Inovista Shield app icon — a shield with a checkmark — above the words Inovista Shield

Inovista Shield — WordPress Malware Scanner & Hardening

$9.99
Skip to product information
Inovista Shield app icon — a shield with a checkmark — above the words Inovista Shield

Inovista Shield — WordPress Malware Scanner & Hardening

$9.99

Inovista Shield was written after cleaning five compromised WordPress sites on one hosting account. Every signature and every protection in it comes from what was actually found there — not from a generic list.

What it finds

  • Core files that are not WordPress, including hidden loaders such as .g_7f4666da.php
  • Hostile drop-insdb.php, advanced-cache.php, object-cache.php that no caching plugin owns
  • Padded must-use plugins — enormous, or stuffed with thousands of blank spaces to hide their payload
  • Known backdoors — warp-feeder, wp-poster-connector, link-factory, plugineditorr and relatives
  • Web shells — Tiny File Manager, Adminer, FilesMan, WSO
  • The ClickFix loader that shows visitors a fake Cloudflare page and pastes a command into their terminal
  • Header-triggered PHP backdoors, PHP files in uploads, hidden dot-PHP files anywhere
  • Rogue administrators, unexpected application passwords, malicious scheduled tasks
  • Anything printing into wp_head, wp_footer or wp_body_open from outside your plugins and theme
  • Hidden spam links in posts and page-builder data, cloaking robots.txt, planted verification files

What it protects

  • A guard in mu-plugins that runs before every plugin and quarantines hostile drop-ins within a minute
  • PHP execution blocked in uploads
  • Theme and plugin file editor switched off
  • Administrators can only be created by an administrator — anything else is demoted and reported
  • Application passwords disabled; username enumeration blocked; XML-RPC optional
  • Scheduled scans with email alerts

Nothing is deleted outright

Findings are quarantined with a copy you can restore. A false positive costs you one click, not your site.

What you get

  • inovista-shield-1.0.0.zip — the plugin, ready to upload
  • A setup PDF covering the first scan, reading the findings, quarantine and restore, and the hardening options

Requirements

WordPress 5.6 or newer · PHP 7.2 or newer · Tested to WordPress 7.1. Licensed GPLv2 or later. Use it on as many sites as you own.

Every purchase

What arrives in your inbox

  • The plugin zip

    Upload it straight to WordPress under Plugins → Add New → Upload Plugin. Do not unzip it first.

  • A setup guide

    A proper PDF: install, configure, every option explained, and what to do when something does not work.

  • A licence that lets you

    GPLv2 or later. Install on as many sites as you own, read the code, change it, keep your changes.

  • Delivery Emailed the moment you pay
  • Licence GPLv2 or later
  • Activation None — no licence server
  • Support Reply from whoever built it

You may also like

Not quite right?

It can be changed to fit

If this nearly does what you need but not quite, say so. Adapting something that already works is usually cheaper than commissioning it from nothing.

Ask about a change