Alternatives
Free WordPress malware removal plugins, and what they remove
Most free security plugins detect malware and stop. Of the twelve in the table below, six remove nothing from a flagged file on their free tier, one deletes and keeps no copy, and five keep something you can put back. Here is what each free tier actually does to an infected file, so you pick before your site is down.
Install the free plugin from WordPress.org
Segurium Free cleans 3 files every 30 days. No card, no trial clock.
The four things vendors call removal
Every plugin below uses the word for four different things, and the difference decides whether your site is still standing afterwards.
- Delete. The file is removed from your server. For a dropper in your uploads folder that is the right answer. For a theme file it takes the page down with it, and the plugin cannot tell you which of the two you are about to do.
- Overwrite from upstream. The file is replaced with the vendor's published copy from WordPress.org. This is the industry norm and it works well, on two conditions: the file came from WordPress.org, and any local edit in it is discarded.
- Quarantine. The file is moved somewhere the web server cannot reach and kept there, so you can put it back. The malware stops running. Nothing is repaired, so the file you put back is still infected.
- Clean in place. The injected code is removed and the rest of the file is kept, so a custom theme file goes on working. This is what Segurium does, and it is rare here.
Your real question is usually what happens to a file that never came from WordPress.org, because that is where injections land. Overwrite has no answer. Quarantine has half of one: the malware stops running, and the page that file rendered stops rendering.
What each free plan actually does to an infected file
| Plugin (active installs) | What the free tier does to a flagged file | Keeps a copy you can restore |
|---|---|---|
| Wordfence (5,000,000) | Overwrite from WordPress.org, or delete. No repair button on a file with no upstream copy | No. What it deletes is gone |
| All-In-One Security (1,000,000) | Nothing. It reports that a file changed and offers to clear the message | Nothing to restore, because nothing is removed |
| Kadence Security (700,000) | Nothing. It never reads file contents, so no file is flagged as malware | Not applicable |
| Sucuri Security (600,000) | Nothing. The free plugin audits, monitors and hardens | Not applicable |
| MalCare (200,000) | Nothing. Their pricing page says removal needs the $299/yr plan | Not applicable |
| Jetpack Protect (100,000) | Nothing, and the free plan does not read your files at all | Not applicable |
| NinjaFirewall + NinjaScanner (100,000 / 30,000) | Quarantine it, restore it from WordPress.org, or ignore it. No in-place cleaning | Yes. On disk, kept until you restore or delete it |
| Defender (80,000) | Delete, or Safe Repair from WordPress.org. Needs a free WPMU DEV account connected | Yes, for wp.org plugin files only. 30 days by default, up to a year |
| Patchstack (50,000) | Nothing. It does not scan files | Not applicable |
| WP Cerber | Deletes what it flags | Yes. A restorable copy, 30 days by default |
| Anti-Malware Security (GOTMLS) | Removes what it flags | Yes. A copy in your posts table, with no expiry |
| Segurium | Writes back a cleaned copy of that same file, including files that never came from WordPress.org. 3 files per 30 days | Yes. Encrypted backup on your own server, one-click restore |
Install counts and ratings from api.wordpress.org on 19 August 2026. Behaviour read from each vendor's own documentation and shipped code on 19 August 2026, except WP Cerber and Anti-Malware Security, read on 18 August 2026. Paid tiers, yearly unless marked: Wordfence Premium $149, All-In-One Security $89 for two sites, Kadence Pro $299 inside a theme bundle, Sucuri Basic $229, MalCare Repair $299, Jetpack Scan $119.40 list, NinjaScanner scheduled scans $29 a domain, the cheapest WPMU DEV membership $60, Patchstack virtual patching $5 a site a month, Segurium Pro $79. Prices are theirs to change. Longer reads on Wordfence, All-In-One Security, Kadence Security, Sucuri, MalCare, Jetpack Protect, NinjaFirewall, Defender and Patchstack.
Four rows deserve their vendor's own words, all read on 19 August 2026. All-In-One Security ships this in its scanner template: "Due to the constantly changing and complex nature of Malware, scanning for such things using a standalone plugin will not work reliably." MalCare's pricing page says "The honest limit: Free detects malware; removal needs Repair or higher", while their WordPress.org listing also reads "UNLIMITED hack cleanups", so read their feature table and not the headline. Patchstack's pricing FAQ says the product "does not scan your files like a malware scanner and won't help you in finding existing malware on your website". Jetpack says Scan "is not designed to fully clean up sites infected before it was active", and its fix restores from your backup, so you need one taken before the infection.
NinjaScanner earns a mention it rarely gets. Its free tier is the most generous here: signatures and quarantine cost nothing, and only scheduled scans and WP-CLI sit behind $29 a domain a year. Before it quarantines a file it sandboxes the change to check your site does not fatal. No other plugin on this page documents that step.
The gap nobody's free tier covers
Read the repair path in all eleven and the same condition appears every time. The file has to be recognised as WordPress core, a WordPress.org plugin, or a WordPress.org theme. Wordfence does not render the Repair control otherwise. Defender limits Safe Repair to "the files of plugins downloaded from WordPress.org" and its quarantine to the same set, so a theme file gets Restore and nothing else. NinjaScanner restores from WordPress.org packages only.
The condition makes sense. To overwrite a file with a clean copy you need a clean copy, and only WordPress.org can hand one over. It also puts the gap exactly where attackers work. Your custom theme, the premium plugin you bought outside the directory, the child theme functions file your developer wrote: none of those have an upstream, so an injection there leaves you delete, quarantine, or an editor and a long evening. Cleaning in place needs no upstream copy, which is why Segurium works on a file nobody else has seen before.
How Segurium cleans a file
Every file on your server is hashed, and the hash is checked against a cloud database of known-good and known-bad files. About 94% resolve on the hash alone and never leave your server, and a lookup takes about 24 milliseconds. Detection is not a paid tier: Free and Pro read the same feed at the same moment. The only thing money changes is how many files you may clean.
Click Fix on an injection in an otherwise-working file and you get a cleaned version of that exact file written back to the same path, so your theme carries on rendering. A file that is nothing but malware becomes zero bytes at the same path. When no clean version can be produced, the cleanup aborts and leaves the file exactly as it found it. It never truncates on failure. The original goes to an encrypted backup on your own server first, one click puts it back, and you can look at what was removed before you decide.
Now the ceiling, before you install rather than after. The free plan cleans 3 files every 30 days. A site with forty infected files is not cleaned by it in one sitting, and no framing changes that. What softens it: the integrity scan compares every core, plugin and theme file against the canonical upstream copy of the exact version you have installed and restores anything that drifted, unlimited on Free while the file is clean and never counted against the cleanup quota. On a typical mass infection that clears the WordPress.org half for nothing and leaves a short list of custom files, which is what the 3 cleanups are for.
Bulk Fix All ships free on every install, with a preflight preview of what it will touch. Pro at $79 a year per site lifts the cleanup limit and turns on unattended fixing on a scheduled scan.
If your budget is zero, here is what we would actually do
The order we would work in on somebody else's infected site with no money on the table. Two of the six steps send you to another vendor.
- Take a backup first, infected and all. Whatever you run next removes files, and a copy of the broken site is the difference between a bad afternoon and a lost one. Most hosts have a snapshot button; if yours does not, a manual copy of wp-content and a database dump will do.
- Install Wordfence Free or NinjaScanner for the detection. Wordfence backs a research team and its free firewall loads before WordPress, though its free signatures reach you 30 days after paying users. NinjaScanner sandboxes a quarantine before it commits. Either one is a real second opinion, and both cost nothing.
- Let the free tools fix what they can fix. Wordfence repairs core, plugin and theme files from WordPress.org for free, and that is a good repair. Every file it fixes is one you do not spend a Segurium cleanup on.
- Use Segurium on what is left. The leftovers are custom files with no upstream copy, and the free plan cleans 3 of them every 30 days with the original backed up first. Run the integrity restore too: free, unlimited, no quota.
- Close the door. Update every plugin and theme, rotate the admin and database passwords, turn on two-factor. Patchstack Free covers three sites and names the plugin with the published vulnerability.
- Scan again in a week. Reinfection means something is still running or the way in is still open. Two clean scans a week apart is where you stop.
If your site is a business and it is down now, a paid cleanup is a reasonable purchase. Sucuri Basic at $229 a year puts their people on it with a 30-hour removal response target, and MalCare Repair at $299 a year gives you the one-click cleanup. Both are honest products, and this page is for the reader without that money today.
What Segurium does not do
Read these before you drop something you already run.
- No firewall in front of WordPress. Wordfence and NinjaFirewall load before WordPress does, so a blocked request never reaches your theme. Ours filters inside WordPress, after PHP accepted the request. Same kind of rules, one layer later. Keep theirs.
- No CDN and no DDoS protection. Sucuri sells both. A bare "no" overstates what you lose, because your host or your CDN normally provides this and you may have it already.
- No curated IP blocklist. Wordfence Premium tracks tens of thousands of known threat actors. You write your own IP and CIDR rules.
- No vulnerability scanning and no virtual patching. Patchstack and Jetpack Protect do the first for free, and Patchstack does the second from $5 a site a month. We read your files, not your versions.
- No blocklist monitoring. Kadence Security checks you against Google Safe Browsing for free. We check no blocklist.
- No security audit log, no backups product, no staging, no uptime monitoring. Those are separate jobs, and other plugins on this list do them.
- No human incident response. Sucuri and Wordfence sell a person who logs in and fixes it. Nobody at Segurium logs into your site. If you want a phone number during an incident, buy theirs.
- No track record. Wordfence has been on WordPress.org since 2012 with five million installs. Segurium arrived in July 2026 with two ratings, so judge it on your own site rather than on our word.
What leaves your server, in plain terms
Scanning is opt-in. Until you accept the disclosure on the plugin page, Segurium does not contact our service and does not scan.
Files are checked by SHA-256 first. A file has its bytes sent in two cases: when its hash is one we have never seen, which in practice is about 6% of them, and when you clean it and we build the replacement. Everything else is settled by hash.
Samples we do receive are kept for up to 365 days and then deleted by an automated purge, and an analyst can delete one sooner once it has been triaged. Our privacy policy lists every retention period we hold to.
Our servers are in the European Economic Area and Segurium is run from Spain, so GDPR applies to us directly rather than reaching us through an adequacy decision. Two subprocessors sit outside the EEA, for payments and for support email. Both are covered by Standard Contractual Clauses and both are named in the privacy policy.
We do not track your visitors. Segurium looks at files and login attempts.
Questions
- Is any of this free, or is free a trial?
- NinjaScanner, WP Cerber and Anti-Malware Security are free with no card. Wordfence Free repairs and deletes with no card. Segurium Free cleans 3 files every 30 days, no card and no trial clock. What is free nowhere is an unlimited cleanup button: MalCare, Sucuri and Jetpack all put removal behind a paid plan, and MalCare says so on their own pricing page.
- What if I have more than three infected files?
- Three files per thirty days is the free ceiling, and a site with forty infected files does not get finished in one sitting. Two things soften it. Integrity restore is unlimited on the free plan and never touches the quota, so every infected core, plugin or wp.org theme file goes back to its upstream content for nothing, which is most of a typical mass infection. What is left is a short list of custom files, and that is what the three cleanups are for. Segurium Pro at $79 a year per site lifts the limit.
- My infected file is in a custom theme. What are my options?
- In Wordfence, Defender and NinjaScanner the repair path is gated on the file coming from WordPress.org, so a custom theme file leaves you delete, quarantine, or an editor. Deleting a theme file takes the page down with it. Segurium asks for a cleaned version of that specific file and writes it back, so the theme keeps rendering. If no clean version can be produced, the cleanup stops and the file is left exactly as it was.
- Can I run two of these at once?
- Yes, and on a zero budget you should. Wordfence Free gives you a firewall that loads before WordPress. NinjaScanner gives you a second signature set and a quarantine. Segurium gives you the cleanup. Turn off all but one malware scanner so you are not scanning the same files three times, and leave the firewall running.
- Can I check my site is clean without a plugin?
- Partly. On WP-CLI, wp core verify-checksums compares your core files against WordPress.org and catches a modified core file. It does not catch an added one: an unknown file in wp-includes/ is a warning there, and the command still prints Success and exits 0. There is no wp theme verify-checksums, whatever the rest of the web says. Neither covers a custom theme, which is where injections land.
- Does removing the file fix the hack?
- It removes what is running. It does not close the door the attacker came through, which is usually an outdated plugin or a password. Update everything, rotate the admin and database passwords, and turn on two-factor. Patchstack Free covers three sites at no cost and names the plugin with the published vulnerability.
Comparing something else?
Scan first, decide after
Install the free plugin and scan alongside whatever you already run. If the two agree, you spent twenty minutes on a second opinion. If they disagree, you found the file nothing else was going to clean.