Title: Turbo Guard – Security &amp; Malware Scanner
Author: Turbo Addons
Published: <strong>2026-08-23</strong>
Last modified: 2026-09-15

---

Szukaj wtyczek

![](https://ps.w.org/turbo-guard/assets/banner-772x250.png?rev=3668036)

![](https://ps.w.org/turbo-guard/assets/icon-256x256.png?rev=3662667)

# Turbo Guard – Security & Malware Scanner

 Autor: [Turbo Addons](https://profiles.wordpress.org/turboaddons/)

[Pobierz](https://downloads.wordpress.org/plugin/turbo-guard.1.1.2.zip)

 * [Szczegóły](https://pl.wordpress.org/plugins/turbo-guard/#description)
 * [Recenzje](https://pl.wordpress.org/plugins/turbo-guard/#reviews)
 *  [Instalacja](https://pl.wordpress.org/plugins/turbo-guard/#installation)
 * [Rozwój](https://pl.wordpress.org/plugins/turbo-guard/#developers)

 [Wsparcie](https://wordpress.org/support/plugin/turbo-guard/)

## Opis

Turbo Guard is a comprehensive WordPress security plugin built by a team that manages
WordPress sites. It solves real problems: malware removal, Japanese/Chinese SEO 
spam cleanup, vulnerability alerts, file integrity monitoring, and bot protection.
Every scan, detection, and list is 100% free — you can clean up to 3 files for free.
Upgrade to Turbo Guard Pro to unlock unlimited cleanup, Live Traffic Monitor, AI
Security Advisor, and Geo-Fence.

#### Malware Scanner

 * Full-site scan: PHP, JavaScript, HTML files across wp-content, wp-admin, wp-includes,
   and WordPress root
 * WordPress Core File Manifest check — compares every file in wp-admin and wp-includes
   against the official WordPress.org checksums API
 * Detects 50+ malware patterns: eval+base64, C99/R57/WSO/b374k/ALFA web shells,
   hidden iframes, pharma spam, code obfuscation
 * Detects Japanese, Chinese, and Korean SEO spam text inside PHP files
 * Scans the WordPress database (wp_posts, wp_options) for injected content and 
   rogue admin accounts
 * PHP-in-uploads detection, PHP-in-core-asset-dirs detection
 * Polyglot image backdoor detection — scans image files for embedded PHP
 * Smart false-positive prevention: trusted plugins and themes are never flagged
   for translation text
 * Chunked AJAX scanning with live progress bar — handles 10,000+ file sites without
   timeout

#### File Integrity and Change Detection

 * Verifies every WordPress core file against official WordPress.org MD5 checksums
 * Detects modified or missing core files
 * File watcher runs every 6 hours via WP-Cron — detects new, modified, and deleted
   files
 * Baseline snapshot of all wp-content PHP/JS files with MD5 comparison
 * Email alert when new files appear

#### One-Click Bulk Malware Cleanup

 * Shows every infected file with path, threat name, severity, and file size
 * Select All Critical button — delete multiple files at once
 * Automatic ZIP backup before any deletion
 * Quarantine option — moves files to a protected directory

#### Web Application Firewall

 * Blocks SQL injection, XSS, directory traversal in real time
 * Prevents PHP file uploads
 * Advanced IP blocking: exact IP, CIDR, ranges, wildcards
 * Rate limiting (120 requests per minute per IP)
 * Bad bot blocker: blocks 25+ vulnerability scanners and scrapers

#### Geo-Fence and Trusted Location

 * Restrict WordPress admin access to specific IP addresses
 * Country-based admin lock: only allow access from your country
 * Block file uploads from untrusted countries
 * One-click trusted IP setup

#### Login Security

 * Brute force protection with configurable thresholds and lockout duration
 * Login attempt logging with IP, timestamp, and user agent
 * Email alert when admin logs in from unrecognised IP
 * Auto-blocks attacker IPs in firewall after brute force detection

#### Two-Factor Authentication (2FA)

 * TOTP/RFC 6238 — compatible with Google Authenticator, Authy, and all TOTP apps
 * Manual secret key setup on user profile page
 * Recovery codes (8 single-use)
 * Per-user enable/disable

#### Vulnerability Scanner

 * Checks all plugins, themes, and WordPress core against WPScan vulnerability database
 * CVSS severity scoring, CVE links, version-aware matching
 * Works without API key (optional WPScan key for higher limits)
 * Email alert when new vulnerabilities are found

#### Live Traffic Monitor

 * Logs every HTTP request with bot/human detection
 * Identifies 30+ bots including AI crawlers (GPTBot, ClaudeBot, PerplexityBot)
 * 24-hour stats: total requests, humans, bots, blocked, errors
 * Paginated — handles large traffic volumes
 * One-click IP block from any traffic row

#### Site Hardening

 * HTTP security headers (X-Frame-Options, HSTS, X-Content-Type-Options, Referrer-
   Policy)
 * Hide WordPress version, block user enumeration
 * Optional: disable XML-RPC, restrict REST API, disable file editor

#### Google Search Console Cleanup

 * Connects to Google Search Console via OAuth
 * Detects indexed SEO spam URLs even when files are deleted from server
 * Lists indexed URLs with one-click spam detection (Japanese/Chinese/doorway)
 * Guides you through Google Search Console’s Removals tool for de-indexing
 * Sitemap resubmission after cleanup

#### Privacy

Turbo Guard does not send your website files to any external server. Vulnerability
checks send only plugin/theme slugs and versions to the WPScan API — and only on
manual scans or when scheduled vulnerability scans are enabled in Settings (off 
by default). The SEO spam scanner reads your site’s own sitemap via a local request
to the site itself — no external service is contacted. Geo-Fence country blocking
sends the visitor IP address to ipapi.co when enabled. 2FA is fully local: TOTP 
secrets are entered manually in your authenticator app and no QR service is used.
GSC integration uses your own Google OAuth credentials. AI analysis (optional OpenAI)
sends only anonymised threat type data. No telemetry. No tracking. No account required.

### External Services

This plugin connects to external services for certain features. All connections 
require explicit user action or opt-in.

#### WordPress.org API

Used to verify WordPress core file integrity by comparing checksums.
 * Data sent:
WordPress version and locale * When: Only when the user runs a malware scan or a
file integrity check (including scheduled scans) * Service: https://api.wordpress.
org/ * Privacy Policy: https://wordpress.org/about/privacy/

#### WPScan Vulnerability Database

Used to check plugins and themes for known security vulnerabilities.
 * Data sent:
Plugin/theme slugs and versions * When: Only when the user runs a manual vulnerability
scan, or when scheduled vulnerability scans are enabled in Settings (off by default)*
Service: https://wpscan.com/ * Terms of Use: https://wpscan.com/terms * Privacy 
Policy: https://automattic.com/privacy/

#### ipapi.co (Geo-Fence)

Used for IP geolocation to support country-based access and upload controls (Geo-
Fence).
 * Data sent: Visitor IP address * When: Only when geo-fence country features
are enabled * Service: https://ipapi.co/ * Terms of Service: https://ipapi.co/terms/*
Privacy Policy: https://ipapi.co/privacy/

#### OpenAI API

Used to provide AI-powered security analysis and recommendations.
 * Data sent: 
Anonymized scan results (no personal data or site content) * When: Only when user
explicitly clicks „AI Analysis” (requires user-provided API key) * Service: https://
api.openai.com/ * Terms of Use: https://openai.com/policies/terms-of-use * Privacy
Policy: https://openai.com/policies/privacy-policy

#### Google APIs (Search Console)

Used for Google Search Console integration to detect SEO spam and manage indexed
URLs.
 * Data sent: OAuth tokens, site URL for search analytics queries * When: 
Only when user connects their Google account and initiates GSC features * Service:
https://developers.google.com/webmaster-tools * Terms of Service: https://developers.
google.com/terms * Privacy Policy: https://policies.google.com/privacy

## Instalacja

 1. Upload the `turbo-guard` folder to `/wp-content/plugins/`
 2. Activate the plugin through the Plugins menu in WordPress
 3. Go to Turbo Guard in your admin sidebar
 4. Click „Start Full Scan” on the Scanner page
 5. Review results and use „Select Critical Only” then „Delete Selected”
 6. Check the AI Advisor page for personalised security guidance

## Najczęściej zadawane pytania

### Is Turbo Guard completely free?

Yes — all scanning, detection, and protection features are 100% free. The free version
can clean up to 3 infected files. Upgrade to Turbo Guard Pro for unlimited cleanup
plus Live Traffic Monitor, AI Security Advisor, and Geo-Fence. No account required.

### Will it slow my website?

No. Scanning runs via AJAX in your browser. The firewall adds negligible overhead.

### My site shows Japanese spam in Google but files are gone. What do I do?

Use the GSC Cleanup page. Connect Google Search Console, fetch indexed URLs, identify
the spam entries, and submit them for removal in Google Search Console’s Removals
tool.

### Does the File Integrity checker work without internet?

It downloads checksums from the WordPress.org API on first use and caches them for
12 hours, so repeat checks work offline.

### Can I use this on all my sites?

Yes. Install on each site. No per-site fees or licence limits.

### Does it conflict with other security plugins?

Turbo Guard whitelists 15+ popular security plugins (Wordfence, Sucuri, MalCare,
iThemes, etc.) to prevent false positive detections. It can run alongside other 
security plugins without issues.

## Recenzje

Wtyczka nie ma jeszcze żadnej recenzji.

## Kontrybutorzy i deweloperzy

„Turbo Guard – Security & Malware Scanner” jest oprogramowaniem open source. Poniższe
osoby miały wkład w rozwój wtyczki.

Zaangażowani

 *   [ Turbo Addons ](https://profiles.wordpress.org/turboaddons/)
 *   [ Md Rashedul islam Siraji ](https://profiles.wordpress.org/siraji2017/)
 *   [ Md Shariful Islam ](https://profiles.wordpress.org/sharifok/)

[Przetłumacz wtyczkę “Turbo Guard – Security & Malware Scanner” na swój język.](https://translate.wordpress.org/projects/wp-plugins/turbo-guard)

### Interesuje cię rozwój wtyczki?

[Przeglądaj kod](https://plugins.trac.wordpress.org/browser/turbo-guard/), sprawdź
[repozytorium SVN](https://plugins.svn.wordpress.org/turbo-guard/) lub czytaj [dziennik rozwoju](https://plugins.trac.wordpress.org/log/turbo-guard/)
przez [RSS](https://plugins.trac.wordpress.org/log/turbo-guard/?limit=100&mode=stop_on_copy&format=rss).

## Rejestr zmian

#### 1.1.2

 * SEO Spam Detector: detects spam-looking URLs in the site sitemap
 * SEO Spam Detector: scans all posts/pages (no 500-post cap) and JS files in uploads
 * SEO Spam Detector: recoverable Trash cleanup with permanent delete (Pro)
 * SEO Spam Detector: Scan All plugin, theme and database at free
 * SEO Spam Detector: ignore/mark-safe allowlist for posts and files
 * GSC Cleanup: Search Cosol API connection, sitemap fetch and removal request at
   free.
 * Added scheduled SEO spam scan option and Pro email alerts
 * Added CJK-content override setting to reduce false positives

#### 1.1.1

 * Update the plugin Dashboard
 * Added more feature

#### 1.0.0

 * Initial release
 * Malware scanner with 30+ pattern signatures and WordPress core file manifest 
   check
 * AI Security Advisor with attack campaign analysis and step-by-step fix guide
 * File Integrity Checker — verifies WordPress core files against WordPress.org 
   checksums
 * File Watcher — baseline snapshot, detects new/modified/deleted files every 6 
   hours
 * Web Application Firewall — SQL injection, XSS, directory traversal blocking
 * Login Security — brute force protection, lockout, IP blocking
 * Two-Factor Authentication (TOTP/RFC 6238)
 * Vulnerability Scanner (WPScan API, CVSS scoring)
 * Live Traffic Monitor with bot/human detection
 * Site Hardening (security headers, XML-RPC, user enumeration)
 * Geo-Fence — restrict admin access to trusted IPs or countries
 * Bot Protection — blocks 25+ vulnerability scanners and bad scrapers
 * Google Search Console Cleanup (OAuth, bulk URL removal)
 * One-click bulk malware cleanup with automatic ZIP backup
 * Database scanning (wp_posts, wp_options, rogue admin users)
 * Japanese/Chinese/Korean SEO spam detection
 * Polyglot image backdoor detection

## Meta

 *  Wersja **1.1.2**
 *  Ostatnia aktualizacja **2 dni temu**
 *  Włączone instalacje **10+**
 *  Wersja WordPressa ** 5.6 lub nowszej **
 *  Testowano do **7.1**
 *  Wersja PHP ** 7.4 lub nowszej **
 *  Język
 * [English (US)](https://wordpress.org/plugins/turbo-guard/)
 * Tagi
 * [2FA](https://pl.wordpress.org/plugins/tags/2fa/)[firewall](https://pl.wordpress.org/plugins/tags/firewall/)
   [malware](https://pl.wordpress.org/plugins/tags/malware/)[scanner](https://pl.wordpress.org/plugins/tags/scanner/)
   [security](https://pl.wordpress.org/plugins/tags/security/)
 *  [Widok zaawansowany](https://pl.wordpress.org/plugins/turbo-guard/advanced/)

## Oceny

Nie przesłano jeszcze żadnych recenzji.

[Twoja opinia](https://wordpress.org/support/plugin/turbo-guard/reviews/#new-post)

[Zobacz wszystkierecenzje.](https://wordpress.org/support/plugin/turbo-guard/reviews/)

## Zaangażowani

 *   [ Turbo Addons ](https://profiles.wordpress.org/turboaddons/)
 *   [ Md Rashedul islam Siraji ](https://profiles.wordpress.org/siraji2017/)
 *   [ Md Shariful Islam ](https://profiles.wordpress.org/sharifok/)

## Wsparcie

Masz coś do dodania? Potrzebujesz pomocy?

 [Zobacz forum wsparcia](https://wordpress.org/support/plugin/turbo-guard/)