WP Freedom: malware recovery, with the evidence to prove it.
Finding malware is not the problem. Deciding what is safe to delete, on a live client site, at 11pm, is. WP Freedom gives that decision a process — what changed, what is malicious, what to preserve, what to repair, and whether the identified malware indicators are gone afterward.
The outcome: go from “this site may be infected” to a documented recovery, with evidence that the known compromise was addressed.
Every WordPress website deserves to be clean and functional.
Not on sale yet. The plugin is built and tested; the store listing and the purchase-to-activation flow are not finished, and we would rather say so than take an order we cannot fulfil. Join the list and you will hear the day it opens.
Where it is today: every capability on this page is built and covered by 106 automated tests, and the plugin has not yet been run on a production website or against a live infection. Detection has been tested for false positives — code that must never be flagged — and not yet for recall against real malware samples. We would rather tell you that than have you assume otherwise.
The Process
A scanner gives you a list. This gives you a decision.
Detect
Signatures and structure together: web shells and encoded payloads, core files that do not match the official checksums, PHP where PHP should never be, injected database content, cron persistence, accounts nobody created.
Triage
Risk ranked critical to verified-safe. Two detectors agreeing on one file confirms it. A weak indicator on a file that has been there since the baseline gets weighted down — obfuscated premium plugins exist.
Investigate
Every finding says what was found, why it was flagged in plain words, and — the part no scanner writes — what happens if the recommendation is wrong.
Preserve
The exact bytes, SHA-256, size, timestamps, ownership, permissions and the detection reason, written to a sealed vault before anything is touched. If preservation fails, recovery does not run.
Recover
Replace a core file with the official copy, checksum-verified before it is written. Remove a malicious file. Unschedule persistence. Remove an unauthorized admin, reassigning their content rather than deleting it.
Rescan & verify
Every detector runs again. Cleared, remaining, new — stated as numbers. A deleted file that reappears is reported as live persistence, not as a successful removal.
Change Intelligence
“17 suspicious files found” is not information.
What WP Freedom says instead
47 files changed against the known-good state.
- Legitimate plugin update32
- Legitimate theme changes8
- Suspicious4
- Confirmed malicious3
Now the agency knows what actually deserves attention — and the other 40 changes never cost anyone an hour.
What it detects
Known indicators plus change analysis — because signatures alone miss anything new, and change analysis alone flags every legitimate update.
Evidence before anything is touched
Cleaning a compromised site destroys the record of how it was entered — and “how did they get in” is the question that always comes a week later.
Before any recovery action, WP Freedom stores the exact bytes, SHA-256 and MD5, size, modified and created timestamps, owner, permissions, matched indicators and the detection reason — in a sealed vault with an unguessable name, no directory index, and nothing executable inside it. The vault survives an uninstall, because incidents outlive the tools that found them.
It never declares clean on a deletion
After recovery, every detector runs again and the result is stated in numbers: addressed, cleared, still present, newly found, site responding or not.
A file deleted and then found back on disk is reported as active persistence — because that is what it is.
The verdict language is bounded on purpose: the identified compromise was addressed. Not “guaranteed clean”. Any tool promising more than that about a compromised site is guessing.
One Price
$249. Up to 5 websites.
One infection handled properly — investigated, preserved, recovered, verified, documented — bills for more than this costs. One payment covers 5 websites permanently. Continued detection updates are optional after the first year.
$249
The whole investigation and recovery process: detection, triage, the evidence vault, verified recovery, the rescan, and the incident report. Good for up to 5 websites.
Includes 12 months of detection updates. After that, $99/year keeps new indicators arriving.
Join The Launch ListAbout that yearly bit
This is the one place a yearly charge is honest. Malware changes; a detection set that stopped being maintained in 2026 is worth less every month. WP Web Manager has no equivalent, because a missing sitemap is a missing sitemap forever.
So here is exactly what lapsing means: the plugin keeps working, every feature stays on, and nothing is disabled or locked. You stop receiving new indicators, and the dashboard tells you how old your detection set is so you can judge that for yourself. A security tool that holds your own site hostage over a renewal is not a security tool.
One payment, up to 5 websites. The plugin stays yours and keeps working — no required subscription. Secure Stripe checkout on livableforms.com.
Two Products, One Story
WP Web Manager runs the site. WP Freedom handles the incident.
WP Web Manager
Technical health, performance, SEO, updates, compatibility, UX, infrastructure, routine repairs, maintenance reporting.
Malware detected
WP Web Manager stops at the boundary and escalates. It never cleans, quarantines or repairs an infection — that is enforced in its code.
WP Freedom
Detection, triage, investigation, evidence, remediation, recovery, verification, incident report. Then the site goes back to normal management.
When WP Freedom verifies a site, it writes the outcome straight into WP Web Manager's activity log — including when an incident was closed with indicators still outstanding. One site, one continuous record.