Quttera ThreatSign – Web Malware Scanner for WordPress
by quttera 3.9 (47 reviews)

Quttera ThreatSign – Web Malware Scanner for WordPress

WordPress multi-level security scanner detecting malware, 0-day threats, brute-force attacks, bot attacks, and unauthorized admin changes.

Quttera ThreatSign ranks #2,042 among WordPress.org plugins with 10,000+ active installations, is #154 of 4,499 in the Security category, a 3.9/5 rating from 47 reviews, and was last updated Sep 15, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v4.1.0.36 Current Version v4.1.0.36
Updated 2 days ago Last Update on 15 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#154 of 4,499 in Security Top 5% by installs Downloads -8.7% this week Actively maintained
View on WordPress.org
Rank
#2,042
+4 this week
Active Installs
10K+
-18.3%
KW Avg Position
15.6
0.2 worse
Downloads
4.4M
+692 today
Support Resolved
100%
No change
Rating
78%
Review 3.9 out of 5
3.9 (47 reviews)

Next Milestone 20K

Total Progress 22.5%
10K+ 20K+
621
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 7,753 more installs to reach 20K+

Rank Changes

1,937 1,989 2,042 2,094 2,146 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
1,935 1,988 2,041 2,094 2,147 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #2,042
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 1K 2K 3K 4K 5K 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 1K 2K 3K 4K 5K 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

3.9
47 reviews
Overall 78%
5
33 (70%)
4
1 (2%)
3
1 (2%)
2
1 (2%)
1
11 (23%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
1
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

3 known vulnerabilities on record · 1 in the last 24 months · checked 1 week ago

  1. Quttera ThreatSign – Web Malware Scanner for WordPress [quttera-web-malware-scanner] < 3.5.2.1

    CVE-2025-8013 · Fixed in v3.5.2.1

  2. Quttera ThreatSign – Web Malware Scanner for WordPress [quttera-web-malware-scanner] < 3.4.2.1

    CVE-2023-6065 · Fixed in v3.4.2.1

  3. Quttera ThreatSign – Web Malware Scanner for WordPress [quttera-web-malware-scanner] < 3.4.2.1

    CVE-2023-6222 · Fixed in v3.4.2.1

TL;DR

AI summary of the plugin's readme

WordPress site owners and administrators who need to protect their site from malware and attacks. It scans for malicious code and threats, blocks brute-force logins and bot attacks, and monitors admin accounts for unauthorized changes.

  • On-demand malware scans
  • 0-day threat detection
  • Detects malicious PHP and JavaScript
  • Checkout skimmer detection
  • Blacklist checks across 40+ authorities
  • IP-based brute force locking
  • Bot protection for REST API and XML-RPC
  • Admin user change monitoring

Frequently Asked Questions

Common questions about Quttera ThreatSign – Web Malware Scanner for WordPress

This plugin uses Quttera's unique, patented malware scanning and detection technology. Its multi-layered heuristic engine gathers intelligence from the analyzed system and digests it into weighted rules to detect malicious code. A self-learning mechanism updates the ruleset using Quttera’s worldwide threat intelligence network.
The scanner identifies a wide range of threats, including: Obfuscated JavaScript Injected or malicious PHP code Hidden iframes, redirects, and links Spam and SEO malware Card skimmers targeting WooCommerce checkout pages Suspicious external links Backdoors and PHP shells Infected or modified WordPress core files Heuristic and AI-powered analysis enables detection of new or unknown malware, not just known signatures.
The free version includes: Malware Detection: * On-demand scans from the WordPress admin * Blacklist checks across 40+ services * Malware detection (JS, PHP, backdoors, spam, iframes, skimmers, etc.) * Investigation report with severity levels (Clean, Potentially Suspicious, Suspicious, Malicious) Brute Force Protection: * IP-based locking and failure detection * User account lockout protection * IP whitelist and blacklist management * Email alerts for locked accounts Bot Protection: * Rate limiting and risk-based evaluation * Legitimate bot recognition * REST API and WooCommerce endpoint protection * Configurable protection modes Admin User Monitoring: * Real-time detection of admin user changes * Email alerts for additions, removals, and role changes * Database audit trail with snapshots To enhance protection with automated responses, scheduled scanning, and advanced WAF features, upgrade to ThreatSign Website Security.
Traditional scanning uses signature matching. Heuristic scanning uses rules, weight-based systems, emulators, flow analyzers, and statistical methods to detect potentially malicious functionality, even in previously unknown threats.
Quttera’s severity levels indicate potential risk. If you're unsure whether a detection is harmful, our team can help. Contact us via ticket at https://helpdesk.quttera.com, email support@quttera.com, or the plugin’s WordPress Support Forum.
Yes. Our ThreatSign Website Security plans provide: Expert malware cleanup Automatic malware removal Continuous & scheduled scans Web Application Firewall (WAF) DDoS protection & mitigation Blacklist removal (40+ authorities) 24/7 monitoring & protection Learn more: https://quttera.com
This usually happens if your hosting assigns only one PHP worker. The scan process occupies the only worker, temporarily blocking the site until the scan completes.
Ensure JavaScript is enabled and your firewall isn’t blocking plugin requests. The plugin communicates with the backend via JavaScript-generated HTTP requests.
Use the "Download Report" button, save the file, and send it to us via https://helpdesk.quttera.com/open.php.
Your hosting may not allow WordPress Cron to function properly. You can enable an alternative cron method by adding this line to wp-config.php: define('ALTERNATE_WP_CRON', true);

Sign In / Register

You need to sign in or register to use this feature.