WordPress multi-level security scanner detecting malware, 0-day threats, brute-force attacks, bot attacks, and unauthorized admin changes.
As of April 2026, Quttera ThreatSign is a WordPress card skimmer plugin with 10K+ active installations and a 3.9/5 rating from 47 reviews. It has been downloaded 4.5M+ times in total. Requires WordPress 3.3.2+ and PHP 7.2+. Available on WordPress.org since 2012. Actively maintained — updated within the last month. Downloads are down 40% this week. Support resolution rate: 0%.
Quttera ThreatSign protects your WordPress website with multi-layered security:
Malware Detection: Powered by Quttera’s AI-driven heuristic engine, the scanner detects malicious PHP, obfuscated JavaScript, hidden iframes, redirects, spam, SEO malware, and credit-card skimmers targeting checkout pages. The plugin performs on-demand scans directly from your WordPress admin and checks your domain against more than 40 global security authorities, including Google, McAfee, Norton, and Yandex. Detection capabilities are continuously enhanced using insights from Quttera’s worldwide threat intelligence network.
Brute Force Protection: Prevents unauthorized login attempts with IP locking, configurable rate limiting, and environment-aware protection policies. Supports both shared hostin…
It just helps when you’re having trouble. Nice cool job, thank you!
Great tool that helps you quickly find out whether and which plugins could be affected by a data leak if you have numerous attacks on WordPress (e.g. on wp-admin). You can then replace all plugin folders with the original plugin files via FTP, done. Very good job, thank you!
It cleaned the malware on my website before it executed and gave me issues. top-notch product.
I wasnt expecting anything from this plugin but it has saved my lots of time and money. First I removed some critical files by wordfence and tried almost all malware scanners but non of the scanners could detect the infected files, infact wordfence was showing no threat but my site was displaying the japanese letters snippet on google and had 62000 links indexed on google console. I would say Malcare did a good job in scanning the malware but it doesnt show any files because of paid service. After running this scanner it showed me some malicious files and I removed them from the control panel by myself. Book malware was disappeared scanner didnt showed site is hacked. Thanks alot guys
Only tells you that it is paid once it has supposedly detected infectoin. This can’t be trusted when the vendor is motivated to detect false positives.
| WordPress | 3.3.2+ requiredTested up to 6.9.4 |
| PHP | 7.2+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.