Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

TeraServer Clinic Scan & Repair Kit Wordpress Plugin - Rating, Reviews, Demo & Download

TeraServer Clinic Scan & Repair Kit Preview Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

TeraServer Clinic is the on-site agent for the TeraServer Clinic service (wpclinic.ai). It connects your
WordPress installation to a TeraServer Clinic account and, depending on your plan, scans for
malicious code, keeps WordPress core/plugins/themes updated, backs up your files, and
applies AI-assisted cleanup when a threat is found.

The free scan works standalone with just a connection token — no payment required.
Paid plans add faster/scheduled autoscan, automatic updates, off-site backups, AI-assisted
repair of infected files, and monitoring across more sites.

Features

  • Malware scan: walks wp-content (uploads first) looking for PHP dropped in the
    uploads folder, double file extensions, known webshell/backdoor signatures, obfuscated
    eval() calls, and cryptomining scripts. Also checks the database for recently created
    administrator accounts and posts/options containing injected/obfuscated code.
  • Security hardening: one-click, reversible fixes for common misconfigurations
    (missing security headers, XML-RPC exposure, user enumeration, exposed readme/info
    files, file editor access, directory listing) plus a built-in login-URL cloak.
  • Automatic updates (paid plans): keeps plugins, themes and WordPress core current,
    each update guarded by an automatic backup, a post-update health check, and a rollback
    if anything breaks. A manual scan/update can also be triggered from the dashboard.
  • Autoscan: periodic scanning (daily or weekly depending on plan) via WordPress cron.
  • Backups (paid plans): a small “repair set” backup before any automated fix, an
    on-demand full-site backup, and an opt-in weekly full backup — all stored off-site on
    TeraServer Clinic’s backup storage, not on your own hosting.
  • PHP compatibility report: analyzes the plugins and themes actually in use to
    recommend the highest PHP version your site can safely run.
  • AI-assisted cleanup (paid plans): when malware is found, a proposed fix is generated
    off-site and applied through the plugin’s own audited code — never as a remote shell —
    always preceded by a backup and followed by a health check with automatic rollback if
    anything breaks.

This WordPress.org edition receives its own updates exclusively through the WordPress.org
plugin directory, like any other listed plugin — it does not use a custom update
mechanism for itself.

External services

This plugin is a thin client: on its own, without a connection, it does nothing. To do
anything useful it must be connected — via a one-time connection token generated in your
TeraServer Clinic account — to the TeraServer Clinic service, using an API key issued to your site. No
data described below is sent anywhere until you complete that connection step, which
itself shows this same disclosure and links to the Terms and Privacy Policy before you
submit a token.

Once connected, this plugin communicates with the TeraServer Clinic backend for the following,
each described with what is sent and when:

  • Connecting/licensing. When you paste a connection token, the plugin sends your
    site’s home URL and the plugin version to exchange that token for a per-site API key
    and your plan’s entitlements. This happens once at connection time, and again if you
    move the site to a different TeraServer Clinic account.
  • Periodic sync. Roughly twice daily (WordPress cron) and right after connecting, the
    plugin sends your site URL, WordPress version, PHP version, plugin version, the current
    login URL, and a full inventory of installed plugins/themes (name, version,
    active/inactive, available updates) so the service can tell you what needs attention
    and, on plans that include it, apply updates.
  • Scan reports. After every scan (free tier included), the plugin sends the list of
    findings — file paths/locations, finding type, and severity/detail text, not full file
    contents — so they show up in your TeraServer Clinic dashboard and can trigger email alerts.
  • Malware-signature confirmation. During any scan (free tier included), if a small,
    bounded set of files (at most 25 files, 1 MB each) already matches a local
    suspicious-pattern check, the plugin sends the full contents of just those flagged
    files
    to the TeraServer Clinic service for a second, server-side confirmation pass. Files that
    don’t match a local pattern first are never sent this way.
  • Off-site backups (paid plans). Manual and scheduled full-site backups, and the
    small “repair set” backup taken automatically before any destructive action (delete,
    repair, update), are uploaded as a zip to TeraServer Clinic’s backup storage, kept for a limited
    retention window so a site can be restored.
  • AI-assisted repair (paid plans). When you request a fix for detected malware, the
    full contents of the specific flagged file(s) (never your whole site) are sent to
    the TeraServer Clinic service, which returns a proposed cleaned version. That content is used
    only to produce the fix and is not retained afterwards. The plugin applies the returned
    patch itself, using its own code — the fix is never executed as a remote script — and
    always backs up first and rolls back automatically if a post-fix health check fails.
  • Admin email breach check. On a connected site, the plugin sends your WordPress
    admin email address to the TeraServer Clinic service, which checks it against known public data
    breaches and returns whether/how many breaches matched (not the breach data itself).
  • Plugin/theme alternative & compatibility suggestions. The plugin sends the slugs and
    versions of installed plugins/themes so the service can suggest actively-maintained
    alternatives or flag PHP/WordPress compatibility issues — no file contents are sent for
    this.

Separately, and independent of the TeraServer Clinic connection above:

  • Cloudflare Turnstile (opt-in, your own keys). If you choose to turn on the optional
    captcha/bot-protection feature on the Security tab, you paste your own free Cloudflare
    Turnstile sitekey and secret key (obtained directly from Cloudflare, not from TeraServer Clinic).
    From then on, the login/comment/registration pages you enabled it for load Cloudflare’s
    Turnstile script (challenges.cloudflare.com), and each submission’s response token is sent
    to Cloudflare’s siteverify endpoint for validation. No data goes to TeraServer Clinic for this
    feature — only to Cloudflare, using your own account. See Cloudflare’s Privacy Policy
    (https://www.cloudflare.com/privacypolicy/) for their handling of this data. If left off
    (the default), no data is ever sent to Cloudflare.

All of the above only happens after you connect the plugin with a valid API key; a
disconnected/inactive install sends nothing. See the TeraServer Clinic Terms of Service
(https://wpclinic.ai/legal/terminos) and Privacy Policy
(https://wpclinic.ai/legal/privacidad) for the full data-handling and retention terms.

Screenshots

  1. Dashboard overview: plan, auto-update status, autoscan cadence, site health, and last scan result.

    Dashboard overview: plan, auto-update status, autoscan cadence, site health, and last scan result.

  2. Cleanup: finds files, folders and database junk that nothing on your site references anymore, and moves them to a reversible quarantine (nothing is ever deleted outright).

    Cleanup: finds files, folders and database junk that nothing on your site references anymore, and moves them to a reversible quarantine (nothing is ever deleted outright).

  3. Alerts / findings list with severity and file/location detail.

    Alerts / findings list with severity and file/location detail.

  4. Harden: one-click, reversible WordPress security hardening (headers, XML-RPC, user enumeration, and more).

    Harden: one-click, reversible WordPress security hardening (headers, XML-RPC, user enumeration, and more).


Reviews & Comments