Beschrijving
Yuga AntiMalware is an admin-focused plugin built to detect suspicious malware indicators and support remediation workflows on WordPress sites.
Main capabilities:
– Tabbed admin interface with left sidebar sections and right helper column.
– Scan modes:
– Quick scan (files in wp-content)
– Targeted scan (plugins/themes/mu-plugins/uploads/root files)
– Database scan
– Frontend scan
– Full scan (files + database + frontend)
– Optional PHP max_execution_time override for scan execution.
– Background scans in saved blocks, with automatic continuation and manual resume when needed.
– Real scan progress: analyzed files, database rows, checked pages and completed modules, without a simulated percentage.
– Automatic quick scans through WP-Cron (hourly, daily, or weekly).
– Findings table with sorting, grouping, and file preview.
– Findings actions: ignore, exclude path, quarantine, delete, copy path.
– Reinfection Trace with database hot spots and writer candidates.
– Writer Hunt for file-level suspect correlation.
– Safe options cleanup workflow: backup + cleanup + restore rollback.
– Content Cleanup for suspicious post/page/revision rows with filters by author, category, type, language/script, and keyword.
– Content cleanup actions with rollback backups, batch-based filtered trashing, and previous revision restore for posts/pages.
– Trash Cleanup for permanently removing WordPress trash items in backed-up batches.
– Cache cleanup tools (targeted suspicious cache cleanup and full transient flush).
– Post-hack plugin/theme inventory with version checks and maintenance actions where supported.
– Quarantine inventory viewer in admin.
– Retention policy for quarantined files, applied from quarantine timestamp.
– Email notifications via default WordPress mail settings.
– Comment protection: optionally send new comments with explicit spam signals to the WordPress Spam folder before publication.
– Comment Cleanup: review comments, trackbacks and pingbacks in batches of up to 1,000, then trash or permanently delete selected items.
– Dedicated manual-review filters for all pending comments, external links and non-Latin letters in names or text.
– Administrator-only JSON export of all comments, preserving original HTML links and moderation context.
Root Integrity Check
Root scans and the root module of Full Scan compare directly contained files
with the official checksums for the installed WordPress version and package
locale. Additional files are review findings, not proof of malware. Modified
core files are flagged separately. This does not verify all of wp-admin or
wp-includes, detect missing files, or inspect extra directories.
Local wp-config.php, .htaccess, .user.ini, robots.txt, web.config, php.ini and
.maintenance are exempt from additional-file warnings, but remain subject to
applicable content rules. Inventory includes all extensions; explicit path
exclusions still apply. Unavailable manifests, excluded/unreadable/oversized
core files or interruption leave the verification incomplete.
Configuration files .htaccess, .user.ini and php.ini are included in content
scans within the selected scope, subject to configured exclusions and limits.
Checks flag active automatic PHP loading directives, Apache Substitute script
or iframe markup, and crawler-conditioned rewrites to PHP or external URLs.
Comments, empty/none PHP loader settings, ordinary WordPress rewrites and
crawler blocking with an unchanged target are not flagged by these checks.
Legitimate firewalls can use automatic loading: review before changing files.
Configuration findings are advisory; no directives are executed by the scanner.
Use the pencil action on .htaccess or .user.ini findings for Configuration
Cleanup. Review the complete before/after proposal and all removed lines;
confirming applies the whole proposal. Containers emptied by the proposal and
their marker comments are removed. Unused rewrite-engine and substitution-filter
lines are removed only when no remaining rule may depend on them. Independent
settings and the WordPress marker block are retained. Ambiguous sections, continued lines
and chained/skipping rewrite rules require manual review. The tool does not
validate the configuration against your hosting server’s active modules.
Before applying, download the current file for recovery outside WordPress.
Every write, including a restore, requires a verified backup in the WordPress
database (not autoloaded), preserves file permissions, rechecks the preview
hash, verifies written bytes and attempts rollback if writing fails. Backups
are listed with download and restore-preview actions; they are removed on
plugin uninstall. Failed rollback requires restoring through the hosting file
manager. Previews expire after 15 minutes. Successful file deletion and quarantine remove that target’s stored findings.
Configuration cleanup and restore recheck the changed file, retain residual
findings and adjust counters. Failed verification leaves findings in place and
shows a pending-verification message. A short history records successful file
actions and verification outcomes. If the previous preview was truncated,
counters are marked approximate until a new scan provides exact totals.
A full scan remains useful for reviewing the rest of the site.
An interrupted operation can leave its safety lock in place; an administrator
must verify that no operation is running before clearing that lock.
External Services
Root integrity verification contacts the WordPress.org checksum API over HTTPS
when a root scan runs, sending the installed WordPress version and package
locale. No file contents or local paths are uploaded. Successful manifests
are cached locally for 24 hours. See https://wordpress.org/about/privacy/
and https://wordpress.org/about/terms-of-service/.
This plugin optionally integrates with PayPal Donate to facilitate donations. No PayPal resource is loaded until an administrator explicitly clicks the “Donate with PayPal” button on the plugin settings page.
- Service Name: PayPal Donate API
- Purpose: To provide a donation button through PayPal.
- Data Sent:
- Network and device information normally included in web requests, such as IP address and user agent
- The hosted PayPal button identifier
- Any payment information the administrator subsequently enters on PayPal
- When: The PayPal SDK is requested only after an administrator clicks the “Donate with PayPal” button.
- Service Links:
Payment transactions are handled by PayPal under its own terms and privacy policy.
How to use Content Cleanup safely
- Run a Database scan or Full scan first.
- Open Dashboard > Content Cleanup and review the filtered suspicious post rows.
- Use filters such as Author, Category, Type, Language/script, and Keyword to narrow the result set.
- Prefer backup-backed actions before trashing content.
- For real posts or pages that were modified, use Restore previous revision when a clean revision is available.
- For suspicious revisions, move them to trash after verifying they are not needed.
- Use Trash Cleanup only after confirming the trashed content should be permanently removed.
Pharmaceutical spam signals in database content
A pharmaceutical keyword alone does not trigger the pharmaceutical promotion
rule. A listed term must occur near buying, discount, shipping or prescription-free
sales wording in the same text segment (up to 100 intervening characters).
The rule recognizes selected English and Italian wording. It does not combine
signals across HTML tags, serialized/JSON field delimiters, lines or sentences.
Results are potential promotions for manual review, not proof of infection.
No links are opened and no stored values are deserialized or modified.
Run a new scan after updating to replace older keyword-only findings. The
preview explains when an old finding no longer matches the contextual rule.
Comment Cleanup and Protection
Open Yuga AntiMalware > Comment Cleanup to manage existing comments, configure
protection for new submissions, or download a review export. The tools support
ordinary comments, trackbacks and pingbacks. Product reviews and other custom
comment types are excluded from detection and cleanup.
Spam protection for new comments
Dashboard > Overview shows the saved Comment protection status (Enabled or
Disabled), with links to its settings and the WordPress Spam folder.
Saving protection records before/after counts for Pending, Approved, Spam and
Trash, displayed with a UTC timestamp in Comment Cleanup for troubleshooting.
The counts describe that save, not current totals; concurrent moderation can
also affect them. No comment content is stored in this diagnostic record.
Protection is optional and disabled by default. Enable “Automatically mark new
comments with explicit spam signals as spam” and save the setting.
When enabled, strong medicine-purchase promotions, linked affiliate invitations,
repeated adult keywords with links, or combined opaque alphanumeric names,
emails and long unbroken alphanumeric text receive WordPress Spam status.
Consonant-heavy names with relay emails alone remain manual-review hints.
After a new submission is successfully stored, protection can also move
related pending comments with matching spam signals to Spam. Approved comments
are left unchanged. Saving the setting itself does not move comments.
Disabling stops automatic moderation without restoring previously moved
comments. No automatic Trash or deletion.
Existing rejection, Spam or Trash decisions are preserved. Imports bypassing
WordPress submission hooks do not trigger the automatic review. No external
anti-spam service is contacted. Review WordPress > Comments > Spam for false
positives and restore legitimate messages. Other tools may purge Spam.
Language or external links alone never trigger automatic Spam.
Reviewing and cleaning existing comments
Choose one of the following views and select “Analyze from the beginning”:
- Marked spam and potential spam.
- Already marked as spam.
- Potential spam only.
- Non-Latin letters in name or text: optional manual review.
- Links to external websites: optional manual review.
- All pending comments: manual review, including unflagged items.
Approved comments require explicit opt-in for potential-spam analysis. The
three manual-review filters show pending comments only, even if that opt-in is
selected. Comments without a spam classification are identified as such.
Each preview examines up to 1,000 comments, not 1,000 spam matches. Select
individual comments or all items in the preview, review the selection and
confirm the chosen action. Continue with “Analyze next batch” to examine the
remaining comments. Start again to revisit skipped or unselected items.
Previews expire after 30 minutes; changed or unavailable comments are skipped.
Manual cleanup offers two actions:
- Move to trash (default): selected existing comments go to WordPress Trash,
not Spam. They can be restored until WordPress empties the trash according
to the site’s retention setting. This action is blocked if trash is disabled. - Delete permanently: requires an additional explicit confirmation. There is
no backup and this action cannot be undone.
Automatic protection and manual cleanup therefore have different destinations:
automatic detections go to Spam; manually trashed comments go to Trash.
Manual cleanup currently has no “Mark as spam” action. Use the WordPress
Comments screen to mark existing comments as Spam instead of trashing them.
Detection and review limits
Review hints include linked-text-only comments, BBCode links (including unclosed
tags), multiple links, executable HTML, explicit commercial pitches, repeated
adult keywords, medicine promotions, contact-only comments and generic greetings
or compliments accompanied by links. URLs with a domain and path are recognized
without an HTTP scheme. HTML anchors retain their destination during analysis.
Manual review also flags combinations of consonant-heavy names and long opaque
email identifiers. Combined alphanumeric names/emails and long unbroken
alphanumeric text also qualify for automatic protection when enabled. Relay addresses, long emails or pseudonyms
alone are not sufficient. Display names advertising online medicines are
also flagged for review. Relay-email and advertising-name hints alone do not
trigger automatic Spam.
Review also considers patterns across comments in the current preview batch.
Related evidence is rechecked before cleanup.
Review hints can include legitimate references, advertising, quotations and
shared networks. They do not prove an infection or guarantee spam detection.
The first 64 KB of each comment body are inspected; whole-body rules apply
only when the complete body is within that limit.
The non-Latin filter checks visible names and text, excluding links and HTML
attributes. It includes Cyrillic, Greek, Arabic and Asian scripts, but does not
identify language or nationality. Accented Latin letters and emoji alone do
not match. The external-links filter compares destinations in comment bodies
and author websites with the public site’s hostname, treating www as the same
hostname. Other subdomains count as external; relative links and email addresses
alone do not match. Destinations are never visited. Neither filter is a spam
verdict, and no items are selected or removed automatically by these filters.
Exporting comments for review
“Export all comments (JSON)” downloads readable JSON with original HTML, text,
author website, email, IP, date, status, article title, edit links and individual
review reasons. Cross-comment correlation and comment metadata are not included.
The export includes every status and type, including approved comments, Spam,
Trash and custom types, independently of preview filters.
The export requires administrator and moderation permissions. No public file
is created. It contains personal data: store and share the download carefully.
Data is read in batches of 200 up to the highest ID at export start; concurrent
edits or deletions can affect it, so it is not a database snapshot. Only valid
JSON ending with complete=true represents a finished export. Retry interrupted
downloads.
Scan continuation
Dashboard and scheduled scans continue in blocks aiming for eight seconds or
at most 100 work items per request. Each file, batch of ten database rows, or
frontend URL finishes before yielding. A slow individual operation can exceed
that target and hosting limits still apply. Results and pending work are saved
together after each successful block.
Progress shows confirmed file, database-row and page counts, the current area,
and completed modules for Full scan. The activity bar is not an estimated
percentage; counters update after each saved block without a preliminary file census.
Keep the dashboard open for prompt continuation. With the page closed,
continuation uses WP-Cron and depends on site traffic or an external cron
trigger. Interrupted requests retry from the last confirmed block. After three
unsuccessful attempts, use Resume saved scan. Stop retains the checkpoint too.
Starting a new scan replaces the previous saved scan.
Cron wakeups are reused, with a separate watchdog for interrupted requests.
Pending one-shot events for completed or replaced jobs expire without scanning.
If scheduling fails, the progress display advises keeping the page open for
AJAX continuation. Persistent database or WordPress cron problems still need
investigation. The summary distinguishes recorded processing milliseconds
from total elapsed time, including waits and manual pauses. Total time remains
unavailable for older completed scans that have no recorded finish timestamp.
The legacy scan time budget does not limit the total duration of these jobs.
The PHP execution-time override applies to individual requests, subject to
hosting policy. A resumed scan uses its original settings; changes apply to a
new scan. Directory names are snapshotted when visited, so files added later
may require another scan. Directories with more than 20,000 entries stop with
an explicit checkpoint-size error to prevent excessive checkpoint storage.
Schermafbeeldingen





Installatie
- Upload the plugin folder to
/wp-content/plugins/yuga-antimalware/. - Activate the plugin in WordPress Plugins.
- Open Yuga AntiMalware from the left admin menu.
Beoordelingen
Er zijn geen beoordelingen voor deze plugin.
Bijdragers & ontwikkelaars
“Yuga AntiMalware” is open source software. De volgende personen hebben bijgedragen aan deze plugin.
BijdragersVertaal “Yuga AntiMalware” in je eigen taal.
Interesse in ontwikkeling?
Bekijk de code, haal de SVN repository op, of abonneer je op het ontwikkellog via RSS.
Changelog
1.2.0
- Added saved scan blocks with automatic continuation, interrupted-request recovery and manual resume when automatic attempts fail.
- Replaced simulated scan percentages with confirmed counters, current module, elapsed time and time since the last saved progress.
- Improved scan cron wakeup handling and distinguished processing duration from total elapsed scan time.
- Added the saved comment-protection status and management links to Dashboard > Overview.
- Added optional protection that marks new submissions with explicit spam signals as Spam before publication; disabled by default, with no automatic deletion.
- Improved comment-protection performance with batched reads and fewer repeated queries, retaining checks for comments changed during processing.
- Added combined opaque-name, email and alphanumeric-text detection to standard comment protection; relay-email and advertising-name hints remain available for manual review.
- Expanded comment review rules for promotional messages, linked text, BBCode and repeated submissions, including trackbacks and pingbacks.
- Added separate manual-review views for pending comments, external links and non-Latin text, without treating those filters as automatic spam verdicts.
- Added a protected JSON export of all comments with original HTML links, author information, moderation state and individual review reasons.
- Improved Comment Cleanup preview layout with proportional columns and wrapping for long text and URLs.
- Updated stored findings after successful file actions and configuration rechecks, with action history and counter limitations.
- Added guided configuration cleanup with before/after review, mandatory backups, downloads and restore previews.
- Added content checks for .htaccess, .user.ini and php.ini: automatic PHP loading, Apache script substitution and crawler-conditioned rewrites.
- Fixed Unicode word boundaries for database pharma detection and stale preview highlighting; truly disabled unavailable file actions.
- Reduced pharmaceutical false positives by requiring nearby purchase or promotional wording instead of a medicine keyword alone.
- Added official package comparison for root files, including additional files and modified core files.
- Added a review rule for LinkPool remote HTML PHP snippets, including renamed files, and self-deleting WordPress environment probes.
- Added Ignored Findings with individual restore actions, including saved references absent from the latest scan.
- Prevented file deletion, quarantine and path exclusions for database/frontend findings, including mixed bulk selections.
- Added Comment Cleanup with a preview of marked spam and potentially suspicious comments, trackbacks and pingbacks.
- Added opt-in scanning of approved comments, per-comment reasons, selection of up to 1,000 comments and a choice between trash and confirmed permanent deletion.
- Protected changed comments and expired previews; blocked the trash action when WordPress trash is disabled.
1.1.2
- Updated the plugin header with the new Yuga AntiMalware logo for dark backgrounds.
- Added screenshot descriptions and refreshed the WordPress.org artwork.
1.1.1
- Lowered the minimum PHP requirement to 7.2 after compatibility regression testing.
- Prevented file deletion when a required backup fails.
- Verified quarantine copies and recovery metadata before removing originals; added checksum validation for new backups and explicit partial-failure notices.
- Added WordPress 7.1 and PHP 7.4 compatibility fixes.
- Changed PayPal integration so external resources load only after explicit administrator interaction.
- Hardened backup and quarantine storage and made quarantined payloads non-executable by extension.
- Added working WP-Cron scheduling for automatic quick scans.
- Preserved modern WordPress option autoload values during backup restore.
- Improved cleanup of plugin-owned data during uninstall.
- Removed inactive signature-update and custom scan-path controls; scans continue to use the documented fixed scopes.
1.1.0
- Improved quarantine UX and lifecycle:
- Added Quarantine > Stored Files inventory table.
- Added event-driven retention purge scheduling based on quarantine insertion date.
- Added writer-candidate quarantine action in Reinfection Trace with consistent icon-based actions.
- UI refinements for Quarantine settings naming and table consistency.
- Added Content Cleanup with filtered post/page/revision review, rollback backups, batch trash actions, previous revision restore, and Trash Cleanup.
1.0.0
- Introduced full security workflow:
- Multi-mode scans (quick, targeted, database, frontend, full).
- Background scan execution with runtime polling.
- Reinfection Trace and Writer Hunt correlation.
- Safe options maintenance (backup + cleanup + restore).
- Cache cleanup tools (targeted + full transient flush).
- Post-hack plugin/theme inventory and recovery actions.
- Email notifications via WordPress mail settings.
0.8.0
- Added targeted scope scanning for plugins, themes, mu-plugins, uploads, and WordPress root files.
- Added frontend and database detection modules and integrated full scan aggregation.
- Added scan findings table with actions and preview foundation.
0.5.0
- Added scan rules, exclusions, heuristic controls, scheduler and notification settings.
- Added initial quick file scan engine on wp-content.
- Added quarantine policy and file isolation hooks.
0.1.0
- Introduced anti-malware admin structure and plugin foundation.
