Malwipe
About Malwipe

We got hacked. Then we got angry. Then we built Malwipe.

In late 2024, my WordPress site — a portfolio I'd built and hosted myself, running standard-issue security plugins — got hacked. I cleaned it. A week later it happened again. I paid a "WordPress expert" ₹15,000 to clean it properly. Two weeks later, it happened a third time.

I was running Wordfence Premium. I was running fail2ban. I had two-factor auth. None of it mattered because the shell was in a mu-plugin nobody thought to check, and the reinfection path was a nulled Elementor add-on I'd inherited from a previous freelancer.

The problem wasn't a lack of security tools. It was that none of them explained anything. Wordfence would flag a file as "suspicious" and move on. Sucuri wanted $299/yr and DNS control. MalCare's dashboard hid every decision behind a black box.

I wanted a tool that would tell me: this file changed by one byte, here's the byte, here's what it does, here's who dropped it, here's your rollback. Nothing existed. So I built one.

Malwipe started as a weekend bash script that byte-compared WordPress core files against the signed manifest on WordPress.org. On the first run, it caught the shell in 4 seconds. The second version added an AI verdict on ambiguous files using Claude Haiku. The third added the upload firewall. Today it's a full WordPress plugin protecting 2,000+ sites, and it's bootstrapped, profitable from month three, and it has never taken a dollar of VC money.

I don't want Malwipe to be enterprise software. I want it to feel like the tool a friend built for you in a weekend — honest, direct, priced fairly, and with a founder who reads every WhatsApp message. That's what we optimize for.

— Machhindranath Kalan, Founder

Our mission

Make WordPress security something a stressed developer at 2 AM can actually use — and can afford.

Machhindranath Kalan
Founder
Machhindranath Kalan

Software engineer since 2014. Previously built infrastructure tooling at two Indian SaaS companies. Based in Pune. Writes PHP for pleasure. Owns three cats that have never contributed a single line of code.

Timeline

  1. 2024
    Malwipe founder's own WordPress site was hacked three times in six months. Wordfence caught none of it.
  2. Early 2025
    First prototype: a bash script that byte-compared WordPress core against WP.org checksums. It caught the shell instantly.
  3. Mid 2025
    Beta released to 50 developers in Pune and Bangalore. Zero support tickets in month one.
  4. Oct 2025
    AI verdict shipped using Claude Haiku. Detection accuracy jumps to 97.3%.
  5. Jan 2026
    1.0 released. 2,000 sites protected within 6 months.
  6. Jul 2026
    Attacker IP forensics + emergency rescue access. Agency plan launches.
Bootstrapped. Profitable from month 3.

No VC. No board. No pivots into AI agents. Just a plugin, four pricing tiers, and a founder who ships weekly.

Made in India

Team in Pune, Maharashtra, India. Bills in INR + USD + EUR + GBP. GST-compliant invoicing via LemonSqueezy. WhatsApp for support. Because if you're an Indian developer, the least we can do is make paying us not feel like paying a US SaaS company.

Our values

Honest pricing
One page, four tiers, INR/USD/EUR/GBP — the price you see is the price you pay.
Real detection
Every finding explains itself. No black boxes, no 'suspicious file, contact support'.
Zero bloat
One plugin, one setup screen. No affiliate upsells, no dark-mode-toggle-as-upgrade.
Fast support
4h response on Pro, WhatsApp for India. Written by humans who own the codebase.
Open changelog
Every ship logged publicly. RSS feed for the paranoid. Full transparency on what changed.

Your site deserves better than 'thoughts and prayers'.

Install the free plugin. Cover your first site in under 3 minutes.