Deep Malware Cleaner
by Themepaste 0 (0 reviews)

Deep Malware Cleaner

Lightweight deep malware scanner for WordPress — deep scan, core integrity check, backdoor fixer, redirect hack fix, and login protection.

Deep Malware Cleaner ranks #21,788 among WordPress.org plugins with 40+ active installations, is #2,394 of 4,566 in the Security category, and was last updated Aug 13, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.6 (Current: 7.1.2)
v1.0.6 Current Version v1.0.6
Updated 1 month ago Last Update on 13 Aug, 2026
Refreshed 6 hours ago Last Refreshed on
#2,394 of 4,566 in Security Downloads -40% this week
View on WordPress.org
Rank
#21,788
No change
Active Installs
40+
+135.3%
KW Avg Position
68.8
34.2 better
Downloads
806
+4 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 50

Total Progress 50%
40+ 50+
1,790
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 5 more installs to reach 50+

Rank Changes

21,517 21,744 21,971 22,197 22,424 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
21,397 21,884 22,371 22,857 23,344 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #21,788
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Deep Malware Cleaner

No. The scanner runs only when you click Start Scan in the admin. It does not hook into page loads or run any background cron jobs. Visitor-facing performance is completely unaffected.
The scanner reads PHP-family files (.php, .php3, .php4, .php5, .php7, .phtml, .phar) plus the client-side formats most often used to deliver malware — JavaScript (.js, .mjs), HTML (.html, .htm), .svg, and .htaccess — inside your wp-content directory. To stay fast on shared hosting, it reads only the first 64 KB of each file (malware is injected at the top) and runs under a 20-second time budget per run.
Legitimate image, video, and document uploads are never .php files. If the scanner finds any PHP file inside wp-content/uploads/, it is almost certainly a backdoor uploaded through a vulnerable plugin or theme — a High severity threat that should be removed immediately.
The free plugin detects and reports threats, and lets you dismiss findings you've confirmed are false positives. Automatically moving an infected file out of harm's way — one-click Quarantine, with Restore to put it back — is available in Deep Malware Cleaner Pro. Without Pro you can still remediate manually: use the reported file path to remove or clean the file over SFTP or your host's file manager. Always review the file path and threat type before deleting anything.
Pro adds the one-click remediation engine: Quarantine safely moves an infected file to a protected, non-executable location (with a warning first if the file belongs to an active plugin or theme), and Restore puts it back if a detection turns out to be a false positive. Everything else — the file scan, database scan, pre-install upload guard, scheduled scans, email alerts, and login protection — is included in the free plugin.
Your scan results never leave your site — they are stored only in your own WordPress database. The plugin makes one external request, and only when you run the Core Integrity check: it downloads the official checksums for your WordPress version from api.wordpress.org, sending nothing but the version number and locale. If you never use that screen, no outbound request is made at all.
Every file in your WordPress installation is hashed with MD5 and compared against the official checksum list for your exact version and locale. Modified means a core file's contents no longer match the official release — the strongest single signal of a compromise. Unknown means a PHP file exists inside wp-admin or wp-includes that is not part of WordPress at all. Missing means a file in the checksums is not on disk, which some hosts cause by stripping optional files and is usually harmless.
Do not edit them by hand. Reinstall WordPress from Dashboard → Updates → Re-install now, which overwrites every core file with a clean copy and leaves your content, themes, and plugins alone. If files are still flagged afterwards, restore from a backup taken before the infection.
Not necessarily. The most common cause is an ordinary plugin that was deactivated or deleted without unscheduling its events, which leaves a hook behind that nothing listens for any more. Treat it as worth a look, not as proof. An event that is flagged both as an unknown hook and as having an obfuscated name is far more suspicious, since legitimate plugins do not name their hooks with random hex strings.
The flags describe patterns, not verdicts. An administrator you added last week is correctly flagged as a new account, and a colleague using a Gmail address is correctly flagged as an external email — both are perfectly normal. The audit's job is to make sure no administrator on the list is one you cannot account for. Nothing is ever changed or deleted automatically.

Sign In / Register

You need to sign in or register to use this feature.