PLUGIN SECURITY
Is Anti-Malware Security and Brute-Force Firewall safe?
This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.
What this plugin does
- Slug:
gotmls - Author: Eli
- 100000+ active installs
- 98/100 rating (783 reviews on wordpress.org)
- 7896300 all-time downloads
- On WordPress.org since 2012-03-27
anti-malwareBrute Forcefirewallscannersecurity
Maintenance status
- Last updated: 2026-06-29 5:58pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
9 known CVEs on file for Anti-Malware Security and Brute-Force Firewall. Reported between 2015 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57691 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.90 | — | Medium 5.8 | < 4.23.90 | 4.23.90 | 2026-07-09 | — |
| CVE-2021-47977 | Anti-Malware Security and Brute-Force Firewall [gotmls] <= 4.20.59 (unfixed) | — | High 7.5 | < 4.20.59 | 4.20.59 | 2026-05-16 | — |
| CVE-2026-39478 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.88 | Deserialization of Untrusted Data | High 8.8 | < 4.23.88 | 4.23.88 | 2026-04-20 | — |
| CVE-2025-11705 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.83 | Missing Authorization | Medium 6.5 | < 4.23.83 | 4.23.83 | 2025-10-28 | — |
| CVE-2024-22144 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.56 | Improper Control of Generation of Code ('Code Injection') | Critical 9.0 | < 4.23.56 | 4.23.56 | 2024-03-12 | — |
| CVE-2022-4327 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86 | — | Unknown | < 4.21.86 | 4.21.86 | 2022-12-21 | — |
| CVE-2022-0953 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.96 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.20.96 | 4.20.96 | 2022-03-28 | — |
| CVE-2022-2599 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.83 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.21.83 | 4.21.83 | 2022-02-08 | — |
+ 16 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2021-25101 | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.20.94 | 4.20.94 | 2022-01-24 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.16.18 | — | Unknown | < 4.16.18 | 4.16.18 | 2016-05-10 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.43 | — | Unknown | < 4.15.43 | 4.15.43 | 2016-04-23 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20 | — | Unknown | < 1.2.07.20 | 1.2.07.20 | 2015-05-26 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23 | — | Unknown | < 4.15.23 | 4.15.23 | 2015-05-26 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23 | — | Unknown | < 4.15.23 | 4.15.23 | 2015-05-25 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23 | — | Unknown | < 4.15.23 | 4.15.23 | 2015-05-25 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.20 | — | Unknown | < 4.15.20 | 4.15.20 | 2015-05-15 | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.44 | — | Unknown | < 4.15.44 | 4.15.44 | — | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23 | — | Unknown | < 4.15.23 | 4.15.23 | — | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.20 | — | Unknown | < 4.15.20 | 4.15.20 | — | — |
| — | Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20 | — | Unknown | < 1.2.07.20 | 1.2.07.20 | — | — |
| — | Get Off Malicious Scripts - Cross-Site Scripting (XSS) | — | Unknown | < 1.2.07.20 | 1.2.07.20 | — | — |
| — | Anti-Malware & Brute-Force Security by ELI < 4.15.20 - Multiple Reflected XSS | — | Unknown | < 4.15.20 | 4.15.20 | — | — |
| — | Anti-Malware & Brute-Force Security by ELI <= 4.15.22 - Stored XSS | — | Unknown | < 4.15.23 | 4.15.23 | — | — |
| — | Anti-Malware Security & Brute-Force Firewall < 4.15.44 - XSS & CSRF | — | Unknown | < 4.15.44 | 4.15.44 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — 1000000+ active installs — 96/100 (1477) — max PHP 8.4
- CloudSecure WP Security — 100000+ active installs — 100/100 (2) — max PHP 8.4
- WP Ghost (Hide My WP Ghost) – Security & Firewall — 100000+ active installs — 90/100 (372) — max PHP 8.4
- WP fail2ban – Advanced Security — 60000+ active installs — 84/100 (71)
- XO Security — 30000+ active installs — 100/100 (11)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.