Turbo Guard – Security & Malware Scanner

Plugin Banner

Turbo Guard – Security & Malware Scanner

by Turbo Addons

Download
Description

Turbo Guard is a comprehensive WordPress security plugin built by a team that manages WordPress sites. It solves real problems: malware removal, Japanese/Chinese SEO spam cleanup, vulnerability alerts, file integrity monitoring, and bot protection. Every scan, detection, and list is 100% free — you can clean up to 3 files for free. Upgrade to Turbo Guard Pro to unlock unlimited cleanup, Live Traffic Monitor, AI Security Advisor, and Geo-Fence.

Malware Scanner

  • Full-site scan: PHP, JavaScript, HTML files across wp-content, wp-admin, wp-includes, and WordPress root
  • WordPress Core File Manifest check — compares every file in wp-admin and wp-includes against the official WordPress.org checksums API
  • Detects 50+ malware patterns: eval+base64, C99/R57/WSO/b374k/ALFA web shells, hidden iframes, pharma spam, code obfuscation
  • Detects Japanese, Chinese, and Korean SEO spam text inside PHP files
  • Scans the WordPress database (wp_posts, wp_options) for injected content and rogue admin accounts
  • PHP-in-uploads detection, PHP-in-core-asset-dirs detection
  • Polyglot image backdoor detection — scans image files for embedded PHP
  • Smart false-positive prevention: trusted plugins and themes are never flagged for translation text
  • Chunked AJAX scanning with live progress bar — handles 10,000+ file sites without timeout

File Integrity and Change Detection

  • Verifies every WordPress core file against official WordPress.org MD5 checksums
  • Detects modified or missing core files
  • File watcher runs every 6 hours via WP-Cron — detects new, modified, and deleted files
  • Baseline snapshot of all wp-content PHP/JS files with MD5 comparison
  • Email alert when new files appear

One-Click Bulk Malware Cleanup

  • Shows every infected file with path, threat name, severity, and file size
  • Select All Critical button — delete multiple files at once
  • Automatic ZIP backup before any deletion
  • Quarantine option — moves files to a protected directory

Web Application Firewall

  • Blocks SQL injection, XSS, directory traversal in real time
  • Prevents PHP file uploads
  • Advanced IP blocking: exact IP, CIDR, ranges, wildcards
  • Rate limiting (120 requests per minute per IP)
  • Bad bot blocker: blocks 25+ vulnerability scanners and scrapers

Geo-Fence and Trusted Location

  • Restrict WordPress admin access to specific IP addresses
  • Country-based admin lock: only allow access from your country
  • Block file uploads from untrusted countries
  • One-click trusted IP setup

Login Security

  • Brute force protection with configurable thresholds and lockout duration
  • Login attempt logging with IP, timestamp, and user agent
  • Email alert when admin logs in from unrecognised IP
  • Auto-blocks attacker IPs in firewall after brute force detection

Two-Factor Authentication (2FA)

  • TOTP/RFC 6238 — compatible with Google Authenticator, Authy, and all TOTP apps
  • Manual secret key setup on user profile page
  • Recovery codes (8 single-use)
  • Per-user enable/disable

Vulnerability Scanner

  • Checks all plugins, themes, and WordPress core against WPScan vulnerability database
  • CVSS severity scoring, CVE links, version-aware matching
  • Works without API key (optional WPScan key for higher limits)
  • Email alert when new vulnerabilities are found

Live Traffic Monitor

  • Logs every HTTP request with bot/human detection
  • Identifies 30+ bots including AI crawlers (GPTBot, ClaudeBot, PerplexityBot)
  • 24-hour stats: total requests, humans, bots, blocked, errors
  • Paginated — handles large traffic volumes
  • One-click IP block from any traffic row

Site Hardening

  • HTTP security headers (X-Frame-Options, HSTS, X-Content-Type-Options, Referrer-Policy)
  • Hide WordPress version, block user enumeration
  • Optional: disable XML-RPC, restrict REST API, disable file editor

Google Search Console Cleanup

  • Connects to Google Search Console via OAuth
  • Detects indexed SEO spam URLs even when files are deleted from server
  • Lists indexed URLs with one-click spam detection (Japanese/Chinese/doorway)
  • Guides you through Google Search Console’s Removals tool for de-indexing
  • Sitemap resubmission after cleanup

Privacy

Turbo Guard does not send your website files to any external server. Vulnerability checks send only plugin/theme slugs and versions to the WPScan API — and only on manual scans or when scheduled vulnerability scans are enabled in Settings (off by default). The SEO spam scanner reads your site’s own sitemap via a local request to the site itself — no external service is contacted. Geo-Fence country blocking sends the visitor IP address to ipapi.co when enabled. 2FA is fully local: TOTP secrets are entered manually in your authenticator app and no QR service is used. GSC integration uses your own Google OAuth credentials. AI analysis (optional OpenAI) sends only anonymised threat type data. No telemetry. No tracking. No account required.

External Services

This plugin connects to external services for certain features. All connections require explicit user action or opt-in.

WordPress.org API

Used to verify WordPress core file integrity by comparing checksums.
* Data sent: WordPress version and locale
* When: Only when the user runs a malware scan or a file integrity check (including scheduled scans)
* Service: https://api.wordpress.org/
* Privacy Policy: https://wordpress.org/about/privacy/

WPScan Vulnerability Database

Used to check plugins and themes for known security vulnerabilities.
* Data sent: Plugin/theme slugs and versions
* When: Only when the user runs a manual vulnerability scan, or when scheduled vulnerability scans are enabled in Settings (off by default)
* Service: https://wpscan.com/
* Terms of Use: https://wpscan.com/terms
* Privacy Policy: https://automattic.com/privacy/

ipapi.co (Geo-Fence)

Used for IP geolocation to support country-based access and upload controls (Geo-Fence).
* Data sent: Visitor IP address
* When: Only when geo-fence country features are enabled
* Service: https://ipapi.co/
* Terms of Service: https://ipapi.co/terms/
* Privacy Policy: https://ipapi.co/privacy/

OpenAI API

Used to provide AI-powered security analysis and recommendations.
* Data sent: Anonymized scan results (no personal data or site content)
* When: Only when user explicitly clicks “AI Analysis” (requires user-provided API key)
* Service: https://api.openai.com/
* Terms of Use: https://openai.com/policies/terms-of-use
* Privacy Policy: https://openai.com/policies/privacy-policy

Google APIs (Search Console)

Used for Google Search Console integration to detect SEO spam and manage indexed URLs.
* Data sent: OAuth tokens, site URL for search analytics queries
* When: Only when user connects their Google account and initiates GSC features
* Service: https://developers.google.com/webmaster-tools
* Terms of Service: https://developers.google.com/terms
* Privacy Policy: https://policies.google.com/privacy

  1. Upload the turbo-guard folder to /wp-content/plugins/
  2. Activate the plugin through the Plugins menu in WordPress
  3. Go to Turbo Guard in your admin sidebar
  4. Click “Start Full Scan” on the Scanner page
  5. Review results and use “Select Critical Only” then “Delete Selected”
  6. Check the AI Advisor page for personalised security guidance
Is Turbo Guard completely free?

Yes — all scanning, detection, and protection features are 100% free. The free version can clean up to 3 infected files. Upgrade to Turbo Guard Pro for unlimited cleanup plus Live Traffic Monitor, AI Security Advisor, and Geo-Fence. No account required.

Will it slow my website?

No. Scanning runs via AJAX in your browser. The firewall adds negligible overhead.

My site shows Japanese spam in Google but files are gone. What do I do?

Use the GSC Cleanup page. Connect Google Search Console, fetch indexed URLs, identify the spam entries, and submit them for removal in Google Search Console’s Removals tool.

Does the File Integrity checker work without internet?

It downloads checksums from the WordPress.org API on first use and caches them for 12 hours, so repeat checks work offline.

Can I use this on all my sites?

Yes. Install on each site. No per-site fees or licence limits.

Does it conflict with other security plugins?

Turbo Guard whitelists 15+ popular security plugins (Wordfence, Sucuri, MalCare, iThemes, etc.) to prevent false positive detections. It can run alongside other security plugins without issues.

1.1.2

  • SEO Spam Detector: detects spam-looking URLs in the site sitemap
  • SEO Spam Detector: scans all posts/pages (no 500-post cap) and JS files in uploads
  • SEO Spam Detector: recoverable Trash cleanup with permanent delete (Pro)
  • SEO Spam Detector: Scan All plugin, theme and database at free
  • SEO Spam Detector: ignore/mark-safe allowlist for posts and files
  • GSC Cleanup: Search Cosol API connection, sitemap fetch and removal request at free.
  • Added scheduled SEO spam scan option and Pro email alerts
  • Added CJK-content override setting to reduce false positives

1.1.1

  • Update the plugin Dashboard
  • Added more feature

1.0.0

  • Initial release
  • Malware scanner with 30+ pattern signatures and WordPress core file manifest check
  • AI Security Advisor with attack campaign analysis and step-by-step fix guide
  • File Integrity Checker — verifies WordPress core files against WordPress.org checksums
  • File Watcher — baseline snapshot, detects new/modified/deleted files every 6 hours
  • Web Application Firewall — SQL injection, XSS, directory traversal blocking
  • Login Security — brute force protection, lockout, IP blocking
  • Two-Factor Authentication (TOTP/RFC 6238)
  • Vulnerability Scanner (WPScan API, CVSS scoring)
  • Live Traffic Monitor with bot/human detection
  • Site Hardening (security headers, XML-RPC, user enumeration)
  • Geo-Fence — restrict admin access to trusted IPs or countries
  • Bot Protection — blocks 25+ vulnerability scanners and bad scrapers
  • Google Search Console Cleanup (OAuth, bulk URL removal)
  • One-click bulk malware cleanup with automatic ZIP backup
  • Database scanning (wp_posts, wp_options, rogue admin users)
  • Japanese/Chinese/Korean SEO spam detection
  • Polyglot image backdoor detection
Back to top