{"id":344919,"date":"2026-07-31T00:20:19","date_gmt":"2026-07-31T00:20:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/defen-so-connector\/"},"modified":"2026-08-13T10:36:13","modified_gmt":"2026-08-13T10:36:13","slug":"defen-so-connector","status":"publish","type":"plugin","link":"https:\/\/me.wordpress.org\/plugins\/defen-so-connector\/","author":23537601,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.1","stable_tag":"1.4.1","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Security, Malware Scan, Firewall, Rate-limiting & Uptime Monitor with Alerts by Defen.so","header_author":"Defen.so","header_description":"Official Defen.so connector for WordPress. One-click connect to Defen.so, block SQL injection \/ XSS \/ bot scanners at the edge, scan every uploaded file for polyglots + malware, watch uptime, and detect brute-force logins. Manage everything from your Defen.so dashboard at https:\/\/defen.so.","assets_banners_color":"0a0a0a","last_updated":"2026-08-13 10:36:13","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/defen.so\/wordpress-security-plugin","header_author_uri":"https:\/\/defen.so","rating":0,"author_block_rating":0,"active_installs":0,"downloads":545,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.8":{"tag":"1.1.8","author":"defenso","date":"2026-07-31 00:20:04"},"1.2.1":{"tag":"1.2.1","author":"defenso","date":"2026-08-01 02:45:15"},"1.2.2":{"tag":"1.2.2","author":"defenso","date":"2026-08-02 02:39:01"},"1.2.4":{"tag":"1.2.4","author":"defenso","date":"2026-08-03 19:18:34"},"1.2.5":{"tag":"1.2.5","author":"defenso","date":"2026-08-03 20:03:56"},"1.2.6":{"tag":"1.2.6","author":"defenso","date":"2026-08-03 22:26:52"},"1.2.7":{"tag":"1.2.7","author":"defenso","date":"2026-08-03 23:47:34"},"1.2.8":{"tag":"1.2.8","author":"defenso","date":"2026-08-04 14:35:05"},"1.2.9":{"tag":"1.2.9","author":"defenso","date":"2026-08-09 13:56:36"},"1.3.0":{"tag":"1.3.0","author":"defenso","date":"2026-08-10 10:31:39"},"1.3.1":{"tag":"1.3.1","author":"defenso","date":"2026-08-10 19:16:34"},"1.3.2":{"tag":"1.3.2","author":"defenso","date":"2026-08-10 19:32:40"},"1.3.3":{"tag":"1.3.3","author":"defenso","date":"2026-08-10 20:00:52"},"1.4.0":{"tag":"1.4.0","author":"defenso","date":"2026-08-13 10:15:16"},"1.4.1":{"tag":"1.4.1","author":"defenso","date":"2026-08-13 10:36:13"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629235,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629235,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629235,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629235,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.8","1.2.1","1.2.2","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.1","1.3.2","1.3.3","1.4.0","1.4.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3644884,"resolution":"1","location":"assets","locale":"","width":1236,"height":2745},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3644884,"resolution":"2","location":"assets","locale":"","width":1280,"height":620},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3644884,"resolution":"3","location":"assets","locale":"","width":1280,"height":680},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3644884,"resolution":"4","location":"assets","locale":"","width":1280,"height":680}},"screenshots":{"1":"Defenso Alerts mobile app \u2014 when a connected site goes down, your phone rings with a full-screen alarm, through silent mode and Do Not Disturb, so you never miss an outage.","2":"One-click connect popup.","3":"Connected dashboard with WAF rule count and event queue.","4":"Live attack log on the Defen.so dashboard."}},"plugin_section":[262246],"plugin_tags":[1174,1184,600,29148,18199],"plugin_category":[54],"plugin_contributors":[273922],"plugin_business_model":[],"class_list":["post-344919","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-firewall","plugin_tags-malware","plugin_tags-security","plugin_tags-uptime","plugin_tags-waf","plugin_category-security-and-spam-protection","plugin_contributors-defenso","plugin_committers-defenso"],"banners":{"banner":"https:\/\/ps.w.org\/defen-so-connector\/assets\/banner-772x250.png?rev=3629235","banner_2x":"https:\/\/ps.w.org\/defen-so-connector\/assets\/banner-1544x500.png?rev=3629235","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/defen-so-connector\/assets\/icon-128x128.png?rev=3629235","icon_2x":"https:\/\/ps.w.org\/defen-so-connector\/assets\/icon-256x256.png?rev=3629235","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/defen-so-connector\/assets\/screenshot-1.png?rev=3644884","caption":"Defenso Alerts mobile app \u2014 when a connected site goes down, your phone rings with a full-screen alarm, through silent mode and Do Not Disturb, so you never miss an outage."},{"src":"https:\/\/ps.w.org\/defen-so-connector\/assets\/screenshot-2.png?rev=3644884","caption":"One-click connect popup."},{"src":"https:\/\/ps.w.org\/defen-so-connector\/assets\/screenshot-3.png?rev=3644884","caption":"Connected dashboard with WAF rule count and event queue."},{"src":"https:\/\/ps.w.org\/defen-so-connector\/assets\/screenshot-4.png?rev=3644884","caption":"Live attack log on the Defen.so dashboard."}],"raw_content":"<!--section=description-->\n<p><strong>Everything you need to keep a WordPress site safe \u2014 in one plugin, most of it running locally for free.<\/strong> Defen.so blocks attacks, scans for malware, watches your files for tampering, hardens the common holes hackers walk through, and \u2014 once you connect a free account \u2014 pings your site from outside so you know the second it goes down or your SSL is about to expire.<\/p>\n\n<p>No API key to paste. No config file. Click <strong>Connect to Defen.so<\/strong>, sign in, and you're protected.<\/p>\n\n<p><strong>\u25b6 Get the free mobile app \u2014 Defenso Alerts:<\/strong> https:\/\/play.google.com\/store\/apps\/details?id=so.defen.alerts \u2014 a phone app that <em>rings you like a phone call<\/em>, an alarm that cuts through silent mode and Do Not Disturb, the moment your site goes down, gets attacked, or your SSL\/domain is about to expire. Also on iOS. This is the feature people install the plugin for and then tell their friends about.<\/p>\n\n<p><strong>Works standalone \u2014 no account required<\/strong><\/p>\n\n<p>You do not need a Defen.so account to use the plugin. These run entirely on your own server, for free, with no sign-up and no limits:<\/p>\n\n<ul>\n<li><strong>Upload scanning<\/strong> \u2014 every uploaded file is checked for dangerous extensions and polyglots (magic bytes that disagree with the declared type). Runs on every upload, for everyone.<\/li>\n<li><strong>Malware scan<\/strong> \u2014 heuristic sweep of your PHP\/JS files for common webshell and obfuscation patterns.<\/li>\n<li><strong>File-modification detection (new in 1.4.0)<\/strong> \u2014 snapshots a trusted sha256 baseline of your files, then flags anything <strong>added, changed, or removed<\/strong> since. This is how you catch a hacked or injected file that a signature scanner would miss \u2014 a backdoor dropped into your theme, a modified <code>wp-config.php<\/code>, a plugin file that isn't the one you installed.<\/li>\n<li><strong>Continuous database scanning (new in 1.4.0)<\/strong> \u2014 a weekly background sweep keeps your malware and vulnerability findings fresh automatically. No manual clicking; your results are never stale.<\/li>\n<li><strong>Background scan with a live progress bar (new in 1.4.0)<\/strong> \u2014 the heavy scan runs on WP-Cron, not inside your admin request, so the dashboard never hangs. A progress bar tracks it and can't get stuck.<\/li>\n<li><strong>Path rate limiting<\/strong> \u2014 throttle any URL slug or wildcard pattern on your own site (e.g. <code>\/wp-login.php<\/code>, <code>\/wp-json\/*<\/code>, <code>\/checkout*<\/code>) per client IP; excess requests get a <code>429<\/code> with a <code>Retry-After<\/code> header. Up to 3 rules run locally for free; connect a free account to add more.<\/li>\n<li><strong>Login \/ brute-force hardening<\/strong> \u2014 per-IP login rate limiting with an adjustable attempt count and window, optional reCAPTCHA v3, optional TOTP 2FA.<\/li>\n<li><strong>Firewall-lite<\/strong> \u2014 blocks known-bad scanner user-agents (sqlmap, nikto, wpscan, nuclei\u2026) and common exploit request patterns (path traversal, LFI\/RFI wrappers, code-in-querystring, wp-config and dotfile probes).<\/li>\n<li><strong>Core-file integrity check<\/strong> \u2014 verifies WordPress core files against the official WordPress.org checksum manifest and flags any modified or missing core file.<\/li>\n<li><strong>Exposed-file check<\/strong> \u2014 probes for publicly-reachable secrets (.env, .git, wp-config backups, database dumps, debug logs).<\/li>\n<li><strong>Activity log<\/strong> \u2014 records the last 100 high-value admin actions locally.<\/li>\n<\/ul>\n\n<p><strong>Common WordPress security holes we close<\/strong><\/p>\n\n<p>Most WordPress compromises come through the same handful of doors. Defen.so shuts them with one-click toggles (safe defaults on for new installs):<\/p>\n\n<ul>\n<li><strong>Brute-force logins<\/strong> \u2014 per-IP throttling and lockout on <code>wp-login.php<\/code> so credential-stuffing bots can't grind your passwords.<\/li>\n<li><strong>User enumeration<\/strong> \u2014 blocks <code>?author=<\/code> scans and the REST <code>\/users<\/code> endpoint that leak your usernames to attackers before they even try a password.<\/li>\n<li><strong>XML-RPC abuse<\/strong> \u2014 disable <code>xmlrpc.php<\/code>, a favourite amplifier for brute-force and pingback DDoS.<\/li>\n<li><strong>Version fingerprinting<\/strong> \u2014 hides your WordPress version so attackers can't cheaply match you to a known exploit.<\/li>\n<li><strong>The built-in file editor<\/strong> \u2014 disables the theme\/plugin editor (<code>DISALLOW_FILE_EDIT<\/code>) so a single stolen admin session can't paste a backdoor into your code.<\/li>\n<li><strong>Missing security headers<\/strong> \u2014 sends X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and optional HSTS.<\/li>\n<li><strong>Geo-block<\/strong> \u2014 reject requests from any list of countries.<\/li>\n<\/ul>\n\n<p><strong>A green \"Security active\" badge in your toolbar (new in 1.4.0)<\/strong><\/p>\n\n<p>A shield icon sits in the WordPress admin bar and turns green when your site is protected, with a one-click menu to <strong>Scan<\/strong>, <strong>Reports &amp; findings<\/strong>, <strong>File changes<\/strong>, <strong>Uptime<\/strong>, and <strong>Upgrade<\/strong>. Security status is visible on every page, not buried in a settings screen.<\/p>\n\n<p><strong>Uptime, SSL &amp; domain-expiry monitoring \u2014 free once connected<\/strong><\/p>\n\n<p>Uptime, SSL-expiry and domain-expiry checks have to run from <em>outside<\/em> your server \u2014 a plugin inside WordPress can't reliably tell whether your own site is reachable. So the moment you connect a free Defen.so account, external checks start running from Defen.so's servers, and you can route alerts to email, Slack, Telegram, Discord, a webhook, or the Defenso Alerts app. <strong>This is free.<\/strong> A paid subscription is how you support development \u2014 and it unlocks more: faster check intervals, more monitors, longer log retention, more scans, and custom WAF rules. Soft ask, honest deal: you never need to pay to stay protected.<\/p>\n\n<p><strong>Better when connected (optional)<\/strong><\/p>\n\n<p>Connecting a free Defen.so account adds a managed cloud layer on top \u2014 nothing above is taken away:<\/p>\n\n<ul>\n<li><strong>Managed WAF<\/strong> \u2014 blocks SQL injection, XSS, path traversal, bot scanners and mass-assignment using the live rule set plus custom rules from your dashboard.<\/li>\n<li><strong>Attack log<\/strong> \u2014 blocked events (including upload and rate-limit blocks) streamed to your dashboard in real time.<\/li>\n<li><strong>CVE vulnerability lookup<\/strong> \u2014 checks your installed plugins and themes against the live CVE feed.<\/li>\n<\/ul>\n\n<p><strong>For AI coding assistants \u2014 MCP server + Claude skill<\/strong><\/p>\n\n<p>The Defen.so ecosystem goes past the browser. There's an <strong>MCP server<\/strong> (<code>@defen.so\/mcp<\/code>) and a <strong>Claude Code skill<\/strong> so AI coding assistants \u2014 Claude Code, Cursor, Windsurf \u2014 can scan a site or repo, guard the code they're writing, and add WAF rules without leaving the editor. If you build with an AI pair-programmer, your security tooling lives where your code does.<\/p>\n\n<p><strong>One-click connect<\/strong><\/p>\n\n<p>Click \"Connect to Defen.so\". A popup opens at <code>app.defen.so<\/code>; you sign in (or sign up) and authorize. The popup postMessages a scoped API key back \u2014 origin-locked to <code>app.defen.so<\/code> so no third party can intercept it.<\/p>\n\n<p>Fails open: if Defen.so is unreachable at request time, the plugin allows the request and ships the log later.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to external services. Here is exactly what is sent, when, and to whom.<\/p>\n\n<p><strong>1. Defen.so API (app.defen.so)<\/strong> \u2014 the plugin's core service.<\/p>\n\n<ul>\n<li>What it is: the managed WAF, uptime monitoring, and attack-log backend the plugin connects your site to.<\/li>\n<li>When data is sent: when you connect your site (one-time OAuth handshake), when the plugin refreshes its cached rule policy, when scan findings (including file-change diffs) are reported, and when a request is blocked\/challenged\/deceived (attack-log events are batched and sent on <code>shutdown<\/code>).<\/li>\n<li>What is sent: your scoped API token, your site URL, per-event metadata \u2014 HTTP method, URL path, visitor IP, User-Agent, matched rule ID, and the action taken \u2014 and scan finding summaries. No request bodies, no cookies, no personal content.<\/li>\n<li>Terms: https:\/\/defen.so\/tos \u2014 Privacy: https:\/\/defen.so\/privacy<\/li>\n<\/ul>\n\n<p><strong>2. Google reCAPTCHA (google.com\/recaptcha)<\/strong> \u2014 optional, only if you enable login hardening with a reCAPTCHA site key.<\/p>\n\n<ul>\n<li>What it is: Google's bot-detection service, used to score login attempts on <code>wp-login.php<\/code>.<\/li>\n<li>When data is sent: only on the login page, and only if you have entered a reCAPTCHA site key. If you leave it blank, no request is ever made to Google.<\/li>\n<li>What is sent: the reCAPTCHA token and the data Google's script collects from the login page (per Google's terms).<\/li>\n<li>Terms: https:\/\/policies.google.com\/terms \u2014 Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<p><strong>3. ip-api.com<\/strong> \u2014 optional, only if you enable the geo-block feature.<\/p>\n\n<ul>\n<li>What it is: a free IP-to-country geolocation lookup, used to find a visitor's country so the geo-block rule can allow or deny it.<\/li>\n<li>When data is sent: only when geo-block is enabled and a visitor's country is not already supplied by your host (e.g. Cloudflare's country header). The visitor's IP is sent for the lookup.<\/li>\n<li>What is sent: the visitor's IP address only.<\/li>\n<li>Terms: https:\/\/ip-api.com\/docs\/legal \u2014 Privacy: https:\/\/ip-api.com\/docs\/legal<\/li>\n<\/ul>\n\n<p><strong>4. api.wordpress.org<\/strong> \u2014 only when you run the \"Verify core files\" check.<\/p>\n\n<ul>\n<li>What it is: the official WordPress.org checksums API, the same one WP-CLI uses to verify core-file integrity.<\/li>\n<li>When data is sent: only when you click \"Verify core files\". Nothing is sent automatically.<\/li>\n<li>What is sent: your WordPress version number and locale only \u2014 no site content, no personal data.<\/li>\n<li>Terms &amp; Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload <code>defen-so-connector<\/code> to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate through the \"Plugins\" menu.<\/li>\n<li>You'll be redirected to the Defen.so setup page. Click \"Connect to Defen.so\" and follow the popup.<\/li>\n<li>(Recommended) Install <strong>Defenso Alerts<\/strong> on your phone from Google Play (https:\/\/play.google.com\/store\/apps\/details?id=so.defen.alerts) or the App Store and sign in with the same account to get alarm-style down alerts.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20slow%20down%20my%20site%3F\"><h3>Does the plugin slow down my site?<\/h3><\/dt>\n<dd><p>No. The WAF check on <code>init<\/code> reads a locally-cached policy (10-min TTL, stale-while-revalidate) \u2014 no external HTTP call on the hot path. The heavy malware and file-integrity scan runs on WP-Cron in the background, not inside your admin request, so the dashboard never hangs. Attack logs ship in a batched, non-blocking request on <code>shutdown<\/code>.<\/p><\/dd>\n<dt id=\"what%20is%20file-modification%20detection%3F\"><h3>What is file-modification detection?<\/h3><\/dt>\n<dd><p>Take a baseline once, and the plugin records a sha256 hash of every PHP\/JS file in your site. From then on it can tell you exactly which files were <strong>added, changed, or removed<\/strong> since \u2014 the fastest way to spot a hacked or injected file, a modified core file, or a backdoor dropped into your theme. The weekly background scan re-checks this automatically.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20defen.so%20is%20down%3F\"><h3>What happens if Defen.so is down?<\/h3><\/dt>\n<dd><p>Fails open. The cached policy stays live for 24 h so protection continues even during an outage. If the cache is also gone, requests are allowed.<\/p><\/dd>\n<dt id=\"is%20my%20data%20safe%3F\"><h3>Is my data safe?<\/h3><\/dt>\n<dd><p>Only attack-log metadata leaves your site: method, URL path, IP, User-Agent, matched rule ID, action. No request bodies, no cookies, no PII.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20defen.so%20account%3F\"><h3>Do I need a Defen.so account?<\/h3><\/dt>\n<dd><p>No \u2014 the firewall (WAF), WordPress hardening, brute-force protection, path rate limiting, malware scan, file-modification detection and core-file verification all run locally with no account. Connecting a free Defen.so account (one click, no API key to paste) adds the cloud layer: uptime &amp; SSL monitoring, the live attack log, alert channels, CVE lookups, and the managed rule feed.<\/p><\/dd>\n<dt id=\"does%20the%20uptime%20monitor%20work%20without%20connecting%20an%20account%3F\"><h3>Does the uptime monitor work without connecting an account?<\/h3><\/dt>\n<dd><p>Uptime, SSL-expiry and domain-expiry monitoring must run from outside your server \u2014 a plugin inside WordPress can't reliably check whether your own site is reachable. So they become active once you connect the site to a Defen.so account, and the checks run from Defen.so's external servers. The local security features work with or without an account.<\/p><\/dd>\n<dt id=\"how%20do%20i%20get%20alerted%20when%20my%20site%20goes%20down%3F\"><h3>How do I get alerted when my site goes down?<\/h3><\/dt>\n<dd><p>Connect the site, then choose your channels: email, Slack, Telegram, Discord, webhook, or the free <strong>Defenso Alerts<\/strong> mobile app (iOS &amp; Android), which rings a full-screen alarm \u2014 through silent mode and Do Not Disturb \u2014 the moment a site goes down, gets attacked, or an SSL\/domain is near expiry. Get it on Google Play: https:\/\/play.google.com\/store\/apps\/details?id=so.defen.alerts<\/p><\/dd>\n<dt id=\"can%20ai%20coding%20assistants%20use%20defen.so%3F\"><h3>Can AI coding assistants use Defen.so?<\/h3><\/dt>\n<dd><p>Yes. There's an MCP server (<code>@defen.so\/mcp<\/code>) and a Claude Code skill, so Claude Code, Cursor and Windsurf can scan, guard code, and add WAF rules directly from the editor.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20free%3F\"><h3>Is this plugin free?<\/h3><\/dt>\n<dd><p>Yes. The plugin and its local protection are free forever, and a free Defen.so account covers a connected site with uptime monitoring and a managed WAF. Paid plans support development and unlock more \u2014 more sites, longer retention, custom WAF rules, faster intervals \u2014 but you never need them to stay protected.<\/p><\/dd>\n<dt id=\"does%20it%20protect%20against%20sql%20injection%2C%20xss%2C%20and%20bad%20bots%3F\"><h3>Does it protect against SQL injection, XSS, and bad bots?<\/h3><\/dt>\n<dd><p>Yes. The firewall inspects each request on <code>init<\/code> against a managed rule set and blocks common attacks \u2014 SQL injection, cross-site scripting (XSS), path traversal, and known bot\/scanner signatures \u2014 before they reach your theme or plugins.<\/p><\/dd>\n<dt id=\"can%20i%20self-host%3F\"><h3>Can I self-host?<\/h3><\/dt>\n<dd><p>Not today. The plugin is the SDK; the classifier, rule store, and dashboard live on Defen.so infra.<\/p><\/dd>\n<dt id=\"will%20it%20conflict%20with%20wordfence%2C%20cloudflare%2C%20or%20another%20security%20plugin%3F\"><h3>Will it conflict with Wordfence, Cloudflare, or another security plugin?<\/h3><\/dt>\n<dd><p>No. Defen.so complements them \u2014 many sites run it alongside Cloudflare or another WAF for a second layer. It doesn't require DNS changes, doesn't take over <code>wp-login.php<\/code> or the REST API, and its checks are additive and fail open.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%20and%20multisite%3F\"><h3>Does it work with WooCommerce and multisite?<\/h3><\/dt>\n<dd><p>Yes. It runs at the request level, so it protects WooCommerce stores and other plugins the same way. It activates per-site on multisite.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Clearer plugin name so the security features are easier to find. No functional changes.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: <strong>file-modification detection<\/strong> \u2014 take a trusted baseline, then flag any file that was added, changed, or removed since. Catches hacked, injected or tampered files (backdoors in a theme, a modified wp-config) that signature scanning alone misses. Findings sync to your Pentest tab when connected.<\/li>\n<li>New: <strong>continuous database scanning<\/strong> \u2014 a weekly background sweep keeps malware and vulnerability findings fresh automatically, with no manual clicking.<\/li>\n<li>New: <strong>background scan with a live progress bar<\/strong> \u2014 the heavy scan runs on WP-Cron, so the admin never hangs, and the progress bar can't get stuck.<\/li>\n<li>New: <strong>green \"Security active\" toolbar badge<\/strong> \u2014 a shield in the WordPress admin bar with quick access to Scan, Reports, File changes, Uptime and Upgrade.<\/li>\n<li>Improved: clearer messaging that uptime, SSL and domain-expiry monitoring is free once you connect an account, and that a paid subscription supports development and unlocks faster checks, more monitors and more scans.<\/li>\n<li>Docs: reordered screenshots to lead with the Defenso Alerts mobile app; documented the MCP server (@defen.so\/mcp) and Claude Code skill for AI coding assistants.<\/li>\n<\/ul>\n\n<h4>1.3.3<\/h4>\n\n<ul>\n<li>New: local Path rate limiting \u2014 throttle any slug or wildcard pattern on your own site by IP, entirely in the plugin. Up to 3 rules free; connect a free account to add more.<\/li>\n<li>i18n: added German (de_DE), Brazilian Portuguese (pt_BR) and Russian (ru_RU) translations; refreshed French and Spanish.<\/li>\n<\/ul>\n\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>Listing: clearer plugin name (Firewall, Malware Scan &amp; Uptime Monitor) for search.<\/li>\n<li>Docs: expanded the FAQ (account requirement, how uptime monitoring works, down alerts, WooCommerce\/multisite, coexisting with Cloudflare\/Wordfence) and added a mobile-app screenshot showing the full-screen down alarm.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Fix: removed the \"Update URI\" header, which is not permitted for plugins hosted on WordPress.org, so the release imports correctly.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Compatibility: confirmed tested with WordPress 7.0. Maintenance release to refresh the WordPress.org listing.<\/li>\n<\/ul>\n\n<h4>1.2.9<\/h4>\n\n<ul>\n<li>Listing: refreshed the plugin tags and short description so people searching WordPress.org for \"security scanner\", \"malware scanner\", \"firewall\" and \"uptime monitor\" can find it. No functional changes.<\/li>\n<\/ul>\n\n<h4>1.2.8<\/h4>\n\n<ul>\n<li>Maintenance release: republish to WordPress.org (registry was serving an older build). No functional changes since 1.2.7.<\/li>\n<\/ul>\n\n<h4>1.2.7<\/h4>\n\n<ul>\n<li>New: Spanish (es_ES) and French (fr_FR) translations \u2014 the admin screen is now fully localised, with the plugin loading its text domain from \/languages.<\/li>\n<li>Every user-facing admin string is now translatable (translators can add more languages via the bundled .pot template).<\/li>\n<\/ul>\n\n<h4>1.2.6<\/h4>\n\n<ul>\n<li>New: three screenshots on the plugin listing (Overview, Firewall &amp; hardening, Uptime &amp; alerts) so you can see the admin before installing.<\/li>\n<li>Fixed: stray HTML entities in the readme description and changelog now render as plain text.<\/li>\n<li>Cleaner links: the admin footer and rate-limit panel link straight to defen.so instead of a pricing page.<\/li>\n<li>Housekeeping: version constant aligned with the plugin header. No changes to any security module behaviour.<\/li>\n<\/ul>\n\n<h4>1.2.5<\/h4>\n\n<ul>\n<li>SEO: refreshed the plugin description with the full feature list (managed WAF, upload scanning, login hardening, malware &amp; file-integrity scans, core-file verification, live attack log).<\/li>\n<li>Housekeeping: aligned the internal version constant with the plugin header. No changes to any security module behaviour.<\/li>\n<\/ul>\n\n<h4>1.2.4<\/h4>\n\n<ul>\n<li>New: the admin screen is now organised into tabs \u2014 Overview, Firewall &amp; hardening, Scans, Rate limits, Uptime &amp; alerts, and Activity log \u2014 so every tool is one click away instead of one long scroll. The tab you were on is remembered across reloads.<\/li>\n<li>New <strong>Rate limits<\/strong> tab: the login brute-force limiter (attempts + window + optional reCAPTCHA) gets its own clear home, alongside a note about the managed per-endpoint \/ per-IP edge limits available when connected.<\/li>\n<li>New <strong>Uptime &amp; alerts<\/strong> tab: everything the Defen.so cloud adds \u2014 multi-region uptime monitoring, SSL &amp; domain-expiry checks, Slack \/ Discord \/ Telegram \/ email \/ webhook alerts, and the call-style Defenso Alerts mobile app \u2014 in one place.<\/li>\n<li>Improved: the Scans tab shows a small count badge when a scan has flagged something, so you can see at a glance whether anything needs attention.<\/li>\n<li>Housekeeping: aligned the internal version constant with the plugin header. No changes to any security module behaviour.<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Improved: the admin screen now uses clean in-page modals and toasts instead of the browser's blocking alert()\/confirm() dialogs \u2014 disconnect and take-baseline confirmations, scan errors and save errors all look native.<\/li>\n<li>SEO: refreshed the plugin description and tags (malware scan, WAF &amp; firewall, brute-force protection, uptime &amp; SSL monitoring, instant alerts).<\/li>\n<li>No changes to any security module behaviour.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Improved: <strong>Upgrade<\/strong> and <strong>Open dashboard<\/strong> buttons now deep-link straight to <em>this<\/em> site's page in your Defen.so dashboard (and its checkout), instead of the generic app home.<\/li>\n<li>Polish: unified the admin UI typeface with the WordPress admin (dropped the bundled monospace face).<\/li>\n<li>No changes to any security module behaviour.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Compatibility: tested up to WordPress 6.8.<\/li>\n<li>Hardening: declare <code>Update URI: false<\/code> so a same-slug plugin can never hijack updates.<\/li>\n<li>Housekeeping: version + metadata alignment; no functional changes to security modules.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New <strong>Firewall-lite<\/strong> (free, local): blocks known-bad scanner user-agents and common exploit request patterns (path traversal, LFI\/RFI wrappers, code-in-querystring, wp-config &amp; dotfile probes) before they reach WordPress. Blocked hits show in your Defen.so dashboard when connected.<\/li>\n<li>New <strong>WordPress hardening<\/strong> panel (free, local): one-click toggles for username-enumeration blocking (?author= + REST \/users), hide WP version, disable the theme\/plugin file editor, disable XML-RPC, comment\/pingback hardening, and security response headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, optional HSTS). Safe defaults on for new installs.<\/li>\n<li>New <strong>Core-file checksum verification<\/strong> (free, local): checks WordPress core files against the official WordPress.org checksum manifest and flags any modified or missing core file.<\/li>\n<li>New <strong>Exposed-file check<\/strong> (free, local): probes for publicly-reachable secrets (.env, .git, wp-config backups, DB dumps, debug logs).<\/li>\n<li>Added tasteful, dismissible admin promos for the optional Defen.so cloud upgrades \u2014 uptime monitoring, multi-channel alerts (Slack\/Discord\/Telegram\/email\/webhook), and the Defenso Alerts mobile app (call-style alarm). No local feature is gated behind them.<\/li>\n<li>Documented the api.wordpress.org checksum service in the External services section.<\/li>\n<\/ul>\n\n<h4>1.1.8<\/h4>\n\n<ul>\n<li>Plugin URI updated to the plugin's page (previous URL now redirects).<\/li>\n<li>No functional changes from 1.1.7.<\/li>\n<\/ul>\n\n<h4>1.1.7<\/h4>\n\n<ul>\n<li>All local tools (malware scan, file integrity, vulnerability listing UI, geo-block, login hardening, activity log) now render and work without connecting an account, per directory Guideline 5. Connection only adds the external Defen.so service (WAF policy, uptime, attack log, CVE lookups), documented per Guideline 6.<\/li>\n<li>Admin menu slug renamed from defen-so to defenso for a consistent unique prefix.<\/li>\n<\/ul>\n\n<h4>1.1.6<\/h4>\n\n<ul>\n<li>Sanitize REQUEST_URI and QUERY_STRING with sanitize_text_field() on receipt; raw copies are used only for in-memory WAF pattern matching, never stored.<\/li>\n<\/ul>\n\n<h4>1.1.5<\/h4>\n\n<ul>\n<li>Upload scanning (dangerous extensions + polyglot detection) now runs for everyone, always \u2014 it no longer required a connected account, since it's fully local.<\/li>\n<li>Sanitized the request path before it's stored in the local attack-log queue.<\/li>\n<li>Fixed the Plugin URI and readme Terms link; documented the optional ip-api.com geo-lookup service.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Plugin Check: set an explicit version arg on the reCAPTCHA script enqueue (false, since Google hosts it) to silence the MissingVersion warning.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Plugin Check cleanup: reCAPTCHA now loads via wp_enqueue_script; prefixed admin-view variables; trimmed tags to 5; documented the WAF's raw-input reads.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Compatibility: tested up to WordPress 7.0.<\/li>\n<li>Housekeeping: shortened the plugin name so the text domain matches the slug.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>All in-plugin features (login hardening, geo-block, local malware scan, file-integrity, activity log) now work fully for everyone, with no account and no plan limits. Plan tiers only affect the optional server-side cloud services.<\/li>\n<li>Every AJAX handler now verifies a nonce; sanitized all request\/server inputs.<\/li>\n<li>Documented external services (Defen.so API, optional Google reCAPTCHA) in the readme.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added login hardening, geo-block, file-integrity, activity log, and vulnerability + malware scanning modules.<\/li>\n<li>Cleaner admin page and connect flow.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release. WAF, upload scan, brute-force signal, uptime monitor, attack log.<\/li>\n<\/ul>","raw_excerpt":"Firewall, malware &amp; file-change scanner, brute-force protection, rate limiting, plus free uptime + SSL monitoring \u2014 one-click connect, no API key.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/344919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=344919"}],"author":[{"embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/defenso"}],"wp:attachment":[{"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=344919"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=344919"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=344919"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=344919"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=344919"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/me.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=344919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}