WordPress security that
scans your database.
A lightweight agent for hosting providers that finds rogue admins, wp_options injections, and SEO spam that Imunify360 and Wordfence can't see — because they don't scan the database. CleanShift does.
Born from a real CVE-2024-28000 incident — built to find what file scanners miss.
Works with
cPanel / WHM
Root or user-level
Plesk
Admin extension
WordPress
mu-plugin guard — no root needed
Any Linux VPS
CentOS · Alma · Ubuntu · CloudLinux
The scanning agent requires root SSH access. The WordPress Guard plugin works on any hosting — no root needed.
What makes us different
Security that sees what others can't.
Database-Level Scanning
The industry scans files. We scan the database. Rogue admin accounts, wp_options injection payloads, SEO spam markers, persistence backdoors — we find what Imunify360 and Wordfence physically cannot detect.
Agent footprint.
Competitor average: 80MB.
Real-Time Guard
A zero-config PHP mu-plugin blocks REST API abuse, unauthorized admin creation, and cron hijacking before anything hits disk.
Cross-Site Correlation
If one site is compromised, CleanShift instantly checks every other site on the server for the same IOCs. No manual work.
CVE Playbooks
Automated remediation procedures specific to each vulnerability. Not generic quarantine — surgical cleanup with 1-click rollback.
Deploy to 1,000 servers in minutes.
Your DevOps team will love the CLI. Your CFO will love the risk mitigation. And you'll finally sleep through the night.
New in v1.4
Detection capabilities that learn and evolve.
SEO Spam Detection
Detects gambling, pharma, and casino keyword injection in your WordPress database. Catches author burst attacks (50+ spam posts per day) and hidden redirect chains.
Dropper & Artifact Detection
Finds zero-byte PHP dropper stubs, compressed backdoor payloads (.gz/.zip in web dirs), and misleading extensions like .php.bak or .jpg.php.
Verification Scanning
Post-remediation mode re-scans only previously-flagged locations. Confirms cleanup in seconds, not minutes. 10x faster than a full scan.
Community Intelligence
Crowd-sourced threat hashes from every CleanShift agent feed into your scanner. New malware patterns detected anywhere protect you everywhere.
IoC Contribution
Every scan automatically contributes discovered indicators back to the collective intelligence — making the entire network smarter.
Three steps
From vulnerable to protected in under 60 seconds.
Install the Agent
A single authenticated command deploys the 600KB agent. No dependencies to wrangle, no Java, no heavy daemons.
Deep Scan Everything
CleanShift scans files AND the database — finding rogue admins, wp_options injections, and persistence markers that legacy scanners miss completely.
Auto-Remediate & Harden
CVE-specific playbooks surgically clean threats and harden configurations. Real-time guards activate to prevent re-infection. You get Telegram alerts.
How we compare
The competition doesn't scan the database.
| Feature | CleanShift | Imunify360 | Wordfence |
|---|---|---|---|
| Database scanning | |||
| Auto-remediation with rollback | |||
| Cross-site correlation | |||
| CVE-specific playbooks | |||
| SEO spam detection | |||
| Email security scanner | |||
| Plugin auto-updater | |||
| Server-level view | |||
| WordPress depth | Deep | Shallow | Deep |
| Resource footprint | 600KB | Heavy | Heavy |
| Real-time guards | |||
| Starting price | ₹0 | $12/mo | $149/yr |
What's Inside
More than a scanner.
A full security platform.
Every paid plan includes the full feature set — no add-ons, no feature gating per module.
File + Database Scanner
Scans both the filesystem and the WordPress database — catching rogue admins, wp_options injections, SEO spam, and persistence backdoors that file-only scanners miss.
Auto-Remediation with Rollback
One-click fixes with timestamped backups. If anything goes wrong, CleanShift rolls back automatically. 4 minutes vs 3 hours of manual cleanup.
Email Security Scanner
SPF, DKIM, and DMARC validation. Blacklist checks across Spamhaus, Barracuda, and SpamCop. Know when your server IP is listed before your clients complain.
Plugin Auto-Updater
Safe update pipeline: backup → update → verify site loads → rollback on failure. Update all outdated plugins across your fleet in one operation.
Fleet Dashboard
One screen for every server. Cross-server threat map, health grades, and bulk scan-all. Built for agencies and hosting providers managing dozens of servers.
Scheduled Scans
Set cron-based schedules per server. Daily, weekly, or custom. Security score trending over time so you can see if you're improving.
AI Threat Analysis
Confidence scoring on every detected threat. Reduces false positives and helps prioritize what to fix first. Built on your crowd-sourced threat intelligence.
Custom Playbooks
Build remediation playbooks matched to specific CVEs. Run them on-demand or trigger automatically when a matching threat is detected.
Joomla & Drupal Support
The scanner adapts to the CMS it finds. WordPress gets the deepest analysis, but Joomla and Drupal installs are also scanned and reported.
SSL Monitor
Tracks certificate expiry across all sites on your server. Get alerted before a certificate lapses and takes a site down.
Server Health Dashboard
PHP version, disk usage, MySQL health, and cPanel/Plesk panel status — all in one view. Spot problems before they become incidents.
Migration Orchestrator
Pre-migration security clearance scan. Flags junk files, active threats, and missing .htaccess before you move an account. Post-migration verification built in.
Pricing
Pay per site. No server tax.
One price per WordPress site — not per server. A server with 50 sites costs what 50 sites cost. Volume discounts kick in automatically as you grow.
Free
1 site. Detect everything. Fix when ready.
- Full scan (file + database)
- Vulnerability scanning
- 30-day scan history
- Telegram alerts
- mu-plugin guard
Starter
1–10 sites. Freelancers & solo devs.
- Everything in Free
- Auto-remediation with rollback
- AI threat analysis
- CVE playbooks
- Scheduled scans
- Fleet dashboard
- Plugin auto-updater
Agency
11–50 sites. For agencies & consultants.
- Everything in Starter
- 30% volume discount
- Multi-client fleet view
- White-label reports
- Email security scanner
- Joomla & Drupal support
Reseller
51–200 sites. Hosting resellers & MSPs.
↓ ₹29/site for 200+ sites (Provider).
- Everything in Agency
- 50% volume discount
- WHMCS billing integration
- Migration orchestrator
- Custom playbooks
- Dedicated onboarding
The maths: 30 sites × ₹69 = ₹2,070/month. One hacked site costs ₹5,000–50,000 in lost revenue & cleanup. CleanShift pays for itself on the first prevention.
FAQ
Common questions
Is CleanShift only for WordPress?
CleanShift is designed primarily for WordPress on shared hosting (cPanel/WHM, Plesk). The agent scans any WordPress installation it finds on the server. Non-WordPress CMS support (Joomla, Drupal) is included in paid plans.
Does CleanShift remove malware or just detect it?
The free tier detects and reports threats with step-by-step manual fix instructions. Paid plans add one-click auto-remediation with timestamped backups and rollback safety.
Why does the agent need root access?
Server-level scanning requires access to all user home directories and database credentials. The agent only reads during scanning — write operations happen only during explicit remediation. All source code is open source and auditable.
Will it slow down my server?
The agent uses ~1.2MB of RAM and scans run as low-priority background processes. No inbound ports are opened. There is zero impact on website load times.
How does per-site pricing work?
You pay per WordPress site, not per server. One server with 50 sites counts as 50 sites. Volume brackets apply automatically — 11+ sites drop to ₹69/site, 51+ to ₹49/site, 200+ to ₹29/site.
What happens when a threat is detected?
You receive a detailed report showing exactly what was found, where, and how to fix it. On paid plans, CleanShift can auto-remediate with timestamped backups and full rollback capability.
Built by people who manage real servers.
CleanShift is built by Kamyab Infotech — a team that runs hosting infrastructure, cleans malware from production servers, and manages WordPress at scale. This tool exists because we needed it ourselves.
Request Early Access
Not ready to deploy yet? Join the waitlist to get exclusive updates and priority access to new enterprise features.