Defender Security – Malware Scanner, Login Security & Firewall

July 24, 2024

Defender Security – Malware Scanner, Login Security & Firewall Plugin

WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.

Defender adds the best in WordPress plugin security to your website with just a few clicks, including malware scanner, firewall, and login security features. Stop brute force login attacks, SQL injections, cross-site scripting XSS, and other WordPress security vulnerabilities and hacks with Defender’s malware scanner, providing antivirus scans, IP blocking, firewall, activity log, security log, and two-factor authentication (2FA) login security.

No more complex security settings, Defender’s malware scanner, firewall, and login security features add all the hardening and security you need.

Enjoy complete site protection from malware, vulnerabilities, and bot attacks from the start with Defender Pro.

Level up security immediately with exclusive Pro features like scheduled malware scanning, Safe Repair for suspicious files, and known WordPress vulnerability detection. Learn more about Pro.

Security Recommendations

Defender’s one-click security hardening recommendations instantly adds layers of protection and security to your site.

Enhance Security and Block Hackers At Every Level:

  • Malware scanner – scan WordPress core files for modifications and unexpected changes which may be caused by malware. Scan for malware and tighten up the security of your files
  • WordPress Security Firewall – block or allowlist IPs, implement IP blocking, and Geo IP blocking, user agent banning and protect against brute force attacks
  • Two-factor authentication (2FA) – Easily set up better security with 2FA to prevent most login attacks such as brute force, App verification, backup codes, lost device email, WooCommerce 2FA, and Web Authentication
  • Login masking – change the location of WordPress’s default login area to improve login security
  • Login lockout – failed login attempts lockout for even more security assurance
  • User Agent Banning – Fortify security by blocking bad bots and user agents from accessing your site
  • Security Headers – Add an extra layer of defense security and protect against common attacks like: XSS, code injection, and more
  • 404 Detection security – automated block of bot IPs
  • Security Configs – Create your ideal Defender security plugin settings and export / import saved configs to any other site
  • Geolocation IP lockout security – block users based on location and country (IP blocking)
  • Disable trackbacks and pingbacks – disable these notifications to enhance spam protection and site security.
  • Core and server update security recommendations – stay on top of your system security
  • Antivirus scan – scan for active security threats, viruses, and other malware
  • Disable file editor – if they get in, they won’t get far
  • Hide error reporting – hide code errors on the frontend so hackers can’t exploit site security
  • Update security keys – update old WordPress security keys to be more encrypted and provide better security
  • Prevent information disclosure – improve server security and protect sensitive files by locking down specific file types
  • Prevent PHP execution – Defender bolsters security by automatically preventing any PHP code from being executed
  • Resolve security recommendations and issues in bulk
  • Google reCAPTCHA security – easy to add, stop fraud and abuse – including BuddyPress and WooCommerce
  • Pwned Password Check – Increase security by protecting against compromised passwords
  • Force Password Reset – Force users with selected roles to reset passwords.

Learn The Ropes With These Hands-On Defender Security Plugin Tutorials

WordPress Security Scans

Defender’s malware scanner security checks for suspicious code and malware. It also compares your WordPress install with the WP directory master copy, and reports any changes so you can restore the original file with a click.

Two-Factor Authentication (2FA) Security

Easily add an extra layer of protection and security to your WordPress sites with Defender’s two-factor authentication (2FA) features. Including: mobile app verification (Google Authenticator, Microsoft Authenticator, Authy), backup code generation, lost device emails, WooCommerce 2FA, Biometric Authentication (fingerprint/facial recognition), and Hardware Key Authentication (USB security keys). Easily prevent brute force attacks and login security vulnerabilities.

Login Protection

Brute force attacks are no match for Defender’s login security. Limit login attempts so hackers can’t guess passwords. Permanently ban IPs or trigger a timed lockout after a set number of failed login attempts. Use Geo IP blocking to ban users from specific countries or locations.

Firewall Security and IP Manager

Improve your website security with Defender’s IP manager and firewall. Manually block specific IPs, import a list of banned IPs, and set automated timed and permanent lockouts. Defender makes it easy to block and unblock specific locations quickly thanks to its advanced firewall security(WAF) offering Geographical IP blocking.

User Agent Banning

Add user agents to the block or allowlist and stop bad bots from spamming and scraping your site. All major search engines and special network bots are allow-listed out of the box. Easy to set up, Defender’s user agent banning tool does all the security work, with no editing of the .htaccess file required.

Google reCAPTCHA Integration

Add reCAPTCHA security to your login / registration pages, lost password forms, and post comments in a couple of steps to up security and help protect from fraud and abuse. Select reCAPTCHA type, language, location, and style to suit. As well as Google, Defender also supports the following reCAPTCHA types:

  • BuddyPress reCAPTCHA
  • WooCommerce reCAPTCHA

Login Screen Masking

Defender makes it easy to move your login screen to a custom URL. Not only does login screen masking improve security, but it also lets you white label your login user experience and improves branding.

Force Password Reset

Enhance site security by forcing all users with selected roles to reset their password at any time. Especially helpful if you suspect a possible data breach on your site.

Security Headers

Protect your site against common attacks, such as: XSS, code injection, cross site scripting, and more. Enable the following security headers:

  • X-Frame-Options
  • X-XSS-Protection
  • X-Content-Type-Options
  • Strict Transport
  • Referrer Policy
  • Permissions-Policy

404 Limiter

Detect when bots are being used to scan your site for security vulnerabilities and shut them down. The 404 limiter lets you stop the scan by detecting when a bot keeps visiting pages that do not exist, which can also save you from a giant strain on your site’s performance.

Security Notifications and Reports

Defender runs surveillance and sends security notifications with information that matters. All activity and notifications are recorded in the activity log to let you see at a glance the website security actions that have been taken by the Defender security plugin.

Reduce Security Setup Time With Saved Configs

Save your Defender security plugin configurations and reapply them to your other sites in just a few clicks. You can create and save an unlimited number of security configurations.

Pwned Password Check

Entered passwords are checked against public database breach records to further boost security. If a password is identified as compromised, the user will be asked to change it.

Global IP Block/Allowlists

Create your IP block/allow list once, then apply and automatically sync it to all your other sites with just a single click. Save hours by not having to manually add IPs to each individual site. *Note: a [free WPMU DEV account] (https://wpmudev.com/register) is required to access this feature.

What Do People Say About Defender?

★★★★★
“I found other pro security plugins a bit too fiddly for my taste…I’m delighted with Defender” – KeithADV

★★★★★
“Thank you for bringing back a free and easy to use 2-Factor Authentication after Clef! Defender helps keep me aware of my site’s security.” – awijasa

★★★★★
“Defender’s interface is very intuitive with warnings that are very helpful” – djohns

★★★★★
“Defender Recently blocked over 3000 attacks in one week without any noticeable impact on the website. WPMUDEV knocking it out of the park on this one.” – David Oswald

Secure Websites, More Trust, Better Profit

If you’re running a business website or eCommerce store, privacy, security, uptime and trust are essential.

The Defender security plugin is here to help you: it’s a one of a kind WordPress security plugin that makes web security easy for anyone, for free!

  • Malware scanner
  • Google two-factor authentication (2FA)
  • Web Authentication
  • Firewall setup and configuration
  • One-click site hardening and security tweaking
  • WordPress core file scanning and repair
  • Ongoing firewall security
  • Google reCAPTCHA
  • Security headers
  • One-click security configs
  • Login Screen Masking
  • Pwned Password Check
  • IP Blocklist manager and logging
  • Geo IP blocking
  • User agent banning
  • Unlimited file scans
  • Timed Lockout brute force login attack shield for login security
  • 404 limiter for blocking vulnerability scans
  • IP lockout notifications and security reports

All the above is free and will enhance WordPress security for you. If you need extra security for your WordPress site, you should get a WPMU DEV Membership.

Our Membership gives you access to Defender Pro – which security features include automated scanning, scheduled malware scans for Core, themes, plugins and other files, audit logs, firewall protection, Safe Repair, Blocklist monitoring – alongside Snapshot Pro cloud backups, the Hub with automated plugin, theme and core updates and safe-upgrade scans, all our premium WordPress plugins, 24/7 WordPress support and if your sites already been hacked our team of security experts will clean it up at no additional cost.

It’s an incredible deal, and you can find out more here.

About Us

WPMU DEV is a premium supplier of quality WordPress plugins and themes. For premium support with any WordPress-related issues you can join us here:
https://wpmudev.com/

Don’t forget to stay up to date on everything WordPress from the Internet’s number one resource:
WPMU DEV Blog

Hey, one more thing… we hope you enjoy our free offerings as much as we’ve loved making them for you!

Installation

  1. Upload the wp-defender plugin to your /wp-content/plugins/ directory.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.
  3. Configure and manage using the defender menu item in the WordPress dashboard.
  4. Done!

Screenshots

  1. Malware scans and one-click website security hardening recommendations.

    Malware scans and one-click website security hardening recommendations.

  2. Layered security recommendations let you harden your site with a few clicks.

    Layered security recommendations let you harden your site with a few clicks.

  3. Compare your WordPress install with the directory and restore original files with a click.

    Compare your WordPress install with the directory and restore original files with a click.

  4. Use 2-Step Verification (2FA) to protect your accounts with your phone.

    Use 2-Step Verification (2FA) to protect your accounts with your phone.

  5. IP blocklisting, 404 limiter, Geo IP Blocking, and Timed Lockout attack shield.

    IP blocklisting, 404 limiter, Geo IP Blocking, and Timed Lockout attack shield.

FAQ

Why should I choose Defender over other security plugins?

Defender is built to add all the best hardening and website security recommendations used by the pros without having to become a security expert. This means you get all the most effective and proven protection methods other services provide with fewer settings, one-click hardening and faster setup.

Is installing Defender the only step I need to take for better WordPress security?

Hackers and bot attacks are not the only security threats to your site. No matter what security plugin or service you use, always be prepared with a secure backup stored in a safe location away from your live site. Security does not protect from hosting outages, server errors and accidentally lost or damaged data. We recommend Snapshot. Defender with scheduled managed backups is the best way to keep your site safe.

Does Defender security protect against harmful bots?

Yes! Defender’s Firewall gives you robust site protection and security by allowing you to block bad bot IPs and use geographical IP blocking

Can I use Defender with other security plugins?

You can. Just make sure not to enable the same security features in the third-party plugin that you also have enabled in Defender, as this might cause conflicts, such as malware scanners, firewall, and login security features.

Is Defender’s security compatible with WordPress Multisite?

Yes! All of Defender’s security features are fully compatible with a multisite installation. It can be network enabled and managed from the network admin.

Does Defender offer spam protection and security?

A high percentage of Trackbacks and Pingbacks are spam. Defender allows you to easily disable both, giving you added security and protection.

Will my site be protected from DDoS attacks and similar security threats?

Yes. Defender’s IP banning, IP lockout, and 404 detection security features can identify DDoS attacks and block bad IPs.

I’ve locked myself out of my admin panel, what can I do?

Add the code below to your theme’s function.php file, which you’ll find in the main directory of an active theme. Replace “YOUR IP HERE” with your IP address. Use a site like whatsmyip to get your IP.

add_filter( 'ip_lockout_default_whitelist_ip', function ( $ips ) { $ip = 'YOUR IP HERE'; $ips[] = $ip; return $ips; } ); 

Help! I was already hacked. What should I do?

WPMU DEV’s expert support can advise you on how to clean up your site if it’s been hacked. Create a new thread in our support forum, or Defender Pro gives you access to 24/7 live support.

How can I report security issues or bugs?

We take plugin security incredibly seriously; if you have a bug or vulnerability to report, you can do so through the Patchstack Vulnerability Disclosure Program. It’s fast, easy, and you will be notified when the issue is fixed. Report a vulnerability.

I have another question, where’s the best place to get help with security?

Please open a new thread in Defender’s support forum. Our support team is always happy to help!

Changelog

4.8.1 ( 2024-07-23 )

  • Enhance: Improvements for Known vulnerabilities
  • Fix: Multiple redirects when Mask Login Redirect Traffic is set to custom/external URL

4.8.0 ( 2024-07-15 )

  • Enhance: Compatibility with WordPress 6.6
  • Enhance: WPCS compliance
  • Fix: Editors can’t close Cloudflare Usage notification

4.7.4 ( 2024-06-27 )

  • Fix: Hide Expert Services when Whitelabel is enabled

4.7.3 ( 2024-06-27 )

  • Fix: Broken Access Control vulnerability on the Configs page

4.7.2 ( 2024-06-18 )

  • Enhance: Option to reset Locations on the IP Banning page
  • Enhance: Removed unnecessary login filters on Mask Login to enhance security
  • Enhance: Show loading icon with message when clicking pagination buttons on Firewall logs
  • Enhance: Change the final text for the WP CLI command to remove log files older than a week
  • Enhance: Added malware signature to detect fake Core Fork plugin enhancing site security
  • Enhance: Email design improvement for 2FA code
  • Enhance: Show loading icon only for the current button
  • Enhance: Updated malware signatures to detect different infected files improving overall security
  • Enhance: Add WP CLI to clear the MaxMind license key
  • Fix: Custom logo overlaps on Malware Scanning progress bar
  • Fix: Update Calotes\DB\Mapper::save() to handle integers correctly
  • Fix: Google reCAPTCHA bypassed using auto-fill on the Login page
  • Fix: Google reCAPTCHA v2 invisible not working with the Ship to a different address option in the WooCommerce plugin
  • Fix: Suspicious files are not detected in the plugin folder when Scan plugin files are enabled
  • Fix: Notification displayed twice on the Notifications page in the free version
  • Fix: Mask Login URL isn’t working when it is a Plain permalink structure
  • Fix: WordPress sends an error email with the Mask_Login::filter_site_url method
  • Fix: Update Support links
  • Fix: UI Improvements
  • Fix: Bulk delete issues fail when files have non-edit permissions
  • Fix: Calendar displayed in blue when High contrast mode is enabled
  • Fix: Ban/unban IP from Firewall Logs not reflected on the IP Banning Tab
  • Fix: Mask URL is not working on the default WP recovery email when a site goes down

4.7.1 ( 2024-05-01 )

  • Enhance: UI enhancements in the Malware Scanning screen

4.7.0 ( 2024-04-22 )

  • Enhance: Create a dropdown for Trusted Proxy Preset
  • Enhance: Add .well-known to scan allowlist
  • Fix: Undefined array key ‘path’ after update
  • Fix: Fix Validation gets bypassed in Google reCAPTCHA
  • Fix: Add malware signature
  • Fix: Unlock time overlaps with the Defender logo in the footer

4.6.0 ( 2024-03-18 )

  • New: Introducing the “Unlock Me” feature to unblock admin on lockout
  • Fix: False positive with BuddyBoss plugin on Malware scan
  • Fix: Undefined variable in two-fa.php

4.5.1 ( 2024-02-26 )

  • Enhance: Improve IP detection with auto-detection for Cloudflare and notices for proxy configurations
  • Enhance: Compatibility with WordPress 6.5
  • Enhance: Replace the old Twitter logo with the new logo in emails

Changelog for previous versions.

Details

  • Version: 4.8.1
  • Active installations: 90,000
  • WordPress Version: 5.2
  • Tested up to: 6.6.1
  • PHP Version: 7.4

Ratings


5 Stars
4 Stars
3 Stars
2 Stars
1 Stars