SPM by Marwan
SPM by Marwan is a professional-grade diagnostics and intelligence platform designed for WordPress administrators and developers. It provides deep visibility into your WordPress ecosystem, offering real-time monitoring, security auditing, and performance profiling to ensure your site remains fast, secure, and stable. The Problem Managing a modern WordPress ecosystem is inherently complex. Site owners and developers frequently struggle with: Slow Extensions: Identifying which specific extension is degrading page load times or consuming excessive server resources. Hidden PHP Errors: Unseen warnings and fatal errors that silently break functionality or create vulnerabilities. Security Risks: Unmaintained, abandoned, or vulnerable code exposing the site to potential exploits. Trust Issues: Uncertainty regarding an extension’s origin, development standards, and code quality. Update Degradation: Performance regressions and unexpected conflicts introduced immediately after updates. Core Features Real-Time Monitoring Engine: Actively tracks resource consumption, database queries, and execution times for every active extension. Identifies performance bottlenecks as they happen, preventing systemic slowdowns. Performance Diagnostics: Deep-dive profiling for individual extensions. Analyzes memory footprint and script execution to provide actionable intelligence on resource utilization. Security & Integrity Scanner: Proactively audits installed extensions against known vulnerability databases, flags high-risk code patterns, and verifies WordPress core files against official checksums to detect malicious tampering. Japanese SEO Spam Auto-Fix Engine: A specialized, deep-scanning engine designed to detect and eradicate the notorious “Japanese Keyword Hack”. Features a one-click Auto-Fix that intelligently restores or quarantines hijacked posts to protect your Google ranking without destroying your original content. Advanced Security: Defeating the Japanese SEO Keyword Hack The “Japanese Keyword Hack” is a devastating black-hat SEO attack where hackers exploit vulnerabilities in outdated plugins to inject massive amounts of auto-generated Japanese text and malicious links into your database and core files. This causes Google to flag your site as “hacked,” instantly destroying your SEO ranking. SPM by Marwan includes a highly specialized engine specifically built to defeat this attack: Deep Database Scanning: Actively crawls your wp_posts and wp_options tables, utilizing advanced Unicode block detection to find injected Japanese Hiragana, Katakana, and Kanji spam hidden within your legitimate content. Intelligent Auto-Fix (No Data Loss): When you click “Auto-Fix”, the scanner doesn’t just blindly delete your hijacked posts. Instead, it scans the WordPress Revision History for each infected post. It finds the last “clean” version of your post (before the hacker touched it) and seamlessly restores it. Fail-Safe Quarantining: If a post was created entirely by the hacker (meaning no clean revision exists), or if you have revisions disabled, the engine will safely quarantine the post by setting its status to Draft. This instantly removes the spam from the public internet—stopping the SEO bleed—while preserving the draft in your admin panel so you don’t lose any data. Orphaned File Detection: Scans your entire server structure to locate and quarantine backdoor PHP scripts that hackers leave behind to reinfect your site after you clean it. Core Checksum Verification: Verifies every single WordPress core file against the official WordPress.org cryptographic checksums to detect hidden cloaking scripts. Trust Verification: Evaluates code based on developer reputation, update frequency, repository standing, and code integrity. Establishes a trust score to help you make informed decisions about your technology stack. Historical Analytics: Maintains a robust ledger of performance and security metrics over time. Visualizes trends to help you understand the long-term impact of specific extensions and updates. Action Layer (Scan / Safe Mode / Reporting): Provides immediate remediation tools. Execute targeted scans, isolate problematic extensions using Safe Mode, and generate comprehensive diagnostics reports. External Services This plugin utilizes the WordPress.org Plugins API (https://api.wordpress.org) to verify plugin licenses and retrieve information about installed plugins. * What data is sent: The names and slugs of your active plugins are sent in the API request. * When it is sent: Data is sent when the plugin performs a scheduled background scan or when you manually click “Deep Scan” or “Refresh Now” on the dashboard. * Why it is used: To verify that the plugins running on your site are authentic, properly licensed, and available on the official WordPress.org directory, which enhances your site’s security and trust metrics. For more information, please refer to the WordPress.org Privacy Policy.
Top keywords
- wordpress11×1.58%
- site7×1.01%
- japanese6×0.86%
- security6×0.86%
- code5×0.72%
- core5×0.72%
- engine5×0.72%
- extensions5×0.72%
- org5×0.72%
- performance5×0.72%
- seo5×0.72%
- wordpress org5×0.72%
Web Plura Diagnostics – Site Health,
Web Plura Diagnostics helps WordPress site owners, agencies, and support teams find problems that quietly hurt leads, sales, trust, and maintenance time. It runs inside wp-admin and turns local site signals into clear, prioritized action items. Use it when you need to answer practical questions before an update, launch, client handoff, or support call: Are forms, password resets, store emails, and lead notifications likely to work? Is the site showing health, hosting, cache, cron, or PHP warning signs? Which plugin, theme, or update risks should be checked before making changes? What should a business owner, developer, host, or support team fix first? What can be exported or shared without sending diagnostics to an external service? For every finding, the plugin focuses on: What is wrong Why it matters What business impact it may cause Who should fix it What to fix first No external account, no tracking, and no frontend scripts are required for the core diagnostics workflow. No external service requirement: core diagnostics, dashboard rendering, exports, and scheduled scans run locally in WordPress. No tracking: diagnostics scans do not send telemetry or site diagnostics to Web Plura by default. Free local checks remain available without an external account. Customer Problems It Helps Solve Missed leads from broken contact forms, weak email setup, or untested notification paths. Risky updates when a site has stale plugins, inactive code, commerce dependencies, or no clear pre-update checklist. Slow or unstable sites caused by cache gaps, low memory, cron pressure, upload limits, or hosting constraints. Confusing support handoffs where clients, developers, and hosts need the same problem summary. Reactive maintenance where issues are discovered only after checkout, login, email, or lead capture fails. Key Checks Fix First dashboard with score, priority groups, recommended actions, and recent-change history. Site Health-style checks for WordPress, database version, PHP limits, timezone, URL alignment, cache signals, and key file permissions. Email readiness checks for local mail transport, SPF, DKIM, DMARC, domain alignment, manual admin-triggered test email results, and optional bounded metadata-only test history. Diagnostics scans do not send email automatically. Lead Capture Health checks for form plugins, contact pages, SMTP readiness, privacy-page status, and form-plugin updates. Pre-update Safety checks for inactive plugins, theme update backlog, commerce plugins, builders, and cache plugins. Hosting Advisor checks for memory, cache, cron pressure, upload limits, execution limits, and host-support guidance. Cron & Background Jobs checks for WP-Cron configuration, overdue events, orphaned callbacks, repeated hooks, Action Scheduler presence, and WooCommerce queue backlog signals. Front-end Response checks for home URL HTTPS, response code, redirect signal, cache-control, compression header, and REST API response. Support-safe diagnostics snapshot with redacted environment, module scores, and top findings for support handoffs. Client-ready diagnostics with problem, impact, owner, urgency, next action, JSON/CSV exports, WP-CLI commands, and multisite network visibility. Good Fit For Site owners who want a clear first-pass health, email, performance, and update-readiness review. Agencies preparing client reports, maintenance checks, launch reviews, or pre-update safety notes. Support teams collecting safe local diagnostics before deeper troubleshooting. WordPress admins who want prioritized actions without telemetry or a required external account. Product page: https://wplura.com/products/web-plura-diagnostics Terms: https://wplura.com/terms Privacy: https://wplura.com/privacy External Services Web Plura Diagnostics is local-first. Diagnostics scans, dashboard rendering, exports, and scheduled scans run inside WordPress by default. The plugin links to Web Plura product, terms, and privacy pages for support and product information: Product page: https://wplura.com/products/web-plura-diagnostics Terms: https://wplura.com/terms Privacy: https://wplura.com/privacy The public WordPress.org package uses WordPress.org update checks. Direct/private Web Plura builds may request a signed Web Plura release manifest from https://api.wplura.com/v1/plugin/updates/web-plura-diagnostics/manifest and send only the plugin slug, current version, and release channel. Data, retention, and uninstall behavior: Diagnostics results, history snapshots, explain-mode preference, scheduled-scan settings, export metadata, and manual test-email metadata are stored locally in WordPress options/transients. Retention settings allow site admins to control how long local diagnostic history and email-test metadata are kept. Uninstall cleanup removes plugin-owned options, transients, scheduled scan hooks, and local diagnostic metadata.