Find the malware hiding in your website.
When a site gets hacked, attackers leave webshells, backdoors and miners behind. JayShield finds them and seals them in a quarantine vault in seconds. It never deletes a file you did not approve.
██╗ █████╗ ██╗ ██╗██╗ ██╗ █████╗ ██████╗██╗ ██╗██████╗ ██████╗ ██████╗
██║██╔══██╗╚██╗ ██╔╝██║ ██║██╔══██╗██╔════╝██║ ██╔╝██╔══██╗██╔══██╗██╔═══██╗
██║███████║ ╚████╔╝ ███████║███████║██║ █████╔╝ ██████╔╝██████╔╝██║ ██║
██ ██║██╔══██║ ╚██╔╝ ██╔══██║██╔══██║██║ ██╔═██╗ ██╔═══╝ ██╔══██╗██║ ██║
╚█████╔╝██║ ██║ ██║ ██║ ██║██║ ██║╚██████╗██║ ██╗██║ ██║ ██║╚██████╔╝
╚════╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═╝ ╚═╝ ╚═════╝What it catches.
One engine, five classes of threat, tuned against real WordPress, Laravel and jQuery so it flags attacks and not your own code.
Webshells and backdoors
c99, r57 and WSO shells, eval-based droppers and remote code execution left behind after a breach.
signature + heuristicObfuscated payloads
Base64 chains, packed JavaScript and hidden iframes, code that works hard not to be seen.
entropy + patternImage polyglots
Executable PHP disguised inside PNG and JPG files, a favorite hiding spot in upload folders.
content inspectionMiners and skimmers
CoinHive-style cryptominers, session skimmers and card sniffers injected into front-end code.
signature + heuristicKnown malicious files
Ships with a hash list of known malware including EICAR, and you can extend it with your own.
sha-256 hash listTwo ways to run it.
The scanner is open source and free forever. Pro adds the automation, alerting and scale that teams need to keep sites clean without watching a terminal.
The full JayShield scanner and remover, for developers who live in the terminal.
Install free- Full scanner and remover engine
- Every detection signature
- Quarantine vault and byte-for-byte restore
- JSON output and CI exit codes
- Runs on any pipeline, zero dependencies
- MIT license, audit every line
- Community support
Everything in open source, running on a schedule, watching every site, alerting you the moment something changes.
JayShield Pro is in active development. Get notified- Everything in Open Source, plus
- Scheduled and real-time monitoring
- Instant signature updates
- Email and Slack alerts
- Multi-site dashboard
- One-click auto-remediation
- PDF audit reports
- REST API access
- Commercial license
- Priority support
Compare in full.
Start scanning in one command.
No account, no install for a first look. Point it at a folder and read the report.
$ npx @jayhackpro/jayshield ./public_html$ npm install -g @jayhackpro/jayshield$ jayshield ./public_html --quarantineQuestions.
Is the open-source version really free?
Yes. The full scanner and remover is MIT licensed, published on GitHub and npm, and free forever. There are no feature nags and nothing is held back to push you toward Pro. If the terminal tool is all you need, it is all you need.
What does Pro actually add?
Automation and scale. Pro runs JayShield on a schedule and in real time across every site you manage, pushes signature updates instantly, alerts you by email and Slack the moment something changes, and gives you a dashboard, one-click remediation, PDF reports, a REST API and a commercial license. It is built for people responsible for more than one site.
Does anything get sent back to JayHackPro?
The open-source scanner sends nothing, ever. It runs entirely on your machine. Pro syncs only the scan results you choose to connect to your dashboard, and never the contents of your files.
Can I try Pro and get a refund?
Pro is covered by a 14-day refund. If it is not right for you, email info@JayHackPro.com and the company will make it right.
Your site is worth an afternoon of certainty.
Run the free scan now. Upgrade when you want it watching for you.