Title: Yuga AntiMalware
Author: Yuga Web
Published: <strong>September 10, 2026</strong>
Last modified: September 15, 2026

---

Search plugins

![](https://ps.w.org/yuga-antimalware/assets/banner-772x250.png?rev=3690084)

![](https://ps.w.org/yuga-antimalware/assets/icon.svg?rev=3690084)

# Yuga AntiMalware

 By [Yuga Web](https://profiles.wordpress.org/yugaweb/)

[Download](https://downloads.wordpress.org/plugin/yuga-antimalware.1.2.0.zip)

 * [Details](https://pcm.wordpress.org/plugins/yuga-antimalware/#description)
 * [Reviews](https://pcm.wordpress.org/plugins/yuga-antimalware/#reviews)
 *  [Installation](https://pcm.wordpress.org/plugins/yuga-antimalware/#installation)
 * [Development](https://pcm.wordpress.org/plugins/yuga-antimalware/#developers)

 [Support](https://wordpress.org/support/plugin/yuga-antimalware/)

## Description

Yuga AntiMalware is an admin-focused plugin built to detect suspicious malware indicators
and support remediation workflows on WordPress sites.

Main capabilities:
 – Tabbed admin interface with left sidebar sections and right
helper column. – Scan modes: – Quick scan (files in wp-content) – Targeted scan (
plugins/themes/mu-plugins/uploads/root files) – Database scan – Frontend scan – 
Full scan (files + database + frontend) – Optional PHP max_execution_time override
for scan execution. – Background scans in saved blocks, with automatic continuation
and manual resume when needed. – Real scan progress: analyzed files, database rows,
checked pages and completed modules, without a simulated percentage. – Automatic
quick scans through WP-Cron (hourly, daily, or weekly). – Findings table with sorting,
grouping, and file preview. – Findings actions: ignore, exclude path, quarantine,
delete, copy path. – Reinfection Trace with database hot spots and writer candidates.–
Writer Hunt for file-level suspect correlation. – Safe options cleanup workflow:
backup + cleanup + restore rollback. – Content Cleanup for suspicious post/page/
revision rows with filters by author, category, type, language/script, and keyword.–
Content cleanup actions with rollback backups, batch-based filtered trashing, and
previous revision restore for posts/pages. – Trash Cleanup for permanently removing
WordPress trash items in backed-up batches. – Cache cleanup tools (targeted suspicious
cache cleanup and full transient flush). – Post-hack plugin/theme inventory with
version checks and maintenance actions where supported. – Quarantine inventory viewer
in admin. – Retention policy for quarantined files, applied from quarantine timestamp.–
Email notifications via default WordPress mail settings. – Comment protection: optionally
send new comments with explicit spam signals to the WordPress Spam folder before
publication. – Comment Cleanup: review comments, trackbacks and pingbacks in batches
of up to 1,000, then trash or permanently delete selected items. – Dedicated manual-
review filters for all pending comments, external links and non-Latin letters in
names or text. – Administrator-only JSON export of all comments, preserving original
HTML links and moderation context.

### Root Integrity Check

Root scans and the root module of Full Scan compare directly contained files
 with
the official checksums for the installed WordPress version and package locale. Additional
files are review findings, not proof of malware. Modified core files are flagged
separately. This does not verify all of wp-admin or wp-includes, detect missing 
files, or inspect extra directories.

Local wp-config.php, .htaccess, .user.ini, robots.txt, web.config, php.ini and
 .
maintenance are exempt from additional-file warnings, but remain subject to applicable
content rules. Inventory includes all extensions; explicit path exclusions still
apply. Unavailable manifests, excluded/unreadable/oversized core files or interruption
leave the verification incomplete.

Configuration files .htaccess, .user.ini and php.ini are included in content
 scans
within the selected scope, subject to configured exclusions and limits. Checks flag
active automatic PHP loading directives, Apache Substitute script or iframe markup,
and crawler-conditioned rewrites to PHP or external URLs. Comments, empty/none PHP
loader settings, ordinary WordPress rewrites and crawler blocking with an unchanged
target are not flagged by these checks. Legitimate firewalls can use automatic loading:
review before changing files. Configuration findings are advisory; no directives
are executed by the scanner. Use the pencil action on .htaccess or .user.ini findings
for Configuration Cleanup. Review the complete before/after proposal and all removed
lines; confirming applies the whole proposal. Containers emptied by the proposal
and their marker comments are removed. Unused rewrite-engine and substitution-filter
lines are removed only when no remaining rule may depend on them. Independent settings
and the WordPress marker block are retained. Ambiguous sections, continued lines
and chained/skipping rewrite rules require manual review. The tool does not validate
the configuration against your hosting server’s active modules.

Before applying, download the current file for recovery outside WordPress.
 Every
write, including a restore, requires a verified backup in the WordPress database(
not autoloaded), preserves file permissions, rechecks the preview hash, verifies
written bytes and attempts rollback if writing fails. Backups are listed with download
and restore-preview actions; they are removed on plugin uninstall. Failed rollback
requires restoring through the hosting file manager. Previews expire after 15 minutes.
Successful file deletion and quarantine remove that target’s stored findings. Configuration
cleanup and restore recheck the changed file, retain residual findings and adjust
counters. Failed verification leaves findings in place and shows a pending-verification
message. A short history records successful file actions and verification outcomes.
If the previous preview was truncated, counters are marked approximate until a new
scan provides exact totals. A full scan remains useful for reviewing the rest of
the site. An interrupted operation can leave its safety lock in place; an administrator
must verify that no operation is running before clearing that lock.

### External Services

Root integrity verification contacts the WordPress.org checksum API over HTTPS
 
when a root scan runs, sending the installed WordPress version and package locale.
No file contents or local paths are uploaded. Successful manifests are cached locally
for 24 hours. See https://wordpress.org/about/privacy/ and https://wordpress.org/
about/terms-of-service/.

This plugin optionally integrates with PayPal Donate to facilitate donations. No
PayPal resource is loaded until an administrator explicitly clicks the “Donate with
PayPal” button on the plugin settings page.

 * **Service Name**: PayPal Donate API
 * **Purpose**: To provide a donation button through PayPal.
 * **Data Sent**:
    - Network and device information normally included in web requests, such as 
      IP address and user agent
    - The hosted PayPal button identifier
    - Any payment information the administrator subsequently enters on PayPal
 * **When**: The PayPal SDK is requested only after an administrator clicks the “
   Donate with PayPal” button.
 * **Service Links**:
    - [PayPal Terms of Service](https://www.paypal.com/us/webapps/mpp/ua/legalhub-full)
    - [PayPal Privacy Policy](https://www.paypal.com/us/webapps/mpp/ua/privacy-full)

Payment transactions are handled by PayPal under its own terms and privacy policy.

### How to use Content Cleanup safely

 1. Run a Database scan or Full scan first.
 2. Open Dashboard > Content Cleanup and review the filtered suspicious post rows.
 3. Use filters such as Author, Category, Type, Language/script, and Keyword to narrow
    the result set.
 4. Prefer backup-backed actions before trashing content.
 5. For real posts or pages that were modified, use Restore previous revision when 
    a clean revision is available.
 6. For suspicious revisions, move them to trash after verifying they are not needed.
 7. Use Trash Cleanup only after confirming the trashed content should be permanently
    removed.

### Pharmaceutical spam signals in database content

A pharmaceutical keyword alone does not trigger the pharmaceutical promotion
 rule.
A listed term must occur near buying, discount, shipping or prescription-free sales
wording in the same text segment (up to 100 intervening characters). The rule recognizes
selected English and Italian wording. It does not combine signals across HTML tags,
serialized/JSON field delimiters, lines or sentences. Results are potential promotions
for manual review, not proof of infection. No links are opened and no stored values
are deserialized or modified.

Run a new scan after updating to replace older keyword-only findings. The
 preview
explains when an old finding no longer matches the contextual rule.

### Comment Cleanup and Protection

Open Yuga AntiMalware > Comment Cleanup to manage existing comments, configure
 
protection for new submissions, or download a review export. The tools support ordinary
comments, trackbacks and pingbacks. Product reviews and other custom comment types
are excluded from detection and cleanup.

#### Spam protection for new comments

Dashboard > Overview shows the saved Comment protection status (Enabled or
 Disabled),
with links to its settings and the WordPress Spam folder.

Saving protection records before/after counts for Pending, Approved, Spam and
 Trash,
displayed with a UTC timestamp in Comment Cleanup for troubleshooting. The counts
describe that save, not current totals; concurrent moderation can also affect them.
No comment content is stored in this diagnostic record.

Protection is optional and disabled by default. Enable “Automatically mark new
 
comments with explicit spam signals as spam” and save the setting.

When enabled, strong medicine-purchase promotions, linked affiliate invitations,

repeated adult keywords with links, or combined opaque alphanumeric names, emails
and long unbroken alphanumeric text receive WordPress Spam status. Consonant-heavy
names with relay emails alone remain manual-review hints.

After a new submission is successfully stored, protection can also move
 related
pending comments with matching spam signals to Spam. Approved comments are left 
unchanged. Saving the setting itself does not move comments. Disabling stops automatic
moderation without restoring previously moved comments. No automatic Trash or deletion.

Existing rejection, Spam or Trash decisions are preserved. Imports bypassing
 WordPress
submission hooks do not trigger the automatic review. No external anti-spam service
is contacted. Review WordPress > Comments > Spam for false positives and restore
legitimate messages. Other tools may purge Spam. Language or external links alone
never trigger automatic Spam.

#### Reviewing and cleaning existing comments

Choose one of the following views and select “Analyze from the beginning”:

 * Marked spam and potential spam.
 * Already marked as spam.
 * Potential spam only.
 * Non-Latin letters in name or text: optional manual review.
 * Links to external websites: optional manual review.
 * All pending comments: manual review, including unflagged items.

Approved comments require explicit opt-in for potential-spam analysis. The
 three
manual-review filters show pending comments only, even if that opt-in is selected.
Comments without a spam classification are identified as such.

Each preview examines up to 1,000 comments, not 1,000 spam matches. Select
 individual
comments or all items in the preview, review the selection and confirm the chosen
action. Continue with “Analyze next batch” to examine the remaining comments. Start
again to revisit skipped or unselected items. Previews expire after 30 minutes; 
changed or unavailable comments are skipped.

Manual cleanup offers two actions:

 * Move to trash (default): selected existing comments go to WordPress Trash,
    not
   Spam. They can be restored until WordPress empties the trash according to the
   site’s retention setting. This action is blocked if trash is disabled.
 * Delete permanently: requires an additional explicit confirmation. There is
    no
   backup and this action cannot be undone.

Automatic protection and manual cleanup therefore have different destinations:
 
automatic detections go to Spam; manually trashed comments go to Trash. Manual cleanup
currently has no “Mark as spam” action. Use the WordPress Comments screen to mark
existing comments as Spam instead of trashing them.

#### Detection and review limits

Review hints include linked-text-only comments, BBCode links (including unclosed

tags), multiple links, executable HTML, explicit commercial pitches, repeated adult
keywords, medicine promotions, contact-only comments and generic greetings or compliments
accompanied by links. URLs with a domain and path are recognized without an HTTP
scheme. HTML anchors retain their destination during analysis.

Manual review also flags combinations of consonant-heavy names and long opaque
 
email identifiers. Combined alphanumeric names/emails and long unbroken alphanumeric
text also qualify for automatic protection when enabled. Relay addresses, long emails
or pseudonyms alone are not sufficient. Display names advertising online medicines
are also flagged for review. Relay-email and advertising-name hints alone do not
trigger automatic Spam.

Review also considers patterns across comments in the current preview batch.
 Related
evidence is rechecked before cleanup.

Review hints can include legitimate references, advertising, quotations and
 shared
networks. They do not prove an infection or guarantee spam detection. The first 
64 KB of each comment body are inspected; whole-body rules apply only when the complete
body is within that limit.

The non-Latin filter checks visible names and text, excluding links and HTML
 attributes.
It includes Cyrillic, Greek, Arabic and Asian scripts, but does not identify language
or nationality. Accented Latin letters and emoji alone do not match. The external-
links filter compares destinations in comment bodies and author websites with the
public site’s hostname, treating www as the same hostname. Other subdomains count
as external; relative links and email addresses alone do not match. Destinations
are never visited. Neither filter is a spam verdict, and no items are selected or
removed automatically by these filters.

#### Exporting comments for review

“Export all comments (JSON)” downloads readable JSON with original HTML, text,
 
author website, email, IP, date, status, article title, edit links and individual
review reasons. Cross-comment correlation and comment metadata are not included.
The export includes every status and type, including approved comments, Spam, Trash
and custom types, independently of preview filters.

The export requires administrator and moderation permissions. No public file
 is
created. It contains personal data: store and share the download carefully. Data
is read in batches of 200 up to the highest ID at export start; concurrent edits
or deletions can affect it, so it is not a database snapshot. Only valid JSON ending
with complete=true represents a finished export. Retry interrupted downloads.

### Scan continuation

Dashboard and scheduled scans continue in blocks aiming for eight seconds or
 at
most 100 work items per request. Each file, batch of ten database rows, or frontend
URL finishes before yielding. A slow individual operation can exceed that target
and hosting limits still apply. Results and pending work are saved together after
each successful block.

Progress shows confirmed file, database-row and page counts, the current area,
 
and completed modules for Full scan. The activity bar is not an estimated percentage;
counters update after each saved block without a preliminary file census.

Keep the dashboard open for prompt continuation. With the page closed,
 continuation
uses WP-Cron and depends on site traffic or an external cron trigger. Interrupted
requests retry from the last confirmed block. After three unsuccessful attempts,
use Resume saved scan. Stop retains the checkpoint too. Starting a new scan replaces
the previous saved scan.

Cron wakeups are reused, with a separate watchdog for interrupted requests.
 Pending
one-shot events for completed or replaced jobs expire without scanning. If scheduling
fails, the progress display advises keeping the page open for AJAX continuation.
Persistent database or WordPress cron problems still need investigation. The summary
distinguishes recorded processing milliseconds from total elapsed time, including
waits and manual pauses. Total time remains unavailable for older completed scans
that have no recorded finish timestamp.

The legacy scan time budget does not limit the total duration of these jobs.
 The
PHP execution-time override applies to individual requests, subject to hosting policy.
A resumed scan uses its original settings; changes apply to a new scan. Directory
names are snapshotted when visited, so files added later may require another scan.
Directories with more than 20,000 entries stop with an explicit checkpoint-size 
error to prevent excessive checkpoint storage.

## Screenshots

[⌊Dashboard scan controls with scan mode selection, progress and completion results.⌉⌊
Dashboard scan controls with scan mode selection, progress and completion results
.⌉[

Dashboard scan controls with scan mode selection, progress and completion results.

[⌊Scan rules: heuristic sensitivity and scan execution time settings.⌉⌊Scan rules:
heuristic sensitivity and scan execution time settings.⌉[

Scan rules: heuristic sensitivity and scan execution time settings.

[⌊Scheduler settings for automatic quick scans using WordPress cron.⌉⌊Scheduler 
settings for automatic quick scans using WordPress cron.⌉[

Scheduler settings for automatic quick scans using WordPress cron.

[⌊Quarantine settings with configurable retention for stored files.⌉⌊Quarantine 
settings with configurable retention for stored files.⌉[

Quarantine settings with configurable retention for stored files.

[⌊Email notification settings for scan reports.⌉⌊Email notification settings for
scan reports.⌉[

Email notification settings for scan reports.

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/yuga-antimalware/`.
 2. Activate the plugin in WordPress Plugins.
 3. Open **Yuga AntiMalware** from the left admin menu.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Yuga AntiMalware” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Yuga Web ](https://profiles.wordpress.org/yugaweb/)

[Translate “Yuga AntiMalware” into your language.](https://translate.wordpress.org/projects/wp-plugins/yuga-antimalware)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/yuga-antimalware/),
check out the [SVN repository](https://plugins.svn.wordpress.org/yuga-antimalware/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/yuga-antimalware/)
by [RSS](https://plugins.trac.wordpress.org/log/yuga-antimalware/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.2.0

 * Added saved scan blocks with automatic continuation, interrupted-request recovery
   and manual resume when automatic attempts fail.
 * Replaced simulated scan percentages with confirmed counters, current module, 
   elapsed time and time since the last saved progress.
 * Improved scan cron wakeup handling and distinguished processing duration from
   total elapsed scan time.
 * Added the saved comment-protection status and management links to Dashboard >
   Overview.
 * Added optional protection that marks new submissions with explicit spam signals
   as Spam before publication; disabled by default, with no automatic deletion.
 * Improved comment-protection performance with batched reads and fewer repeated
   queries, retaining checks for comments changed during processing.
 * Added combined opaque-name, email and alphanumeric-text detection to standard
   comment protection; relay-email and advertising-name hints remain available for
   manual review.
 * Expanded comment review rules for promotional messages, linked text, BBCode and
   repeated submissions, including trackbacks and pingbacks.
 * Added separate manual-review views for pending comments, external links and non-
   Latin text, without treating those filters as automatic spam verdicts.
 * Added a protected JSON export of all comments with original HTML links, author
   information, moderation state and individual review reasons.
 * Improved Comment Cleanup preview layout with proportional columns and wrapping
   for long text and URLs.
 * Updated stored findings after successful file actions and configuration rechecks,
   with action history and counter limitations.
 * Added guided configuration cleanup with before/after review, mandatory backups,
   downloads and restore previews.
 * Added content checks for .htaccess, .user.ini and php.ini: automatic PHP loading,
   Apache script substitution and crawler-conditioned rewrites.
 * Fixed Unicode word boundaries for database pharma detection and stale preview
   highlighting; truly disabled unavailable file actions.
 * Reduced pharmaceutical false positives by requiring nearby purchase or promotional
   wording instead of a medicine keyword alone.
 * Added official package comparison for root files, including additional files 
   and modified core files.
 * Added a review rule for LinkPool remote HTML PHP snippets, including renamed 
   files, and self-deleting WordPress environment probes.
 * Added Ignored Findings with individual restore actions, including saved references
   absent from the latest scan.
 * Prevented file deletion, quarantine and path exclusions for database/frontend
   findings, including mixed bulk selections.
 * Added Comment Cleanup with a preview of marked spam and potentially suspicious
   comments, trackbacks and pingbacks.
 * Added opt-in scanning of approved comments, per-comment reasons, selection of
   up to 1,000 comments and a choice between trash and confirmed permanent deletion.
 * Protected changed comments and expired previews; blocked the trash action when
   WordPress trash is disabled.

#### 1.1.2

 * Updated the plugin header with the new Yuga AntiMalware logo for dark backgrounds.
 * Added screenshot descriptions and refreshed the WordPress.org artwork.

#### 1.1.1

 * Lowered the minimum PHP requirement to 7.2 after compatibility regression testing.
 * Prevented file deletion when a required backup fails.
 * Verified quarantine copies and recovery metadata before removing originals; added
   checksum validation for new backups and explicit partial-failure notices.
 * Added WordPress 7.1 and PHP 7.4 compatibility fixes.
 * Changed PayPal integration so external resources load only after explicit administrator
   interaction.
 * Hardened backup and quarantine storage and made quarantined payloads non-executable
   by extension.
 * Added working WP-Cron scheduling for automatic quick scans.
 * Preserved modern WordPress option autoload values during backup restore.
 * Improved cleanup of plugin-owned data during uninstall.
 * Removed inactive signature-update and custom scan-path controls; scans continue
   to use the documented fixed scopes.

#### 1.1.0

 * Improved quarantine UX and lifecycle:
 * Added Quarantine > Stored Files inventory table.
 * Added event-driven retention purge scheduling based on quarantine insertion date.
 * Added writer-candidate quarantine action in Reinfection Trace with consistent
   icon-based actions.
 * UI refinements for Quarantine settings naming and table consistency.
 * Added Content Cleanup with filtered post/page/revision review, rollback backups,
   batch trash actions, previous revision restore, and Trash Cleanup.

#### 1.0.0

 * Introduced full security workflow:
 * Multi-mode scans (quick, targeted, database, frontend, full).
 * Background scan execution with runtime polling.
 * Reinfection Trace and Writer Hunt correlation.
 * Safe options maintenance (backup + cleanup + restore).
 * Cache cleanup tools (targeted + full transient flush).
 * Post-hack plugin/theme inventory and recovery actions.
 * Email notifications via WordPress mail settings.

#### 0.8.0

 * Added targeted scope scanning for plugins, themes, mu-plugins, uploads, and WordPress
   root files.
 * Added frontend and database detection modules and integrated full scan aggregation.
 * Added scan findings table with actions and preview foundation.

#### 0.5.0

 * Added scan rules, exclusions, heuristic controls, scheduler and notification 
   settings.
 * Added initial quick file scan engine on wp-content.
 * Added quarantine policy and file isolation hooks.

#### 0.1.0

 * Introduced anti-malware admin structure and plugin foundation.

## Meta

 *  Version **1.2.0**
 *  Last updated **2 weeks ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.2 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/yuga-antimalware/)
 * Tags
 * [antivirus](https://pcm.wordpress.org/plugins/tags/antivirus/)[hardening](https://pcm.wordpress.org/plugins/tags/hardening/)
   [malware](https://pcm.wordpress.org/plugins/tags/malware/)[scan](https://pcm.wordpress.org/plugins/tags/scan/)
   [security](https://pcm.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://pcm.wordpress.org/plugins/yuga-antimalware/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/yuga-antimalware/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/yuga-antimalware/reviews/)

## Contributors

 *   [ Yuga Web ](https://profiles.wordpress.org/yugaweb/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/yuga-antimalware/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://www.paypal.com/donate/?hosted_button_id=BR8Q3AKCBYML4)