Inovista Shield — WordPress Malware Scanner & Hardening
Inovista Shield was written after cleaning five compromised WordPress sites on one hosting account. Every signature and every protection in it comes from what was actually found there — not from a generic list.
What it finds
-
Core files that are not WordPress, including hidden loaders such as
.g_7f4666da.php -
Hostile drop-ins —
db.php,advanced-cache.php,object-cache.phpthat no caching plugin owns - Padded must-use plugins — enormous, or stuffed with thousands of blank spaces to hide their payload
- Known backdoors — warp-feeder, wp-poster-connector, link-factory, plugineditorr and relatives
- Web shells — Tiny File Manager, Adminer, FilesMan, WSO
- The ClickFix loader that shows visitors a fake Cloudflare page and pastes a command into their terminal
- Header-triggered PHP backdoors, PHP files in uploads, hidden dot-PHP files anywhere
- Rogue administrators, unexpected application passwords, malicious scheduled tasks
-
Anything printing into
wp_head,wp_footerorwp_body_openfrom outside your plugins and theme -
Hidden spam links in posts and page-builder data, cloaking
robots.txt, planted verification files
What it protects
- A guard in
mu-pluginsthat runs before every plugin and quarantines hostile drop-ins within a minute - PHP execution blocked in uploads
- Theme and plugin file editor switched off
- Administrators can only be created by an administrator — anything else is demoted and reported
- Application passwords disabled; username enumeration blocked; XML-RPC optional
- Scheduled scans with email alerts
Nothing is deleted outright
Findings are quarantined with a copy you can restore. A false positive costs you one click, not your site.
What you get
-
inovista-shield-1.0.0.zip— the plugin, ready to upload - A setup PDF covering the first scan, reading the findings, quarantine and restore, and the hardening options
Requirements
WordPress 5.6 or newer · PHP 7.2 or newer · Tested to WordPress 7.1. Licensed GPLv2 or later. Use it on as many sites as you own.
Every purchase
What arrives in your inbox
The plugin zip
Upload it straight to WordPress under Plugins → Add New → Upload Plugin. Do not unzip it first.
A setup guide
A proper PDF: install, configure, every option explained, and what to do when something does not work.
A licence that lets you
GPLv2 or later. Install on as many sites as you own, read the code, change it, keep your changes.
- Delivery Emailed the moment you pay
- Licence GPLv2 or later
- Activation None — no licence server
- Support Reply from whoever built it
You may also like
Not quite right?
It can be changed to fit
If this nearly does what you need but not quite, say so. Adapting something that already works is usually cheaper than commissioning it from nothing.