BrandBees Malware Guardian Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
BrandBees Malware Guardian is a powerful, easy-to-use local malware detection and removal tool for WordPress. It scans your WordPress installation’s filesystem and database for malicious code, injected scripts, backdoors, and other security threats. The plugin provides automated cleanup capabilities with automatic backups and rollback support.
Key Features:
- Filesystem Scanning – Scans themes, plugins, and uploads directories for malicious PHP, JavaScript, HTML, and CSS files
- Database Scanning – Scans posts, pages, options, widgets, and comments for injected scripts, spam links, and malicious shortcodes
- Signature-Based Detection – Uses comprehensive malware signature database to identify known threats
- Pattern Matching – Detects obfuscated code, base64-encoded payloads, eval() usage, and other suspicious patterns
- One-Click Cleanup – Automated patching with automatic backup creation before any changes
- Rollback Support – Restore original content from backups if needed
- Scheduled Scans – Daily or weekly automatic scans via WP-Cron
- Email Alerts – Receive notifications when new threats are detected
- Incremental Scanning – Only scan changed files and database records for faster performance
- Progress Tracking – Real-time progress updates during scans
How It Works:
- Navigate to BrandBees Malware Guardian in your WordPress admin menu
- Click Start Scan to begin scanning your site
- Review detected threats in the dashboard
- Use Clean button to automatically remove threats (with automatic backup)
- Configure scheduled scans and email alerts in settings
Use Cases:
- WordPress site owners monitoring their site security
- Web development agencies maintaining client sites
- WordPress maintenance providers
- Security-conscious website administrators
- Post-infection cleanup and verification
External services
This plugin can optionally use the following third-party services when you enable and configure them. No data is sent to any external service unless you explicitly enable the integration and provide your own API key.
-
PhishTank (Operated by Cisco Talos) – Used to check URLs against a database of known phishing sites. When enabled, the plugin downloads the PhishTank data feed (online-valid list) from PhishTank’s servers. No URLs from your site are sent to PhishTank; the feed is stored and used locally for lookups. Data is requested when you update the PhishTank database (manual or scheduled). Terms of use: https://phishtank.org/terms.php. Privacy policy: https://www.phishtank.org/privacy.php.
-
VirusTotal – Optional URL scanning. When you enable VirusTotal and enter your API key, the plugin may send URLs you choose to scan to VirusTotal’s API to get threat reports. Data is sent only when a scan uses the VirusTotal integration (e.g. when you run a scan that includes URL checks). Terms of service: https://www.virustotal.com/gui/terms-of-service. Privacy policy: https://www.virustotal.com/gui/privacy-policy.
-
Google Safe Browsing API – Optional URL threat lookup. When you enable it and provide an API key, the plugin may send URL hashes (not full URLs) to Google’s Safe Browsing API to check against Google’s threat lists. Data is sent only when a scan uses the Safe Browsing integration. Terms of service: https://developers.google.com/safe-browsing/v4/terms. Google privacy policy: https://policies.google.com/privacy.
WordPress.org APIs (e.g. core/plugin version checks) are used only to fetch update information; see WordPress.org privacy and terms for those services.
Privacy Policy
BrandBees Malware Guardian respects user privacy:
- Local scanning only: All scanning is performed locally on your server
- No external data transmission: Scan results are not sent to external servers unless you enable optional integrations (see External services above)
- Optional API integrations: PhishTank, Google Safe Browsing, and VirusTotal are optional and require your API keys where applicable
- Data storage: Scan results are stored locally in your WordPress database
- Backup storage: Backups are stored locally in wp-content/uploads/bbmg-backups/
Credits
Developed by Brand Bees (https://brandbees.net/)
Screenshots
No screenshots provided

