Sep 24, 2026 · WPGuard Team

Quarantine vs. Delete: Why WPGuard Never Deletes a Suspicious Plugin

Quarantine vs. Delete: Why WPGuard Never Deletes a Suspicious Plugin

When a security tool flags a plugin as malicious, the instinct is to remove it immediately and completely. That instinct is understandable, and it is also the wrong default for any automated or semi-automated remediation system, for two specific reasons.

Reason 1: false positives happen, and deletion is unrecoverable

No detection system, automated or human, has a zero false-positive rate. A legitimate plugin with an unusual file structure, a custom in-house plugin that happens to trip a heuristic, or a plugin update that temporarily doesn’t match an expected baseline can all trigger a flag that turns out to be wrong. If the remediation action is permanent deletion, a false positive means real, sometimes business-critical functionality is gone — and depending on the plugin, may not be trivially reinstallable if it held custom configuration or licensing state.

Reason 2: deleted files can’t be investigated

When a plugin genuinely is malicious, the file itself is the evidence. What did it actually do? Did it create a backdoor admin account, exfiltrate data, or modify other files? Answering those questions after the fact requires the actual malicious code to still exist somewhere to be examined — not just a log entry saying "we deleted something." Deletion destroys the forensic trail at exactly the moment it becomes most valuable.

What quarantine does instead

Quarantine moves the flagged plugin folder, intact, into a separate directory that WordPress can no longer load code from — typically enforced with a deny-all access rule at that folder, so even if WordPress were somehow pointed at it, nothing would execute. The plugin stops running immediately, achieving the same practical security outcome as deletion, but the files themselves are preserved.

Two outcomes, both better than deletion

If the flag turns out to be a false positive, restoring from quarantine is a single reversible action — the exact files come back, nothing was lost. If the flag was correct, the quarantined files remain available for a closer look: confirming what the plugin actually did, checking whether it modified anything else, and building a better signature to catch the same threat faster next time.

The broader principle

Any automated security action that runs without a human confirming each individual case should default to the most reversible option that still achieves the security goal. Quarantine achieves the same immediate protection as deletion — the malicious code stops executing — while keeping the door open to undo the action if it turns out to be wrong.

This is a direct design decision in WPGuard's own signed-command system — every remediation action is reversible by default. Read the full model, including how commands are signed and verified, on the Security page.

See what WPGuard would catch on your site.

Connect a site in a few minutes and get your first inventory scan back immediately.

Try free →