Turbo Guard – Security & Malware Scanner Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Turbo Guard is a comprehensive, 100% free WordPress security plugin built by a team that manages 40+ WordPress sites. It solves real problems: bulk malware removal, Japanese/Chinese SEO spam cleanup, vulnerability alerts, file integrity monitoring, and live traffic analysis — all with AI-powered guidance that explains what happened and exactly what to do.
AI Security Advisor
- After every scan, Turbo Guard AI identifies the attack campaign (Japanese SEO spam, web shell, brute force, database injection)
- Explains in plain English what happened and the business risk
- Provides numbered, step-by-step fix instructions tailored to your specific threats
- Optional OpenAI GPT integration for richer analysis (your own API key)
- Sends email advisory after every scan
- 30-day security score trend chart
Malware Scanner
- Full-site scan: PHP, JavaScript, HTML files across wp-content, wp-admin, wp-includes, and WordPress root
- WordPress Core File Manifest check — compares every file in wp-admin and wp-includes against the official WordPress.org checksums API
- Detects 30+ malware patterns: eval+base64, C99/R57/WSO web shells, hidden iframes, pharma spam, code obfuscation
- Detects Japanese, Chinese, and Korean SEO spam text inside PHP files
- Scans the WordPress database (wp_posts, wp_options) for injected content and rogue admin accounts
- PHP-in-uploads detection, PHP-in-core-asset-dirs detection
- Polyglot image backdoor detection — scans image files for embedded PHP
- Smart false-positive prevention: trusted plugins and themes are never flagged for translation text
- Chunked AJAX scanning with live progress bar — handles 10,000+ file sites without timeout
File Integrity and Change Detection
- Verifies every WordPress core file against official WordPress.org MD5 checksums
- Detects modified or missing core files
- File watcher runs every 6 hours via WP-Cron — detects new, modified, and deleted files
- Baseline snapshot of all wp-content PHP/JS files with MD5 comparison
- Email alert when new files appear
One-Click Bulk Malware Cleanup
- Shows every infected file with path, threat name, severity, and file size
- Select All Critical button — delete multiple files at once
- Automatic ZIP backup before any deletion
- Quarantine option — moves files to a protected directory
Web Application Firewall
- Blocks SQL injection, XSS, directory traversal in real time
- Prevents PHP file uploads
- Advanced IP blocking: exact IP, CIDR, ranges, wildcards
- Rate limiting (120 requests per minute per IP)
- Bad bot blocker: blocks 25+ vulnerability scanners and scrapers
Geo-Fence and Trusted Location
- Restrict WordPress admin access to specific IP addresses
- Country-based admin lock: only allow access from your country
- Block file uploads from untrusted countries
- One-click trusted IP setup
Login Security
- Brute force protection with configurable thresholds and lockout duration
- Login attempt logging with IP, timestamp, and user agent
- Email alert when admin logs in from unrecognised IP
- Auto-blocks attacker IPs in firewall after brute force detection
Two-Factor Authentication (2FA)
- TOTP/RFC 6238 — compatible with Google Authenticator, Authy, and all TOTP apps
- Manual secret key setup on user profile page
- Recovery codes (8 single-use)
- Per-user enable/disable
Vulnerability Scanner
- Checks all plugins, themes, and WordPress core against WPScan vulnerability database
- CVSS severity scoring, CVE links, version-aware matching
- Works without API key (optional WPScan key for higher limits)
- Email alert when new vulnerabilities are found
Live Traffic Monitor
- Logs every HTTP request with bot/human detection
- Identifies 30+ bots including AI crawlers (GPTBot, ClaudeBot, PerplexityBot)
- 24-hour stats: total requests, humans, bots, blocked, errors
- Paginated — handles large traffic volumes
- One-click IP block from any traffic row
Site Hardening
- HTTP security headers (X-Frame-Options, HSTS, X-Content-Type-Options, Referrer-Policy)
- Hide WordPress version, block user enumeration
- Optional: disable XML-RPC, restrict REST API, disable file editor
Google Search Console Cleanup
- Connects to Google Search Console via OAuth
- Detects indexed SEO spam URLs even when files are deleted from server
- Bulk removal requests with one click
- Sitemap resubmission after cleanup
Privacy
Turbo Guard does not send your website files to any external server. Vulnerability checks send only plugin/theme slugs and versions to the WPScan API — and only on manual scans or when scheduled vulnerability scans are enabled in Settings (off by default). Geo-Fence country blocking sends the visitor IP address to ipapi.co when enabled. 2FA is fully local: TOTP secrets are entered manually in your authenticator app and no QR service is used. GSC integration uses your own Google OAuth credentials. AI analysis (optional OpenAI) sends only anonymised threat type data. No telemetry. No tracking. No account required.
External Services
This plugin connects to external services for certain features. All connections require explicit user action or opt-in.
WordPress.org API
Used to verify WordPress core file integrity by comparing checksums.
* Data sent: WordPress version and locale
* When: Only when the user runs a malware scan or a file integrity check (including scheduled scans)
* Service: https://api.wordpress.org/
* Privacy Policy: https://wordpress.org/about/privacy/
WPScan Vulnerability Database
Used to check plugins and themes for known security vulnerabilities.
* Data sent: Plugin/theme slugs and versions
* When: Only when the user runs a manual vulnerability scan, or when scheduled vulnerability scans are enabled in Settings (off by default)
* Service: https://wpscan.com/
* Terms of Use: https://wpscan.com/terms
* Privacy Policy: https://automattic.com/privacy/
ipapi.co (Geo-Fence)
Used for IP geolocation to support country-based access and upload controls (Geo-Fence).
* Data sent: Visitor IP address
* When: Only when geo-fence country features are enabled
* Service: https://ipapi.co/
* Terms of Service: https://ipapi.co/terms/
* Privacy Policy: https://ipapi.co/privacy/
OpenAI API
Used to provide AI-powered security analysis and recommendations.
* Data sent: Anonymized scan results (no personal data or site content)
* When: Only when user explicitly clicks “AI Analysis” (requires user-provided API key)
* Service: https://api.openai.com/
* Terms of Use: https://openai.com/policies/terms-of-use
* Privacy Policy: https://openai.com/policies/privacy-policy
Google APIs (Search Console)
Used for Google Search Console integration to detect SEO spam and manage indexed URLs.
* Data sent: OAuth tokens, site URL for search analytics queries
* When: Only when user connects their Google account and initiates GSC features
* Service: https://developers.google.com/webmaster-tools
* Terms of Service: https://developers.google.com/terms
* Privacy Policy: https://policies.google.com/privacy
Screenshots
No screenshots provided

