Description

Defender adds the best in WordPress plugin security to your website with just a few clicks. Stop brute force login attacks, SQL injections, cross-site scripting XSS, and other WordPress vulnerabilities and hacks with Defender’s malware scanner, antivirus scans, IP blocking, firewall, activity log, security log, and two-factor authentication (2FA) login security.
No longer do you have to go through hideously complex security settings and get a virtual PhD in security. Defender adds all the hardening and security recommendations you need.

Security Recommendations

Defender starts with a list of one-click hardening techniques that will instantly add layers of protection and security to your site.

Block hackers at every level:

  • Two-factor authentication (2FA) – App verification, backup codes, lost device email, WooCommerce 2FA, and Web Authentication
  • Login masking – change the location of WordPress’s default login area
  • Login lockout – failed login attempts lockout
  • Malware scanner – scan WordPress core files for modifications and unexpected changes
  • Security Headers – Add an extra layer of defense security and protect against common attacks like: XSS, code injection, and more
  • 404 Detection – automated block of bot IPs
  • Configs – Create your ideal Defender security settings and export / import saved configs to any other site
  • Geolocation IP lockout – block users based on location and country (IP blocking)
  • WordPress Security Firewall – block or allowlist IPs
  • Disable trackbacks and pingbacks – spam prevention
  • Core and server update recommendations – stay on top of your system
  • Antivirus scan – scan for active security threats and viruses
  • Disable file editor – if they get in, they won’t get far
  • Hide error reporting – don’t reveal your security issues
  • Update security keys – reset on-demand
  • Prevent information disclosure – why tell them what you have
  • Prevent PHP execution – because it’s daaaangerous
  • Resolve security recommendations and issues in bulk
  • Google reCAPTCHA – easy to add, stop fraud and abuse.
  • Pwned Password Check – Protect against compromised passwords.
  • Force Password Reset – Force users with selected roles to reset passwords.
  • User Agent Banning – Block bad bots and user agents from accessing your site.

Learn The Ropes With These Hands-On Defender Security Tutorials

WordPress Security Scans

Defender’s free malware scanner checks WordPress for suspicious code and malware. The Defender scan tool compares your WordPress install with the master copy in WP directory, reports changes and lets you restore the original file with a click.

Two-Factor Authentication (2FA)

Easily add an extra layer of protection to your WordPress sites with Defender’s range of two-factor authentication (2FA) features. Including: mobile app verification (Google Authenticator, Microsoft Authenticator, Authy), backup code generation, lost device emails, WooCommerce 2FA, Biometric Authentication (fingerprint/facial recognition), and Hardware Key Authentication (USB security keys).

Google reCAPTCHA Integration

Add reCAPTCHA to your login, registration, and password reset pages in a couple of steps to up security and help protect from fraud and abuse. Select reCAPTCHA type, language, location, and style to suit.

Firewall and IP Manager

Keep your site safe with Defender’s IP manager and firewall. Manually block specific IPs, import a list of banned IPs and set automated timed and permanent lockouts. Defender makes it easy to block and unblock specific locations quickly thanks to its advanced firewall (WAF).

Login Protection

Brute force login attacks are no match for Defender. Limit login attempts to stop users trying to guess passwords. Permanently ban IPs or trigger a timed lockout after a set number of failed login attempts.

Login Screen Masking

Defender makes it easy to move your login screen to a custom URL. Not only does login screen masking improve security, but it also lets you white label your login user experience and improves branding.

Force Password Reset

Password Reset enables you to force all users with selected roles to reset their password at any time. Especially helpful if you suspect a possible data breach on your site.

User Agent Banning

Add user agents to the block or allowlist and stop bad bots from spamming and scraping your site. All major search engines and special network bots are allow-listed out of the box. Easy to set up, Defender does all the security work, no editing of the .htaccess file required.

Security Headers

Security headers protect your site against the most likely types of attacks, such as: XSS, code injection, cross site scripting, and more. You can enable the following headers:

  • X-Frame-Options
  • X-XSS-Protection
  • X-Content-Type-Options
  • Strict Transport
  • Referrer Policy
  • Permissions-Policy

404 Limiter

Defender detects when bots are being used to scan your site for vulnerabilities and shuts them down. The 404 limiter lets you stop the scan by detecting when a bot keeps visiting pages that do not exist, which can also save you from a giant strain on your site’s performance.

Notifications and Reports

Defender runs surveillance and sends security notifications with information that matters.

Reduce Setup Time With Saved Configs

The configs module allows you to save your Defender configurations and reapply them to your other sites in just a few clicks. You can create and save an unlimited number of security configurations.

Pwned Password Check

Protect your site against password leak attacks. Entered passwords are checked against public database breach records. If a password is identified as compromised, the user will be asked to change it.

What Do People Say About…