Title: Turbo Guard – Security &amp; Malware Scanner
Author: Turbo Addons
Published: <strong>August 23, 2026</strong>
Last modified: August 23, 2026

---

Search plugins

![](https://ps.w.org/turbo-guard/assets/icon-256x256.png?rev=3662667)

# Turbo Guard – Security & Malware Scanner

 By [Turbo Addons](https://profiles.wordpress.org/turboaddons/)

[Download](https://downloads.wordpress.org/plugin/turbo-guard.1.1.0.zip)

 * [Details](https://wordpress.org/plugins/turbo-guard/#description)
 * [Reviews](https://wordpress.org/plugins/turbo-guard/#reviews)
 *  [Installation](https://wordpress.org/plugins/turbo-guard/#installation)
 * [Development](https://wordpress.org/plugins/turbo-guard/#developers)

 [Support](https://wordpress.org/support/plugin/turbo-guard/)

## Description

Turbo Guard is a comprehensive, 100% free WordPress security plugin built by a team
that manages 40+ WordPress sites. It solves real problems: bulk malware removal,
Japanese/Chinese SEO spam cleanup, vulnerability alerts, file integrity monitoring,
and live traffic analysis — all with AI-powered guidance that explains what happened
and exactly what to do.

#### AI Security Advisor

 * After every scan, Turbo Guard AI identifies the attack campaign (Japanese SEO
   spam, web shell, brute force, database injection)
 * Explains in plain English what happened and the business risk
 * Provides numbered, step-by-step fix instructions tailored to your specific threats
 * Optional OpenAI GPT integration for richer analysis (your own API key)
 * Sends email advisory after every scan
 * 30-day security score trend chart

#### Malware Scanner

 * Full-site scan: PHP, JavaScript, HTML files across wp-content, wp-admin, wp-includes,
   and WordPress root
 * WordPress Core File Manifest check — compares every file in wp-admin and wp-includes
   against the official WordPress.org checksums API
 * Detects 30+ malware patterns: eval+base64, C99/R57/WSO web shells, hidden iframes,
   pharma spam, code obfuscation
 * Detects Japanese, Chinese, and Korean SEO spam text inside PHP files
 * Scans the WordPress database (wp_posts, wp_options) for injected content and 
   rogue admin accounts
 * PHP-in-uploads detection, PHP-in-core-asset-dirs detection
 * Polyglot image backdoor detection — scans image files for embedded PHP
 * Smart false-positive prevention: trusted plugins and themes are never flagged
   for translation text
 * Chunked AJAX scanning with live progress bar — handles 10,000+ file sites without
   timeout

#### File Integrity and Change Detection

 * Verifies every WordPress core file against official WordPress.org MD5 checksums
 * Detects modified or missing core files
 * File watcher runs every 6 hours via WP-Cron — detects new, modified, and deleted
   files
 * Baseline snapshot of all wp-content PHP/JS files with MD5 comparison
 * Email alert when new files appear

#### One-Click Bulk Malware Cleanup

 * Shows every infected file with path, threat name, severity, and file size
 * Select All Critical button — delete multiple files at once
 * Automatic ZIP backup before any deletion
 * Quarantine option — moves files to a protected directory

#### Web Application Firewall

 * Blocks SQL injection, XSS, directory traversal in real time
 * Prevents PHP file uploads
 * Advanced IP blocking: exact IP, CIDR, ranges, wildcards
 * Rate limiting (120 requests per minute per IP)
 * Bad bot blocker: blocks 25+ vulnerability scanners and scrapers

#### Geo-Fence and Trusted Location

 * Restrict WordPress admin access to specific IP addresses
 * Country-based admin lock: only allow access from your country
 * Block file uploads from untrusted countries
 * One-click trusted IP setup

#### Login Security

 * Brute force protection with configurable thresholds and lockout duration
 * Login attempt logging with IP, timestamp, and user agent
 * Email alert when admin logs in from unrecognised IP
 * Auto-blocks attacker IPs in firewall after brute force detection

#### Two-Factor Authentication (2FA)

 * TOTP/RFC 6238 — compatible with Google Authenticator, Authy, and all TOTP apps
 * Manual secret key setup on user profile page
 * Recovery codes (8 single-use)
 * Per-user enable/disable

#### Vulnerability Scanner

 * Checks all plugins, themes, and WordPress core against WPScan vulnerability database
 * CVSS severity scoring, CVE links, version-aware matching
 * Works without API key (optional WPScan key for higher limits)
 * Email alert when new vulnerabilities are found

#### Live Traffic Monitor

 * Logs every HTTP request with bot/human detection
 * Identifies 30+ bots including AI crawlers (GPTBot, ClaudeBot, PerplexityBot)
 * 24-hour stats: total requests, humans, bots, blocked, errors
 * Paginated — handles large traffic volumes
 * One-click IP block from any traffic row

#### Site Hardening

 * HTTP security headers (X-Frame-Options, HSTS, X-Content-Type-Options, Referrer-
   Policy)
 * Hide WordPress version, block user enumeration
 * Optional: disable XML-RPC, restrict REST API, disable file editor

#### Google Search Console Cleanup

 * Connects to Google Search Console via OAuth
 * Detects indexed SEO spam URLs even when files are deleted from server
 * Bulk removal requests with one click
 * Sitemap resubmission after cleanup

#### Privacy

Turbo Guard does not send your website files to any external server. Vulnerability
checks send only plugin/theme slugs and versions to the WPScan API — and only on
manual scans or when scheduled vulnerability scans are enabled in Settings (off 
by default). Geo-Fence country blocking sends the visitor IP address to ipapi.co
when enabled. 2FA is fully local: TOTP secrets are entered manually in your authenticator
app and no QR service is used. GSC integration uses your own Google OAuth credentials.
AI analysis (optional OpenAI) sends only anonymised threat type data. No telemetry.
No tracking. No account required.

### External Services

This plugin connects to external services for certain features. All connections 
require explicit user action or opt-in.

#### WordPress.org API

Used to verify WordPress core file integrity by comparing checksums.
 * Data sent:
WordPress version and locale * When: Only when the user runs a malware scan or a
file integrity check (including scheduled scans) * Service: https://api.wordpress.
org/ * Privacy Policy: https://wordpress.org/about/privacy/

#### WPScan Vulnerability Database

Used to check plugins and themes for known security vulnerabilities.
 * Data sent:
Plugin/theme slugs and versions * When: Only when the user runs a manual vulnerability
scan, or when scheduled vulnerability scans are enabled in Settings (off by default)*
Service: https://wpscan.com/ * Terms of Use: https://wpscan.com/terms * Privacy 
Policy: https://automattic.com/privacy/

#### ipapi.co (Geo-Fence)

Used for IP geolocation to support country-based access and upload controls (Geo-
Fence).
 * Data sent: Visitor IP address * When: Only when geo-fence country features
are enabled * Service: https://ipapi.co/ * Terms of Service: https://ipapi.co/terms/*
Privacy Policy: https://ipapi.co/privacy/

#### OpenAI API

Used to provide AI-powered security analysis and recommendations.
 * Data sent: 
Anonymized scan results (no personal data or site content) * When: Only when user
explicitly clicks “AI Analysis” (requires user-provided API key) * Service: https://
api.openai.com/ * Terms of Use: https://openai.com/policies/terms-of-use * Privacy
Policy: https://openai.com/policies/privacy-policy

#### Google APIs (Search Console)

Used for Google Search Console integration to detect SEO spam and manage indexed
URLs.
 * Data sent: OAuth tokens, site URL for search analytics queries * When: 
Only when user connects their Google account and initiates GSC features * Service:
https://developers.google.com/webmaster-tools * Terms of Service: https://developers.
google.com/terms * Privacy Policy: https://policies.google.com/privacy

## Installation

 1. Upload the `turbo-guard` folder to `/wp-content/plugins/`
 2. Activate the plugin through the Plugins menu in WordPress
 3. Go to Turbo Guard in your admin sidebar
 4. Click “Start Full Scan” on the Scanner page
 5. Review results and use “Select Critical Only” then “Delete Selected”
 6. Check the AI Advisor page for personalised security guidance

## FAQ

### Is Turbo Guard completely free?

Yes. All features are 100% free with no feature limits and no account required.

### Will it slow my website?

No. Scanning runs via AJAX in your browser. The firewall adds negligible overhead.
Live traffic logging uses PHP shutdown function (after the response is sent to the
visitor).

### My site shows Japanese spam in Google but files are gone. What do I do?

Use the GSC Cleanup page. Connect Google Search Console, fetch indexed URLs, and
bulk-remove spam entries in one click.

### Does the File Integrity checker work without internet?

It downloads checksums from the WordPress.org API on first use and caches them for
12 hours, so repeat checks work offline.

### Can I use this on all my sites?

Yes. Install on each site. No per-site fees or licence limits.

### Does it conflict with other security plugins?

Turbo Guard whitelists 15+ popular security plugins (Wordfence, Sucuri, MalCare,
iThemes, etc.) to prevent false positive detections. It can run alongside other 
security plugins without issues.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Turbo Guard – Security & Malware Scanner” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ Turbo Addons ](https://profiles.wordpress.org/turboaddons/)

[Translate “Turbo Guard – Security & Malware Scanner” into your language.](https://translate.wordpress.org/projects/wp-plugins/turbo-guard)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/turbo-guard/), check
out the [SVN repository](https://plugins.svn.wordpress.org/turbo-guard/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/turbo-guard/) by
[RSS](https://plugins.trac.wordpress.org/log/turbo-guard/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release
 * Malware scanner with 30+ pattern signatures and WordPress core file manifest 
   check
 * AI Security Advisor with attack campaign analysis and step-by-step fix guide
 * File Integrity Checker — verifies WordPress core files against WordPress.org 
   checksums
 * File Watcher — baseline snapshot, detects new/modified/deleted files every 6 
   hours
 * Web Application Firewall — SQL injection, XSS, directory traversal blocking
 * Login Security — brute force protection, lockout, IP blocking
 * Two-Factor Authentication (TOTP/RFC 6238)
 * Vulnerability Scanner (WPScan API, CVSS scoring)
 * Live Traffic Monitor with bot/human detection
 * Site Hardening (security headers, XML-RPC, user enumeration)
 * Geo-Fence — restrict admin access to trusted IPs or countries
 * Bot Protection — blocks 25+ vulnerability scanners and bad scrapers
 * Google Search Console Cleanup (OAuth, bulk URL removal)
 * One-click bulk malware cleanup with automatic ZIP backup
 * Database scanning (wp_posts, wp_options, rogue admin users)
 * Japanese/Chinese/Korean SEO spam detection
 * Polyglot image backdoor detection

## Meta

 *  Version **1.1.0**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.6 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [2FA](https://wordpress.org/plugins/tags/2fa/)[firewall](https://wordpress.org/plugins/tags/firewall/)
   [malware](https://wordpress.org/plugins/tags/malware/)[scanner](https://wordpress.org/plugins/tags/scanner/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/turbo-guard/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/turbo-guard/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/turbo-guard/reviews/)

## Contributors

 *   [ Turbo Addons ](https://profiles.wordpress.org/turboaddons/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/turbo-guard/)