Plugin Directory

Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal

Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal


No. 1 Plugin for cleaning up hacked websites. Scans entire WordPress files & database for malicious redirects, viruses, malware, infections, security-threats, trojans, backdoors, dolohen, code injections and over 50,000+ security threats & vulnerabilities. It’s the most precise WordPress malware scanner yet light-weight, extremely simple and easy-to-use.

No false positives. Now remove malware with confidence.

Malcure Malware Scanner scans all the WordPress files (including backups, archives, images, hidden files, logs, etc.) and database for malware including variants like C99, R57, RootShell, dolohan, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx and many more… Our Full-find Infection Scanner scans each and every file on your WordPress install for security threats & vulnerabilities.

Nothing escapes Malcure WordPress Malware Scanner. It’s light-weight, simple and easy-to-use and extremely thorough.


  • Malware scanner checks core files, themes, plugins and database for malware, infection, malicious redirects and code injections.
  • Checksum / Integrity Check: Compares the core files, themes and plugins on your site with respective files on WordPress.org repository to check their integrity and report any changes by auto-syncing with WordPress Checksum API.
  • Got a security warning from Google Search Console? Google Webmaster Tools? Malcure WordPress Malware Scanner integrates with Google™ Search Console to fetch security warnings or notices to warn you in time.
  • Malware details for each of the infected details.
  • Clear classification of infection under the following heads: Redirect Hijack, Title Hack Results, Database Scan Results and WordPress File Scan Results.
  • Inspect files: Instantly inspect infected files via Malware Inspector.
  • System Status: Quickly get an overview of all the critical WordPress and site related information.
  • One-click copy results.
  • Rescan files in case a file fails to scan the first time.
  • Full compatibility with latest WordPress release.
  • A well-maintained scans log for last 30 days.

Premium Features:

  • Single click repair, clean and whitelisting of files.
  • Real-time malware definition updates.
  • WP CLI support for scanning via command line.
  • Use custom definitions and patterns to scan for new virus strains.
  • Skip / Scan specific files and directories to save time.

Click here to purchase Malcure Advanced Edition now!

Features You’ll Love:

  • Ultra-high-precision results.
  • Auto-sync with WordPress Checksum API.
  • Checks for viruses and infections using malware definitions.
  • Latest and regularly updated WordPress malware signatures.
  • Connects to the definition update server to fetch the latest definitions.

Malcure WordPress Malware Scanner & Firewall is sophisticated and extremely powerful. It’s simple and does the job.

If your site is infected, check out the following links:

Malware issues are time-sensitive and the fastest way to fix your hacked site is to request malware cleanup by our security specialists.

Our security team will fix and restore your hacked website before it damages your brand-reputation & kills SEO. Our malware clean-up service covers blacklist removal as well as restoration of Google Ad campaigns.

Click here to avail our popular WordPress malware removal service




NOTICE: The plugin makes call to our malware definition api to check for latest WordPress malware signatures (pretty much like what WordPress does when checking your plugins and themes for new versions. Staying up-to-date is a security best-practice. Malcure WordPress Malware Scanner & Firewall will inform you when there are new definition updates available. If you’re allergic to “phone home” scripts then don’t use this plugin (or WordPress at all for that matter).


  • This screen shot description corresponds to screenshot-1.(png|jpg|jpeg|gif).
  • This is the second screen shot


Upload Malcure WordPress Malware Scanner plugin to your blog. Activate it. You may configure Firewall settings (optional). Create a support thread in case of any issues.


My site is hacked. What should I do?

Option 1: If you are tech-savvy, you can use this plugin, analyse the site and remove malware yourself.

Option 2: You can file a service request with us. Our service includes malware cleanup and blacklist removal by our security analysts. Please click here to file a support request.

Why should I use Malcure WordPress malware scanner?

Several reasons: a) Malcure WordPress Malware Scanner scans all files, even images and archives so deep hidden malware is also easily detected. b) Checks all WordPress and repo plugins for checksums. c) Scans over 50,000+ known malware including variants like C99, R57, RootShell, dolohan, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx and many more. d) Hybrid scan ensures unknown threats are also identified.

In short, nothing escapes Malcure WordPress Malware Scanner. It’s fast, simple to use and extremely thorough.

What support options are available for Malcure WordPress Malware Scanner users?

Providing excellent support is extremely important to us. You can file a ticket at Malcure website and our dedicated web-security specialist will ensure that the matter is resolved to your satisfaction.

Some files are detected by Malcure WordPress Malware Scanner as “suspicious”. What gives?

Malcure’s SmartScan checks each file for malware. However some files aren’t pure malware but may contain code that is suspicious and could do nasty things. You should carefully review and analyse them to see if they indeed do anything nasty.

I can’t get Malcure WordPress Malware Scanner to work. It hangs / doesn’t complete the scan / breaks for some reason.

If you think that the plugin is broken, please report it here.

Malcure WordPress Malware Scanner (or for that matter other plugins) may break on malware affected / broken websites. Malcure Advanced Edition integrates with WP CLI and allows you to complete the scan from WP CLI.

My site is infected however Malcure WordPress Malware Scanner doesn’t detect the infection.

Malware keeps evolving. If you come across malware that Malcure WordPress Malware Scanner is not able to identify, you may please report it here.

Is Malcure WordPress Malware Scanner better than Sucuri / Wordfence / Quttera (insert favourite plugin here)?

We can’t comment on other plugins but Malcure WordPress Malware Scanner is a local WordPress scanner which means its way ahead of remote scanners. Malcure WordPress Malware Scanner does its job very well. If you have feedback, please do not hesitate to share with us.

Also Malcure WordPress Malware Scanner scans every file regardless of whether it’s an image, archive etc. Modern malware hides in unsuspicious files and Malcure WordPress Malware Scanner makes sure those are not missed. Malcure WordPress Malware Scanner is extremely thorough and leaves no aspect of the site to speculation.

Will Malcure WordPress Malware Scanner impact the performance of my website?

Malcure WordPress Malware Scanner only runs when you want it to. At all other times it sleeps silently. The firewall triggers extremely quickly and is optimized for performance.

The scan gets stuck midway. What should I do?

In case of such an event, please file a support request with us and we’ll be more than happy to troubleshoot the issue.

Please visit this page.

I cleaned my site but it got infected again. What should I do?

Malware cleanup is a waste of time and effort until you find the root cause behind malware infection. How was someone able to infect your website? Have you plugged in that security hole?

Please read Why Do WordPress Websites Get Hacked.

Google Safe Browsing site status (or some other scanner) still shows my site as infected. What should I do?

First make sure you purge your site cache. Second, Google (and other scanners) cache the results for some time. You’ll need to force or refresh the scan.

Where can I find the Malcure Terms of Use and Privacy Policy?

These are available on our website: Terms of Use and Privacy Policy


June 18, 2024
Plugin does a deep scan of the site and other folders in root.
March 23, 2024
used it on my hacked website to clean the infections and it worked very well
March 20, 2024
…when your website has been attacked. It´s pain in the ass to see, when someone/thing disturbing and destroying your work. It´s good to have Malcure to swipe them out. Great. Thanks for this!
Read all 49 reviews

Contributors & Developers

“Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal” is open source software. The following people have contributed to this plugin.




  • Changed default UI to dark skin.
  • Added file blacklist.


  • Updated logging.
  • Made redirect scan optional.
  • Other minor UI updates.


  • Updated to exclude database records of a few security plugins.


  • Bugfix: Incorrect activations displayed in Malcure Advanced Edition.


  • Feature: Consistent UI.


  • Feature: Allow clearing logs (Advanced Edition).
  • Bugfix: Reset via WP CLI would fail.
  • Several UI Updates.
  • Several UX Updates.
  • Updated WP CLI Help / Documentation.


  • Bugfix: File Inspector doesn’t reset when inspecting a new file.
  • Bugfix: Unreadable files are not reported.
  • Bugfix: Infection count is not copied in Advanced Edition.


  • Minor Bugfix: Some hosts deny access to certain files.
  • Minor Bugfix: Sometimes WP CLI scan times out.
  • Minor Bugfix: Consolidated file validation calls.
  • Major Update: Retired HTTP based scan via WP CLI.


  • Minor Bugfix: Audio notifications not working by default.


  • Feature: Audio notifications on scan completion.
  • Bugfix: Better locale detection.


  • Minor UI Update.
  • Tweak to reduce load on API Server.


  • Bugfix: Fully compatible with PHP 8.2.
  • Bugfix: Fixed timeout issues. Our server is slow and we are working to expand our infrastructure and costs.
  • Feature: Verbose details when copying results (Advanced Edition).


  • Bugfix: Some ajax actions throw PHP warnings.


  • Bugfix: Aggregate Scan-speed and start-time broken on second iteration.


  • UX: Mouse-wheel event to update the scan speed slider.
  • UX: Updated the default scan speed to 11.
  • UX: Realistic time remaining on second iteration.


  • Bugfix: File incorrectly being reported as a file inside core direrctories.


  • Bugfix: Notification doesn’t show correct message in some cases.


  • Major UX improvements.
  • Feature: Better notification system.
  • Feature: WordPress Salt Shuffler.


  • Feature: Added ability to save scan-log to a file when used with WP-CLI.


  • Bugfix: Fixed formatting of copied results.
  • Bugfix: Fixed js error when trying to repair a file.


  • Bugfix: Error thrown when repairing a file.
  • Bugfix: UI not reflecting the updated version of signatures.
  • Bugfix: Better file filtering when WordPress is installed in a custom directory.
  • Bugfix: Better verbosity in WP CLI.
  • Feature: Major revamp in CLI functions.
  • Feature: Major revamp in CLI function documentation.


  • Bugfix: Better support for symlinks on some web-hosts.
  • Bugfix: Minor performance optimisations.


  • Bugfix: Better support for symlinks.
  • Bugfix: Results do not reset on rescan.


  • Bugfix: Emergency Release. Missing function hrtime in PHP 5.6 breaks the plugin.


  • Bugfix: Definition updates not available when automating with WP CLI.
  • Feature: Ability to force reset in unattended mode with WP CLI
  • Bugfix: Inconsistency with get_home_path and ABSPATH.
  • Feature: Report timings during scan.
  • Feature: Report when WordPress is installed in a custom directory.
  • Feature: Many UX improvements.
  • Feature: Many code optimisations / refactoring, ability to traverse into softlinks.


  • Bugfix: Scan failure reported as suspicious.
  • Bugfix: Core file not reported if suspicious.
  • Bugfix: Mismatching of version.php.
  • Feature: Reset plugin settings via CLI.
  • Feature: Other CLI improvements.


  • Feature: Massive speed optimizations.
  • Feature: Switched to more secure hash.


  • Bugfix: Invalid suspicious incident count.


  • New Feature: Infection Count.


  • Bugfix: User not alerted by out of date definitions under certain conditions.


  • Bugfix: User not alerted by out of date definitions.


  • Better UX with CLI.
  • Output detailed setup information during scan via CLI.
  • Output customer info on license page.


  • Bugfix: Definition Update Available notice doesn’t get removed after updating definitions.
  • Bugfix: Incorrect reflection of meta_id as post_id in database scan results.


  • Enhancement: Report max_execution_time, memory_limit and memory_usage on WP CLI.
  • UX: User-sessions-list takes up huge amount of vertical space on multi-user sites. Shifted it down.


  • Bugfix: Visibly display message if site is experience an HTTP error.


  • Bugfix: CLI scan dies after the default apache timeout on mod_php.
  • Bugfix: Prioritised core files.


  • Bugfix: CLI scan dies after the default apache timeout on mod_php.
  • Bugfix: Fixed an error if PHP DOM extension php-xml is missing.


  • Feature: Skin changer to configure UI for long working hours.


  • Bugfix: Scan fails to initialize on large databases or huge number of files.
  • Bugfix: CLI fails to clear infection status.
  • Feature: Several other UI updates.
  • Others: Code refactoring.


  • Feature: UI updates.
  • Feature: Disabled skipping binary files.
  • Bugfix: Several minor bugfixes.


  • Feature: Major UI overhaul.
  • Feature: Added DeepScan™ & SpeedScan.
  • Bugfix: Warning thrown when optimising checksums.
  • Bugfix: Fixed the Copy button copying invalid file format to clipboard.
  • Bugfix: Several scan optimisations.


  • Bugfix: Prevent third-party metaboxes from polluting the UI.


  • Major Bugfix: Prevent engine stats error / delays from hanging the UI.


  • Feature: WP-CLI progressbar shows the file being scanned.
  • Bugfix: WP-CLI colors remain affected if infection is detected.
  • Bugfix: De-duplication of scan when batch size is 1.


  • Bugfix: Advanced version throws error when running via WP-CLI


  • Bugfix: Cannot activate license from commandline.
  • Bugfix: WP CLI scan timesout in certain conditions.
  • Bugfix: WP CLI scan throws fatal error in certain conditions.
  • Several UI fixes.


  • Bugfix: Logs generating PHP warnings.


  • Added error control operator to suppress errors if allow_url_fopen is not available.


  • Updated readme documentation.


  • Minor UI Fixes


  • Improvement: License activation shouldn’t accept empty key.


  • Recommit due to previous commit failure..
  • Branding update.
  • Bugfix: Definition-auto-update broken on WP CLI.


  • Branding update.
  • Bugfix: Definition-auto-update broken on WP CLI.


  • UI bugfixes.


  • Minor bugfixes.
  • Added support button to report plugin issues.


  • Minor bugfixes.


  • Bugfix: Regression slowing down the scan.


  • Option to disable automatic-definition updates.
  • Theme checksums from the API.


  • Bugfix: Suspicious files not reported sometimes.
  • Updated first-run experience.


  • Minor UI Updates.


  • Major Bugfix: severe infections were missed sometimes.
  • Bugfix: Report accurate definition count.


  • Several minor bugfixes, optimizations and code refactoring.


  • Bugfix: Files in root are ignored sometimes.
  • Bugfix: Scan Only Dir not working.


  • Feature: Check rougue redirects


  • Added automation routines.


  • Fixed a bug with capabilities.


  • Added timestamp label on clean-scan notice.


  • Bugfix: Manually entered search strings are not found (Advanced Version only).


  • Bugfix: Fallback to default locale checksums in case checksums are not available.


  • UI updates.
  • Better message for clean site status.


  • Bugfix: Updated textdomain as per specs “The text domain must match the slug of the plugin”.


  • Added verbose license status.


  • Whitelist module update.
  • Fixed missing asset throwing 404.


  • UI improvements plus CSS refactorings.


  • UI, Dashboard and branding updates.


  • Clean, repair, whitelist, unwhitelist files.
  • Major UI improvements.
  • Real-time display of the file being scanned.
  • Updated styles to match system / browser dark-mode.
  • Major feature launch for Malcure Advanced Edition.


  • Bugfix: License is not deactivated on plugin deactivation.
  • Better cleanup on uninstall / deactivation.
  • Better UI indicators for features available only in Advanced Edition.
  • Tested and removed broken functions from CLI which only have full integration in Advanced Edition.


  • Fixed a warning on WP CLI.
  • Updated compatibility with WordPress 5.4.1.
  • Admin notice experience update.


  • Several performance improvements and minor bugfixes.


  • Tweaked checksum validity.
  • Fixed compatibility error with wp_timezone_string on old WP installs.


  • Scan-speed optimizations.


  • Reuploaded due to svn issue.


  • Show user role in user sessions.


  • Bugfix: File repair operations throw error in error log if the operation fails.
  • Update: List malware definition / signature version visibly on the CLI as well as web-UI.
  • Several other minor updates.


  • Bugfix: Show relevant notices only to relevant user-levels.
  • Bugfix: Signup prompt breaks because of $ instead of jQuery.
  • Bugfix: Title scan doesn’t give reliable results.


  • Fixes to time format in logs.
  • Bugfix: Dashboard widget shows for all user-roles.
  • Alternative async scan in WP CLI mode.


  • Better handling of cleaned up files in scan logs.
  • Multiple UI updates to “Logs” view.
  • Bugfix: Scan status doesn’t clear on clean scan.


  • Feature: File clean up operations.
  • Better visibility of support options.


  • Disabled paranoid mode by default.
  • Scan comments for malware-spam.


  • Optimised scan for filesize.
  • Added signature reporting in WP CLI.
  • Minor bugfix in database scan.


  • Bugfix: Typo in variable name.


  • Feature: Malware scan logs for last 30 days.
  • Implemented help section.
  • Included links to T&C and privacy policy.
  • Better first-run experience.
  • Optimized memory usage.


  • Linked results to infection details.
  • Implemented notice before navigating away from results.


  • Bugfix: Scan breaks if path has non-Latin1 characters.
  • Bugfix: Force a premium checksum update on license activation.
  • Bugfix: File name and path doesn’t change in file inspector.


  • Bugfix: Definition check times-out.
  • UI updates.


  • Fixed a bug that would break results in case of invalid response.


  • Added infection details.
  • Optimized performance.


  • UX Revamp from the ground up.


  • Bugfix: File scan results wouldn’t show up sometimes.


  • Fixed: Scroll to results wouldn’t work when infnection is detected.
  • Updated default no. of files per batch for faster scans.


  • Bugfix: Definition update won’t trigger sometimes.
  • Bugfix: Result actionable wouldn’t trigger sometimes.
  • Bugfix: Plugin throws php warnings due to typo in function definition.


  • Updated firewall settings.
  • Ability to reset plugin data.
  • Compatibility with WordPress 5.3.