Security & Malware Scan by CleanTalk (also known as Security, FireWall, Malware removal by CleanTalk) is a WordPress security plugin that helps protect your site from malware, brute-force attacks, suspicious traffic, and other online threats. It combines a web application firewall, malware scanner, traffic controls, login security, and activity logging — all backed by the CleanTalk cloud-based security service — to give you proactive protection and visibility into threats affecting your website.
WordPress.org
+1
⚠️ The plugin works in conjunction with the CleanTalk cloud security platform, so some features (like traffic logs and threat datasets) are stored and managed via CleanTalk’s dashboard. You’ll need a CleanTalk account and access key to use the full suite of features.
CleanTalk
🔐 Core Features & Protection Tools
🔥 Web Application Firewall (WAF)
The integrated Security Firewall monitors incoming requests and blocks malicious behavior such as SQL injection, cross-site scripting (XSS), exploit attempts, bots, and suspicious GET/POST parameters before they reach your WordPress installation. You can block by IP, subnet, or country using built-in services and custom black/white lists.
CleanTalk
🦠 Malware Scanner
CleanTalk’s malware scanner checks all WordPress files — including core, theme, plugin, and upload files — for malicious code, infections, and unusual modifications. The scan categorizes results (e.g., critical, suspicious, unknown) and helps you review and handle potentially harmful files.
CleanTalk
🚫 Brute-Force & Login Protection
The plugin includes protections to limit login attempts, slow repeated failures, and block automated brute-force attacks on login pages (including /wp-login.php). You can also configure login security options such as protected login URLs and notification alerts for backend access.
WordPress.org Esperanto
📊 Traffic & Activity Logging
CleanTalk’s service tracks traffic and security events, including failed login attempts, blocked requests, and malicious traffic. These logs help you analyze activity and spot suspicious patterns over time.
CleanTalk
🌍 IP & Country Blocking
You can configure global and custom block lists, enforcing firewall rules by IP range or even by entire countries if needed, helping you prevent attacks from specific sources.
CleanTalk
📩 Notifications & Reporting
Receive security notifications and summaries via email or in your CleanTalk dashboard about key events such as login attempts, malware detections, and firewall blocks.
CleanTalk
📌 Why Use CleanTalk Security?
✔ Comprehensive Protection: Combines firewall, malware scanning, brute-force protection, IP blocking, and logging in one plugin.
CleanTalk
✔ Cloud-Powered Threat Intelligence: Leverages CleanTalk’s database of dangerous IPs and attack patterns, updated from global data.
CleanTalk
✔ Real-Time Logging & Analysis: Shows detailed logs for security events, helping you investigate issues.
CleanTalk
✔ Login Hardening: Adds defenses against unauthorized access and automated login abuse.
CleanTalk
✔ Traffic Control: Helps prevent overloads or DoS-style attacks by blocking excessive requests.
CleanTalk
⚠️ Security & Updates
Security researchers have noted that older versions of this plugin (pre-latest) have had vulnerabilities related to unsafe file handling and other issues in past releases. Because plugins that scan and modify files can themselves be sensitive, it’s especially important to keep the plugin up to date and ensure you’re running the most recent release available.
Download