Linux 软件免费装
Banner图

Segurium – Free Malware Removal & Antivirus Scanner, Hacked Website Cleanup, Firewall, 2FA

开发者 segurium
更新时间 2026年8月27日 00:24
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

antivirus malware-scanner malware-removal hacked-website virus-removal

下载

1.0.1 1.0.0 1.0.2 1.1.0 1.1.1 1.1.2 1.2.0 0.1.8 1.2.1 1.2.2

详情介绍:

Site hacked? Segurium removes the malware, for free. Most security plugins scan the site, name the infected files, and then ask for money to clean them. Segurium does the cleanup. It finds the infected files, removes the malicious code, and puts the original file back, with a reversible encrypted backup. The free tier covers up to 3 cloud cleanups per rolling 30 days, which is enough for a typical incident. No ad walls, no background processes that chew through your shared-hosting CPU budget. If you are reading this because Google flagged your site, your host suspended the account, or visitors get redirected to a spam page, that is the job this plugin was built for. Segurium finds the malicious code these attacks leave behind in your files: injected redirects, Japanese SEO spam, pharma spam, uploaded shells and backdoors. How to clean a hacked WordPress site with Segurium
  1. Install Segurium and accept the service disclosure.
  2. Run a malware scan. Files on the server are hashed and checked against the cloud verdict database.
  3. Clean the infected files, one at a time or all at once with Fix All.
  4. Run an integrity scan, and restore any WordPress core, plugin or theme file the attack rewrote.
  5. Switch on the firewall, brute-force protection and two-factor authentication so the site does not get hacked again.
A file of yours that an attacker injected code into gets repaired: the injection goes, your content stays. A file that is nothing but malware, such as an uploaded shell, is emptied instead. Either way the original lands in an encrypted local backup first, and one click puts it back. A small plugin in front of a large engine Segurium hashes your files on the server and checks each against a continuously-updated, machine-learning-curated cloud verdict database — so most files are classified by hash alone, the scan is fast, the plugin stays small, and fresh threats are recognised the moment the classifier picks them up. When a file's hash is not yet known to the cloud, Segurium uploads that file's bytes for deeper analysis so you don't get stuck with an unresolved verdict. Data is only sent with your consent. What you get on every install Every feature below ships in the plugin and runs on every install — Free and Pro alike: How the Pro service tier differs Our cloud service performs the cleanups and counts each against a per-installation quota. The Free service tier covers up to 3 cleanups per rolling 30 days — enough for an occasional incident on a typical site. The Pro service tier raises that quota for sites that need higher volume (recurring infections, hosts under sustained attack, sites with high reliability requirements). The plugin code, the detection engines, and every feature listed above are identical on both tiers; the only difference is the quota ceiling enforced server-side. Privacy by default

安装:

  1. Upload the segurium folder to /wp-content/plugins/, or install through Plugins → Add New in the WordPress admin.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Open Segurium in the admin sidebar and accept the service disclosure to enable scanning.
  4. (Optional) Import settings from your previous security plugin via Segurium → Migration.
  5. (Optional) Enable two-factor authentication, geo-blocking and security headers from their respective tabs.

屏幕截图:

  • The scan that found them — every infected file listed with a Clean button.
  • Security Self-Check — an A+ to F grade with one-click fixes.
  • Integrity scan — per-component status, with Fix and Restore for drifted files.
  • Geo-blocking — preset regions and per-country control.
  • Firewall — IPv4, IPv6 and CIDR lists, proxy ranges auto-detected.
  • Brute-force protection — lockout windows, extended bans, live attack statistics.
  • Two-Factor Authentication — TOTP and email, per-role enforcement, trusted devices.
  • Security headers — presets and cookie hardening, with a live preview.
  • Information Shield — hides the version and discovery metadata WordPress exposes.
  • Migration tool — previews another security plugin's settings before import.
  • Scheduled scans — off, daily or weekly, with email alerts.
  • Plans — $0 forever, 3 cleanups every 30 days; $79 a year per site lifts the cap.

常见问题:

Which security features are free in Segurium that other plugins sell as premium?

All of them. Two-factor authentication with an authenticator app (TOTP), email codes, backup codes, trusted devices and per-role enforcement. Brute force protection with login attempt limits, lockouts, a honeypot and xmlrpc coverage. A firewall with IP, CIDR and country rules, so you can block a country from your login page. Security headers with HSTS, CSP, Referrer-Policy and Permissions-Policy, plus cookie hardening. Geoblocking from a local database, by country or by preset region (EU, Americas, Asia-Pacific, Africa, Middle East, High-Risk). None of it is a trial and none of it is gated behind a pro plan. Only the number of cloud cleanups is capped on the free tier: three every 30 days.

Is Segurium an antivirus for a WordPress website?

In practice, yes. People call the same problem a website virus, a WordPress virus or malware, and it is one thing: files on your server that should not be there, plus code an attacker added to files that should. Segurium hashes the files on your server and asks the cloud verdict database what each one is, so an anti-malware scan of a whole website is a hash lookup rather than a file-by-file inspection. A desktop antivirus protects your laptop. Segurium does that job for your WordPress files, and it removes what it finds.

Can Segurium replace a paid security plugin?

For malware removal, two-factor authentication, a firewall, geoblocking and security headers, yes. Those are the parts most plugins sell as a premium subscription, and Segurium ships them free on every install. The paid tier only raises the cloud cleanup quota. If you are moving from another security plugin, the Migration tab imports your settings from Wordfence, All-In-One Security and Solid Security so the switch does not cost you your hardening.

What does a Segurium scan look for?

Files the cloud verdict database has already classified as malicious. In a normal break-in that means an uploaded web shell or backdoor, a redirect injected into a theme file, spam pages, hidden links, a phishing page dropped in an upload folder, the Japanese keyword hack, and leftovers from a crypto miner. Segurium does not care what the family is called, whether someone labels it a trojan or a virus. It checks whether a file is malicious and whether it can put the clean version back.

My WordPress site is hacked. What do I do first?

Install Segurium, open it from the admin sidebar, accept the service disclosure, and run a malware scan. Segurium lists the infected files and cleans them on one click, keeping an encrypted backup of every original. Then run an integrity scan, so any WordPress core, plugin or theme file the attack rewrote is restored to its official content. Finish by turning on the firewall, brute-force protection and two-factor authentication.

Does Segurium remove malware for free, or only detect it?

It removes it. Malware removal runs on the free service tier: up to 3 cloud cleanups per rolling 30 days, enough for a typical incident. Most other plugins report the malware for free and charge for the repair. Every one is reversible from a local encrypted backup.

How do I clean a hacked WordPress site when I have no backup?

That is the usual case, and it is what the cleanup engine is for. Where an attacker injected code into a file of yours, Segurium strips the injection and leaves the rest of the file alone. Where the file is nothing but malware, it gets emptied. For WordPress core, plugin and theme files, the integrity scan pulls the official content from upstream manifests, so you get a clean copy even with nothing of your own to restore from.

Can Segurium fix a Japanese SEO spam, pharma or redirect hack?

Yes, wherever the infection lives in a file. These hacks inject spam pages, hidden links or redirects into theme, plugin and core files. The scanner flags those files, cleanup strips the injected code, and an integrity pass restores any legitimate file the attack rewrote. Check again afterwards to confirm the site is clean.

My site redirects visitors to another domain. How do I stop it?

A WordPress redirect hack is usually a small block of injected code sitting in a theme file, a plugin file or index.php. Run a malware scan and Segurium points at the files carrying the redirect, then cleans them. Follow with an integrity scan to catch a core file that was rewritten.

Google blacklisted my website or my host suspended it. What now?

A blacklist entry and a suspension both follow the malicious content, so remove the content first. Run a malware scan, clean the flagged files, then run an integrity scan so any core, plugin or theme file the attack rewrote goes back to its official content. Once the website is clean, request a review in Google Search Console or ask your host to lift the suspension. Segurium does not file those requests for you. It removes the reason for them.

Will Segurium slow my site down?

It shouldn't. Scans run in chunked background jobs, behind a lock so a single run can't pile on top of itself. Real-time scanning only inspects new and modified files. The plugin keeps no large tables in memory and ships no bundled binaries.

What happens if Segurium flags a file that isn't really malware?

Every cleanup is reversible. Originals are encrypted (AES-256-GCM) and stored locally — retained for up to 30 days, subject to per-bucket count and size caps — and you can restore from backup in one click. You can also submit a false-positive report directly from the threats list, and our team uses those to improve classification.

Does Segurium quarantine suspicious files, and does it check for vulnerabilities?

There is no separate quarantine folder. Segurium handles a suspicious file in place: it encrypts the original (AES-256-GCM), stores that copy locally, then strips the malicious code out, so the file is neutralised and you can put the original back for up to 30 days. Segurium is not a vulnerability scanner and reads no CVE feed. Its integrity check compares WordPress core, plugins and themes against upstream manifests and flags tampered, delisted and abandoned components, which is where an unpatched or unmaintained component shows up.

Can I use Segurium alongside my existing security plugin?

You can, but we recommend migrating. The Migration tab imports settings from Wordfence, All-In-One Security and Solid Security so you can switch without losing your hardening. It also detects Sucuri Security, but Sucuri keeps its rules in its own cloud dashboard, so those settings have to be re-entered by hand. Running two security plugins in parallel usually means double the cron overhead for no extra protection.

Is hCaptcha required for brute-force protection?

No. Brute-force protection works out of the box with rate limits, honeypot and lockouts. hCaptcha is optional — if you already have an hCaptcha site key and secret, you can enable it on the login form for an additional layer. When disabled (the default), no hCaptcha scripts or requests are ever loaded.

What PHP and WordPress versions are supported?

PHP 7.4 or newer and WordPress 6.2 or newer. Regularly tested against PHP 8.1 / 8.2 / 8.3 and WordPress 6.3 through 7.0.

What happens if I uninstall the plugin?

Plugin options, custom tables and local scan backups are removed. The local encrypted backups remain extractable with a small PHP one-liner before uninstall (see the Disaster Recovery documentation on segurium.com) if you want to keep copies.

How do I report a security issue in Segurium itself?

Email security@segurium.com rather than opening a public support topic. Our disclosure policy, testing ground rules and researcher acknowledgements are at https://segurium.com/security/ — it also explains what we can and cannot offer in return. Please keep details private until a fix is available to users.

更新日志:

1.2.2 - 2026-08-26 1.2.1 - 2026-08-25 1.2.0 - 2026-08-24 1.1.2 - 2026-08-21 1.1.1 - 2026-08-20 1.1.0 - 2026-08-16 1.0.2 - 2026-08-10 1.0.1 - 2026-08-08