Malware removal plugins are sold as though they all do the same job, and they do not. Most of what gets recommended is a scanner: it finds the infection, flags the file, and leaves you holding the shovel. Actual removal, meaning someone who logs in and pulls a backdoor out of your uploads folder, is a separate product at a separate price. This roundup keeps the two apart, because that gap is where people get caught.
Quick verdict
Best overall: the Sucuri platform at $229 a year. It is the cheapest plan here that bundles unlimited analyst cleanups, under a 30-hour response target, so a hack becomes a support ticket rather than your evening.
Best free: Wordfence. The free scanner is genuinely good at finding things. Just understand that its “removal” is a delete button you press yourself.
Cheapest hands-on cleanup: of the options priced in dollars here, Sucuri’s one-time cleanup at $98 for one site, no subscription attached. CleanTalk’s equivalent is $119 and bundles a year of its plugin.
Skip it if: you are shopping for a free plugin that cleans an infected site by itself. That product does not exist. Every free tier on this page detects and stops there.
Our call: if your site is infected right now, buy a cleanup today and pick a plugin afterwards. If it is clean, run Wordfence free alongside real off-server WordPress backup plugins and put the money into better hosting instead.
Scanner, cleaner, or cleanup service?
Three different things get sold under one label, and telling them apart is most of the buying decision.
A scanner compares your files against known-good copies and a signature database, then tells you which ones look wrong. That is nearly always what a free tier gives you.
A cleaner acts on that list without a human: it overwrites or deletes the offending file. Wordfence free can do a narrow version of this, because it can pull clean copies of core, theme and plugin files straight from WordPress.org. It cannot repair a file you wrote yourself, and it cannot tell a legitimate custom snippet from an injected one.
A cleanup service is a person. They read the access logs, find the entry point, remove the backdoors the scanner missed, and tell you what happened. This is what you are actually buying from Sucuri, MalCare’s Repair tier, CleanTalk and SecuPress, and it is priced accordingly.
MalCare is unusually honest about the split. Its $99 Protect tier scans daily, runs a firewall and applies virtual patches, and its own pricing page marks “Instant malware cleanup” as Not included. You have to reach the $299 Repair tier for a human. Most roundups quote the $99 figure and let you assume it covers a hack. It does not.
Malware removal plugins compared in 2026
| Tool | What it actually does | Price, one site | Hands-on cleanup? |
|---|---|---|---|
| Sucuri Platform (Basic) | Remote scan every 12 hrs, cloud WAF, analyst cleanups | $229/yr, recurring | Yes, unlimited, 30-hr target |
| Sucuri one-time cleanup | Analyst cleanup with a report, no plan required | $98 one-off | Yes, one incident only |
| Wordfence (free) | Endpoint firewall, file scanner, login security | Free | No, you press delete |
| MalCare Free | Weekly scan, vulnerability alerts, basic firewall | Free | No |
| MalCare Protect | Daily scan, firewall, virtual patching | $99/yr, recurring | No, explicitly excluded |
| MalCare Repair | Everything above plus one-click cleanup | $299/yr, recurring | Yes, 24-hr expert target |
| Kadence Security (ex-iThemes) | Firewall, 2FA, virtual patching, vulnerability scan | $299/yr inside Kadence Pro | No, and no file scanner |
| CleanTalk Security | Daily malware scan, WAF, spam filtering | $9/yr, recurring | No, $119 one-off service |
| SecuPress Pro | PHP malware scan, hardening checks | €60/yr, auto-renews | No, €299 removal service |
| BulletProof Security | .htaccess hardening, file change monitoring | Free plugin | No |
| Astra Security Suite | Plugin closed on WordPress.org; vendor now sells pentests | Not applicable | No |
Sucuri

Sucuri splits neatly into two products, and only one of them is a plugin. The free Sucuri Security plugin is a monitoring tool: file integrity checks, remote scanning, blocklist alerts and hardening. Its WordPress.org listing calls it the Sucuri Security Monitoring Plugin, and its post-hack features reset passwords and user accounts rather than removing malicious code.
The paid platform is where the cleanups live. Every tier includes unlimited manual cleanups by Sucuri’s own analysts, which is unusual: most competitors either cap incidents or sell them separately. What you pay more for is speed. Basic targets 30 hours and scans every 12; Pro at $339 targets 12 hours and scans every 6; Business at $549 targets 6 hours and scans every 30 minutes.
There is also a one-time cleanup at $98 for a single site with no ongoing plan, which is the cheapest of the dollar-priced options here for getting a person onto an infected site. It buys you exactly one incident and explicitly does not cover re-infection, so treat it as an ambulance rather than insurance.
Key features: cloud WAF that filters traffic before it reaches your server, unlimited analyst cleanups, blocklist monitoring and delisting, DNS and uptime monitoring.
Price: $229, $339 or $549 a year for one site; $999.98 a year covers five. Full Sucuri platform pricing is on their site.
Best for: anyone who wants a hack to be someone else’s problem, and small agencies. Five sites on Basic separately would run $1,145, so the $999.98 Junior Dev plan is cheaper and upgrades the response target from 30 hours to 12.
Skip it if: you only want a plugin. The free plugin monitors and nothing more, and the cloud WAF means pointing your DNS at Sucuri, which is a real change to how your site is served.
Wordfence

Wordfence sits on about five million active installs, far more than anything else here, and the free version earns most of that reach. The firewall runs at the endpoint rather than in the cloud, so there is no DNS change and nothing to break your SSL. The scanner checks core, themes and plugins against the WordPress.org repository and flags backdoors, SEO spam and malicious redirects.
Now the part the marketing glides over. According to Wordfence’s own WordPress.org listing, the free version’s malware removal tools are “Delete File” and “Delete All Deletable Files”. That is you, reading scan results at midnight, deciding which files are safe to destroy. The same listing confirms free users receive new firewall rules and malware signatures 30 days after paying customers, which matters most in the window right after a new plugin vulnerability goes public.
Wordfence sells Premium, Care and Response tiers, with Care and Response adding hands-on incident work by their team. Those prices could not be verified: the Wordfence pricing page sat behind a bot challenge on the check date and returned no content. Rather than repeat figures from third-party blogs, none are quoted here. Confirm at checkout.
Key features: endpoint firewall, file-integrity scanner, repair of core and repository files from clean originals, two-factor authentication, live traffic view, rate limiting.
Price: free tier is complete and genuinely usable. Paid tier pricing not verified at the check date.
Best for: a healthy site that wants a good scanner and a firewall that does not touch DNS.
Skip it if: you are already hacked and want it fixed for you, or your host is tight on resources. Full file scans are the most common reason a site hits its PHP memory ceiling, and raising the WordPress memory limit is usually the fix before you blame the plugin.
MalCare

MalCare’s selling point is that scanning happens on their servers, not yours. It syncs your files off-site and analyses them there, so a deep scan does not drag your response times down. If you have ever watched a scan flatten a shared host, that design matters.
The tiers are the clearest illustration of this article’s whole point. Free scans weekly and alerts you. Protect at $99 adds daily scanning, a proper firewall, geo-blocking and virtual patching, and still lists cleanup as not included. Repair at $299 is the first tier with a human attached, at a 24-hour response target and a post-cleanup report. Fortify at $499 scans hourly with a 6-hour target and unlimited manual fixes.
The five-site bundles are where agencies win: Repair for five sites is $899 against $1,495 for five single licences, a saving of $596.
Key features: off-site scanning, one-click cleanup on Repair and above, firewall with virtual patching, bot protection, WordPress admin 2FA, web host suspension recovery on the top tier.
Price: free; $99, $299 or $499 a year for one site, per MalCare’s pricing page. Refunds within 14 days, except once a cleanup has been performed.
Best for: stores and anything where downtime costs money, and freelancers running several client sites on one account.
Skip it if: your budget stops at $99. That tier buys prevention, not rescue, and buying it while already infected is the most common mistake with this product.
Kadence Security, formerly iThemes Security

The screenshot above is a museum piece, and that is the point. This plugin began as Better WP Security, became iThemes Security, then Solid Security, and Liquid Web has now folded it into Kadence. The WordPress.org listing still uses the slug better-wp-security and reports around 700,000 active installs, and its readme now describes the plugin as Kadence Security.
Two things have changed that most roundups have not caught up with. First, it is no longer sold on its own. The vendor’s Kadence pricing page lists Essentials at $99 a year for the theme and blocks, Pro at $299 which is the tier that “Adds Security, Backups, Shop Kit for WooCommerce, and Memberships”, and Elite at $499. To get the security plugin you buy the whole bundle at $299, which is $200 more than Essentials and a strange purchase if you already run a different theme.
Second, and more importantly for this article: it is not a malware scanner. Its Site Scan checks your core, plugins and themes against a known-vulnerability database and queries Google Safe Browsing for your blocklist status. It has file change detection, which tells you a file changed, not that the change was malicious. The readme lists no signature-based file scan and no cleanup at any tier. An earlier version of this article described it as offering malware scanning and removal. That was wrong.
Key features: brute force protection network, 2FA and passkeys, vulnerability site scan, file change detection, Patchstack virtual patching on Pro.
Price: $299 a year via Kadence Pro; the free plugin covers login hardening.
Best for: people already buying the Kadence stack, who get a solid brute force protection layer as part of the deal.
Skip it if: you came here to find malware. This tool prevents the break-in; it does not investigate one.
CleanTalk Security and Malware Scan

CleanTalk is best known for spam filtering, which is what the homepage above still leads with, but its Security and Malware Scan plugin is a separate product and the pricing is the most interesting thing about it. One site costs $9 a year. Unlimited sites cost $27 a month. Nothing else here priced in dollars comes close.
What $9 buys is a daily malware scan, a firewall backed by their IP reputation database, a WAF and brute force protection. What it does not buy is cleanup. That is a separate $119 service where their specialists clean the site, hand you an analysis report and tune your settings, and it includes a year of the security plugin. Since the plugin alone is $9, the cleanup is effectively $110 with a year of monitoring thrown in.
The trade-off is scale. At roughly 40,000 active installs on its WordPress.org listing it has a fraction of Wordfence’s reach, so there is less community knowledge to lean on when something behaves oddly. The upside is that the same account also covers their anti-spam service, which is worth something if you were paying for that separately.
Key features: daily automatic malware scan, security firewall with a live IP database, WAF, brute force protection, audit log.
Price: $9 a year for one site, up to $180 a year for 40, or $27 a month unlimited, per CleanTalk’s WordPress security pricing. Cleanup is $119 per site.
Best for: people running a lot of small sites where $229 a year each is absurd, and anyone who already pays CleanTalk for spam.
Skip it if: you want the biggest community and the most documentation behind your security stack.
SecuPress

SecuPress is a French plugin with a clean interface and a genuinely useful one-click security audit that grades your configuration and explains each failure in plain language. It is the friendliest tool here for someone who wants to understand what is wrong rather than just be told.
Note the currency. The pricing page serves euros by default with a US dollar switch, and the listed figure is €60 per site per year, renewing automatically. Because it is a different currency from everything else on this page, we are not going to rank it against the dollar prices; converting today’s rate into a permanent claim is how these comparisons go stale and wrong.
The pattern holds here too. The Pro licence includes a PHP malware scan. Malware removal is a separate service listed at €299. So the plugin finds it, a person fixes it, and those are two different invoices.
Key features: one-click security audit with graded results, PHP malware scan, hardening rules, backups, anti-spam, alerts.
Price: €60 per site per year on the SecuPress pricing page, with a €99 one-off surcharge for agency and multisite use. Removal service €299.
Best for: European buyers who want invoicing in euros, and anyone who learns better from an audit that explains itself.
Skip it if: you need cleanup bundled with the licence, or you want a large support community. Its WordPress.org listing shows roughly 40,000 installs, so it is a small player.
BulletProof Security

BulletProof Security is a survivor. Its WordPress.org listing shows around 20,000 active installs, a 96% rating across nearly 700 reviews, and an update shipped in August 2026. It is fundamentally an .htaccess hardening tool: it writes server rules that block a wide class of requests before PHP ever runs, and it monitors your files for changes.
Two honest caveats. It is not a malware cleaner in the sense this article means, and the vendor’s site shows its age; the Pro pricing pages returned 404 at the check date, so no figure is quoted. Check with them directly before buying. The free plugin on WordPress.org is the version most people should evaluate anyway.
Key features: .htaccess firewall rules, login security, database backup, file monitoring, security logging.
Price: the plugin is free on WordPress.org. Pro pricing was not reachable at the check date; confirm with the vendor.
Best for: people on Apache hosting who like server-level rules and are comfortable with a dense settings screen.
Skip it if: you are on Nginx, where .htaccess does nothing, or you want a modern interface. This one assumes you know what you are doing.
Astra Security Suite: skip it

This one is a straight correction. The Astra Security Suite plugin is closed on WordPress.org, which is the repository’s way of saying it is no longer available for download. The company has moved upmarket: the site now sells continuous penetration testing and API security, as the screenshot above shows, with plans running into the thousands per year.
None of that is a criticism of Astra as a business. It is a warning that a lot of “best malware removal plugins” lists, including the earlier version of this one, still recommend a plugin you cannot install. If you find it recommended elsewhere, that list has not been checked in a while.
What most roundups get wrong
They treat “detects malware” and “removes malware” as one feature. Every free tier on this page detects. None of them cleans an infected site unattended. The moment you need a person, you are looking at $98 to $299, and that number belongs in the comparison rather than in a footnote.
They recommend prevention tools as cures. Patchstack is excellent at what it does, virtually patching known vulnerabilities before the vendor ships a fix, and its Developer plan runs $828 a year. Patchstack’s own pricing page says it plainly: it “does not scan your files like a malware scanner and won’t help you in finding existing malware on your website.” A tool that stops the next break-in cannot undo the last one, and the same caveat applies to Kadence Security.
They ignore where the infection actually lives. Plenty of compromises sit outside WordPress entirely: a cron job on the server, a second site in the same hosting account, a stolen SFTP credential. A plugin runs inside WordPress and cannot see any of that. If your site keeps getting re-infected after clean scans, the problem is the account, not the install, and the answer is a migration to properly isolated hosting rather than another plugin.
They skip the part where a scan finds nothing and the site is still hacked. Signature scanners miss novel code. If Google flags your site but the scanner is clean, check for spam injected into the database rather than the filesystem, and view the source as Googlebot rather than as a logged-in admin. Cloaked SEO spam is written to be invisible to you specifically.
Which one should you buy?
Infected right now, need it gone today: Sucuri’s $98 one-time cleanup, or CleanTalk’s $119 if you want a year of monitoring included. Do not buy a subscription tier hoping it covers the current mess.
Infected more than once: Sucuri Basic at $229 a year. Unlimited cleanups is the point, and the cloud firewall stops the traffic before it lands.
Running a store: MalCare Repair at $299, or Fortify at $499 if hourly scanning and a six-hour response are worth the difference to you. Off-site scanning also keeps checkout responsive, which a local file scanner will not.
Managing many small sites: CleanTalk at $9 each, with the $119 cleanup held in reserve. Or MalCare’s five-site Repair bundle at $899 if the clients expect a guaranteed response time.
Clean site, small budget: Wordfence free, off-server backups, and a serious look at your wider WordPress security setup. Most infections start with an abandoned plugin nobody updated, not with a missing scanner.
After the cleanup: the part everybody skips
A cleanup that stops when the files are clean is half a job. Rotate every password and every application password, including the ones belonging to clients and contractors. Force a logout of all sessions, because a stolen cookie survives a password change. Regenerate your WordPress salts so existing sessions die properly. Delete unknown administrator accounts, then check the ones you recognise for a changed email address.
Then update everything, and delete what you are not using. A deactivated plugin sitting in wp-content/plugins is still a file the web server can be tricked into executing.
If the site handled personal data and you have European or UK visitors, a compromise may trigger a notification duty on a 72-hour clock, so this is worth knowing before you need it. Our notes on GDPR compliance for WordPress cover the ground. And if the same account keeps getting hit, move the site properly rather than restoring in place; restoring a backup onto a compromised server just re-infects the backup.
Frequently Asked Questions
Does a free malware removal plugin actually remove malware?
Mostly no. Free tiers detect. MalCare’s free plan states plainly that removal needs its Repair tier or higher. Wordfence’s free scanner can overwrite core, theme and plugin files with clean copies from WordPress.org and delete files you select, but anything sitting in your uploads folder or your own code is your problem.
What is the cheapest way to get a hacked site cleaned by a person?
Of the options priced in US dollars on this page, Sucuri’s one-time cleanup at $98 for a single site is the lowest. CleanTalk charges $119 and includes a year of its security plugin. Both cover one incident; neither covers you if the site gets re-infected next month.
Will a malware scanner slow my site down?
File scanners read every file on your server on a schedule, which costs CPU and PHP memory. That is usually fine on decent hosting and painful on cheap shared plans. If your scans stall or die partway through, the memory limit is the first thing to raise, not the plugin to blame.
Do I still need backups if I have a malware removal plugin?
Yes, and more than ever. Cleanup strips out malicious code. It does not undo what the attacker did to your database, your user accounts or your deleted files. A backup taken before the infection is often the fastest route back, provided it is stored somewhere other than the infected server.
Can I run two security plugins at the same time?
Not comfortably. Two firewalls competing over the same requests cause false lockouts and strange redirect loops, and two file scanners double your server load to answer one question. Pick one plugin for the firewall and the scan, then buy a separate one-off cleanup service if you actually get hit.
My host suspended my site for malware. What do I do now?
Ask the host for the exact file paths they flagged, because they always have them. Clean those files or buy a cleanup, then reply with a list of what you changed. No plugin helps while the site is offline, so this is a service job rather than a plugin job.
Is iThemes Security still available?
Not under that name. It became Solid Security, and Liquid Web has since folded it into Kadence. The security features now ship inside Kadence Pro at $299 per year, so you buy a theme and blocks bundle to get them. It has no file-level malware scanner at any tier.
How often should a malware scan run?
Daily is plenty for a normal blog or brochure site. Stores handling card details want hourly, which is what MalCare’s top tier and Sucuri’s Business plan sell. Scanning more often does not prevent an infection. It only shortens the gap between getting hit and finding out.
Our call
If your site is infected today, buy Sucuri’s $98 one-time cleanup. Among the dollar-priced options here it is the cheapest route to a person who will actually fix it, and you can decide on a subscription once you can think straight.
If you have been hit more than once, Sucuri Basic at $229 a year is the pick, because unlimited cleanups turn an emergency into a support ticket. Stores should pay the $299 for MalCare Repair instead and keep their checkout fast.
And if your site is fine right now, do not buy anything. Install Wordfence free, get backups off the server, update what you have and delete what you do not use. The best malware removal plugin remains the one you never have to open.





[…] checks. It does not do them and does not pretend to. Pair it with something from our roundup of malware removal plugins if that is the […]
[…] from the repository. If either is still active on a site you look after, remove it today and run a malware scan before you assume you got there […]