跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Malcure Security Suite

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Malcure Security Suite

由 Malware Intercept 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

Malcure Security

★★★★★

Protect your WordPress site from hacks and downtime.

Malcure Security Suite is a fast, lightweight, cloud-connected security platform for WordPress. It performs deep server-side scans (files + database) to catch malware and unauthorized changes, allows you to monitor login activity, enables a site-wide forced re-login after incidents, and sends email alerts of incidents upon scan. Built for commercial workloads—WooCommerce stores, memberships, LMS, bookings, directories, and multi-vendor marketplaces—it plays nicely with caching/CDNs and won’t get in the way of checkout, lessons, or bookings.

What Malcure Security Suite Focuses On

  • Detect: Deep server-side malware scans (files + database), integrity/diff checks, and vulnerabilities.
  • Control: Session analytics (user/IP/device), Emergency Logout (everyone except you), rotate auth keys & salts to invalidate tokens, and force site-wide re-login post-incident. Compatible with 2FA/SSO.
  • Report: Clear, actionable summaries with exact file paths and reasons, email alerts with next steps, and audit-friendly logs for teams and compliance (coming-soon).
  • Logging: Event logs with identifiable and traceable details.

How It Works (SaaS)

  1. Secure Handshake: Your site authenticates with Malcure and pulls fresh threat intelligence (signatures, heuristics, rules and analysis).
  2. Local-first scanning: Scans your files and database in the background.
  3. Severity-ranked results: Findings are grouped by Critical/High/Medium/Low with exact specs, the reason they were flagged, and one-click actions plus email alerts and audit-ready logs.
  4. Graceful: If the cloud is temporarily unreachable, Malcure Security Suite continues with last-known rules and logs locally until it reconnects.

Features

  • Deep server-side malware scans (files + database) using tuned signatures + heuristics.
  • Background scanning so long runs finish reliably on large sites.
  • Low overhead by design; preserves Core Web Vitals and optimized to minimize impact on site speed
  • Session management: see who’s logged in, from where.
  • Emergency Logout: one-click sign-out (everyone except you); rotate auth keys & salts to invalidate sessions.
  • Robust Event Monitor.
  • Optimal Dark Mode.

Highlights

  • Signature + heuristic detection for obfuscated/injected PHP/JS (backdoor/web-shell traits).
  • Database scan of options, postmeta, posts, and comments for malicious payloads.
  • Email notifications for critical events and scan results
  • Security status panel (permissions, environment)
  • Compatible with WooCommerce, LearnDash/TutorLMS, MemberPress/PMP, major booking/event plugins, WPML/Polylang, Elementor/Divi/Block Editor, and caching/CDNs (LiteSpeed Cache, WP Rocket, NGINX FastCGI, Cloudflare).

Premium (Pro)

  • Scheduled scans (daily/weekly/monthly) with summary emails.
  • WP-CLI automation for headless/CI workflows and cron.
  • Priority support with accelerated SLAs.

螢幕擷圖

  • Dashboard overview: Start a deep server-side scan in one click, review site status, control logins (Emergency Logout), and force re-login by rotating keys & salts—plus quick access to color scheme, connection, and license details.
  • Scan in progress: DeepScan™ runs in the background with real-time progress—non-blocking, reliable, and safe to navigate away while it completes.
  • Actionable results: Prioritized detections with clear severity labels and exact file paths so you can triage and remediate fast.
  • Light & dark UI: The same streamlined dashboard in light mode—readable, consistent, and accessible across themes.
  • First-run setup: Establish a secure cloud connection to Malcure services in seconds with minimal fields; privacy notice and color-scheme controls included.

安裝方式

Upload the plugin to your blog. Activate it. Create a support thread in case of any issues.

常見問題集

Will it work without connecting to Malcure services?

Malcure Security Suite is a cloud-connected solution. A working connection to Malcure services is required for core features like scanning, signatures/heuristics, and dashboards.

Will it slow down my website?

Malcure Security Suite is optimized for low overhead. Long scans run in the background so normal traffic isn’t blocked.

How does Malcure Security Suite find malware?

It runs deep server-side scans of WordPress files and the database using tuned signatures and heuristics, plus integrity hints to spot unauthorized changes. Vulnerability checks are included.

What happens when malware is detected?

You’ll see a clear report with paths, signatures/hashes, and guidance. Malcure Security Suite focuses on detection, control, and reporting—so you can act quickly and safely.

Does Malcure Security Suite include a firewall or automatic malware cleaning?

No. Firewall and one-click malware removal are to be implemented in upcoming versions. Malcure Security Suite plays well alongside reputable firewall or cleanup tools if you use them.

Can I control logins if something looks suspicious?

Yes. Use Emergency Logout to sign out everyone except you, and rotate keys & salts to force re-login across the site.

Is it compatible with WooCommerce and Multisite?

Yes. Malcure Security Suite is built and tested for WooCommerce stores and WordPress Multisite.

Can I schedule automatic scans?

Yes, in Pro. Schedule daily, weekly, or monthly scans at a chosen time.

Does it support WP-CLI?

Yes, in Pro. Run and manage scans from WP CLI.

How often are malware signatures updated?

Regularly. The cloud keeps signatures and heuristics current so detections stay effective.

Can I use Malcure Security Suite with other security plugins?

Yes. Malcure Security Suite is designed to coexist with reputable security/firewall plugins.

I already have backups. Why do I need Malcure Security Suite?

Backups are essential, but they don’t detect active compromises and can end up restoring vulnerabilities and backdoors. Malcure Security Suite reduces “dwell time” by surfacing issues early so you can restore or remediate with confidence without losing data.

Will Malcure Security Suite work if my site is down or blocked from the internet?

Scanning requires the site to be reachable and allowed to connect out. If outbound requests are blocked or the site is offline, scanning and dashboards won’t run until connectivity is restored.

What data leaves my site?

Only what’s needed to deliver scanning and reporting. See Privacy & Data for details.

Is there a free vs Pro difference?

Free includes deep malware scans (files + DB), vulnerability checks, email alerts, session analytics, Emergency Logout, and keys/salts rotation. Pro adds scheduled scans, WP-CLI automation, and priority support.

How do I get support?

Free community support is available on the Malcure forums:
https://malcure.com/forums/
Priority support is included with Pro.

Who is Malcure Security Suite for?

Site owners who want clear, actionable detection; agencies managing many sites; and hosts/maintainers standardizing incident controls across fleets.

使用者評論

The ONLY plugin that scans files in real-time.

Zeeshan A. 2025 年 4 月 26 日
I am a web developer and have tried many security plugins with millions of downloads, but none compare to MalCure. This plugin thoroughly scans all files and accurately detects malware-infected files in WordPress installations. I have used Wordfence and several other top-rated plugins, but none were able to detect the hidden infected files. Surprisingly, MalCure works exceptionally well and identifies all malware-infected files effectively.

works in the background

michelleroberts237 2025 年 2 月 28 日
I always come back to this. I initiate a scan and it finds everything.
閱讀全部 2 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈Malcure Security Suite〉的開發相關工作。

參與者
  • Malware Intercept
  • Malcure Web Security
  • cybermalcure

將〈Malcure Security Suite〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

3.1

  • UX: Added new checksum endpoint.

3.0

  • Feature: Event Log.
  • Bugfix: Toggling cron did not retain previous schedule.
  • UI: Revamped Setup screen.

2.9

  • Bugfix: Fixed a bug where UI would show undefined on the operations progress screen.
  • Bugfix: Fixed a bug where UI would show inaccurate time elapsed for completed scans.
  • Bugfix: Added database exclusions where known database records would get flagged.

2.8

  • Bugfix: Fixed a bug where false unreadable file message would come up under certain conditions.

2.7

  • Feature: Schedule automatic scans daily, weekly and monthly at a day and time of your choosing. *Premium Feature.
  • Bugfix: Fixed various nonce validations.
  • Bugfix: Implemented stricted nonce checks.
  • Bugfix: Fixed an error when registration would time out under certain conditions.

2.6

  • Feature: Vulnerability scan.
  • Feature: Detect unreadable files and directories.
  • Bugfix: Scan recovery would not work under certain conditions.
  • Bugfix: Optimized checksum updates.

2.5

  • Feature: Added summary of scan.
  • Feature: Better email summary of issues detected during scan.

2.4

  • Bugfix: Fixed cron scheduling.
  • Bugfix: Updated email notifications.
  • Bugfix: Fixed scan recovery attempts.
  • Bugfix: Fixed typo in CLI deactivation.

2.3

  • Bugfix: Fixed broken scan recovery.

2.2

  • Feature: Cron scheduling for periodic scans in Premium Edition.
  • Feature: Continue broken scans.
  • Feature: Sleep occasionally for low CPU usage and stability.
  • Feature: New commands in WP CLI mode.
  • Others: Code refactoring.
  • Others: Documentation.

2.1

  • Bugfix: Ensure low CPU usage during scan.
  • Others: removed donation links.

2.0

  • Feature: WP CLI integration in pro version.
  • Bugfix: Cancelling scan took a long time.
  • Others: Updated UI.

1.9

  • Feature: Better UI Updates.
  • Feature: Easier load handling for server.
  • Feature: Uninstall script.
  • Bugfix: Email notifications not being sent.
  • Bugfix: Some database records skipped during scan.
  • Bugfix: Scan couldn’t be cancelled undersome instances.

1.8

  • Bugfix: Database scan progress not reported.
  • Bugfix: Calls to localhost could break.

1.7

  • Bugfix: Updated UI for first-run.
  • Minor: Updated compatibility.

1.6

  • Feature: Major UI Update.
  • Bugfix: Fixed skin change.
  • Bugfix: Support for large scans.

1.5

  • Updated Readme
  • Updated Compatibility

1.4

  • Feature: UI Update.
  • Several stability improvements.

1.3

  • Feature: UI Update.
  • Bugfix: database scan sometimes kills the entire scan.
  • Bugfix: database scan sometimes exits midway.
  • Bugfix: Limited database scan by size.
  • Several other minor bugfixes.

1.2

  • Bugfix: Scan would break on certain hosts.

1.1

  • Major revamp.
  • Server-side scanner built from scratch.

0.6

  • Tested for compatibility with WordPress 6.0.1

0.5

  • Implemented basic scanner

0.4

  • Streamlined features.

0.3

  • Feature: System Status.

0.2

  • Feature: Shuffle WordPress salts.
  • Feature: WordPress Integrity Check.

0.1

  • Submitted for review.

中繼資料

  • 版本 3.1
  • 最後更新 8 個月前
  • 啟用安裝數 200+
  • WordPress 版本需求 3.7.4 或更新版本
  • 已測試相容的 WordPress 版本 6.8.5
  • PHP 版本需求 5.6 或更新版本
  • 語言
    English (US)
  • 標籤:
    firewallloginmalwarescannersecurity
  • 進階檢視

評分

5 星,滿分為 5 星
  • 2 個 5 星使用者評論 5 星 2
  • 0 個 4 星使用者評論 4 星 0
  • 0 個 3 星使用者評論 3 星 0
  • 0 個 2 星使用者評論 2 星 0
  • 0 個 1 星使用者評論 1 星 0

Your review

查看全部使用者評論

參與者

  • Malware Intercept
  • Malcure Web Security
  • cybermalcure

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.