Plugin Pulse
← Pulse

Quttera ThreatSign – Web Malware Scanner for WordPress

by quttera · Security

WordPress multi-level security scanner detecting malware, 0-day threats, brute-force attacks, bot attacks, and unauthorized admin changes.

How scoring works →
83 Health · B
Maintenance 100/100
Rating quality 73/100
Support 70/100

83 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

96 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 80/100
Listing tuning 100/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+44% vs prior 30d
4.5KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

48.1K

now · peak 67.6K

48.4K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Quttera ThreatSign · #2037 you MalCare WordPress Se · #283 WebDefender Security · #6494 Site Lockdown Securi · #8388

Rating trend

Star average over time · dips mark rough releases

3.9Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

4.8Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

75

releases in the last 12 months

2mo ago

latest release · v4.1.0.20

1,047

tagged releases on record

Recent releases

4.1.0.20 · 2mo ago4.1.0.19 · 2mo ago4.1.0.18 · 2mo ago4.1.0.17 · 2mo ago4.1.0.16 · 2mo ago4.1.0.15 · 2mo ago4.1.0.14 · 2mo ago4.1.0.13 · 2mo ago4.1.0.12 · 3mo ago4.1.0.11 · 3mo ago4.1.0.10 · 3mo ago4.1.0.9 · 3mo ago4.1.0.8 · 3mo ago4.1.0.7 · 3mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 58% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v4.1 58%
v3.5 28%
v4.0 8.1%
v3.4 5.1%
Older / other versions 1.7%

Estimated active installs

The public count shows “10K+”. Our estimate pins where the real number sits.

tracked estimate
10K–20K ≈19K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-19 · 1,482 observations

10KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
4.1.0.31
Last updated
2d ago
Added
2012-06-07 · 14 yrs old
Requires WP
3.3.2
Tested up to
7.1
Requires PHP
7.2

Recent reviews

All reviews on wp.org ↗
  1. romeroz
    1.6y ago

    It just helps when you’re having trouble. Nice cool job, thank you!

    Read on wp.org ↗
  2. nmrockswp
    2.4y ago

    Great tool that helps you quickly find out whether and which plugins could be affected by a data leak if you have numerous attacks on WordPress (e.g. on wp-admin). You can then replace all plugin folders with the original plugin files via FTP, done. Very good job, thank you!

    Read on wp.org ↗
  3. oscarma007
    3.6y ago

    It cleaned the malware on my website before it executed and gave me issues. top-notch product.

    Read on wp.org ↗
  4. rocky12
    3.8y ago

    I wasnt expecting anything from this plugin but it has saved my lots of time and money. First I removed some critical files by wordfence and tried almost all malware scanners but non of the scanners could detect the infected files, infact wordfence was showing no threat but my site was displaying the japanese letters snippet on google and had 62000 links indexed on google console. I would say Malcare did a good job in scanning the malware but it doesnt show any files because of paid service. After running this scanner it showed me some malicious files and I removed them from the control panel by myself. Book malware was disappeared scanner didnt showed site is hacked. Thanks alot guys

    Read on wp.org ↗
  5. WilliamCampbell
    4.2y ago

    Only tells you that it is paid once it has supposedly detected infectoin. This can’t be trusted when the vendor is motivated to detect false positives.

    Read on wp.org ↗
  6. dfyz1337
    5.0y ago

    Отличный плагин! Теперь я могу спать спокойно. Поддержка ответила очень быстро и даже просмотрела мои подозрительные файлы вручную!

    Read on wp.org ↗
  7. Harald Wenzel
    5.5y ago

    The Only thing is that one has to sort out and whitelist quite a lot. One remark to the review before this one: Probably Quttera is not prepared for a XXAMP-server. The problems might be caused by the different file systems on Windows.

    Read on wp.org ↗
  8. Andrés Sorolla
    5.9y ago

    This security plugin is a complete fraud. Once installed on my website and performed a high sensitivity test it found no less than 5 MALICIOUS FILES, 8 POTENTIALLY SUSPICIOUS FILES AND THE WORST 1381 SUSPICIOUS FILES!!!! Suspecting that this was not true, I proceeded to perform the following test. On a computer with a freshly installed copy of the original W10, all the updates done, an updated antivirus and without any virus detection, I installed a local copy of the latest version of WordPress in XAMPP. I named this local version of WordPress Quttera in honor of these gentlemen. I installed only the Quttera plugin and performed a high-sensitivity scan on this completely new installation of wordpress and then found: 3 MALICIOUS FILES and 8 POTENTIALLY SUSPICIOUS FILES !!!! Funny, isn’t it? I proceeded to install the Elementor plugin and then changed the report to: 3 MALICIOUS ARCHIVES and 11 POTENTIALLY SUSPECTIVE ARCHIVES !!!! I proceeded to perform a third test.I installed the plugin Duplicator by Snap Creek and RANK MATH SEO this time the report was: 5 MALICIOUS AND 11 POTENTIALLY SUSPICIOUS FILES !!!! These results appear in a clean WordPress installation, with no post, image, or page created, nothing! I am completely convinced that this plugin is a scam. Quttera’s owners scare you with false positives and countless suspicious files with the sole aim of making you pay for disinfecting something that is not infected and fattening Quttera’s wallet. I hope this test will save users the time lost trying to clean something from viruses that is definitely not infected. Wordpress should remove this plugin from its list This topic was modified 5 years, 9 months ago by Andrés Sorolla. This topic was modified 5 years, 9 months ago by Andrés Sorolla.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 4.1.0.21 Added new detection rules Improved database scanning capabilities 4.1.0.21
  2. Version 4.0.0.15 Added new detection rules 4.0.0.15
  3. Version 4.0.0.11 Added new detection rules Fixed summary email body 4.0.0.11
  4. Version 4.0.0.1 Major: Added Brute Force Protection system with configurable policies Major: Added Bot Protection with token-bucket rate limiting Major: Added Admin User Monitoring with real-time alerts Added Emergency Bypass mechanism 4.0.0.1
  5. Version 3.5.2.1 Fixed vulnerability type: Stored XSS Administrator+ role Affected Plugin. Thanks to Artyom Krugov for reporting and helping to improve our plugin. Fixed vulnerability type: Server-Side Request Forgery. Thanks to Jonas Be 3.5.2.1
  6. Version 3.5.1.41 Added new detection rules 3.5.1.41

Known vulnerabilities

via Wordfence Intelligence

3 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2025-08-14 CVE-2025-8013 Server-Side Request Forgery (SSRF) Affects <= 3.5.1.41 Patched in 3.5.2.1
  2. 2023-11-21 CVE-2023-6065 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.4.1.48 Patched in 3.4.2.1
  3. 2023-11-21 CVE-2023-6222 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.4.1.48 Patched in 3.4.2.1

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2023-03-03 20K+ → 10K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Quttera ThreatSign – Web Malware Scanner for WordPress into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/quttera-web-malware-scanner" width="480" height="300" style="border:0" loading="lazy" title="Quttera ThreatSign – Web Malware Scanner for WordPress — Plugin Pulse"></iframe>
Preview card ↗

Quttera ThreatSign – Web Malware Scanner for WordPress: 10K+ active installs, 3.9★ (47 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/quttera-web-malware-scanner