{"id":366104,"date":"2026-09-10T08:42:17","date_gmt":"2026-09-10T08:42:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/yuga-antimalware\/"},"modified":"2026-09-15T14:26:05","modified_gmt":"2026-09-15T14:26:05","slug":"yuga-antimalware","status":"publish","type":"plugin","link":"https:\/\/nl.wordpress.org\/plugins\/yuga-antimalware\/","author":23200303,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1.1","requires":"5.8","requires_php":"7.2","requires_plugins":null,"header_name":"Yuga AntiMalware","header_author":"Yuga Web","header_description":"Security plugin for WordPress to configure scans and detect malware indicators from a dedicated admin panel.","assets_banners_color":"c0e8fc","last_updated":"2026-09-15 14:26:05","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.paypal.com\/donate\/?hosted_button_id=BR8Q3AKCBYML4","header_plugin_uri":"","header_author_uri":"https:\/\/www.yugaweb.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":137,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"1.1.1":{"tag":"1.1.1","author":"yugaweb","date":"2026-09-10 14:49:32","revision":3690084},"1.1.2":{"tag":"1.1.2","author":"yugaweb","date":"2026-09-10 14:49:32","revision":3690084},"1.2.0":{"tag":"1.2.0","author":"yugaweb","date":"2026-09-15 14:26:05","revision":3697133}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3690084,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690084,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3690084,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3690084,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3690084,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.1","1.1.2","1.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3690084,"resolution":"1","location":"assets","locale":"","width":1720,"height":824},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3690084,"resolution":"2","location":"assets","locale":"","width":1720,"height":824},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3690084,"resolution":"3","location":"assets","locale":"","width":1720,"height":824},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3690084,"resolution":"4","location":"assets","locale":"","width":1720,"height":824},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3690084,"resolution":"5","location":"assets","locale":"","width":1720,"height":824}},"screenshots":{"1":"Dashboard scan controls with scan mode selection, progress and completion results.","2":"Scan rules: heuristic sensitivity and scan execution time settings.","3":"Scheduler settings for automatic quick scans using WordPress cron.","4":"Quarantine settings with configurable retention for stored files.","5":"Email notification settings for scan reports."}},"plugin_section":[],"plugin_tags":[1175,31093,1184,1181,600],"plugin_category":[54],"plugin_contributors":[237429],"plugin_business_model":[],"class_list":["post-366104","plugin","type-plugin","status-publish","hentry","plugin_tags-antivirus","plugin_tags-hardening","plugin_tags-malware","plugin_tags-scan","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-yugaweb","plugin_committers-yugaweb"],"banners":{"banner":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/banner-772x250.png?rev=3690084","banner_2x":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/banner-1544x500.png?rev=3690084","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/icon.svg?rev=3690084","icon":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/icon.svg?rev=3690084","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/screenshot-1.jpg?rev=3690084","caption":"Dashboard scan controls with scan mode selection, progress and completion results."},{"src":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/screenshot-2.jpg?rev=3690084","caption":"Scan rules: heuristic sensitivity and scan execution time settings."},{"src":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/screenshot-3.jpg?rev=3690084","caption":"Scheduler settings for automatic quick scans using WordPress cron."},{"src":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/screenshot-4.jpg?rev=3690084","caption":"Quarantine settings with configurable retention for stored files."},{"src":"https:\/\/ps.w.org\/yuga-antimalware\/assets\/screenshot-5.jpg?rev=3690084","caption":"Email notification settings for scan reports."}],"raw_content":"<!--section=description-->\n<p>Yuga AntiMalware is an admin-focused plugin built to detect suspicious malware indicators and support remediation workflows on WordPress sites.<\/p>\n\n<p>Main capabilities:\n- Tabbed admin interface with left sidebar sections and right helper column.\n- Scan modes:\n  - Quick scan (files in wp-content)\n  - Targeted scan (plugins\/themes\/mu-plugins\/uploads\/root files)\n  - Database scan\n  - Frontend scan\n  - Full scan (files + database + frontend)\n- Optional PHP max_execution_time override for scan execution.\n- Background scans in saved blocks, with automatic continuation and manual resume when needed.\n- Real scan progress: analyzed files, database rows, checked pages and completed modules, without a simulated percentage.\n- Automatic quick scans through WP-Cron (hourly, daily, or weekly).\n- Findings table with sorting, grouping, and file preview.\n- Findings actions: ignore, exclude path, quarantine, delete, copy path.\n- Reinfection Trace with database hot spots and writer candidates.\n- Writer Hunt for file-level suspect correlation.\n- Safe options cleanup workflow: backup + cleanup + restore rollback.\n- Content Cleanup for suspicious post\/page\/revision rows with filters by author, category, type, language\/script, and keyword.\n- Content cleanup actions with rollback backups, batch-based filtered trashing, and previous revision restore for posts\/pages.\n- Trash Cleanup for permanently removing WordPress trash items in backed-up batches.\n- Cache cleanup tools (targeted suspicious cache cleanup and full transient flush).\n- Post-hack plugin\/theme inventory with version checks and maintenance actions where supported.\n- Quarantine inventory viewer in admin.\n- Retention policy for quarantined files, applied from quarantine timestamp.\n- Email notifications via default WordPress mail settings.\n- Comment protection: optionally send new comments with explicit spam signals to the WordPress Spam folder before publication.\n- Comment Cleanup: review comments, trackbacks and pingbacks in batches of up to 1,000, then trash or permanently delete selected items.\n- Dedicated manual-review filters for all pending comments, external links and non-Latin letters in names or text.\n- Administrator-only JSON export of all comments, preserving original HTML links and moderation context.<\/p>\n\n<h3>Root Integrity Check<\/h3>\n\n<p>Root scans and the root module of Full Scan compare directly contained files\nwith the official checksums for the installed WordPress version and package\nlocale. Additional files are review findings, not proof of malware. Modified\ncore files are flagged separately. This does not verify all of wp-admin or\nwp-includes, detect missing files, or inspect extra directories.<\/p>\n\n<p>Local wp-config.php, .htaccess, .user.ini, robots.txt, web.config, php.ini and\n.maintenance are exempt from additional-file warnings, but remain subject to\napplicable content rules. Inventory includes all extensions; explicit path\nexclusions still apply. Unavailable manifests, excluded\/unreadable\/oversized\ncore files or interruption leave the verification incomplete.<\/p>\n\n<p>Configuration files .htaccess, .user.ini and php.ini are included in content\nscans within the selected scope, subject to configured exclusions and limits.\nChecks flag active automatic PHP loading directives, Apache Substitute script\nor iframe markup, and crawler-conditioned rewrites to PHP or external URLs.\nComments, empty\/none PHP loader settings, ordinary WordPress rewrites and\ncrawler blocking with an unchanged target are not flagged by these checks.\nLegitimate firewalls can use automatic loading: review before changing files.\nConfiguration findings are advisory; no directives are executed by the scanner.\nUse the pencil action on .htaccess or .user.ini findings for Configuration\nCleanup. Review the complete before\/after proposal and all removed lines;\nconfirming applies the whole proposal. Containers emptied by the proposal and\ntheir marker comments are removed. Unused rewrite-engine and substitution-filter\nlines are removed only when no remaining rule may depend on them. Independent\nsettings and the WordPress marker block are retained. Ambiguous sections, continued lines\nand chained\/skipping rewrite rules require manual review. The tool does not\nvalidate the configuration against your hosting server's active modules.<\/p>\n\n<p>Before applying, download the current file for recovery outside WordPress.\nEvery write, including a restore, requires a verified backup in the WordPress\ndatabase (not autoloaded), preserves file permissions, rechecks the preview\nhash, verifies written bytes and attempts rollback if writing fails. Backups\nare listed with download and restore-preview actions; they are removed on\nplugin uninstall. Failed rollback requires restoring through the hosting file\nmanager. Previews expire after 15 minutes. Successful file deletion and quarantine remove that target's stored findings.\nConfiguration cleanup and restore recheck the changed file, retain residual\nfindings and adjust counters. Failed verification leaves findings in place and\nshows a pending-verification message. A short history records successful file\nactions and verification outcomes. If the previous preview was truncated,\ncounters are marked approximate until a new scan provides exact totals.\nA full scan remains useful for reviewing the rest of the site.\nAn interrupted operation can leave its safety lock in place; an administrator\nmust verify that no operation is running before clearing that lock.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>Root integrity verification contacts the WordPress.org checksum API over HTTPS\nwhen a root scan runs, sending the installed WordPress version and package\nlocale. No file contents or local paths are uploaded. Successful manifests\nare cached locally for 24 hours. See https:\/\/wordpress.org\/about\/privacy\/\nand https:\/\/wordpress.org\/about\/terms-of-service\/.<\/p>\n\n<p>This plugin optionally integrates with PayPal Donate to facilitate donations. No PayPal resource is loaded until an administrator explicitly clicks the \"Donate with PayPal\" button on the plugin settings page.<\/p>\n\n<ul>\n<li><strong>Service Name<\/strong>: PayPal Donate API<\/li>\n<li><strong>Purpose<\/strong>: To provide a donation button through PayPal.<\/li>\n<li><strong>Data Sent<\/strong>:\n\n<ul>\n<li>Network and device information normally included in web requests, such as IP address and user agent<\/li>\n<li>The hosted PayPal button identifier<\/li>\n<li>Any payment information the administrator subsequently enters on PayPal<\/li>\n<\/ul><\/li>\n<li><strong>When<\/strong>: The PayPal SDK is requested only after an administrator clicks the \"Donate with PayPal\" button.<\/li>\n<li><strong>Service Links<\/strong>:\n\n<ul>\n<li><a href=\"https:\/\/www.paypal.com\/us\/webapps\/mpp\/ua\/legalhub-full\">PayPal Terms of Service<\/a><\/li>\n<li><a href=\"https:\/\/www.paypal.com\/us\/webapps\/mpp\/ua\/privacy-full\">PayPal Privacy Policy<\/a><\/li>\n<\/ul><\/li>\n<\/ul>\n\n<p>Payment transactions are handled by PayPal under its own terms and privacy policy.<\/p>\n\n<h3>How to use Content Cleanup safely<\/h3>\n\n<ol>\n<li>Run a Database scan or Full scan first.<\/li>\n<li>Open Dashboard &gt; Content Cleanup and review the filtered suspicious post rows.<\/li>\n<li>Use filters such as Author, Category, Type, Language\/script, and Keyword to narrow the result set.<\/li>\n<li>Prefer backup-backed actions before trashing content.<\/li>\n<li>For real posts or pages that were modified, use Restore previous revision when a clean revision is available.<\/li>\n<li>For suspicious revisions, move them to trash after verifying they are not needed.<\/li>\n<li>Use Trash Cleanup only after confirming the trashed content should be permanently removed.<\/li>\n<\/ol>\n\n<h3>Pharmaceutical spam signals in database content<\/h3>\n\n<p>A pharmaceutical keyword alone does not trigger the pharmaceutical promotion\nrule. A listed term must occur near buying, discount, shipping or prescription-free\nsales wording in the same text segment (up to 100 intervening characters).\nThe rule recognizes selected English and Italian wording. It does not combine\nsignals across HTML tags, serialized\/JSON field delimiters, lines or sentences.\nResults are potential promotions for manual review, not proof of infection.\nNo links are opened and no stored values are deserialized or modified.<\/p>\n\n<p>Run a new scan after updating to replace older keyword-only findings. The\npreview explains when an old finding no longer matches the contextual rule.<\/p>\n\n<h3>Comment Cleanup and Protection<\/h3>\n\n<p>Open Yuga AntiMalware &gt; Comment Cleanup to manage existing comments, configure\nprotection for new submissions, or download a review export. The tools support\nordinary comments, trackbacks and pingbacks. Product reviews and other custom\ncomment types are excluded from detection and cleanup.<\/p>\n\n<h4>Spam protection for new comments<\/h4>\n\n<p>Dashboard &gt; Overview shows the saved Comment protection status (Enabled or\nDisabled), with links to its settings and the WordPress Spam folder.<\/p>\n\n<p>Saving protection records before\/after counts for Pending, Approved, Spam and\nTrash, displayed with a UTC timestamp in Comment Cleanup for troubleshooting.\nThe counts describe that save, not current totals; concurrent moderation can\nalso affect them. No comment content is stored in this diagnostic record.<\/p>\n\n<p>Protection is optional and disabled by default. Enable \"Automatically mark new\ncomments with explicit spam signals as spam\" and save the setting.<\/p>\n\n<p>When enabled, strong medicine-purchase promotions, linked affiliate invitations,\nrepeated adult keywords with links, or combined opaque alphanumeric names,\nemails and long unbroken alphanumeric text receive WordPress Spam status.\nConsonant-heavy names with relay emails alone remain manual-review hints.<\/p>\n\n<p>After a new submission is successfully stored, protection can also move\nrelated pending comments with matching spam signals to Spam. Approved comments\nare left unchanged. Saving the setting itself does not move comments.\nDisabling stops automatic moderation without restoring previously moved\ncomments. No automatic Trash or deletion.<\/p>\n\n<p>Existing rejection, Spam or Trash decisions are preserved. Imports bypassing\nWordPress submission hooks do not trigger the automatic review. No external\nanti-spam service is contacted. Review WordPress &gt; Comments &gt; Spam for false\npositives and restore legitimate messages. Other tools may purge Spam.\nLanguage or external links alone never trigger automatic Spam.<\/p>\n\n<h4>Reviewing and cleaning existing comments<\/h4>\n\n<p>Choose one of the following views and select \"Analyze from the beginning\":<\/p>\n\n<ul>\n<li>Marked spam and potential spam.<\/li>\n<li>Already marked as spam.<\/li>\n<li>Potential spam only.<\/li>\n<li>Non-Latin letters in name or text: optional manual review.<\/li>\n<li>Links to external websites: optional manual review.<\/li>\n<li>All pending comments: manual review, including unflagged items.<\/li>\n<\/ul>\n\n<p>Approved comments require explicit opt-in for potential-spam analysis. The\nthree manual-review filters show pending comments only, even if that opt-in is\nselected. Comments without a spam classification are identified as such.<\/p>\n\n<p>Each preview examines up to 1,000 comments, not 1,000 spam matches. Select\nindividual comments or all items in the preview, review the selection and\nconfirm the chosen action. Continue with \"Analyze next batch\" to examine the\nremaining comments. Start again to revisit skipped or unselected items.\nPreviews expire after 30 minutes; changed or unavailable comments are skipped.<\/p>\n\n<p>Manual cleanup offers two actions:<\/p>\n\n<ul>\n<li>Move to trash (default): selected existing comments go to WordPress Trash,\nnot Spam. They can be restored until WordPress empties the trash according\nto the site's retention setting. This action is blocked if trash is disabled.<\/li>\n<li>Delete permanently: requires an additional explicit confirmation. There is\nno backup and this action cannot be undone.<\/li>\n<\/ul>\n\n<p>Automatic protection and manual cleanup therefore have different destinations:\nautomatic detections go to Spam; manually trashed comments go to Trash.\nManual cleanup currently has no \"Mark as spam\" action. Use the WordPress\nComments screen to mark existing comments as Spam instead of trashing them.<\/p>\n\n<h4>Detection and review limits<\/h4>\n\n<p>Review hints include linked-text-only comments, BBCode links (including unclosed\ntags), multiple links, executable HTML, explicit commercial pitches, repeated\nadult keywords, medicine promotions, contact-only comments and generic greetings\nor compliments accompanied by links. URLs with a domain and path are recognized\nwithout an HTTP scheme. HTML anchors retain their destination during analysis.<\/p>\n\n<p>Manual review also flags combinations of consonant-heavy names and long opaque\nemail identifiers. Combined alphanumeric names\/emails and long unbroken\nalphanumeric text also qualify for automatic protection when enabled. Relay addresses, long emails or pseudonyms\nalone are not sufficient. Display names advertising online medicines are\nalso flagged for review. Relay-email and advertising-name hints alone do not\ntrigger automatic Spam.<\/p>\n\n<p>Review also considers patterns across comments in the current preview batch.\nRelated evidence is rechecked before cleanup.<\/p>\n\n<p>Review hints can include legitimate references, advertising, quotations and\nshared networks. They do not prove an infection or guarantee spam detection.\nThe first 64 KB of each comment body are inspected; whole-body rules apply\nonly when the complete body is within that limit.<\/p>\n\n<p>The non-Latin filter checks visible names and text, excluding links and HTML\nattributes. It includes Cyrillic, Greek, Arabic and Asian scripts, but does not\nidentify language or nationality. Accented Latin letters and emoji alone do\nnot match. The external-links filter compares destinations in comment bodies\nand author websites with the public site's hostname, treating www as the same\nhostname. Other subdomains count as external; relative links and email addresses\nalone do not match. Destinations are never visited. Neither filter is a spam\nverdict, and no items are selected or removed automatically by these filters.<\/p>\n\n<h4>Exporting comments for review<\/h4>\n\n<p>\"Export all comments (JSON)\" downloads readable JSON with original HTML, text,\nauthor website, email, IP, date, status, article title, edit links and individual\nreview reasons. Cross-comment correlation and comment metadata are not included.\nThe export includes every status and type, including approved comments, Spam,\nTrash and custom types, independently of preview filters.<\/p>\n\n<p>The export requires administrator and moderation permissions. No public file\nis created. It contains personal data: store and share the download carefully.\nData is read in batches of 200 up to the highest ID at export start; concurrent\nedits or deletions can affect it, so it is not a database snapshot. Only valid\nJSON ending with complete=true represents a finished export. Retry interrupted\ndownloads.<\/p>\n\n<h3>Scan continuation<\/h3>\n\n<p>Dashboard and scheduled scans continue in blocks aiming for eight seconds or\nat most 100 work items per request. Each file, batch of ten database rows, or\nfrontend URL finishes before yielding. A slow individual operation can exceed\nthat target and hosting limits still apply. Results and pending work are saved\ntogether after each successful block.<\/p>\n\n<p>Progress shows confirmed file, database-row and page counts, the current area,\nand completed modules for Full scan. The activity bar is not an estimated\npercentage; counters update after each saved block without a preliminary file census.<\/p>\n\n<p>Keep the dashboard open for prompt continuation. With the page closed,\ncontinuation uses WP-Cron and depends on site traffic or an external cron\ntrigger. Interrupted requests retry from the last confirmed block. After three\nunsuccessful attempts, use Resume saved scan. Stop retains the checkpoint too.\nStarting a new scan replaces the previous saved scan.<\/p>\n\n<p>Cron wakeups are reused, with a separate watchdog for interrupted requests.\nPending one-shot events for completed or replaced jobs expire without scanning.\nIf scheduling fails, the progress display advises keeping the page open for\nAJAX continuation. Persistent database or WordPress cron problems still need\ninvestigation. The summary distinguishes recorded processing milliseconds\nfrom total elapsed time, including waits and manual pauses. Total time remains\nunavailable for older completed scans that have no recorded finish timestamp.<\/p>\n\n<p>The legacy scan time budget does not limit the total duration of these jobs.\nThe PHP execution-time override applies to individual requests, subject to\nhosting policy. A resumed scan uses its original settings; changes apply to a\nnew scan. Directory names are snapshotted when visited, so files added later\nmay require another scan. Directories with more than 20,000 entries stop with\nan explicit checkpoint-size error to prevent excessive checkpoint storage.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/yuga-antimalware\/<\/code>.<\/li>\n<li>Activate the plugin in WordPress Plugins.<\/li>\n<li>Open <strong>Yuga AntiMalware<\/strong> from the left admin menu.<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added saved scan blocks with automatic continuation, interrupted-request recovery and manual resume when automatic attempts fail.<\/li>\n<li>Replaced simulated scan percentages with confirmed counters, current module, elapsed time and time since the last saved progress.<\/li>\n<li>Improved scan cron wakeup handling and distinguished processing duration from total elapsed scan time.<\/li>\n<li>Added the saved comment-protection status and management links to Dashboard &gt; Overview.<\/li>\n<li>Added optional protection that marks new submissions with explicit spam signals as Spam before publication; disabled by default, with no automatic deletion.<\/li>\n<li>Improved comment-protection performance with batched reads and fewer repeated queries, retaining checks for comments changed during processing.<\/li>\n<li>Added combined opaque-name, email and alphanumeric-text detection to standard comment protection; relay-email and advertising-name hints remain available for manual review.<\/li>\n<li>Expanded comment review rules for promotional messages, linked text, BBCode and repeated submissions, including trackbacks and pingbacks.<\/li>\n<li>Added separate manual-review views for pending comments, external links and non-Latin text, without treating those filters as automatic spam verdicts.<\/li>\n<li>Added a protected JSON export of all comments with original HTML links, author information, moderation state and individual review reasons.<\/li>\n<li>Improved Comment Cleanup preview layout with proportional columns and wrapping for long text and URLs.<\/li>\n<li>Updated stored findings after successful file actions and configuration rechecks, with action history and counter limitations.<\/li>\n<li>Added guided configuration cleanup with before\/after review, mandatory backups, downloads and restore previews.<\/li>\n<li>Added content checks for .htaccess, .user.ini and php.ini: automatic PHP loading, Apache script substitution and crawler-conditioned rewrites.<\/li>\n<li>Fixed Unicode word boundaries for database pharma detection and stale preview highlighting; truly disabled unavailable file actions.<\/li>\n<li>Reduced pharmaceutical false positives by requiring nearby purchase or promotional wording instead of a medicine keyword alone.<\/li>\n<li>Added official package comparison for root files, including additional files and modified core files.<\/li>\n<li>Added a review rule for LinkPool remote HTML PHP snippets, including renamed files, and self-deleting WordPress environment probes.<\/li>\n<li>Added Ignored Findings with individual restore actions, including saved references absent from the latest scan.<\/li>\n<li>Prevented file deletion, quarantine and path exclusions for database\/frontend findings, including mixed bulk selections.<\/li>\n<li>Added Comment Cleanup with a preview of marked spam and potentially suspicious comments, trackbacks and pingbacks.<\/li>\n<li>Added opt-in scanning of approved comments, per-comment reasons, selection of up to 1,000 comments and a choice between trash and confirmed permanent deletion.<\/li>\n<li>Protected changed comments and expired previews; blocked the trash action when WordPress trash is disabled.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Updated the plugin header with the new Yuga AntiMalware logo for dark backgrounds.<\/li>\n<li>Added screenshot descriptions and refreshed the WordPress.org artwork.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Lowered the minimum PHP requirement to 7.2 after compatibility regression testing.<\/li>\n<li>Prevented file deletion when a required backup fails.<\/li>\n<li>Verified quarantine copies and recovery metadata before removing originals; added checksum validation for new backups and explicit partial-failure notices.<\/li>\n<li>Added WordPress 7.1 and PHP 7.4 compatibility fixes.<\/li>\n<li>Changed PayPal integration so external resources load only after explicit administrator interaction.<\/li>\n<li>Hardened backup and quarantine storage and made quarantined payloads non-executable by extension.<\/li>\n<li>Added working WP-Cron scheduling for automatic quick scans.<\/li>\n<li>Preserved modern WordPress option autoload values during backup restore.<\/li>\n<li>Improved cleanup of plugin-owned data during uninstall.<\/li>\n<li>Removed inactive signature-update and custom scan-path controls; scans continue to use the documented fixed scopes.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Improved quarantine UX and lifecycle:<\/li>\n<li>Added Quarantine &gt; Stored Files inventory table.<\/li>\n<li>Added event-driven retention purge scheduling based on quarantine insertion date.<\/li>\n<li>Added writer-candidate quarantine action in Reinfection Trace with consistent icon-based actions.<\/li>\n<li>UI refinements for Quarantine settings naming and table consistency.<\/li>\n<li>Added Content Cleanup with filtered post\/page\/revision review, rollback backups, batch trash actions, previous revision restore, and Trash Cleanup.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Introduced full security workflow:<\/li>\n<li>Multi-mode scans (quick, targeted, database, frontend, full).<\/li>\n<li>Background scan execution with runtime polling.<\/li>\n<li>Reinfection Trace and Writer Hunt correlation.<\/li>\n<li>Safe options maintenance (backup + cleanup + restore).<\/li>\n<li>Cache cleanup tools (targeted + full transient flush).<\/li>\n<li>Post-hack plugin\/theme inventory and recovery actions.<\/li>\n<li>Email notifications via WordPress mail settings.<\/li>\n<\/ul>\n\n<h4>0.8.0<\/h4>\n\n<ul>\n<li>Added targeted scope scanning for plugins, themes, mu-plugins, uploads, and WordPress root files.<\/li>\n<li>Added frontend and database detection modules and integrated full scan aggregation.<\/li>\n<li>Added scan findings table with actions and preview foundation.<\/li>\n<\/ul>\n\n<h4>0.5.0<\/h4>\n\n<ul>\n<li>Added scan rules, exclusions, heuristic controls, scheduler and notification settings.<\/li>\n<li>Added initial quick file scan engine on wp-content.<\/li>\n<li>Added quarantine policy and file isolation hooks.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Introduced anti-malware admin structure and plugin foundation.<\/li>\n<\/ul>","raw_excerpt":"WordPress anti-malware plugin with tabbed admin panel, multi-mode scanning, quarantine, cleanup tooling, and post-hack recovery checks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/366104","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=366104"}],"author":[{"embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/yugaweb"}],"wp:attachment":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=366104"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=366104"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=366104"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=366104"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=366104"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=366104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}