress malware scanner and malware removal

Why DevDome Malware Scanner instead of the alternatives

DevDome Malware Scanner Wordfence Sucuri MalCare Solid Security (iThemes) NinjaScanner GOTMLS Anti-Malware
Price Free Premium from $149 / year Platform from $199.99 / year from $99 / year Pro from $99 / year Scheduled scans from $19.50 / year Donation $29+ for definitions
Malware scan of files and database Yes Yes Server-side scan is paid Yes, on their cloud Basic Files Files
Malware removal for free Yes, quarantine and trusted repair Premium (Care plan) Paid Paid Partial No Free tier limited
Core, plugin and theme integrity against WordPress.org Yes Yes Core only Yes Core only Yes Core only
Backdoor and reinfection checks (rogue admins, cron, MU plugins, drop-ins) Yes, own tab with Neutralize Partial Partial Partial Partial No No
Quarantine with one-click restore (restorable database copies) Yes No No No No Quarantine Auto delete
Severity and confidence shown separately Yes No No No No No No
Scan runs on your own server, no account required Yes Yes Plugin yes, scan no No, cloud Yes Yes Yes
Scheduled scans free Yes Yes Paid Paid Yes Paid Yes

Prices reflect published plans in September 2026. Quarantine preserves a restorable copy; permanent deletion is a separate action.

What it finds: a security scan of files and data

Use the security scanner for a website security review or recurring security check:

  • Malware, malicious code, backdoors and web shells.
  • Modified core, plugin and theme files; suspicious PHP in uploads.
  • Database injections, scripts, iframes, encoded payloads, seo spam and hidden links in options, posts, revisions and meta.
  • Rogue administrators, malicious WP-Cron tasks and cron beacons.
  • Planted must-use plugins and drop-ins that could enable reinfection.
  • Suspicious changes to wp-config.php, .htaccess and .user.ini.

For a website hacked through injected content, these checks help investigate a pharma hack, japanese keyword hack or redirect hack involving malicious redirects. Findings need review; a changed file alone does not prove infection.

Features

Malware detection and integrity check

The malware checker separates severity from confidence. Known-signature matches have 100% confidence; an entropy blob alone is a signal. Coverage gaps remain visible, supporting an evidence-based security audit.

An integrity check uses official core and plugin checksums and official theme packages. Premium and custom code use a baseline and change timeline; the baseline does not certify safety.

Malware removal, virus removal and quarantine

The malware cleaner helps remove malware through One click fix for eligible findings:

  • Quarantine known malware and eligible suspicious files.
  • Reinstall eligible core or official plugins at the installed version, backing up every affected file first.
  • Verify repaired packages against official checksums, then rescan to review remaining findings.

Quarantine stores non-executable database copies, compressed when available, with one-click restore. Protected startup files and official core files cannot be quarantined. Uncertain findings stay under Needs your decision.

Hack cleanup and reinfection risks

After a hack, review the Reinfection risks tab. Neutralize can demote rogue administrators, remove suspicious scheduled events or quarantine planted files. Account roles and quarantined files can be restored; removed tasks cannot be restored through the plugin.

Optional vulnerability scanner

Enable the vulnerability scanner in Settings to compare installed core, plugin and theme versions against WPVulnerability records for known vulnerabilities. It is off by default and does not attempt exploits.

Scheduled malware scan and account options

  • Daily or weekly scans: short batches, WP-Cron fallback, pause, resume and cancel.
  • Local anti malware checks: scanning engines run on your server without an account; official verification contacts WordPress.org.
  • Optional free account: 90,000+ known-malware signatures, hash lookups sending hashes only, downloaded signatures, a multi-site site security dashboard and alert emails. Enhanced analysis separately opts into sending suspicious code fragments.
  • Dashboard: Simple and Advanced views, bulk actions, search, scan history and multisite support.
  • AI agents and MCP: 20 abilities covering dashboard actions.

Screenshots

WordPress malware scan overview with protection score, threat severity counts and one-click malware removal Malware Scan Overview: threat status, severity counts and safe cleanup actions.

Malware and backdoor findings list with severity, status, file path and evidence for each suspicious file Malware and Backdoor Findings: suspicious files, malicious code and evidence.

File integrity log of created, modified, quarantined and repaired WordPress files over 90 days File Changes: created, modified, quarantined and repaired files.

Reinfection risks tab listing rogue administrators, malicious cron jobs, must-use plugins and drop-ins Reinfection Risks: rogue admins, cron jobs, must-use plugins and drop-ins.

Malware quarantine with restorable non-executable copies of removed files Malware Quarantine: restorable file copies.

Malware scan history with files checked, database rows checked and findings per severity Scan History: previous scans and threats.

Malware scanner settings: DevDome account features, vulnerability check, scan limits and excluded paths Settings: account features, vulnerability check, limits and exclusions.

AI agents and MCP (WordPress Abilities API)

Since 1.2.0, hardened in 1.2.1, WordPress 6.9+ exposes 20 WordPress Abilities through the WordPress MCP Adapter. Claude, ChatGPT or Cursor can discover them to review infection status, preview fixes, mark false positives and schedule scans.

Abilities require administrator access, or network administrator on multisite. Changes to the site or threat visibility require confirm: true, prompting agent confirmation. Finding actions and quarantine deletion are annotated destructive. Output excludes absolute server paths, emails and secrets.

Ability What it does
get-security-summary Verdict, score, severity counts, fixable/decision findings, reinfection, last scan, coverage, signatures, account
get-fix-plan Proposed fixes, decisions and rescans with reasons
get-findings Filters: severity, status, object_type, type, reinfection_only, search; paging and available actions
get-finding-details Facts, redacted evidence and advice
get-finding-diff Core/plugin differences from official copies
get-scan-progress Status, stage, percent, files and rows
get-scan-history Previous scans, counts and errors
get-quarantine Copies; include_history includes restored/deleted records
get-file-changes Created, modified, quarantined, restored and repaired files over 90 days
get-event-log Events filtered by type
get-settings Settings, account, signatures, next scan and view
run-malware-scan Start background scan
control-malware-scan Pause, resume, cancel
fix-all Confirmed quarantine/official reinstall with backups; repeat batches while remaining > 0
finding-action quarantine, repair, trust, false_positive, ignore, acknowledge, reopen, neutralize; dashboard eligibility applies; six changing/hiding actions require confirmation; core repair-only; task removal includes arguments
restore-quarantined Confirmed restore with hash/permission checks and rollback; repair backups overwrite reinstalled files
delete-quarantined Confirmed permanent deletion; retry unfinished deletion, or remove restored/deleted records
update-settings deep_scan_max_kb, batch_seconds, exclusions, schedule, vuln_intel, connected account features; immediate rescheduling; readback before updated: true; confirmation for reduced protection/cloud analysis
set-view-mode Simple/Advanced for current user
sync-signatures Start/force download on connected sites

Install the MCP Adapter, create an administrator application password, then add the site to Claude Code:

{"mcpServers":{"my-site":{"type":"http","url":"https://example.com/wp-json/mcp/mcp-adapter-default-server","headers":{"Authorization":"Basic <base64 user:application-password>"}}}}

Requirements

WordPress 6.0+, PHP 7.4+. Scanning engines run on your server; no account needed.

Installation

  1. In wp-admin, open Plugins > Add New, search DevDome Malware Scanner, install and activate.
  2. Open Malware Scanner > Scan Now. The first scan verifies integrity and seeds the baseline; later scans add the change timeline.

Part of the DevDome plugin family

Free plugins by DevDome: Analytics (cookieless, bot/AI crawler split, public API and MCP server), Malware Scanner, Redirect Manager, Media Cleaner, Link Monitor, Affiliate Manager. Each includes the DevDome Dashboard for one-click installation of the others.

Development

This repository mirrors WordPress.org releases. Open an issue for bugs or feature requests, or use the support forum.

License

GPL-2.0 or later. See LICENSE.