Malcure Security Suite
Malcure Security ★★★★★ Protect your WordPress site from hacks and downtime. Malcure Security Suite is a fast, lightweight, cloud-connected security platform for WordPress. It performs deep server-side scans (files + database) to catch malware and unauthorized changes, allows you to monitor login activity, enables a site-wide forced re-login after incidents, and sends email alerts of incidents upon scan. Built for commercial workloads—WooCommerce stores, memberships, LMS, bookings, directories, and multi-vendor marketplaces—it plays nicely with caching/CDNs and won’t get in the way of checkout, lessons, or bookings. What Malcure Security Suite Focuses On Detect: Deep server-side malware scans (files + database), integrity/diff checks, and vulnerabilities. Control: Session analytics (user/IP/device), Emergency Logout (everyone except you), rotate auth keys & salts to invalidate tokens, and force site-wide re-login post-incident. Compatible with 2FA/SSO. Report: Clear, actionable summaries with exact file paths and reasons, email alerts with next steps, and audit-friendly logs for teams and compliance (coming-soon). Logging: Event logs with identifiable and traceable details. How It Works (SaaS) Secure Handshake: Your site authenticates with Malcure and pulls fresh threat intelligence (signatures, heuristics, rules and analysis). Local-first scanning: Scans your files and database in the background. Severity-ranked results: Findings are grouped by Critical/High/Medium/Low with exact specs, the reason they were flagged, and one-click actions plus email alerts and audit-ready logs. Graceful: If the cloud is temporarily unreachable, Malcure Security Suite continues with last-known rules and logs locally until it reconnects. Features Deep server-side malware scans (files + database) using tuned signatures + heuristics. Background scanning so long runs finish reliably on large sites. Low overhead by design; preserves Core Web Vitals and optimized to minimize impact on site speed Session management: see who’s logged in, from where. Emergency Logout: one-click sign-out (everyone except you); rotate auth keys & salts to invalidate sessions. Robust Event Monitor. Optimal Dark Mode. Highlights Signature + heuristic detection for obfuscated/injected PHP/JS (backdoor/web-shell traits). Database scan of options, postmeta, posts, and comments for malicious payloads. Email notifications for critical events and scan results Security status panel (permissions, environment) Compatible with WooCommerce, LearnDash/TutorLMS, MemberPress/PMP, major booking/event plugins, WPML/Polylang, Elementor/Divi/Block Editor, and caching/CDNs (LiteSpeed Cache, WP Rocket, NGINX FastCGI, Cloudflare). Premium (Pro) Scheduled scans (daily/weekly/monthly) with summary emails. WP-CLI automation for headless/CI workflows and cron. Priority support with accelerated SLAs.
Top keywords
- security6×1.53%
- database5×1.27%
- malcure5×1.27%
- scans5×1.27%
- email4×1.02%
- files4×1.02%
- logs4×1.02%
- malcure security4×1.02%
- alerts3×0.76%
- deep3×0.76%
- deep server-side3×0.76%
- email alerts3×0.76%
Safe Sites
Safe Sites provides advanced security features to help keep your WordPress website safe from threats. With real-time monitoring, detailed security insights, and easy-to-use permission management, you can ensure your site is always protected. Key Features Two-Factor Authentication (2FA) – Secure your login with TOTP-based 2FA. Smart File Permission Control – Easily manage file permissions based on your server type (Windows/Linux). Visual File Permissions Map – See a color-coded structure of your site’s file security. Malware Scanner – Analyze your domain, URLs, and HTML security headers for vulnerabilities via VirusTotal. Security Dashboard – View a complete overview of your site’s security health. Plugin & Theme Security – Detect vulnerabilities in plugins and themes and receive alerts. Login & User Security – Monitor login attempts and manage user sessions. Site Hardening – Apply recommended security tweaks to your WordPress installation. Code Signing – Verify the integrity of your plugin files. Detailed Features General Security & Server Health: SSL Status – Check if SSL is active for secure connections. Site Health & Server Info – Displays PHP version, database version, and server details. Panic Mode – Quickly lock down your site in case of an emergency. Access & User Security: Two-Factor Authentication (2FA): TOTP Support – Use Google Authenticator, Authy, or any TOTP app. Configurable for All Roles – Require 2FA for specific user roles. Backup Codes – Generate backup codes for emergency access. Login Monitoring – Track failed login attempts and monitor user activity. Security Monitoring & Protection: File Permissions Management: Windows Servers – Show file read/write permissions. Linux Servers – Display numeric file permissions along with current and recommended settings. Fix Permissions – Select files and fix incorrect permissions directly. Visual File Permission Map – Interactive file structure with security indicators. Hardening – One-click security hardening for common WP vulnerabilities. Code Signing – Ensure plugin files haven’t been tampered with. Malware & Security Scanner: Domain & URL Analysis – Scan domain and URLs for malware using VirusTotal API. Security Header & DNS Scan – Check security headers and DNS settings. Alert System – Receive alerts for detected threats. WordPress Management & Security: Plugin & Theme Security: Vulnerability Scanner – Check for known security flaws. Inactive Plugin Alerts – Warns about inactive components that pose risks. Security Dashboard – A centralized panel for all security settings. External Services Used Safe Sites relies on the following third-party services for security analysis and malware detection. Below is a detailed breakdown of what each service does, what data is sent, and where you can review their policies: 1. VirusTotal API Purpose: Used to scan domain, URLs, and file hashes for malware detection and security threats. What data is sent & when? – When a user initiates a manual malware or URL scan, the plugin sends the target URL or domain to VirusTotal for analysis. – No user private data is sent—only the target URLs/domains or hash values of files are transmitted. Terms of Service & Privacy Policy: – VirusTotal Terms of Service – VirusTotal Privacy Policy