A diagnosis and handling tool for suspicious WordPress files: scan, findings, quarantine, and ROLL BACK. Not a WAF and not a regularly updated antivirus.
When you suspect a breach, you should not guess over FTP. The plugin gives a clear picture inside WordPress: what was found, why it is suspicious, and what you can isolate safely with a restore option.
Built for site admins and maintenance teams. A free scan with real findings; PRO unlocks automatic checks, full details, code view, quarantine, and ROLL BACK.
Install, back up the site (files + database), run a scan, and only then decide whether to isolate a file.
What the plugin does, what it does not do, and the difference between Free and PRO.
Free download · 1-year PRO license · one site · activation after payment.
icomm Malware Guard is a practical tool for a suspected incident: scan, understand, and isolate files one by one with ROLL BACK. No automatic deletion, and no promise that it catches «everything».
The scan is split into four detection types: A suspicious location, B built-in content patterns, C WordPress core and official plugin files, D database, administrator accounts, scheduled tasks, and unknown plugins. Severity is shown in a separate column.
What's new in 0.8.19
Alert emails include the plugin logo and a designed layout.
What's new in 0.8.18
Display improvements on the plugin details page.
What's new in 0.8.17
English plugin details on English store pages.
Activate the plugin from the Plugins screen. Before a scan or quarantine: a full site backup (files + database).
What does the plugin actually do?
Helps diagnose suspicious files on a WordPress site, and in PRO lets you isolate a file to quarantine and restore it (ROLL BACK).
What is included in Free and what is in PRO?
Free: a real scan and real findings in a shortened view. In PRO: automatic checks with an email on new critical findings, full path, reason, code view, quarantine, ROLL BACK, and plugin updates.
What do levels A / B / C / D mean?
Detection type: A suspicious location, B built-in content pattern, C a change or missing WordPress core or official plugin file, D database, administrator accounts, scheduled tasks, or an unknown plugin. Severity is shown in a separate column.
Does the plugin scan by itself?
Yes, in PRO. Turn on a daily or weekly check in Settings. You get an email only if a new critical finding appears. The same items already on the list do not send another email. This is not protection on every page view.
Is this a regularly updated antivirus?
No. There are built-in detection patterns that update with plugin versions. Automatic checks repeat the same scan on a schedule. This is a diagnosis and handling tool, not a live antivirus on every request.
Are files deleted automatically?
No. Every quarantine or cleanup requires an admin confirmation. You can restore a quarantined item. Administrator accounts are never deleted automatically.
The site or admin did not load after quarantine. What now?
PHP may still try to load that file on every request (often a WAF helper in the site root). Restore it from Quarantine and restore. If WordPress is down, in the host file manager open .user.ini and comment out the auto_prepend_file line, then wait a few minutes. Current versions leave a placeholder so this does not happen.
Is a backup required?
Yes. A full backup (files + database) is recommended before a scan or handling.
Does this replace a WAF or a server cleanup?
No. This is a WordPress tool for diagnosis and isolation. It does not replace a firewall, a backup, or hosting-level handling.
How do I activate PRO?
On the plugin License screen: purchase on icomm.market, or paste a key and activate. The license is tied to the site domain.
A file was flagged. Could it be legitimate?
Yes. A risky location is not a malware verdict. A compiled cache file in uploads, or a login-attempt log, can match a pattern even when it is not malware. The plugin reads the content and recommends exclude or quarantine. You confirm. An optional AI check in Settings is a second opinion.
Can I clean injected code without moving the whole file?
Yes, in PRO, when the plugin finds an injected block in a theme or configuration file. You review the block, then remove it. The original file is saved so you can restore it.
What does suspected breach cleanup do?
It walks you through backup, a deeper scan, review, handling, common persistence checks, passwords and plugins, and a rescan. You still approve every change.
Can I restore a changed WordPress core file?
Yes, in PRO, from the findings list. The official copy is written after a previous copy is saved, so you can ROLL BACK.
The page looks empty. Why is there a finding?
The match can be in stored HTML that the page builder does not show on the canvas. Open View code. Visitors typically see the builder version.
Does the scan check installed plugins?
Yes. Official plugin files are compared with the published copy. A plugin that is not in the official directory, or that was added recently and is not official, is listed for review. Installed icomm plugins and paid plugins from known vendors are not listed as unknown. Extra PHP that is not in the package can be quarantined. A small protection file that a plugin creates in a storage folder is not listed. There is no mass delete.
Can I restore an official plugin file automatically?
No. Review the finding, then reinstall the plugin from WordPress if the copy should match. Official plugin files are not overwritten automatically.
Does the scan check the database and administrator accounts?
Yes. It looks for suspicious stored settings, page content, new or oddly named administrators, and scheduled tasks. Cleanup is optional, with restore. Users are not deleted automatically.
| Price for 1 year(s) | $116 |
|---|---|
| Total to pay | $116 |
$116