{"title":"Plugins","description":"\u003cp\u003eWordPress plugins built from real client work, sold as instant downloads.\u003c\/p\u003e","products":[{"product_id":"review-engine-wordpress-google-reviews-plugin","title":"Review Engine — Google Reviews for WordPress","description":"\u003cp\u003eReview Engine keeps your Google reviews in your own database, merges them across every business profile you run, and renders them anywhere with one shortcode.\u003c\/p\u003e\n\n\u003cp\u003eThe display layer does not care where a review came from. A CSV paste, the Google Places API and an external collector all produce the same normalised review, so you can change how reviews arrive without touching how they look.\u003c\/p\u003e\n\n\u003ch3\u003eWhat it does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eOne shortcode, every profile.\u003c\/strong\u003e \u003ccode\u003e[testimonials]\u003c\/code\u003e merges all your business profiles, de-duplicates and sorts. \u003ccode\u003e[five_star_reviews]\u003c\/code\u003e shows five-star reviews only.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAggregate header.\u003c\/strong\u003e \"4.8 ★ · Based on 65 reviews\", taken from your stored reviews or from Google's own totals.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSix ways to show them.\u003c\/strong\u003e Grid, list, carousel, quote and stack layouts; 1–4 columns; card, plain, outline and soft skins; light, dark or automatic.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eFilter chips and load-more\u003c\/strong\u003e by location and star rating.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTwo live sources.\u003c\/strong\u003e Google Places API for the true rating and review count, or a SerpApi key for the full review history without Google approval.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eBulk import.\u003c\/strong\u003e CSV or JSON with a preview step and duplicate merging, plus CSV export of everything stored.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSidebar widget\u003c\/strong\u003e with style, count, five-star-only and accent colour.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCaching that clears itself\u003c\/strong\u003e whenever a review changes — reviews render from your own database, not a live API call.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWP-CLI commands\u003c\/strong\u003e and theme-overridable templates.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eBuilt-in security lock\u003c\/h3\u003e\n\u003cp\u003eOptional, and off until you switch it on. It turns off the code editors, blocks plugin and theme uploads, fingerprints every plugin file and checks them from a must-use guard \u003cem\u003ebefore\u003c\/em\u003e the plugin loads, quarantines planted scripts, and requires a password to switch any of it back off.\u003c\/p\u003e\n\n\u003ch3\u003eRestyling\u003c\/h3\u003e\n\u003cp\u003eEvery colour is a CSS custom property, and both templates can be overridden by copying them into \u003ccode\u003eyour-theme\/review-engine\/\u003c\/code\u003e. No CSS is loaded that you cannot reach.\u003c\/p\u003e\n\n\u003ch3\u003eWhat you get\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003ccode\u003ereview-engine-2.3.0.zip\u003c\/code\u003e — the plugin, ready to upload\u003c\/li\u003e\n  \u003cli\u003eA setup PDF covering installation, profiles, sources, shortcode attributes and the security lock\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eRequirements\u003c\/h3\u003e\n\u003cp\u003eWordPress 5.8 or newer · PHP 7.4 or newer · Tested to WordPress 6.7. Licensed GPLv2 or later. Use it on as many sites as you own.\u003c\/p\u003e","brand":"Inovista","offers":[{"title":"Default Title","offer_id":54140794634424,"sku":null,"price":9.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0982\/5511\/0328\/files\/review-engine-hero.png?v=1789834024"},{"product_id":"inovista-shield-wordpress-malware-scanner-plugin","title":"Inovista Shield — WordPress Malware Scanner \u0026 Hardening","description":"\u003cp\u003eInovista Shield was written after cleaning five compromised WordPress sites on one hosting account. Every signature and every protection in it comes from what was actually found there — not from a generic list.\u003c\/p\u003e\n\n\u003ch3\u003eWhat it finds\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCore files that are not WordPress\u003c\/strong\u003e, including hidden loaders such as \u003ccode\u003e.g_7f4666da.php\u003c\/code\u003e\n\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHostile drop-ins\u003c\/strong\u003e — \u003ccode\u003edb.php\u003c\/code\u003e, \u003ccode\u003eadvanced-cache.php\u003c\/code\u003e, \u003ccode\u003eobject-cache.php\u003c\/code\u003e that no caching plugin owns\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePadded must-use plugins\u003c\/strong\u003e — enormous, or stuffed with thousands of blank spaces to hide their payload\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eKnown backdoors\u003c\/strong\u003e — warp-feeder, wp-poster-connector, link-factory, plugineditorr and relatives\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWeb shells\u003c\/strong\u003e — Tiny File Manager, Adminer, FilesMan, WSO\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eThe ClickFix loader\u003c\/strong\u003e that shows visitors a fake Cloudflare page and pastes a command into their terminal\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHeader-triggered PHP backdoors\u003c\/strong\u003e, PHP files in uploads, hidden dot-PHP files anywhere\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRogue administrators\u003c\/strong\u003e, unexpected application passwords, malicious scheduled tasks\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAnything printing into\u003c\/strong\u003e \u003ccode\u003ewp_head\u003c\/code\u003e, \u003ccode\u003ewp_footer\u003c\/code\u003e or \u003ccode\u003ewp_body_open\u003c\/code\u003e from outside your plugins and theme\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHidden spam links\u003c\/strong\u003e in posts and page-builder data, cloaking \u003ccode\u003erobots.txt\u003c\/code\u003e, planted verification files\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhat it protects\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eA guard in \u003ccode\u003emu-plugins\u003c\/code\u003e that runs \u003cem\u003ebefore every plugin\u003c\/em\u003e and quarantines hostile drop-ins within a minute\u003c\/li\u003e\n  \u003cli\u003ePHP execution blocked in uploads\u003c\/li\u003e\n  \u003cli\u003eTheme and plugin file editor switched off\u003c\/li\u003e\n  \u003cli\u003eAdministrators can only be created by an administrator — anything else is demoted and reported\u003c\/li\u003e\n  \u003cli\u003eApplication passwords disabled; username enumeration blocked; XML-RPC optional\u003c\/li\u003e\n  \u003cli\u003eScheduled scans with email alerts\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eNothing is deleted outright\u003c\/h3\u003e\n\u003cp\u003eFindings are quarantined with a copy you can restore. A false positive costs you one click, not your site.\u003c\/p\u003e\n\n\u003ch3\u003eWhat you get\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003ccode\u003einovista-shield-1.0.0.zip\u003c\/code\u003e — the plugin, ready to upload\u003c\/li\u003e\n  \u003cli\u003eA setup PDF covering the first scan, reading the findings, quarantine and restore, and the hardening options\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eRequirements\u003c\/h3\u003e\n\u003cp\u003eWordPress 5.6 or newer · PHP 7.2 or newer · Tested to WordPress 7.1. Licensed GPLv2 or later. Use it on as many sites as you own.\u003c\/p\u003e","brand":"Inovista","offers":[{"title":"Default Title","offer_id":54140794667192,"sku":null,"price":9.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0982\/5511\/0328\/files\/inovista-shield-hero.png?v=1789839321"},{"product_id":"clickfix-remover-wordpress-malware-plugin","title":"ClickFix Remover — Fake CAPTCHA Injection Cleaner for WordPress","description":"\u003cp\u003eClickFix is the attack that asks your visitors to infect themselves. A compromised page shows what looks like a Cloudflare security check, tells the visitor to press a key combination and paste \"the verification code\", and the clipboard already holds a command that downloads a payload. No browser exploit, no file download — just a person following instructions.\u003c\/p\u003e\n\n\u003cp\u003eClickFix Remover finds that injection and takes it out.\u003c\/p\u003e\n\n\u003ch3\u003eIt searches everywhere the payload hides\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEvery table in the database\u003c\/strong\u003e, whatever your table prefix is — not just \u003ccode\u003ewp_posts\u003c\/code\u003e and \u003ccode\u003ewp_options\u003c\/code\u003e. Page-builder data, widget content and theme settings are where these injections usually survive a cleanup.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEvery file\u003c\/strong\u003e in the install, PHP and JavaScript alike.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eIt knows what it is looking for\u003c\/h3\u003e\n\u003cp\u003eThe signatures are the actual shape of the loader, not a guess: the obfuscated \u003ccode\u003eatob()\u003c\/code\u003e block, indirect \u003ccode\u003e(0,eval)\u003c\/code\u003e execution of the decoded payload, and the long base64 strings that carry it. That specificity is what keeps it from flagging your legitimate JavaScript.\u003c\/p\u003e\n\n\u003ch3\u003eIt protects visitors while you work\u003c\/h3\u003e\n\u003cp\u003eTurn the shield on and the injection is filtered out of page output immediately, before you have removed a single file. Your visitors stop seeing the fake check while you take your time cleaning up properly.\u003c\/p\u003e\n\n\u003ch3\u003eEverything is reversible\u003c\/h3\u003e\n\u003cp\u003eEvery file and every database row it touches is backed up first. If a match turns out to be legitimate, you restore it. Nothing is destroyed on your behalf.\u003c\/p\u003e\n\n\u003ch3\u003eWhat you get\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003ccode\u003eclickfix-remover-3.0.0.zip\u003c\/code\u003e — the plugin, ready to upload\u003c\/li\u003e\n  \u003cli\u003eA setup PDF covering the scan, reading the results, the shield, cleaning safely and closing the way back in\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eRequirements\u003c\/h3\u003e\n\u003cp\u003eWordPress 5.0 or newer · PHP 7.0 or newer. Licensed GPLv2 or later. Use it on as many sites as you own.\u003c\/p\u003e\n\n\u003cp\u003e\u003cem\u003eRemoving the injection is half the job. If the site is reinfected, the way in is still open — usually an outdated or abandoned plugin. \u003ca href=\"\/products\/inovista-shield-wordpress-malware-scanner-plugin\"\u003eInovista Shield\u003c\/a\u003e covers that side.\u003c\/em\u003e\u003c\/p\u003e","brand":"Inovista","offers":[{"title":"Default Title","offer_id":54140954640568,"sku":null,"price":9.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0982\/5511\/0328\/files\/clickfix-remover-hero.png?v=1789839324"}],"url":"https:\/\/inovistatech.shop\/collections\/plugins.oembed","provider":"My Store 2","version":"1.0","type":"link"}