devdome / devdome-malware-scanner
Free WordPress malware scanner, virus scanner and malware removal. Backdoor detection, quarantine, trusted repair. Free alternative to Wordfence, Sucuri and MalCare.
Package info
github.com/DevDomeFamily/devdome-malware-scanner
Type:wordpress-plugin
pkg:composer/devdome/devdome-malware-scanner
Requires
- php: >=7.4
- composer/installers: ^1.0 || ^2.0
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Scan for backdoor and webshell patterns. Review findings, quarantine files and repair eligible WordPress core and official plugin packages. This free WordPress malware scanner checks files, database content and reinfection risks without an account. Use it as a virus scanner for a manual virus scan or scheduled antimalware checks.
The free alternative to Wordfence, Sucuri and MalCare for scanning and removing malware in WordPress.
- Install from WordPress.org: https://wordpress.org/plugins/devdome-malware-scanner/
- Website: https://devdome.com
- Support: https://wordpress.org/support/plugin/devdome-malware-scanner/
Why DevDome Malware Scanner instead of the alternatives
| DevDome Malware Scanner | Wordfence | Sucuri | MalCare | Solid Security (iThemes) | NinjaScanner | GOTMLS Anti-Malware | |
|---|---|---|---|---|---|---|---|
| Price | Free | Premium from $149 / year | Platform from $199.99 / year | from $99 / year | Pro from $99 / year | Scheduled scans from $19.50 / year | Donation $29+ for definitions |
| Malware scan of files and database | Yes | Yes | Server-side scan is paid | Yes, on their cloud | Basic | Files | Files |
| Malware removal for free | Yes, quarantine and trusted repair | Premium (Care plan) | Paid | Paid | Partial | No | Free tier limited |
| Core, plugin and theme integrity against WordPress.org | Yes | Yes | Core only | Yes | Core only | Yes | Core only |
| Backdoor and reinfection checks (rogue admins, cron, MU plugins, drop-ins) | Yes, own tab with Neutralize | Partial | Partial | Partial | Partial | No | No |
| Quarantine with one-click restore (restorable database copies) | Yes | No | No | No | No | Quarantine | Auto delete |
| Severity and confidence shown separately | Yes | No | No | No | No | No | No |
| Scan runs on your own server, no account required | Yes | Yes | Plugin yes, scan no | No, cloud | Yes | Yes | Yes |
| Scheduled scans free | Yes | Yes | Paid | Paid | Yes | Paid | Yes |
Prices reflect published plans in September 2026. Quarantine preserves a restorable copy; permanent deletion is a separate action.
What it finds: a security scan of files and data
Use the security scanner for a website security review or recurring security check:
- Malware, malicious code, backdoors and web shells.
- Modified core, plugin and theme files; suspicious PHP in uploads.
- Database injections, scripts, iframes, encoded payloads, seo spam and hidden links in options, posts, revisions and meta.
- Rogue administrators, malicious WP-Cron tasks and cron beacons.
- Planted must-use plugins and drop-ins that could enable reinfection.
- Suspicious changes to
wp-config.php,.htaccessand.user.ini.
For a website hacked through injected content, these checks help investigate a pharma hack, japanese keyword hack or redirect hack involving malicious redirects. Findings need review; a changed file alone does not prove infection.
Features
Malware detection and integrity check
The malware checker separates severity from confidence. Known-signature matches have 100% confidence; an entropy blob alone is a signal. Coverage gaps remain visible, supporting an evidence-based security audit.
An integrity check uses official core and plugin checksums and official theme packages. Premium and custom code use a baseline and change timeline; the baseline does not certify safety.
Malware removal, virus removal and quarantine
The malware cleaner helps remove malware through One click fix for eligible findings:
- Quarantine known malware and eligible suspicious files.
- Reinstall eligible core or official plugins at the installed version, backing up every affected file first.
- Verify repaired packages against official checksums, then rescan to review remaining findings.
Quarantine stores non-executable database copies, compressed when available, with one-click restore. Protected startup files and official core files cannot be quarantined. Uncertain findings stay under Needs your decision.
Hack cleanup and reinfection risks
After a hack, review the Reinfection risks tab. Neutralize can demote rogue administrators, remove suspicious scheduled events or quarantine planted files. Account roles and quarantined files can be restored; removed tasks cannot be restored through the plugin.
Optional vulnerability scanner
Enable the vulnerability scanner in Settings to compare installed core, plugin and theme versions against WPVulnerability records for known vulnerabilities. It is off by default and does not attempt exploits.
Scheduled malware scan and account options
- Daily or weekly scans: short batches, WP-Cron fallback, pause, resume and cancel.
- Local anti malware checks: scanning engines run on your server without an account; official verification contacts WordPress.org.
- Optional free account: 90,000+ known-malware signatures, hash lookups sending hashes only, downloaded signatures, a multi-site site security dashboard and alert emails. Enhanced analysis separately opts into sending suspicious code fragments.
- Dashboard: Simple and Advanced views, bulk actions, search, scan history and multisite support.
- AI agents and MCP: 20 abilities covering dashboard actions.
Screenshots
Malware Scan Overview: threat status, severity counts and safe cleanup actions.
Malware and Backdoor Findings: suspicious files, malicious code and evidence.
File Changes: created, modified, quarantined and repaired files.
Reinfection Risks: rogue admins, cron jobs, must-use plugins and drop-ins.
Malware Quarantine: restorable file copies.
Scan History: previous scans and threats.
Settings: account features, vulnerability check, limits and exclusions.
AI agents and MCP (WordPress Abilities API)
Since 1.2.0, hardened in 1.2.1, WordPress 6.9+ exposes 20 WordPress Abilities through the WordPress MCP Adapter. Claude, ChatGPT or Cursor can discover them to review infection status, preview fixes, mark false positives and schedule scans.
Abilities require administrator access, or network administrator on multisite. Changes to the site or threat visibility require confirm: true, prompting agent confirmation. Finding actions and quarantine deletion are annotated destructive. Output excludes absolute server paths, emails and secrets.
| Ability | What it does |
|---|---|
get-security-summary |
Verdict, score, severity counts, fixable/decision findings, reinfection, last scan, coverage, signatures, account |
get-fix-plan |
Proposed fixes, decisions and rescans with reasons |
get-findings |
Filters: severity, status, object_type, type, reinfection_only, search; paging and available actions |
get-finding-details |
Facts, redacted evidence and advice |
get-finding-diff |
Core/plugin differences from official copies |
get-scan-progress |
Status, stage, percent, files and rows |
get-scan-history |
Previous scans, counts and errors |
get-quarantine |
Copies; include_history includes restored/deleted records |
get-file-changes |
Created, modified, quarantined, restored and repaired files over 90 days |
get-event-log |
Events filtered by type |
get-settings |
Settings, account, signatures, next scan and view |
run-malware-scan |
Start background scan |
control-malware-scan |
Pause, resume, cancel |
fix-all |
Confirmed quarantine/official reinstall with backups; repeat batches while remaining > 0 |
finding-action |
quarantine, repair, trust, false_positive, ignore, acknowledge, reopen, neutralize; dashboard eligibility applies; six changing/hiding actions require confirmation; core repair-only; task removal includes arguments |
restore-quarantined |
Confirmed restore with hash/permission checks and rollback; repair backups overwrite reinstalled files |
delete-quarantined |
Confirmed permanent deletion; retry unfinished deletion, or remove restored/deleted records |
update-settings |
deep_scan_max_kb, batch_seconds, exclusions, schedule, vuln_intel, connected account features; immediate rescheduling; readback before updated: true; confirmation for reduced protection/cloud analysis |
set-view-mode |
Simple/Advanced for current user |
sync-signatures |
Start/force download on connected sites |
Install the MCP Adapter, create an administrator application password, then add the site to Claude Code:
{"mcpServers":{"my-site":{"type":"http","url":"https://example.com/wp-json/mcp/mcp-adapter-default-server","headers":{"Authorization":"Basic <base64 user:application-password>"}}}}
Requirements
WordPress 6.0+, PHP 7.4+. Scanning engines run on your server; no account needed.
Installation
- In wp-admin, open Plugins > Add New, search DevDome Malware Scanner, install and activate.
- Open Malware Scanner > Scan Now. The first scan verifies integrity and seeds the baseline; later scans add the change timeline.
Part of the DevDome plugin family
Free plugins by DevDome: Analytics (cookieless, bot/AI crawler split, public API and MCP server), Malware Scanner, Redirect Manager, Media Cleaner, Link Monitor, Affiliate Manager. Each includes the DevDome Dashboard for one-click installation of the others.
Development
This repository mirrors WordPress.org releases. Open an issue for bugs or feature requests, or use the support forum.
License
GPL-2.0 or later. See LICENSE.