Nova Scan is a free WordPress malware scanner that catches obfuscated, polymorphic, and novel malware that Wordfence, Sucuri, and Patchstack miss. Four detection engines covering PHP, JavaScript, database, and firewall layers. Install in two minutes. Free forever. No credit card.
The N-Dimensional Engine
Not pattern matching. Not signature databases. Real detection intelligence built from real-world WordPress malware.
Four dedicated NDE engines - PHP, JS, DB, and WAF - each built from real-world attack data. Designed to catch zero-day threats across every attack surface that signature databases typically miss.
4 NDE Engines · N-Dimensional Analysis
Built for hostile environments
Shared hosting isn't friendly to security tools. Nova Scan was designed from the ground up to work within those constraints.
- NDE Detection Engine - Four dedicated NDE models - PHP, JS, DB, and WAF - each built from real-world attack data. Designed to catch zero-day threats across every attack surface that signature databases typically miss.
- Two-Mode Firewall - A dual-layer WAF that loads before WordPress even boots. Blocks SQL injection, XSS, and shell attacks in real time - before they reach your site.
- 341K+ Verified Samples - NDE built from 341,000+ verified samples across PHP, JS, SQL, and WAF payloads - backdoors, cryptominers, card skimmers, SEO spam, obfuscated payloads, and zero-day variants.
- Deep Database Scanner - Goes beyond files - scans your entire database for injected scripts, rogue admin accounts, weak passwords, and hidden cron jobs.
- Repository Integrity - Compares every file against official WordPress.org originals. Instantly flags anything modified, added, or deleted. Premium plugin support included.
- Brute-Force & Geo-Block - Stops login attacks with smart rate limiting. Block entire countries or whitelist trusted IPs. Free geolocation built in.
- Auto-Clean & Rollback - One-click repair replaces infected files with clean originals. If anything goes wrong, automatic rollback restores your site instantly.
- Canary Tripwire Sentinels - Hidden honeypot files planted across your site. If an attacker touches anything, you get an instant email alert.
- Forensic Analysis - Deep-dive into any flagged file - entropy analysis, string extraction, and behavioural scoring reveal exactly what the threat is doing and why it was flagged.
- Community Feed Network - Opt-in threat intelligence sharing across Nova Scan installations. When one site detects a new threat, every site in the network learns instantly. Privacy-first - no site data ever leaves your server.
- Signed Model Integrity - Every NDE predictor is cryptographically signed and verified. At runtime, Nova Scan checks the manifest signature and every file hash before loading any model. Tampered models are disabled instantly with admin alerts.
- Canary Integrity Checks - Beyond file hashes - canary tests run known benign and malicious vectors through each model at load time. Detects behavioural tampering even if hashes somehow pass. If a model doesn't behave as expected, it's killed on the spot.
- Private Honeypot Network - Decoy WordPress installs attract real attackers. Early warning for zero-day exploits feeds threat data directly into NDE detection - Nova Scan sees threats before they reach your site.
What Nova Scan catches
Signatures from known 2025–2026 campaigns. Not just CVEs - behavioural patterns too.
- Verified Hashes
- Recall
- False Positives
- Threats Detected
- Verified Samples
- NDE Engines
- Features
Three steps to secure
Upload & Activate Install Nova Scan like any WordPress plugin. Create a free account, activate your licence, and you're ready.
Run a Scan Hit the scan button. Nova Scan crawls your entire installation in safe batch chunks that respect hosting limits.
Review & Fix Get a full severity-coded report. Quarantine, delete, or reinstall compromised files right from the dashboard.
Your Frontend. Protected. Even On A Different Domain.
Wordfence, Sucuri, MalCare - they all stop at your server. Nova Shield runs in your visitors' browsers and reports back the moment anything is injected into your frontend. No other scanner does this.
Threats don't sleep
Real-time intelligence from 5 threat feeds across 14 global hotspots. Hover to explore.
Start scanning in minutes
Upload, activate, and run your first scan. Free forever.
© Nova Heaven. All rights reserved.