Linux 软件免费装
Banner图

Segurium – Free Malware Removal & Auto Cleanup for Hacked Websites, Antivirus Scanner, Vulnerability Alerts

开发者 segurium
更新时间 2026年9月15日 18:01
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

antivirus hacked malware-scanner malware-removal virus-removal

下载

1.0.1 1.4.1 1.3.1 1.3.0 1.0.0 1.0.2 1.4.2 1.2.3 1.1.0 1.1.1 1.1.2 1.2.0 1.2.1 1.2.2 0.1.8 1.3.2 1.4.0

详情介绍:

Site hacked? Segurium removes the malware, for free. Most security plugins scan the site, name the infected files, and then ask for money to clean them. Segurium does the cleanup. It finds the infected files, removes the malicious code, and puts the original file back, with a reversible encrypted backup. The free tier covers up to 3 cloud cleanups per rolling 30 days, which is enough for a typical incident. No ad walls, no background processes that chew through your shared-hosting CPU budget. Run it on every site you look after and the setup stays the same. Switch on auto-cleanup and a file that real-time scanning flags is repaired before anyone opens the dashboard. Plugins and themes with a known vulnerability get a red Vulnerable badge and an Update button. Export the settings once, import them on the next site, accept the service disclosure from WP-CLI, and let each site email you within 24 hours when malware turns up. What you get on every install Every feature below ships in the plugin and runs on every install — Free and Pro alike: How the Pro service tier differs Our cloud service performs the cleanups and counts each against a per-installation quota. The Free service tier covers up to 3 cleanups per rolling 30 days — enough for an occasional incident on a typical site. The Pro service tier raises that quota for sites that need higher volume (recurring infections, hosts under sustained attack, sites with high reliability requirements). The plugin code, the detection engines, and every feature listed above are identical on both tiers; the only difference is the quota ceiling enforced server-side. Privacy by default

安装:

  1. Upload the segurium folder to /wp-content/plugins/, or install through Plugins → Add New in the WordPress admin.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Open Segurium in the admin sidebar and accept the service disclosure to enable scanning.
  4. (Optional) Import settings from your previous security plugin via Segurium → Migration.
  5. (Optional) Enable two-factor authentication, geo-blocking and security headers from their respective tabs.

屏幕截图:

  • The scan that found them — every infected file listed with a Clean button.
  • Security Self-Check — an A+ to F grade with one-click fixes.
  • Integrity scan — per-component status, with Fix and Restore for drifted files.
  • Geo-blocking — preset regions and per-country control.
  • Firewall — IPv4, IPv6 and CIDR lists, proxy ranges auto-detected.
  • Brute-force protection — lockout windows, extended bans, live attack statistics.
  • Two-Factor Authentication — TOTP and email, per-role enforcement, trusted devices.
  • Security headers — presets and cookie hardening, with a live preview.
  • Information Shield — hides the version and discovery metadata WordPress exposes.
  • Migration tool — previews another security plugin's settings before import.
  • Scheduled scans — off, daily or weekly, with email alerts.
  • Plans — $0 forever, 3 cleanups every 30 days; $79 a year per site lifts the cap.

常见问题:

Which security features are free in Segurium that other plugins sell as premium?

All of them. Two-factor authentication with an authenticator app (TOTP), email codes, backup codes, trusted devices and per-role enforcement. Brute force protection with login attempt limits, lockouts, a honeypot and xmlrpc coverage. A firewall with IP, CIDR and country rules, so you can block a country from your login page. Security headers with HSTS, CSP, Referrer-Policy and Permissions-Policy, plus cookie hardening. Geoblocking from a local database, by country or by preset region (EU, Americas, Asia-Pacific, Africa, Middle East, High-Risk). None of it is a trial and none of it is gated behind a pro plan. Only the number of cloud cleanups is capped on the free tier: three every 30 days.

Can I set up malware cleanup on many sites without opening each dashboard?

Yes. WP-CLI accepts the service disclosure and reports the cleanup quota, and settings export and import carry one site's configuration to the next. Every install runs the same plugin code and the same free quota, so a site that joins later behaves like the rest.

Is Segurium an antivirus for a WordPress website?

In practice, yes. People call the same problem a website virus, a WordPress virus or malware, and it is one thing: files on your server that should not be there, plus code an attacker added to files that should. Segurium hashes the files on your server and asks the cloud verdict database what each one is, so an anti-malware scan of a whole website is a hash lookup rather than a file-by-file inspection. A desktop antivirus protects your laptop. Segurium does that job for your WordPress files, and it removes what it finds.

Can Segurium replace a paid security plugin?

For malware removal, two-factor authentication, a firewall, geoblocking and security headers, yes. Those are the parts most plugins sell as a premium subscription, and Segurium ships them free on every install. The paid tier only raises the cloud cleanup quota. If you are moving from another security plugin, the Migration tab imports your settings from Wordfence, All-In-One Security and Solid Security so the switch does not cost you your hardening.

What does a Segurium scan look for?

Files the cloud verdict database has already classified as malicious. In a normal break-in that means an uploaded web shell or backdoor, a redirect injected into a theme file, spam pages, spam links, hidden links, a phishing page dropped in an upload folder, the Japanese keyword hack, and leftovers from a crypto miner. Segurium does not care what the family is called, whether someone labels it a trojan or a virus. It checks whether a file is malicious and whether it can put the clean version back.

Does Segurium remove malware for free, or only detect it?

It removes it. Malware removal runs on the free service tier: up to 3 cloud cleanups per rolling 30 days, enough for a typical incident. Most other plugins report the malware for free and charge for the repair. Every one is reversible from a local encrypted backup.

How do I clean a hacked WordPress site when I have no backup?

That is the usual case, and it is what the cleanup engine is for. Where an attacker injected code into a file of yours, Segurium strips the injection and leaves the rest of the file alone. Where the file is nothing but malware, it gets emptied. For WordPress core, plugin and theme files, the integrity scan pulls the official content from upstream manifests, so you get a clean copy even with nothing of your own to restore from.

My site is hacked, redirects visitors, or Google blacklisted it. What do I do?

Install Segurium on the hacked site, accept the service disclosure and run a malware scan. Segurium lists the infected files and cleans them on one click, keeping an encrypted backup of every original. Then run an integrity scan, so any core, plugin or theme file the attack rewrote is restored to its official content. Redirect, Japanese SEO spam and pharma hacks live in exactly those files. Once the malware is gone, request a review in Google Search Console or ask your host to lift the suspension; Segurium removes the reason for them, it does not file the requests.

Will Segurium slow my site down?

It shouldn't. Scans run in chunked background jobs, behind a lock so a single run can't pile on top of itself. Real-time scanning only inspects new and modified files. The plugin keeps no large tables in memory and ships no bundled binaries.

What happens if Segurium flags a file that isn't really malware?

Every cleanup is reversible. Originals are encrypted (AES-256-GCM) and stored locally — retained for up to 30 days, subject to per-bucket count and size caps — and you can restore from backup in one click. You can also submit a false-positive report directly from the threats list, and our team uses those to improve classification.

Does Segurium quarantine infected files, and does it flag vulnerable plugins?

There is no separate quarantine folder. Segurium handles a suspicious file in place: it encrypts the original (AES-256-GCM), stores that copy locally, then strips the malicious code out, so the file is neutralised and you can put the original back for up to 30 days. The integrity check compares WordPress core, plugins and themes against upstream manifests and marks a component whose installed release carries a known vulnerability with a red Vulnerable badge and an Update button; tampered, delisted and abandoned components show up there too.

Is hCaptcha required for brute-force protection?

No. Brute-force protection works out of the box with rate limits, honeypot and lockouts. hCaptcha is optional — if you already have an hCaptcha site key and secret, you can enable it on the login form for an additional layer. When disabled (the default), no hCaptcha scripts or requests are ever loaded.

What PHP and WordPress versions are supported?

PHP 7.4 or newer and WordPress 6.2 or newer. Regularly tested against PHP 8.1 / 8.2 / 8.3 and WordPress 6.3 through 7.0.

What happens if I uninstall the plugin?

Plugin options, custom tables and local scan backups are removed. The local encrypted backups remain extractable with a small PHP one-liner before uninstall (see the Disaster Recovery documentation on segurium.com) if you want to keep copies.

How do I report a security issue in Segurium itself?

Email security@segurium.com rather than opening a public support topic. Our disclosure policy, testing ground rules and researcher acknowledgements are at https://segurium.com/security/ — it also explains what we can and cannot offer in return. Please keep details private until a fix is available to users.

更新日志:

1.4.2 - 2026-09-15 1.4.1 - 2026-09-13