We got hacked. Then we got angry. Then we built Malwipe.
In late 2024, my WordPress site — a portfolio I'd built and hosted myself, running standard-issue security plugins — got hacked. I cleaned it. A week later it happened again. I paid a "WordPress expert" ₹15,000 to clean it properly. Two weeks later, it happened a third time.
I was running Wordfence Premium. I was running fail2ban. I had two-factor auth. None of it mattered because the shell was in a mu-plugin nobody thought to check, and the reinfection path was a nulled Elementor add-on I'd inherited from a previous freelancer.
The problem wasn't a lack of security tools. It was that none of them explained anything. Wordfence would flag a file as "suspicious" and move on. Sucuri wanted $299/yr and DNS control. MalCare's dashboard hid every decision behind a black box.
I wanted a tool that would tell me: this file changed by one byte, here's the byte, here's what it does, here's who dropped it, here's your rollback. Nothing existed. So I built one.
Malwipe started as a weekend bash script that byte-compared WordPress core files against the signed manifest on WordPress.org. On the first run, it caught the shell in 4 seconds. The second version added an AI verdict on ambiguous files using Claude Haiku. The third added the upload firewall. Today it's a full WordPress plugin protecting 2,000+ sites, and it's bootstrapped, profitable from month three, and it has never taken a dollar of VC money.
I don't want Malwipe to be enterprise software. I want it to feel like the tool a friend built for you in a weekend — honest, direct, priced fairly, and with a founder who reads every WhatsApp message. That's what we optimize for.
— Machhindranath Kalan, Founder
Our mission
Make WordPress security something a stressed developer at 2 AM can actually use — and can afford.
Software engineer since 2014. Previously built infrastructure tooling at two Indian SaaS companies. Based in Pune. Writes PHP for pleasure. Owns three cats that have never contributed a single line of code.
Timeline
- 2024Malwipe founder's own WordPress site was hacked three times in six months. Wordfence caught none of it.
- Early 2025First prototype: a bash script that byte-compared WordPress core against WP.org checksums. It caught the shell instantly.
- Mid 2025Beta released to 50 developers in Pune and Bangalore. Zero support tickets in month one.
- Oct 2025AI verdict shipped using Claude Haiku. Detection accuracy jumps to 97.3%.
- Jan 20261.0 released. 2,000 sites protected within 6 months.
- Jul 2026Attacker IP forensics + emergency rescue access. Agency plan launches.
No VC. No board. No pivots into AI agents. Just a plugin, four pricing tiers, and a founder who ships weekly.
Made in India
Team in Pune, Maharashtra, India. Bills in INR + USD + EUR + GBP. GST-compliant invoicing via LemonSqueezy. WhatsApp for support. Because if you're an Indian developer, the least we can do is make paying us not feel like paying a US SaaS company.
Our values
Your site deserves better than 'thoughts and prayers'.
Install the free plugin. Cover your first site in under 3 minutes.