Content Guard Pro – Database Malware Scanner & SEO Spam Detector

content-guard-pro · by contentguardpro · wordpress.org ↗ · SVN ↗
Active installs
40
Current version
1.4.0
Added
2026-02-01
Last updated
2026-05-21 (2mo ago)
First seen by beacon
3mo ago
Total downloads
1,010

Statistics

2026-05-19 → 2026-07-02 · 45 days
Downloads today
2
7-day total 15
Week over week
▲ +0%
vs prior 7 days
30-day trend
flat
▼ -51% MoM
Abandonment
●○○○○
install base on one version
Downloads/day Linear trend
302315802026-052026-052026-062026-062026-062026-062026-06
302315802026-052026-052026-062026-062026-062026-062026-06
1085302026-062026-062026-062026-062026-062026-06

Active versions

1.4
1.4 · 100.0%

Ratings

5★
1
4★
0
3★
0
2★
0
1★
0

Support: 0/0 resolved

Alerts (0)

No open alerts.

Show 1 resolved alert
Critical code_pattern Resolved · fp_security_scanner_signature_db 2026-07-02 12:40:16 (23d ago)
Slugcontent-guard-pro
Patternobfuscated_payload_in_data_file
Kindbuiltin
Version1.4.0
Hit count1
First hit
File
includes/signatures.pack
Line
0
Snippet
(PHP payload in data file — decoded via base64+gzuncompress)
Explanationa non-PHP data file (`.dat`/`.gzs`/`.bin`/etc.) contains PHP source — either stored raw under a misleading extension or sealed behind base64/gzip — and/or matches a catalog IOC once decoded. This is the payload-hiding evasion the siteguarding burner fleet used to defeat PHP-only IOC greps: `wp-plugin-management`/`plugin.dat` (gzip+base64 → siteguarding_tools.php v1.7), `speedup-optimization`/`classes/tools.gzs` (base64 → v2.1), `bytedefense`/`core/scan_sigs_db.dat` (raw PHP disguised as a "scan signatures database", `include`d by a web-reachable `scan.php`). The scanner now decodes these blobs and matches PHP markers + content IOCs inside them.
View raw JSON
{
    "slug": "content-guard-pro",
    "pattern": "obfuscated_payload_in_data_file",
    "kind": "builtin",
    "version": "1.4.0",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/signatures.pack",
        "line": 0,
        "snippet": "(PHP payload in data file \u2014 decoded via base64+gzuncompress)"
    },
    "explanation": "a non-PHP data file (`.dat`/`.gzs`/`.bin`/etc.) contains PHP source \u2014 either stored raw under a misleading extension or sealed behind base64/gzip \u2014 and/or matches a catalog IOC once decoded. This is the payload-hiding evasion the siteguarding burner fleet used to defeat PHP-only IOC greps: `wp-plugin-management`/`plugin.dat` (gzip+base64 \u2192 siteguarding_tools.php v1.7), `speedup-optimization`/`classes/tools.gzs` (base64 \u2192 v2.1), `bytedefense`/`core/scan_sigs_db.dat` (raw PHP disguised as a \"scan signatures database\", `include`d by a web-reachable `scan.php`). The scanner now decodes these blobs and matches PHP markers + content IOCs inside them."
}

SVN committers (2)

Accounts with actual commit access to content-guard-pro on plugins.svn.wordpress.org, reconstructed from svn log. This is the list that matters for ownership changes — not the readme contributors.

Committer Member since Commits First commit Latest commit
contentguardpro Young account 2026-01-09 21 2026-02-01 · r3451611 2026-05-21 · r3542803
plugin-master 2007-03-09 1 2026-01-23 · r3445697 2026-01-23 · r3445697

Readme contributors (1)

Names the plugin's readme declares as contributors. A soft signal — anyone can be listed. The SVN access column is the ground-truth cross-reference: does this contributor actually commit code?

Contributor Member since SVN access Status
contentguardpro 2026-01-09 21 commits Active

Versions (10 most recent)

Release dates not yet populated — run wp beacon crawl-svn --slug=content-guard-pro to fill them from svn ls /tags/.

Version Released Download
1.4.0 zip
1.3.1 zip
1.0.3 zip
1.0.4 zip
1.0.5 zip
1.0.6 zip
1.1.0 zip
1.1.1 zip
1.2.0 zip
1.3.0 zip