Pro
Features · Protection

One-click WordPress malware removal, fix it without touching the filesystem.

When a scan flags an infected file, Guardian Gaze tells you exactly what to do next. For WordPress core, plugin, and theme files, it can automatically fetch a clean, original copy directly from the official WordPress.org repository and restore it, overwriting the infected code in one click. For unrecognized or custom malicious files that aren't part of any active plugin or theme, Guardian Gaze performs a safety check to confirm the file isn't in use, then lets you permanently delete it with a clear warning before removal.

Why it matters

Detection without remediation is half the job.

Most security plugins are good at finding malware. Far fewer help you remove it cleanly. The traditional cleanup workflow involves SFTP'ing into the server, identifying the right repository version, downloading the clean files, comparing them by hand, and overwriting just the bad ones, all while hoping you don't break a custom modification someone forgot to document.

Guardian Gaze closes that gap. The same engine that detects a compromised file can fetch the pristine version and restore it directly, turning a 30-minute SFTP session into a single click.

Two paths, one workflow

Different files need different responses.

🔄

Known file → restore

If the infected file belongs to WordPress core, an installed plugin, or a theme, Guardian Gaze pulls the clean version directly from the official WordPress.org repository, matching the exact version installed, and overwrites the infected copy.

🗑️

Unknown file → safety-checked delete

If the file isn't part of any active plugin or theme, a typical webshell or backdoor signature, Guardian Gaze verifies the file isn't referenced anywhere in active code, shows you a clear warning, and lets you permanently delete it.

Safety first

We won't break your site to save it.

Every removal action runs through a chain of safety checks before anything is touched:

  • Backup first. The original infected file is copied to a quarantine folder before being overwritten or deleted. If a restore goes wrong, the original is recoverable.
  • Version pinning. Restored files come from the exact plugin/theme version installed on your site, never a newer version that might break compatibility.
  • Reference scan. Before any unknown file is deleted, Guardian Gaze checks whether anything in the active codebase references it. If it's loaded by another file, you're warned.
  • Explicit confirmation. Destructive actions always require a deliberate click. There is no silent auto-cleanup that could surprise you.
  • Action logged. Every removal is recorded in the audit log with the file path, action taken, the user who approved it, and timestamp.
When it can't auto-fix

Custom code gets guidance, not guesswork.

Some files don't have a clean reference, heavily customized theme files, bespoke plugins, or wp-config edits made for the site. In those cases Guardian Gaze won't blindly overwrite or delete. Instead, it shows you the suspicious diff, explains why it was flagged, and surfaces the exact lines that look malicious, so you (or your developer) can make a clean, informed manual edit.

From detection to clean site, one click.

One-click malware removal is included in the Pro tier. Detection itself is free.