Anti-Malware Security and Brute-Force Firewall (also known as GOTMLS) is a dedicated malware scanner and firewall plugin that has been protecting WordPress sites since 2012. Unlike all-in-one security suites that try to cover every aspect of site protection, this plugin focuses on two specific tasks: detecting and removing malicious code from your files and database, and blocking brute-force login attempts. It scans your site against an updated database of known threat definitions, identifying backdoor scripts, database injections, and suspicious PHP code patterns that other security tools might miss. The plugin has close to 8 million downloads and an excellent 98 out of 100 rating on WordPress.org, making it one of the highest-rated security plugins available. Its narrow focus means it works well alongside broader security solutions like Wordfence Premium, which handles firewall and traffic monitoring while Anti-Malware Security covers deep file scanning.
The plugin operates with a two-tier scanning system. The free version scans for potential threats and flags suspicious code patterns, leaving the final judgment to you. The registered version downloads definition updates from GOTMLS.NET and can automatically remove known threats. For brute-force protection, it patches the wp-login page and XML-RPC endpoint without modifying core WordPress files.
Competitive Features
- Known threat detection — identifies and automatically removes malware based on regularly updated definition files from GOTMLS.NET
- Potential threat analysis — flags suspicious PHP code patterns like eval(), base64_decode(), and system() calls for manual review
- Brute-force login protection — patches wp-login.php and XML-RPC to block automated login attempts and DDoS attacks
- Database scan — scans wp_posts, wp_options, and wp_comments for injected malicious content and SQL-based backdoors
- Core file integrity check — compares your WordPress core files against originals to detect unauthorized modifications
- Timthumb vulnerability patching — detects and upgrades vulnerable versions of timthumb scripts
- Revolution Slider exploit blocking — automatically blocks attempts to exploit known vulnerabilities in Revolution Slider
Key Features
- Complete scan engine — recursively scans all WordPress files for known malware signatures, suspicious patterns, and hidden backdoor scripts
- Definition update system — downloads new threat definitions from GOTMLS.NET to stay current with emerging malware variants
- Quick scan mode — focused scan of core WordPress files and recently modified files for faster daily checks
- Whitelist management — exclude trusted files from scans to prevent false positives on legitimate custom code
- PHP session-based login protection — blocks brute-force attacks by requiring JavaScript and session validation before login form submission
- Hidden file detection — identifies dot-files, encrypted PHP shells, and other concealed malicious scripts
- Scan result logging — stores detailed scan history with the ability to review, compare, and restore flagged files
Comparison with Competitors
Anti-Malware Security Pro vs Wordfence Premium
| Aspect | Anti-Malware Security Pro | Wordfence Premium |
|---|---|---|
| Primary focus | Malware scanning + login protection | Full security suite |
| Threat definitions | GOTMLS.NET database | Wordfence Threat Defense Feed |
| Automatic removal | Yes (registered) | Yes |
| Live traffic monitoring | No | Yes |
| Web application firewall | No | Yes (WAF rules) |
| Country blocking | No | Yes |
| Resource usage | Low (scan on demand) | Medium (constant monitoring) |
Bottom line: Wordfence Premium is the more comprehensive solution with live traffic monitoring, WAF rules, and country blocking. Anti-Malware Security Pro is a leaner alternative that excels at deep file scanning and works well alongside other security tools without conflicts.
Anti-Malware Security Pro vs Solid Security
| Aspect | Anti-Malware Security Pro | Solid Security |
|---|---|---|
| Malware scanning | Yes (definition-based) | Yes (via add-on) |
| Brute-force protection | Yes (session-based) | Yes (lockout rules) |
| File integrity | Yes | Yes |
| Two-factor auth | No | Yes |
| Version management | No | Yes |
| Database cleanup | Yes (malware in DB) | No |
| Setup complexity | Minimal | Moderate (many settings) |
Bottom line: Solid Security offers broader protection with two-factor authentication and version management. Anti-Malware Security Pro is simpler to set up and has a better built-in malware scanner with actual definition-based detection rather than relying on add-ons.
Anti-Malware Security Pro vs iThemes Security Pro
| Aspect | Anti-Malware Security Pro | iThemes Security Pro |
|---|---|---|
| Malware scanning | Yes (definition updates) | Via add-on |
| Brute-force protection | Yes (session + JS check) | Yes (lockout + recaptcha) |
| Google reCAPTCHA | No | Yes |
| Scheduled scanning | Yes | Via add-on |
| Password enforcement | No | Yes |
| Away mode | No | Yes |
| Server compatibility | Broad (PHP 5.6+) | Modern hosts only |
Bottom line: iThemes Security Pro offers the most granular security controls with features like away mode and schedule-based site locking. Anti-Malware Security Pro is the better choice for older hosting environments or for users who want a focused malware scanner that doesn’t require a complex setup.
Recommended Stack: Anti-Malware Security Pro handles malware scanning and login protection. For complete disaster recovery, pair it with a dedicated backup solution like UpdraftPlus Premium to schedule automatic backups and restore your site quickly if malware damage occurs.
Official Changelog (3 Last Versions)
Data sourced from WordPress.org plugin repository.
Version 4.23.90
Release Date: June 29, 2026
- Incremented version number to force update of index file that was missing changes from the last update
Version 4.23.89
Release Date: June 15, 2026
- Fixed XSS vulnerability to prevent WP Administrators from inserting script into the REQUEST_URI
- Checked code for compatibility with WordPress 7.0 and ClassicPress 2.7
Version 4.23.88
Release Date: June 1, 2026
- Fixed PHP Object Injection vulnerability with database scan
Frequently Asked Questions
Does Anti-Malware Security work alongside other security plugins?
Yes. The plugin is designed to complement other security solutions rather than replace them. Since it focuses specifically on malware scanning and login protection, it works well alongside broader security suites like Wordfence or Solid Security. Just avoid overlapping brute-force protection features to prevent conflicts.
How does the malware scanning engine work?
The scanner iterates through all files on your WordPress installation and compares them against a database of known threat definitions downloaded from GOTMLS.NET. It also performs heuristic analysis to detect suspicious code patterns — eval() calls with encoded strings, base64_decode() with long payloads, and hidden PHP shells in image upload directories.
What is the difference between free and registered versions?
The free version scans for potential threats and flags suspicious files for manual review. After registering on GOTMLS.NET, you gain access to definition updates that identify known threats with automatic removal, core file integrity checking, and brute-force login protection patches for wp-login and XML-RPC.
How does the brute-force protection work?
The plugin patches your login page to require JavaScript execution and PHP session validation before the login form becomes available. This blocks automated bots and scripts that try to submit login credentials directly without going through the browser’s JavaScript rendering pipeline.
Is the scanner resource-intensive?
No. The scan runs on demand or on a schedule, not on every page load. It processes files sequentially and reports progress as it goes. For large sites with thousands of files, the initial scan may take a while, but subsequent scans are faster. The plugin is designed to work on shared hosting without exhausting PHP memory limits.






Leave a Reply