Beschrijving
Website gehackt? Segurium verwijdert de malware, gratis.
De meeste beveiligingsplugins scannen de website, noemen de besmette bestanden en vragen daarna geld om ze op te schonen. Segurium schoont ze zelf op. Het vindt de besmette bestanden, verwijdert de kwaadaardige code en zet het originele bestand terug, met een omkeerbare versleutelde back-up. Het gratis niveau dekt tot 3 opschoonacties in de cloud per voortschrijdende 30 dagen, genoeg voor een gewone besmetting. Geen opdringerige reclame, geen achtergrondprocessen die het CPU-budget van je gedeelde hosting opslokken.
Run it on every site you look after and the setup stays the same. Switch on auto-cleanup and a file that real-time scanning flags is repaired before anyone opens the dashboard. Plugins and themes with a known vulnerability get a red Vulnerable badge and an Update button. Export the settings once, import them on the next site, accept the service disclosure from WP-CLI, and let each site email you within 24 hours when malware turns up.
Wat je op elke installatie krijgt
Alle functies hieronder zitten in de plugin en draaien op elke installatie, zowel Free als Pro:
- Malware verwijderen en opschonen — Een volledige scan van het bestandssysteem vindt de besmette bestanden; één klik haalt de kwaadaardige code eruit en bewaart een versleutelde, omkeerbare back-up, zodat een verkeerde inschatting nooit blijvend is. Eén gezamenlijke weergave “Bedreigingen” verzamelt alle bevindingen.
- Bulkherstel met “Alles oplossen” — Zet met één klik alle gevonden bedreigingen in de wachtrij om opgeschoond te worden, zowel in het malwarepaneel als in het integriteitspaneel.
- Auto-cleanup on detection — Switch it on and a file that real-time scanning flags is cleaned without waiting for an admin to open the dashboard. Off by default; at its best next to a daily schedule, which applies the same rule.
- Realtime scannen en scannen bij upload — Nieuwe en gewijzigde bestanden worden automatisch gecontroleerd; besmette uploads worden geblokkeerd voordat ze op schijf belanden.
- Integriteitsscan — Controleer de WordPress core, plugins en thema’s tegen de manifesten van de bron, en zet een herschreven bestand terug naar de officiële inhoud. Zo draai je een hack terug die legitieme bestanden heeft bewerkt. Gemanipuleerde, uit de directory gehaalde en verlaten componenten worden hier ook getoond.
- Opschonen met versleutelde back-ups die je kan terugdraaien — Voordat er iets wordt opgeschoond, wordt het originele bestand versleuteld (AES-256-GCM) en lokaal opgeslagen. Back-ups blijven tot 30 dagen bewaard, binnen de limieten voor aantal en grootte per bak. “Origineel tonen” en “Terugzetten” zijn één klik weg.
- Geplande scans — Uit / dagelijks / wekelijks, met een tijdkiezer die je taalinstelling volgt. Elke ronde hangt een integriteitscontrole achter de malwareronde, in hetzelfde ritme.
- Twee-factor authenticatie — TOTP apps, e-mail als terugvaloptie, back-upcodes, vertrouwde apparaten, verplichting per rol en een overgangsperiode.
- Brute-force bescherming — Blokkades in meerdere stappen op wp-login.php en XML-RPC, een honeypotveld, handmatig deblokkeren van IP-adressen en optioneel hCaptcha bij login.
- Firewall — Regels om IP-adressen toe te laten of te blokkeren, CIDR-reeksen en filters per land, met één centrale IP-lijst die geldt voor login, beheer en het filteren van aanvragen.
- Geo-blokkering — Blokkeer login- of beheerverkeer per land met een lokale binaire database (automatisch bijgewerkt), met een vangnet dat bevestigt of terugdraait, zodat je jezelf niet buitensluit.
- Beveiligingsheaders — HTTP-responseheaders voor beveiliging, strengere cookies (SameSite/Secure/HttpOnly) en vijf standen die je met één klik instelt.
- Informatieschild — Schakelaars die de WordPress versie, discovery endpoints,
?ver=-strings op assets en XML-RPC verbergen als je ze niet gebruikt. - Zelfcontrole met beveiligingscijfer — De controles vormen samen een cijfer van A+ tot F, elk met knoppen die het met één klik oplossen en vergeleken met diensten van derden.
- Migration importer — Import your settings from Wordfence, All-In-One Security and Solid Security so you don’t lose your hardening when you switch. Sucuri Security is detected too, but its settings live in Sucuri’s cloud dashboard and cannot be read locally, so there is nothing to import.
- Disaster recovery — Lokale versleutelde back-ups zijn met een minieme regel PHP uit te pakken, zelfs als Segurium verwijderd is.
- Ingebouwde ondersteuning.
Hoe het Pro dienstniveau verschilt
Our cloud service performs the cleanups and counts each against a per-installation quota. The Free service tier covers up to 3 cleanups per rolling 30 days — enough for an occasional incident on a typical site. The Pro service tier raises that quota for sites that need higher volume (recurring infections, hosts under sustained attack, sites with high reliability requirements). The plugin code, the detection engines, and every feature listed above are identical on both tiers; the only difference is the quota ceiling enforced server-side.
Privacy als standaard
- Scanning is opt-in. Until you accept the service disclosure on the plugin’s admin page, nothing contacts the cloud and the plugin stays idle.
- Eerst de hash, de inhoud alleen als het moet. Tijdens een scan worden bestanden eerst op SHA-256 gecontroleerd. Alleen van bestanden waarvan de cloud de hash niet kent, worden de bytes geüpload voor classificatie. Zo blijft de hoeveelheid inhoud die je server echt verlaat klein en beperkt tot wat nieuw op schijf staat.
- No telemetry on your visitors. We look at files and security incidents, not at the people who visit your site.
- On-premise modus. Zet cloudgestuurde malware-detectie uit, dan verzenden scans alleen hashes, paden en metadata.
Externe diensten
Segurium verbindt met externe diensten om je WordPress installatie beschermd te houden. Elke dienst staat hieronder beschreven, met de gegevens die worden verzonden en wanneer. Er wordt niets verzonden voordat je de bekendmaking van externe diensten op de beheerpagina van de plugin accepteert.
Cloud Threat Inspection
Cloud Threat Inspection, our own service at cti.segurium.com, provides malware verdicts, integrity manifests, geo-location data, trusted-proxy IP ranges, support intake, cleanup files, and a per-installation quota on how many files it will clean in a rolling 30-day window. The service is contacted when:
- Er loopt een malwarescan, integriteitsscan, realtime scan of scan bij upload.
- You act on a plugin page. Accepting the service disclosure sends four things at once: a one-time installation registration (a random commitment hash, your site name, your site URL, your WordPress version, and, if you enabled email alerts, the alert email address you entered), a one-line
plugin_activatedping, aconsentrecord, and a first platform snapshot of the kind described below. Requesting cleanup of an infected file sends only that file’s SHA-256; the cleaned bytes come back by hash. A support request, false-positive report or missed-malware report sends the data you typed plus the file bytes you attached. A settings change sends a snapshot of that settings group. Deactivating the plugin sends a one-lineplugin_deactivatedping, skipped entirely if you never accepted the disclosure. Activating it sends nothing on its own. - A daily scheduled job runs. Four of them exist. The GeoIP database update and the trusted-proxies update only fetch data. The component-inventory ping sends your installed plugin/theme slugs and versions and your WordPress version, so we can spot tampered, delisted or abandoned components. The platform snapshot sends how your site is built: your WordPress version, locale, multisite and debug flags, whether WP-Cron is disabled and whether the site is served over HTTPS; your PHP version, SAPI, memory limit, maximum execution time and maximum input vars; your web server and its version; your database engine and version; your operating system family and architecture; the plugin version; and your active theme’s slug and version. It carries no file contents, no paths and nothing about your visitors.
- A brute-force lockout, geo-block or other security event fires. That sends a small JSON payload with the event type, your site URL, your domain, your WordPress / PHP / plugin versions, and a SHA-256 hash of the username, never the username itself or the password.
Data sent during scans (malware, real-time and upload alike): SHA-256 hashes of files on your server, file paths relative to your WordPress installation, file sizes, file modification times, plugin and theme version strings, and your WordPress version. For files whose SHA-256 is not yet known to the cloud verdict database, we also upload the file’s bytes so the file can be classified.
Turning the upload off: the “Cloud-assisted malware detection” setting on the Settings tab controls it. Switch it off for On-premise mode and scans send hashes, paths and metadata only, so a file whose hash the cloud does not recognise stays unresolved. Two uploads survive that mode, because you pick the file yourself: a false-positive report and a support-ticket attachment.
Retention: we keep file samples uploaded for analysis for up to 365 days, then an automated nightly purge removes them. The full schedule is in the privacy policy linked below.
A random installation identifier (IID), issued at registration time, identifies each request. We do not send your posts, pages, or anything about your visitors, and we never send passwords. The privacy policy linked below names the data controller and how to reach them.
- Servicevoorwaarden: https://segurium.com/terms
- Privacybeleid: https://segurium.com/privacy
Freemius (api.freemius.com, checkout.freemius.com, wp.freemius.com)
Segurium uses the Freemius WordPress SDK (bundled in freemius/) for license activation, paid-plan checkout and account management on the Pro plan. The SDK ships in anonymous mode: on activation Segurium tells it to skip the connect prompt, so it sends no request to Freemius and collects no telemetry from your install. Freemius, Inc. operates the service.
Freemius servers hear from your site only when you click an upgrade or “Manage billing” button on the account page and complete the checkout on checkout.freemius.com, or when you activate, sync or deactivate a Pro license there. In that second case the SDK posts the licence key, your site URL, your WordPress / PHP versions and the plugin version to api.freemius.com. Never open the account page and never enter a licence, and your site never calls Freemius at all.
- Servicevoorwaarden van Freemius: https://freemius.com/terms/
- Privacybeleid van Freemius: https://freemius.com/privacy/
hCaptcha (js.hcaptcha.com, hcaptcha.com) — OPTIONEEL
Als — en alleen als — je hCaptcha aanzet op de instellingenpagina voor brute-force bescherming en je je eigen hCaptcha website sleutel en geheime sleutel invult, gaat Segurium:
- Het JavaScript van hCaptcha laden vanaf
https://js.hcaptcha.com/1/api.jsop de pagina wp-login.php, zodat de uitdaging getoond kan worden. - Het hCaptcha token en het IP-adres van de bezoeker naar
https://hcaptcha.com/siteverifysturen om de uitdaging bij loginpogingen te controleren.
hCaptcha staat standaard uit. Zolang je het niet aanzet, worden er geen hCaptcha-scripts of aanvragen geladen. hCaptcha wordt geleverd door Intuition Machines, Inc.; hun voorwaarden en privacybeleid gelden zodra je de functie aanzet.
- hCaptcha servicevoorwaarden: https://www.hcaptcha.com/terms
- hCaptcha-privacybeleid: https://www.hcaptcha.com/privacy
Broncode van meegeleverde bibliotheken
Every release is mirrored at https://github.com/Segurium/segurium-plugin.
Segurium levert de Freemius WordPress SDK mee in freemius/ voor licenties, afrekenen en ondersteuning. Een paar bestanden in die SDK (freemius/assets/js/jquery.form.js en freemius/assets/js/postmessage.js) zijn bij de bron al geminificeerd en worden ongewijzigd meegeleverd. De niet-geminificeerde broncode van de volledige SDK is gepubliceerd onder GPL-3.0 op:
- https://github.com/Freemius/wordpress-sdk
De versie van de SDK die bij deze release zit, staat in freemius/start.php ($this_sdk_version).
Schermafbeeldingen












forever, 3 cleanups every 30 days; a year per site lifts the cap.” class=”wp-image-9000013″ width=”1280″ height=”960″ loading=”eager” fetchpriority=”low” decoding=”async”/>Installatie
- Upload de map
seguriumnaar/wp-content/plugins/, of installeer via Plugins Nieuwe plugin toevoegen in het WordPress-beheer. - Activeer de plugin via het menu Plugins in WordPress.
- Open Segurium in de zijbalk van het beheer en accepteer de bekendmaking van externe diensten om scannen aan te zetten.
- (Optioneel) Importeer instellingen uit je vorige beveiligingsplugin via Segurium Migratie.
- (Optioneel) Zet twee-factor authenticatie, geo-blokkering en beveiligingsheaders aan via hun eigen tabs.
FAQ
-
All of them. Two-factor authentication with an authenticator app (TOTP), email codes, backup codes, trusted devices and per-role enforcement. Brute force protection with login attempt limits, lockouts, a honeypot and xmlrpc coverage. A firewall with IP, CIDR and country rules, so you can block a country from your login page. Security headers with HSTS, CSP, Referrer-Policy and Permissions-Policy, plus cookie hardening. Geoblocking from a local database, by country or by preset region (EU, Americas, Asia-Pacific, Africa, Middle East, High-Risk). None of it is a trial and none of it is gated behind a pro plan. Only the number of cloud cleanups is capped on the free tier: three every 30 days.
-
Can I set up malware cleanup on many sites without opening each dashboard?
-
Yes. WP-CLI accepts the service disclosure and reports the cleanup quota, and settings export and import carry one site’s configuration to the next. Every install runs the same plugin code and the same free quota, so a site that joins later behaves like the rest.
-
Is Segurium een antivirusprogramma voor een WordPress website?
-
In de praktijk wel. Mensen noemen hetzelfde probleem een websitevirus, een WordPress virus of malware, en het is één ding: bestanden op je server die er niet horen, plus code die een aanvaller heeft toegevoegd aan bestanden die er wel horen. Segurium berekent de hash van de bestanden op je server en vraagt de cloud beoordelingsdatabase wat elk bestand is, zodat een antimalwarescan van een hele website een hash opzoeking wordt in plaats van een controle bestand voor bestand. Een antivirusprogramma op je bureaublad beschermt je laptop. Segurium doet dat werk voor je WordPress bestanden, en verwijdert wat het vindt.
-
Kan Segurium een betalende beveiligingsplugin vervangen?
-
Voor malware verwijderen, tweefactorauthenticatie, een firewall, geoblocking en beveiligingsheaders: ja. Dat zijn net de onderdelen die de meeste plugins als premium abonnement verkopen, en Segurium levert ze gratis bij elke installatie. Het betaalde niveau verhoogt alleen het quotum voor opschoningen in de cloud. Verplaats je je instellingen van een andere beveiligingsplugin, dan haalt het tabblad Migratie ze op uit Wordfence, All-In-One Security en Solid Security, zodat de overstap je je hardening niet kost.
-
Waar zoekt een Segurium scan naar?
-
Files the cloud verdict database has already classified as malicious. In a normal break-in that means an uploaded web shell or backdoor, a redirect injected into a theme file, spam pages, spam links, hidden links, a phishing page dropped in an upload folder, the Japanese keyword hack, and leftovers from a crypto miner. Segurium does not care what the family is called, whether someone labels it a trojan or a virus. It checks whether a file is malicious and whether it can put the clean version back.
-
Verwijdert Segurium malware gratis, of detecteert het die alleen?
-
Het verwijdert de malware. Malware verwijderen draait op het gratis dienstniveau: tot 3 opschoonacties in de cloud per voortschrijdende 30 dagen, genoeg voor een gewone besmetting. De meeste andere plugins melden de malware gratis en vragen geld voor de reparatie. Elke opschoonactie is terug te draaien vanuit een lokale versleutelde back-up.
-
Hoe schoon ik een gehackte WordPress website op als ik geen back-up heb?
-
Dat is het gewone geval, en daar is de opschoonengine voor. Waar een aanvaller code in een van je bestanden heeft geïnjecteerd, haalt Segurium de injectie eruit en laat de rest van het bestand met rust. Waar het bestand niets anders dan malware is, wordt het geleegd. Voor bestanden van de WordPress core, van plugins en van thema’s haalt de integriteitsscan de officiële inhoud uit de manifesten van de bron, dus je krijgt een schone kopie, ook al heb je zelf niets om terug te zetten.
-
My site is hacked, redirects visitors, or Google blacklisted it. What do I do?
-
Install Segurium on the hacked site, accept the service disclosure and run a malware scan. Segurium lists the infected files and cleans them on one click, keeping an encrypted backup of every original. Then run an integrity scan, so any core, plugin or theme file the attack rewrote is restored to its official content. Redirect, Japanese SEO spam and pharma hacks live in exactly those files. Once the malware is gone, request a review in Google Search Console or ask your host to lift the suspension; Segurium removes the reason for them, it does not file the requests.
-
Maakt Segurium mijn website trager?
-
Dat hoort niet te gebeuren. Scans draaien in opgeknipte achtergrondtaken, achter een slot zodat één ronde niet over zichzelf heen kan lopen. Realtime scannen bekijkt alleen nieuwe en gewijzigde bestanden. De plugin houdt geen grote tabellen in het geheugen en levert geen binaries mee.
-
Wat gebeurt er als Segurium een bestand markeert dat helemaal geen malware is?
-
Elke opschoonactie is terug te draaien. Originelen worden versleuteld (AES-256-GCM) en lokaal bewaard — tot 30 dagen, binnen de limieten voor aantal en grootte per bak — en je zet ze met één klik terug vanuit de back-up. Je kan ook een rapport van een vals positief versturen, rechtstreeks vanuit de lijst met bedreigingen; ons team gebruikt die om de classificatie te verbeteren.
-
Does Segurium quarantine infected files, and does it flag vulnerable plugins?
-
There is no separate quarantine folder. Segurium handles a suspicious file in place: it encrypts the original (AES-256-GCM), stores that copy locally, then strips the malicious code out, so the file is neutralised and you can put the original back for up to 30 days. The integrity check compares WordPress core, plugins and themes against upstream manifests and marks a component whose installed release carries a known vulnerability with a red Vulnerable badge and an Update button; tampered, delisted and abandoned components show up there too.
-
Is hCaptcha nodig voor brute-force bescherming?
-
Nee. Brute-force bescherming werkt meteen, met snelheidslimieten, een honeypot en blokkades. hCaptcha is optioneel — heb je al een hCaptcha website sleutel en geheime sleutel, dan kan je die op het loginformulier aanzetten als extra laag. Is hij uitgeschakeld (de standaard), dan worden er nooit hCaptcha-scripts of aanvragen geladen.
-
Welke versies van PHP en WordPress worden ondersteund?
-
PHP 7.4 of nieuwer en WordPress 6.2 of nieuwer. Wordt regelmatig getest op PHP 8.1 / 8.2 / 8.3 en WordPress 6.3 tot en met 7.0.
-
Wat gebeurt er als ik de plugin verwijder?
-
Plugin-opties, aangepaste tabellen en lokale scanback-ups worden verwijderd. De lokale versleutelde back-ups blijven vóór het verwijderen uit te pakken met een korte regel PHP (zie de documentatie over disaster recovery op segurium.com), als je kopieën wil bewaren.
-
Hoe rapporteer ik een beveiligingsprobleem in Segurium zelf?
-
Stuur een e-mail naar security@segurium.com in plaats van een openbaar onderwerp op het ondersteuningsforum te openen. Ons openbaarmakingsbeleid, de spelregels voor tests en de vermeldingen van onderzoekers staan op https://segurium.com/security/ — daar staat ook wat we wel en niet kunnen bieden in ruil. Houd de details privé tot er voor gebruikers een oplossing beschikbaar is.
Beoordelingen
Bijdragers & ontwikkelaars
“Segurium – Free Malware Removal & Auto Cleanup for Hacked Websites, Antivirus Scanner, Vulnerability Alerts” is open source software. De volgende personen hebben bijgedragen aan deze plugin.
Bijdragers“Segurium – Free Malware Removal & Auto Cleanup for Hacked Websites, Antivirus Scanner, Vulnerability Alerts” is vertaald in 20 talen. Dank voor de vertalers voor hun bijdragen.
Interesse in de ontwikkeling?
Bekijk de code, haal de SVN repository op, of abonneer je op het ontwikkellog via RSS.
Changelog
1.4.2 – 2026-09-15
- Minor UI improvements.
- Integrity tab flags components delisted from WordPress.org.
1.4.1 – 2026-09-13
- Faster response.
- Integrity scan no longer flags empty files as new.
Older entries are in changelog.txt, which ships with the plugin, and the full history is published at https://segurium.com/changelog/.
