Webshells and backdoors
c99, r57 and WSO shells, eval-based droppers and remote code execution left behind after a breach.
signature + heuristicJayShield® Open-source malware scanner
When a site gets hacked, attackers leave webshells, backdoors and miners behind. JayShield finds them and seals them in a quarantine vault in seconds. It never deletes a file you did not approve.
npx @jayhackpro/jayshield scan .$ npx @jayhackpro/jayshield scan ./public_html JayShield v1.2.1 · scanning ./public_html 1,284 files read · 0 modified · 0.8s CRITICAL uploads/07/IMG_0412.jpg php_in_media HIGH wp-includes/css/.cache.php webshell.wso MEDIUM themes/site/footer.php obfuscation.b64 3 threats · exit 1 · nothing was modified $ jayshield quarantine ./public_html 3 files sealed in .jayshield-vault/ · site still serving
Detection
One engine, five classes of threat, tuned against real WordPress, Laravel and jQuery so it flags attacks and not your own code.
c99, r57 and WSO shells, eval-based droppers and remote code execution left behind after a breach.
signature + heuristicBase64 chains, packed JavaScript and hidden iframes, code that works hard not to be seen.
entropy + patternExecutable PHP disguised inside PNG and JPG files, a favorite hiding spot in upload folders.
content inspectionCoinHive-style cryptominers, session skimmers and card sniffers injected into front-end code.
pattern + domain listShips with a hash list of known malware including EICAR, and you can extend it with your own.
sha-256 hash listPlans
The scanner is open source and free forever. Pro adds the automation, alerting and scale that teams need to keep sites clean without watching a terminal.
$0forever
The full JayShield scanner and remover, for developers who live in the terminal.
Install freeAnnounced at launch
Everything in open source, running on a schedule, watching every site, alerting you the moment something changes.
Get notifiedSide by side
| Feature | Open Source | Pro |
|---|---|---|
| Scanner and remover engine | Included | Included |
| Every detection signature | Included | Included |
| Quarantine vault and restore | Included | Included |
| JSON output and CI exit codes | Included | Included |
| Zero dependencies | Included | Included |
| License | MIT | Commercial |
| Scheduled and real-time monitoring | Not included | Included |
| Instant signature updates | Not included | Included |
| Email and Slack alerts | Not included | Included |
| Multi-site dashboard | Not included | Included |
| One-click auto-remediation | Not included | Included |
| PDF audit reports | Not included | Included |
| REST API access | Not included | Included |
| Support | Community | Priority |
Quick start
No account, no install for a first look. Point it at a folder and read the report.
npx @jayhackpro/jayshield scan ./public_htmlnpx fetches the latest release from npm and runs it. Nothing is installed globally, nothing is modified.
Every finding is labeled by severity and rule, with the exact path. Add --json for your pipeline.
Happy with the report? quarantine moves the files into a vault. restore brings any of them back.
FAQ
Yes. The full scanner and remover is MIT licensed, published on GitHub and npm, and free forever. There are no feature nags and nothing is held back to push you toward Pro. If the terminal tool is all you need, it is all you need.
Automation and scale. Pro runs JayShield on a schedule and in real time across every site you manage, pushes signature updates instantly, alerts you by email and Slack the moment something changes, and gives you a dashboard, one-click remediation, PDF reports, a REST API and a commercial license. It is built for people responsible for more than one site.
The open-source scanner sends nothing, ever. It runs entirely on your machine. Pro syncs only the scan results you choose to connect to your dashboard, and never the contents of your files.
Pro is covered by a 14-day refund. If it is not right for you, email info@JayHackPro.com and the company will make it right.
Run the free scan now. Upgrade when you want it watching for you.