{"product_id":"inovista-shield-wordpress-malware-scanner-plugin","title":"Inovista Shield — WordPress Malware Scanner \u0026 Hardening","description":"\u003cp\u003eInovista Shield was written after cleaning five compromised WordPress sites on one hosting account. Every signature and every protection in it comes from what was actually found there — not from a generic list.\u003c\/p\u003e\n\n\u003ch3\u003eWhat it finds\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCore files that are not WordPress\u003c\/strong\u003e, including hidden loaders such as \u003ccode\u003e.g_7f4666da.php\u003c\/code\u003e\n\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHostile drop-ins\u003c\/strong\u003e — \u003ccode\u003edb.php\u003c\/code\u003e, \u003ccode\u003eadvanced-cache.php\u003c\/code\u003e, \u003ccode\u003eobject-cache.php\u003c\/code\u003e that no caching plugin owns\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePadded must-use plugins\u003c\/strong\u003e — enormous, or stuffed with thousands of blank spaces to hide their payload\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eKnown backdoors\u003c\/strong\u003e — warp-feeder, wp-poster-connector, link-factory, plugineditorr and relatives\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWeb shells\u003c\/strong\u003e — Tiny File Manager, Adminer, FilesMan, WSO\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eThe ClickFix loader\u003c\/strong\u003e that shows visitors a fake Cloudflare page and pastes a command into their terminal\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHeader-triggered PHP backdoors\u003c\/strong\u003e, PHP files in uploads, hidden dot-PHP files anywhere\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRogue administrators\u003c\/strong\u003e, unexpected application passwords, malicious scheduled tasks\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAnything printing into\u003c\/strong\u003e \u003ccode\u003ewp_head\u003c\/code\u003e, \u003ccode\u003ewp_footer\u003c\/code\u003e or \u003ccode\u003ewp_body_open\u003c\/code\u003e from outside your plugins and theme\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHidden spam links\u003c\/strong\u003e in posts and page-builder data, cloaking \u003ccode\u003erobots.txt\u003c\/code\u003e, planted verification files\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhat it protects\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eA guard in \u003ccode\u003emu-plugins\u003c\/code\u003e that runs \u003cem\u003ebefore every plugin\u003c\/em\u003e and quarantines hostile drop-ins within a minute\u003c\/li\u003e\n  \u003cli\u003ePHP execution blocked in uploads\u003c\/li\u003e\n  \u003cli\u003eTheme and plugin file editor switched off\u003c\/li\u003e\n  \u003cli\u003eAdministrators can only be created by an administrator — anything else is demoted and reported\u003c\/li\u003e\n  \u003cli\u003eApplication passwords disabled; username enumeration blocked; XML-RPC optional\u003c\/li\u003e\n  \u003cli\u003eScheduled scans with email alerts\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eNothing is deleted outright\u003c\/h3\u003e\n\u003cp\u003eFindings are quarantined with a copy you can restore. A false positive costs you one click, not your site.\u003c\/p\u003e\n\n\u003ch3\u003eWhat you get\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003ccode\u003einovista-shield-1.0.0.zip\u003c\/code\u003e — the plugin, ready to upload\u003c\/li\u003e\n  \u003cli\u003eA setup PDF covering the first scan, reading the findings, quarantine and restore, and the hardening options\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eRequirements\u003c\/h3\u003e\n\u003cp\u003eWordPress 5.6 or newer · PHP 7.2 or newer · Tested to WordPress 7.1. Licensed GPLv2 or later. Use it on as many sites as you own.\u003c\/p\u003e","brand":"Inovista","offers":[{"title":"Default Title","offer_id":54140794667192,"sku":null,"price":9.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0982\/5511\/0328\/files\/inovista-shield-hero.png?v=1789839321","url":"https:\/\/inovistatech.shop\/products\/inovista-shield-wordpress-malware-scanner-plugin","provider":"My Store 2","version":"1.0","type":"link"}