A new plugin flaw is disclosed.Your site is patched first.

Attackers weaponize a new plugin flaw in about five hours; the official fix takes about 12 days — and a third never come. MalCare puts a tested firewall rule in front of the flaw within hours of disclosure, so exploit attempts die before they reach the plugin.

LIVE IN ~4 H · 19,000+ PATCHES SHIPPED · 3× THE NEAREST COMPETITOR
Trusted by 400,000+ sites · 120 countries
After disclosure

Mass exploitation starts about five hours after a flaw goes public.

The official fix takes about 12 days — everything in between, your site is attackable by script.

97% of the exposure window eliminated vs waiting for the official patch.
91%
of WordPress hacks

Start with a plugin or theme vulnerability

Source: MalCare incident analysis, rolling 12 months.

46%
of disclosed flaws

Have no official patch that day

A firewall rule is the protection available in the gap.

11,334
new disclosures last year

Up 42% year over year

Every disclosure starts another race to exploit exposed sites.

The mechanism

A virtual patch is a firewall rule aimed at one exploit.

We write a rule that recognizes attempts to trigger the disclosed flaw; the firewall returns 403 before the request reaches the plugin. Nothing on your site changes — the official update is still the permanent fix.

  • 2.1Blocked at the firewallThe exploit never executes — it dies as an HTTP request.
  • 2.2Your files untouchedNo code is injected into the plugin; updates apply normally.
  • 2.3Applied automaticallyLive within hours of disclosure, with nothing to configure.
How you find out you're exposed

In both cases the plugin file on your server is byte-for-byte unchanged — the rule lives at the firewall, never in your code.

Other virtual patches block one form of the attack. Ours block all of them.

An advisory shows one way to trigger a flaw. The vulnerable code shows the operation every version of the attack must reach — so one rule covers all of them.

5 OF 5

Attack forms blocked

Advisory rules stop about two; source-built rules cover the operation itself.

SPOOF-PROOF

Faked versions don't fool it

Rules hold when attackers fake plugin versions or manipulate headers.

OPEN-SOURCE VERIFIED

Run the tests yourself

Every patch ships with test scripts that show exactly what it blocks.

The pipeline

No one tests a patch harder. ~500 pentests before it ships.

Each one has to block the exploit, pass real traffic, and survive the bypasses attackers try next.

Step 1

Read the code

We download the plugin; the vendor's fix diff shows exactly where the danger lives.

Step 2

Trace every route

The advisory names one entry point. We follow the input to the dangerous operation and find the rest.

Step 3

Write one rule

Strong enough to catch every variant, precise enough to never block a customer.

Step 4

Test, then ship

Pentested, canaried on live sites, then rolled out to the network.

The benchmark

One plugin flaw, five attack forms, four defenses.

Each defense tested alone against the same requests. Every layer is good at its own job — only one is built for plugin exploits.

Attack formHost security
Kinsta · WP Engine · SiteGround
Generic WAF
Cloudflare · Sucuri · Imunify360
Advisory rules
Wordfence · Solid · Patchstack
MalCare
built from vulnerable code
The published exploit
Re-encoded payload
Method swapped
Alternate route
Flaw with no patch yet
Verdict0/51/52/55/5
◐ = partial or sometimes. Each tested alone; this measures one thing only — WordPress plugin exploits in the forms attackers actually send them.
The published exploit
HostGeneric WAFAdvisoryMalCare
Re-encoded payload
HostGeneric WAFAdvisoryMalCare
Method swapped
HostGeneric WAFAdvisoryMalCare
Alternate route
HostGeneric WAFAdvisoryMalCare
Flaw with no patch yet
HostGeneric WAFAdvisoryMalCare

Some attacks look exactly like real traffic. When we can't block one safely, we tell you.

No sloppy rule with a green check on it. You get a partial-protection flag and the update path instead.

  • A tested barrier in front of the known exploit
  • Safe time to update on your terms
  • Runs off your server — no slowdown
  • Survives the evasions attackers try next
The product

Patching runs automatically, end to end.

You don't write rules or tune settings. You get the alert, the Patched stamp, and a score that says when the official update is safe to run.

  • 7.1Detected within hoursNew flaws in your plugins, with severity.
  • 7.2Patched while you readThe Patched stamp is often the first you hear of it.
  • 7.3Update on your scheduleA risk score shows when the official update is safe to run.

A virtual patch covers a known flaw from disclosure to update. Three more layers cover the rest of the timeline.

INCLUDED

Atomic Security

Hardens your site's structure before any flaw is disclosed.

INCLUDED

Real-time firewall

A threat on any of 400,000+ sites becomes a rule on yours, instantly.

INCLUDED

Malware scanner

Daily and off-server — catches anything that got in first.

In their words. Patched before it mattered.

Rated 5 out of 5
I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress Expert
Rated 5 out of 5
Always one step ahead! Before any clients or customers have a weird experience, I get a vulnerability notification which is easily fixed with one click. Really impressed with their scanner precision!
David McCanWebTNG
Rated 5 out of 5
I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverConciergeWP · Founder

Running client sites? One disclosure can hit fifty of them.

Every site in one dashboard, patched from the same screen. At 10+ sites, WPRemote adds sandbox updates, client reports, and bulk pricing.

Protect my sites Explore WPRemote
ONE DASHBOARD · ALL SITES · <5 MIN SETUP EACH

Common questions, answered.

Under 5 minutes — install, connect, done. Patching starts after the first sync.
No. It runs alongside Cloudflare, host firewalls, and other plugins as a complementary WordPress-specific layer — not a replacement for your broader perimeter.
Every patch is tested against real traffic — checkout, forms, logins, uploads, admin saves, and API calls. If legitimate behavior breaks, the patch goes back. A security rule should never become an outage.
No. Analysis runs off-server on our infrastructure, and matching requests are handled at the firewall. Your site performance is unaffected.
Yes. Most customers run MalCare alongside their existing tools specifically for the source-built patching layer those tools don't provide.
We tell you. We flag it as partial protection and recommend the update path — no fake green checkmarks.
Any host. If you migrate, your protection migrates with you.
Yes. Virtual patching buys safe time; the update is the permanent fix. We'll remind you when it's ready.

The next disclosure is coming. You'll already be patched.

Live in hours. Tested against real traffic. Honest when protection is partial.

NO CREDIT CARD / <5-MIN SETUP / ANY HOST