Anti-Malware Security and Brute-Force Firewall
by Eli 4.9 (783 reviews)

Anti-Malware Security and Brute-Force Firewall

This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.

Anti-Malware Security and Brute-Force Firewall ranks #304 among WordPress.org plugins with 100,000+ active installations, is #18 of 1,576 in the Authentication category, a 4.9/5 rating from 783 reviews, and was last updated Jun 29, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.4 (Current: 7.1)
v4.23.90 Current Version v4.23.90
Updated 2 months ago Last Update on 29 Jun, 2026
Refreshed 11 hours ago Last Refreshed on
#18 of 1,576 in Authentication Top 1% by installs Downloads -26.9% this week
View on WordPress.org
Rank
#304
No change
Active Installs
100K+
-47.7%
KW Avg Position
14
0.2 better
Downloads
7.9M
+440 today
Support Resolved
100%
No change
Rating
98%
Review 4.9 out of 5
4.9 (783 reviews)

Next Milestone 200K

Total Progress 89.9%
100K+ 200K+
18
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 10,056 more installs to reach 200K+

Rank Changes

284 294 304 314 324 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
283 293 304 314 324 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #304
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

400 500 600 700 800 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
400 500 600 700 800 900 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
783 reviews
Overall 98%
5
758 (97%)
4
19 (2%)
3
0 (0%)
2
1 (0%)
1
5 (1%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
1
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

22 known vulnerabilities on record · 4 in the last 24 months · checked 1 week ago

  1. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.90

    CVE-2026-57691 · Fixed in v4.23.90

  2. UNPATCHED

    Anti-Malware Security and Brute-Force Firewall [gotmls] <= 4.20.59 (unfixed)

    CVE-2021-47977 · No fix released

  3. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.88

    CVE-2026-39478 · Fixed in v4.23.88

  4. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.83

    CVE-2025-11705 · Fixed in v4.23.83

  5. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.56

    CVE-2024-22144 · Fixed in v4.23.56

  6. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86

    Fixed in v4.21.86

  7. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86

    CVE-2022-4327 · Fixed in v4.21.86

  8. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.96

    CVE-2022-0953 · Fixed in v4.20.96

  9. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.83

    CVE-2022-2599 · Fixed in v4.21.83

  10. Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.94

    CVE-2021-25101 · Fixed in v4.20.94

Showing the 10 most recent of 22 records.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want to detect malware, viruses, and other security threats on their server. It scans for known and potential threats like backdoor scripts, database injections, and vulnerable plugin code, and offers optional premium patches and brute-force protection for further hardening.

  • Downloads malware definition updates
  • Runs complete malware scans
  • Removes known security threats
  • Firewall blocks SoakSoak malware
  • Blocks Revolution Slider exploits
  • Upgrades vulnerable timthumb scripts
  • Patches wp-login and XMLRPC
  • Checks WordPress Core file integrity

Frequently Asked Questions

Common questions about Anti-Malware Security and Brute-Force Firewall

If you register on GOTMLS.NET you will have access to download definitions of New Threats and added features like automatic removal of "Known Threats" and patches for specific security issues like old versions of timthumb and brute-force attacks on wp-login.php. Otherwise, this plugin only scans for "Potential Threats" on your site, it would then be up to you to identify the good from the bad and remove them accordingly.
Easy, if you have installed and activated my this Anti-Malware plugin on your site then it will automatically block attempts to exploit the Revolution Slider vulnerability.
The WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. This plugin can apply a patch that will block access to the WordPress Login page whenever this type of attack is detected. Just click the Install Patch button under Brute-force Protection on the Anti-Malware Setting page. For more information on this subject read my blog.
Many of these files may use eval and other powerful PHP function for perfectly legitimate reasons and removing that code from the files would likely cripple or even break your site so I have only enabled the Auto remove feature for "Know Threats".
Click on the linked filename to examine it, then click each numbered link above the file content box to highlight the suspicious code. If you cannot tell whether or not the code is malicious just leave it alone or ask someone else to look at it for you. If you find that it is malicious please send me a copy of the file so that I can add it to my definition update as a "Know Threat", then it can be automatically removed.
First just leave it for a while. If there are a lot of files on your server it could take quite a while and could sometimes appear to not be moving along at all even if it really is working. If it still seems stuck after a while then try running the scan again, be sure you try both the Complete Scan and the Quick scan.
First, don't take the attack personally. Lots of hackers routinely run automated script that crawl the internet looking for easy targets. Your site probably got hacked because you are unknowingly an easy target. This might be because you are running an older version of WordPress or have installed a Plugin or Theme with a backdoor or known security vulnerability. However, the most common type of infection I see is cross-contamination. This can happen when your site is on a shared server with other exploitable sites that got infected. In most shared hosting environments it's possible for hackers to use an one infected site to infect other sites on the same server, sometimes even if the sites are on different accounts.
There is no sure way to protect your site from every kind of hack attempt. That said, don't be an easy target. Some basic steps should include: hardening your password, keeping all your sites up-to-date, and run regular scans with Anti-Malware software like GOTMLS.NET
sucuri.net caches their scan results and will not refresh the scan until you click the small link near the bottom of the page that says "Force a Re-scan" to clear the cache. Google also caches your infected pages and usually takes some time before crawling your site again, but you can speed up that process by Requesting a Review in the Malware or Security section of Google Webmaster Tools. It is a good idea to have a Webmaster Tools account for your site anyway as it can provide lots of other helpful information about your site.
You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.

Sign In / Register

You need to sign in or register to use this feature.