Alternatives

Free WordPress malware removal plugins, and what they remove

Most free security plugins detect malware and stop. Of the twelve in the table below, six remove nothing from a flagged file on their free tier, one deletes and keeps no copy, and five keep something you can put back. Here is what each free tier actually does to an infected file, so you pick before your site is down.

Install the free plugin from WordPress.org

Segurium Free cleans 3 files every 30 days. No card, no trial clock.

The four things vendors call removal

Every plugin below uses the word for four different things, and the difference decides whether your site is still standing afterwards.

Your real question is usually what happens to a file that never came from WordPress.org, because that is where injections land. Overwrite has no answer. Quarantine has half of one: the malware stops running, and the page that file rendered stops rendering.

What each free plan actually does to an infected file

Plugin (active installs) What the free tier does to a flagged file Keeps a copy you can restore
Wordfence (5,000,000) Overwrite from WordPress.org, or delete. No repair button on a file with no upstream copy No. What it deletes is gone
All-In-One Security (1,000,000) Nothing. It reports that a file changed and offers to clear the message Nothing to restore, because nothing is removed
Kadence Security (700,000) Nothing. It never reads file contents, so no file is flagged as malware Not applicable
Sucuri Security (600,000) Nothing. The free plugin audits, monitors and hardens Not applicable
MalCare (200,000) Nothing. Their pricing page says removal needs the $299/yr plan Not applicable
Jetpack Protect (100,000) Nothing, and the free plan does not read your files at all Not applicable
NinjaFirewall + NinjaScanner (100,000 / 30,000) Quarantine it, restore it from WordPress.org, or ignore it. No in-place cleaning Yes. On disk, kept until you restore or delete it
Defender (80,000) Delete, or Safe Repair from WordPress.org. Needs a free WPMU DEV account connected Yes, for wp.org plugin files only. 30 days by default, up to a year
Patchstack (50,000) Nothing. It does not scan files Not applicable
WP Cerber Deletes what it flags Yes. A restorable copy, 30 days by default
Anti-Malware Security (GOTMLS) Removes what it flags Yes. A copy in your posts table, with no expiry
Segurium Writes back a cleaned copy of that same file, including files that never came from WordPress.org. 3 files per 30 days Yes. Encrypted backup on your own server, one-click restore

Install counts and ratings from api.wordpress.org on 19 August 2026. Behaviour read from each vendor's own documentation and shipped code on 19 August 2026, except WP Cerber and Anti-Malware Security, read on 18 August 2026. Paid tiers, yearly unless marked: Wordfence Premium $149, All-In-One Security $89 for two sites, Kadence Pro $299 inside a theme bundle, Sucuri Basic $229, MalCare Repair $299, Jetpack Scan $119.40 list, NinjaScanner scheduled scans $29 a domain, the cheapest WPMU DEV membership $60, Patchstack virtual patching $5 a site a month, Segurium Pro $79. Prices are theirs to change. Longer reads on Wordfence, All-In-One Security, Kadence Security, Sucuri, MalCare, Jetpack Protect, NinjaFirewall, Defender and Patchstack.

Four rows deserve their vendor's own words, all read on 19 August 2026. All-In-One Security ships this in its scanner template: "Due to the constantly changing and complex nature of Malware, scanning for such things using a standalone plugin will not work reliably." MalCare's pricing page says "The honest limit: Free detects malware; removal needs Repair or higher", while their WordPress.org listing also reads "UNLIMITED hack cleanups", so read their feature table and not the headline. Patchstack's pricing FAQ says the product "does not scan your files like a malware scanner and won't help you in finding existing malware on your website". Jetpack says Scan "is not designed to fully clean up sites infected before it was active", and its fix restores from your backup, so you need one taken before the infection.

NinjaScanner earns a mention it rarely gets. Its free tier is the most generous here: signatures and quarantine cost nothing, and only scheduled scans and WP-CLI sit behind $29 a domain a year. Before it quarantines a file it sandboxes the change to check your site does not fatal. No other plugin on this page documents that step.

Install the free plugin from WordPress.org

The gap nobody's free tier covers

Read the repair path in all eleven and the same condition appears every time. The file has to be recognised as WordPress core, a WordPress.org plugin, or a WordPress.org theme. Wordfence does not render the Repair control otherwise. Defender limits Safe Repair to "the files of plugins downloaded from WordPress.org" and its quarantine to the same set, so a theme file gets Restore and nothing else. NinjaScanner restores from WordPress.org packages only.

The condition makes sense. To overwrite a file with a clean copy you need a clean copy, and only WordPress.org can hand one over. It also puts the gap exactly where attackers work. Your custom theme, the premium plugin you bought outside the directory, the child theme functions file your developer wrote: none of those have an upstream, so an injection there leaves you delete, quarantine, or an editor and a long evening. Cleaning in place needs no upstream copy, which is why Segurium works on a file nobody else has seen before.

How Segurium cleans a file

Every file on your server is hashed, and the hash is checked against a cloud database of known-good and known-bad files. About 94% resolve on the hash alone and never leave your server, and a lookup takes about 24 milliseconds. Detection is not a paid tier: Free and Pro read the same feed at the same moment. The only thing money changes is how many files you may clean.

Click Fix on an injection in an otherwise-working file and you get a cleaned version of that exact file written back to the same path, so your theme carries on rendering. A file that is nothing but malware becomes zero bytes at the same path. When no clean version can be produced, the cleanup aborts and leaves the file exactly as it found it. It never truncates on failure. The original goes to an encrypted backup on your own server first, one click puts it back, and you can look at what was removed before you decide.

Now the ceiling, before you install rather than after. The free plan cleans 3 files every 30 days. A site with forty infected files is not cleaned by it in one sitting, and no framing changes that. What softens it: the integrity scan compares every core, plugin and theme file against the canonical upstream copy of the exact version you have installed and restores anything that drifted, unlimited on Free while the file is clean and never counted against the cleanup quota. On a typical mass infection that clears the WordPress.org half for nothing and leaves a short list of custom files, which is what the 3 cleanups are for.

Bulk Fix All ships free on every install, with a preflight preview of what it will touch. Pro at $79 a year per site lifts the cleanup limit and turns on unattended fixing on a scheduled scan.

Install the free plugin from WordPress.org

If your budget is zero, here is what we would actually do

The order we would work in on somebody else's infected site with no money on the table. Two of the six steps send you to another vendor.

  1. Take a backup first, infected and all. Whatever you run next removes files, and a copy of the broken site is the difference between a bad afternoon and a lost one. Most hosts have a snapshot button; if yours does not, a manual copy of wp-content and a database dump will do.
  2. Install Wordfence Free or NinjaScanner for the detection. Wordfence backs a research team and its free firewall loads before WordPress, though its free signatures reach you 30 days after paying users. NinjaScanner sandboxes a quarantine before it commits. Either one is a real second opinion, and both cost nothing.
  3. Let the free tools fix what they can fix. Wordfence repairs core, plugin and theme files from WordPress.org for free, and that is a good repair. Every file it fixes is one you do not spend a Segurium cleanup on.
  4. Use Segurium on what is left. The leftovers are custom files with no upstream copy, and the free plan cleans 3 of them every 30 days with the original backed up first. Run the integrity restore too: free, unlimited, no quota.
  5. Close the door. Update every plugin and theme, rotate the admin and database passwords, turn on two-factor. Patchstack Free covers three sites and names the plugin with the published vulnerability.
  6. Scan again in a week. Reinfection means something is still running or the way in is still open. Two clean scans a week apart is where you stop.

If your site is a business and it is down now, a paid cleanup is a reasonable purchase. Sucuri Basic at $229 a year puts their people on it with a 30-hour removal response target, and MalCare Repair at $299 a year gives you the one-click cleanup. Both are honest products, and this page is for the reader without that money today.

What Segurium does not do

Read these before you drop something you already run.

What leaves your server, in plain terms

Scanning is opt-in. Until you accept the disclosure on the plugin page, Segurium does not contact our service and does not scan.

Files are checked by SHA-256 first. A file has its bytes sent in two cases: when its hash is one we have never seen, which in practice is about 6% of them, and when you clean it and we build the replacement. Everything else is settled by hash.

Samples we do receive are kept for up to 365 days and then deleted by an automated purge, and an analyst can delete one sooner once it has been triaged. Our privacy policy lists every retention period we hold to.

Our servers are in the European Economic Area and Segurium is run from Spain, so GDPR applies to us directly rather than reaching us through an adequacy decision. Two subprocessors sit outside the EEA, for payments and for support email. Both are covered by Standard Contractual Clauses and both are named in the privacy policy.

We do not track your visitors. Segurium looks at files and login attempts.

Questions

Is any of this free, or is free a trial?
NinjaScanner, WP Cerber and Anti-Malware Security are free with no card. Wordfence Free repairs and deletes with no card. Segurium Free cleans 3 files every 30 days, no card and no trial clock. What is free nowhere is an unlimited cleanup button: MalCare, Sucuri and Jetpack all put removal behind a paid plan, and MalCare says so on their own pricing page.
What if I have more than three infected files?
Three files per thirty days is the free ceiling, and a site with forty infected files does not get finished in one sitting. Two things soften it. Integrity restore is unlimited on the free plan and never touches the quota, so every infected core, plugin or wp.org theme file goes back to its upstream content for nothing, which is most of a typical mass infection. What is left is a short list of custom files, and that is what the three cleanups are for. Segurium Pro at $79 a year per site lifts the limit.
My infected file is in a custom theme. What are my options?
In Wordfence, Defender and NinjaScanner the repair path is gated on the file coming from WordPress.org, so a custom theme file leaves you delete, quarantine, or an editor. Deleting a theme file takes the page down with it. Segurium asks for a cleaned version of that specific file and writes it back, so the theme keeps rendering. If no clean version can be produced, the cleanup stops and the file is left exactly as it was.
Can I run two of these at once?
Yes, and on a zero budget you should. Wordfence Free gives you a firewall that loads before WordPress. NinjaScanner gives you a second signature set and a quarantine. Segurium gives you the cleanup. Turn off all but one malware scanner so you are not scanning the same files three times, and leave the firewall running.
Can I check my site is clean without a plugin?
Partly. On WP-CLI, wp core verify-checksums compares your core files against WordPress.org and catches a modified core file. It does not catch an added one: an unknown file in wp-includes/ is a warning there, and the command still prints Success and exits 0. There is no wp theme verify-checksums, whatever the rest of the web says. Neither covers a custom theme, which is where injections land.
Does removing the file fix the hack?
It removes what is running. It does not close the door the attacker came through, which is usually an outdated plugin or a password. Update everything, rotate the admin and database passwords, and turn on two-factor. Patchstack Free covers three sites at no cost and names the plugin with the published vulnerability.

Comparing something else?

Scan first, decide after

Install the free plugin and scan alongside whatever you already run. If the two agree, you spent twenty minutes on a second opinion. If they disagree, you found the file nothing else was going to clean.