Defender — WordPress Security, Malware Scanner and Firewall Plugin

Updated:

Defender is WPMU Dev’s security layer, and its design bet is integration: if you run other WPMU Dev plugins — Smush, Hummingbird, SmartCrawl — Defender shares their management surface, and the whole stack reports into one Hub dashboard. Standalone, it covers the standard hardening surface: malware scanning against WordPress.org checksums plus the WPMU Dev vulnerability database, firewall rules for injections and suspicious requests, TOTP and email two-factor authentication, and an activity log detailed enough to restore content changed during a specific window. The guided security checklist walks through the unglamorous hardening steps — disable file editing, hide version strings, secure wp-config.php — that most sites skip. Against checklist-driven rivals like All In One WP Security Pro, Defender’s counterargument is the restorable audit log and ecosystem consolidation.

Its honest position against specialists like Cerber Security Pro: Defender lacks per-page admin access control and live traffic viewing, but its audit UI is cleaner, 2FA ships free without gating, and the 6.2.x line’s audit improvements (sync to Hub, better event context labels) show active maintenance on the logging side — which is the feature most security plugins treat as an afterthought.

Competitive Features

  • Checksum + vulnerability dual scanning — core files against WordPress.org, plugins/themes against WPMU Dev’s database
  • Free full 2FA — TOTP apps, email codes, and backup codes with no premium gate
  • Restore-capable activity log — tracked content changes can be rolled back from the log
  • Guided hardening checklist — prioritized actions with explanations, not just toggles
  • 404 threshold blocking — IPs generating scanner-style 404 storms get blocked automatically
  • Hub integration — multi-site security reporting for WPMU Dev members
  • Scheduled audit reports — email digests of security events and scan outcomes

Key Features

  • Firewall protection — SQL injection, XSS, and path traversal request filtering
  • File integrity monitoring — comparisons against official repository checksums
  • Login protection — attempt limits, lockouts, strong password enforcement
  • reCAPTCHA v3 — on login, registration, and password reset forms
  • IP management — automated blocklist plus manual whitelist/blacklist control
  • Security recommendations — prioritized fixes derived from scan results
  • Configurable log retention — audit history up to 6 months

Comparison with Competitors

Defender vs Solid Security

Aspect Defender Solid Security
Malware scanning Checksums + vulnerability DB Checksum-based
Two-factor auth Free (TOTP + email) Free (TOTP)
Activity logging Detailed, restorable Standard
Password policy No Yes
Version management No Yes
Multi-site reporting Via WPMU Dev Hub Per-site

Bottom line: Solid Security adds password policy and version management that Defender lacks; Defender answers with restorable audit logs, free email-based 2FA, and the Hub for managing many sites. The WPMU Dev ecosystem lock-in is either the selling point or the dealbreaker.

Defender vs All In One WP Security Pro

Aspect Defender All In One WP Security Pro
Interface polish Modern, Hub-connected Functional, denser
Malware scanning Vulnerability DB integrated Signature-based
Traffic-light checklist Yes Yes
2FA TOTP + email free TOTP + CAPTCHA
Audit log Restorable Standard
Ecosystem WPMU Dev suite Standalone

Bottom line: All In One WP Security Pro matches most features standalone with its traffic-light audit; Defender’s advantages are the vulnerability database, restorable logs, and multi-site Hub. Both are free-tier friendly — pick by whether you live in the WPMU Dev ecosystem.

Recommended Stack — security detects and blocks; backup recovers. Pair Defender with WPMU Dev Backup for ecosystem-consistent recovery — same dashboard, same support channel, same retention logic.

Official Changelog

Version 6.2.4

Release Date: September 1, 2026

  • Fix: Username not appearing in some Audit Log events.
  • Fix: Audit module storing un-interpolated {{user_login}} in some log entries.
  • Fix: Minor improvements in vulnerability detection.

Version 6.2.3

Release Date: August 31, 2026

  • Enhancement: Improved Audit Log UI across Dashboard and Audit Log pages.
  • Enhancement: Added a “Save your API keys to load” preview state for Bot Protection CAPTCHA settings.
  • Enhancement: Updated the event type label in the detailed Audit Log view from ‘Content’ to ‘Context’.
  • Fix: Resolved an issue where audit log events from multi-event requests were not synchronizing to the Hub.
  • Fix: Fixed a UI layout issue when editing Nginx configuration under Hardening > Prevent Information Disclosure.
  • Fix: Addressed a deprecation notice for Webauthn::verify_response().
  • Fix: Fixed a visual bug where the “Learn how we detect your IP” link overlapped the background border at 1280px screen widths.

Version 6.2.2

Release Date: August 24, 2026

  • Fix: Streamlined schema method by removing bootstrap trait.

Frequently Asked Questions

Does Defender replace Wordfence?

It covers the same core surface — malware scanning, firewall, login protection — but not Wordfence’s kernel-level WAF with live traffic view. Defender’s case is the free 2FA, restorable activity logs, and WPMU Dev Hub integration rather than raw firewall depth.

How does the activity log work?

Every user action is logged: content edits, plugin installs, settings changes, login attempts. Filtering by user, date, and action type, with retention up to six months. Content changes tracked in the log can be restored directly — the feature that separates auditing from forensics.

Is two-factor authentication free?

Yes. TOTP via any authenticator app, email-based codes, and backup codes are all included without premium gating — an area where Defender is more generous than several competitors.

What’s the difference between free and Pro?

Core protections — scanning, firewall, 2FA, audit logging — are free. The WPMU Dev membership adds white-label client reporting, advanced scheduling, Hub multi-site management, and support.

How does the malware scanner detect threats?

Three layers: core files verified against WordPress.org checksums, plugin and theme code checked against the WPMU Dev vulnerability database, and pattern scanning for suspicious constructs like eval() with encoded payloads or large base64_decode() strings.

Rating★★★★★ 4.8/5
Version6.2.4
PriceFree
Active Installs80,000+
Tested up toWP 7.0.4

Related Plugins

Share your experience

Leave a Reply

Your email address will not be published. Required fields are marked *