One-click malware removal, fix it without touching the filesystem.
When a scan flags an infected file, Guardian Gaze tells you exactly what to do next. For WordPress core, plugin, and theme files, it can automatically fetch a clean, original copy directly from the official WordPress.org repository and restore it, overwriting the infected code in one click. For unrecognized or custom malicious files that aren’t part of any active plugin or theme, Guardian Gaze performs a safety check to confirm the file isn’t in use, then lets you permanently delete it with a clear warning before removal.
Availability: included from Pro upwards, via the Premium add-on · One-click malware removal

The plugin view: findings, severity and next steps inside the WordPress admin
One-Click Malware Removal at a glance
Known file → restore
If the infected file belongs to WordPress core, an installed plugin, or a theme, Guardian Gaze pulls the clean version directly from the official WordPress.org repository, matching the exact version installed, and overwrites the infected copy.
Unknown file → safety-checked delete
If the file isn’t part of any active plugin or theme, a typical webshell or backdoor signature, Guardian Gaze verifies the file isn’t referenced anywhere in active code, shows you a clear warning, and lets you permanently delete it.
One-Click Malware Removal
When a scan flags an infected file, Guardian Gaze tells you exactly what to do next. For WordPress core, plugin, and theme files, it can automatically
Detection without removal is an accurate description of your problem
A scanner that finds malware and stops there has done the hard technical work and left you with the hard practical one. You now know there is a backdoor in a theme file at a path you have never opened, and it is late, and the site is live.
The market has largely settled on selling those two things separately. You buy the scanner, it finds something, and cleanup is a professional service billed per incident: typically between $200 and $500, sometimes more, usually with a turnaround measured in hours you do not have.
Pro includes removal at roughly $8 a month. That comparison is the entire commercial argument for the plan, and it survives being stated plainly: one incident, once, pays for several years of the licence.
Quarantine first, delete second
Removal cleans confirmed malware from files and from database rows, and it does it with quarantine underneath rather than in place of it. A suspect file is isolated so it cannot execute, and it can be restored if the call turns out to be wrong.
That ordering is what makes the button safe to press. Irreversible cleanup on a live site is a genuinely frightening action, and the fear is well founded: the failure mode of an aggressive scanner is deleting a legitimate file that a plugin needs, at which point you have traded a possible compromise for a certain outage.
For database findings, cleanup targets the flagged content rather than dropping whole rows, which matters because a wp_options row may contain one injected script inside a large legitimate settings blob. Deleting the row would take the settings with it.
What a plugin cannot fix from inside WordPress
Some things sit outside what any WordPress plugin can reach, and pretending otherwise is how people end up believing a site is clean when it is not.
A compromised hosting account, a stolen SFTP credential, a vulnerable server configuration, malware living outside the WordPress directory, or a backdoor in a cron job at the system level, none of those are reachable from inside WordPress, whatever the plugin claims. If the route back in is at the host level, cleaning WordPress buys you the interval until they use it again.
When removal cannot complete, you get the finding in full (path, severity, explanation) and quarantine to contain it, rather than a false all-clear. On Agency, critical findings can be escalated to the RedSecLabs research team.
One-Click Malware Removal - common questions
Which plan includes one-click removal?
Pro and above. Free and Basic report findings in full; Pro adds the removal action.
Is removal reversible?
Quarantine sits underneath it, so files are isolated rather than destroyed and can be restored. Take a backup before any cleanup regardless: that is true of every tool, not just this one.
Will it delete legitimate files?
Removal acts on confirmed findings, and quarantine makes the action reversible if a judgement was wrong. This is exactly why the safe path is isolate-then-verify rather than delete-and-hope.
What if the malware comes back?
Reinfection almost always means the route in was never closed, or a database row was missed. Run a database scan, check the audit log for the account that was used, and review hardening, recurrence is a symptom of an unfixed cause, not a failed cleanup.
Can it clean an infection outside WordPress?
No. Nothing running inside WordPress can. If the compromise is at the hosting account or server level, you need your host involved, and we would rather say so than report a clean site.
Works with
Malware Scanning →
Four detection methods, cross-referenced.
Database Scanning →
Payloads hide in tables, not just files.
File Integrity →
Byte-level change detection on every file.
See it on your own site
The free scan takes under five minutes and tells you the truth.

