icomm Malware Guard v0.8.19

A diagnosis and handling tool for suspicious WordPress files: scan, findings, quarantine, and ROLL BACK. Not a WAF and not a regularly updated antivirus.

Overview

icomm Malware Guard is a practical tool for a suspected incident: scan, understand, and isolate files one by one with ROLL BACK. No automatic deletion, and no promise that it catches «everything».

The scan is split into four detection types: A suspicious location, B built-in content patterns, C WordPress core and official plugin files, D database, administrator accounts, scheduled tasks, and unknown plugins. Severity is shown in a separate column.

What you get in a scan

  • Level A: files in problematic locations (for example PHP in the uploads folder, a double extension).
  • Level B: a match to built-in suspicious content patterns (for example common webshell patterns).
  • Level C: WordPress core files, and official plugin files, that were changed or are missing.
  • Level D: stored settings, page content, administrator accounts, scheduled tasks, and plugins that are not in the official directory.
  • Also checks configuration files, must-use plugins, the active theme, and installed plugins against the official copy when available.
  • Free: a real count + a shortened list. PRO: full path, reason, code view, and automatic checks with an email on new critical findings.

Controlled handling (PRO)

  • Automatic checks (PRO): daily or weekly scan. An email is sent only when a new critical finding appears. The plugin does not change files by itself.
  • Quarantine only after an admin confirms. No automatic deletion.
  • ROLL BACK: restore the file to its original path from the quarantine screen.
  • You can inspect the file contents before deciding.
  • Built-in review of the file or stored content: a recommendation to exclude or quarantine when it looks like a cache file or a login log. You still confirm.
  • Select several findings and exclude, quarantine, or dismiss them together.
  • When a WordPress core file was changed or is missing, you can restore the official copy. The previous file is saved so you can ROLL BACK.
  • An extra PHP file that is not in the official plugin package can be moved to quarantine after review. Official plugin files are not deleted in bulk.
  • When an injected block is found in a theme or configuration file, you can remove that block and keep the rest of the file. The original is saved for ROLL BACK.
  • When a stored setting, page, or scheduled task is flagged, you can clean it after review. A copy is saved so you can restore it. Administrator accounts are never deleted automatically.
  • Optional AI check (your API key in Settings): review one finding or all open findings. The flagged block is sent. A recommendation to exclude or quarantine. You still confirm.

Who it is for

  • You want the site checked on a schedule, with an email only if a new critical finding appears.
  • You suspect a breach and want to see what is actually suspicious on the site.
  • Focused cleanup of a single file or stored item with a way back.
  • Restore a changed WordPress core file from the official copy.
  • Check whether WordPress core files were changed.
  • Check whether installed plugin files were changed, and review unknown or recently added plugins.

What it is not

  • Not a firewall (WAF) and not continuous protection on every request.
  • Does not replace a full backup or a hosting-level cleanup.
  • Does not promise to catch every new or custom malware.

What's new in 0.8.19
Alert emails include the plugin logo and a designed layout.

What's new in 0.8.18
Display improvements on the plugin details page.

What's new in 0.8.17
English plugin details on English store pages.