[ad_1]
Hi,
A wordpress store that im managing has a plugin named
“Do not remove me”
This plugin enables LoginWall Protection for WordPress logins.
Version 1.1.0 | By Ananomyous | Visit plugin site <- plugin site directs to an ip [http://127.0.0.1/](http://127.0.0.1/)
If i deactivate the plugin i get a bunch of errors.
Is this a legit plugin?
Currently the site was taken offline due to being used for phishing by some “Hermes” post company and that was the only suspicious plugin that i found.

I would for sure name a plugin like that if I am doing custom development for my site. And at the same time I doubt a hacker will use them.
But without looking at the code there is no way of knowing.
Mate you can do a ‘hard’ deactivation of a plugin by renaming the plugin folder via FTP. Then delete it.
I highly recommend you get a full backup of your website and database before you do