{"id":344919,"date":"2026-07-31T00:20:19","date_gmt":"2026-07-31T00:20:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/defen-so-connector\/"},"modified":"2026-07-31T00:20:04","modified_gmt":"2026-07-31T00:20:04","slug":"defen-so-connector","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/defen-so-connector\/","author":23537601,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.8","stable_tag":"1.1.8","tested":"7.0.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Defen.so Connector","header_author":"Defen.so","header_description":"Official Defen.so connector for WordPress. One-click connect to Defen.so, block SQL injection \/ XSS \/ bot scanners at the edge, scan every uploaded file for polyglots + malware, watch uptime, and detect brute-force logins. Manage everything from your Defen.so dashboard at https:\/\/defen.so.","assets_banners_color":"0a0a0a","last_updated":"2026-07-31 00:20:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/defen.so\/wordpress-security-plugin","header_author_uri":"https:\/\/defen.so","rating":0,"author_block_rating":0,"active_installs":0,"downloads":18,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.8":{"tag":"1.1.8","author":"defenso","date":"2026-07-31 00:20:04"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629235,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629235,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629235,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629235,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.8"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"One-click connect popup.","2":"Connected dashboard with WAF rule count and event queue.","3":"Live attack log on the Defen.so dashboard."}},"plugin_section":[262246],"plugin_tags":[2439,1174,1184,600,18199],"plugin_category":[54],"plugin_contributors":[273922],"plugin_business_model":[],"class_list":["post-344919","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-malware","plugin_tags-security","plugin_tags-waf","plugin_category-security-and-spam-protection","plugin_contributors-defenso","plugin_committers-defenso"],"banners":{"banner":"https:\/\/ps.w.org\/defen-so-connector\/assets\/banner-772x250.png?rev=3629235","banner_2x":"https:\/\/ps.w.org\/defen-so-connector\/assets\/banner-1544x500.png?rev=3629235","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/defen-so-connector\/assets\/icon-128x128.png?rev=3629235","icon_2x":"https:\/\/ps.w.org\/defen-so-connector\/assets\/icon-256x256.png?rev=3629235","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Defen.so is a developer-first web application security SaaS. This plugin gives your WordPress site real, local protection out of the box, and connects to Defen.so in one click for a managed cloud layer on top \u2014 no API key to paste, no config file.<\/p>\n\n<p><strong>Works standalone \u2014 no account required<\/strong><\/p>\n\n<p>You do not need a Defen.so account to use the plugin. These features run entirely on your own server, for free, with no sign-up and no limits:<\/p>\n\n<ul>\n<li><strong>Upload scanning<\/strong> \u2014 every uploaded file is checked for dangerous extensions and polyglots (magic bytes that disagree with the declared type). Runs on every upload for everyone.<\/li>\n<li><strong>Login hardening<\/strong> \u2014 per-IP brute-force rate limiting with adjustable attempt count + window, optional reCAPTCHA v3, optional TOTP 2FA.<\/li>\n<li><strong>Geo-block<\/strong> \u2014 reject requests from any list of countries.<\/li>\n<li><strong>Local malware scan<\/strong> \u2014 heuristic sweep of your PHP\/JS files for common webshell \/ obfuscation patterns.<\/li>\n<li><strong>File-integrity baseline<\/strong> \u2014 snapshot your files and compare for changes.<\/li>\n<li><strong>Activity log<\/strong> \u2014 records the last 100 high-value admin actions locally.<\/li>\n<\/ul>\n\n<p><strong>Better when connected (optional)<\/strong><\/p>\n\n<p>Connecting a free Defen.so account adds the managed cloud layer \u2014 none of it takes anything away from the standalone features above:<\/p>\n\n<ul>\n<li><strong>Managed WAF<\/strong> \u2014 blocks SQL injection, XSS, path traversal, bot scanners, mass assignment, using the rule set + custom rules from your Defen.so dashboard.<\/li>\n<li><strong>Attack log + uptime monitor<\/strong> \u2014 blocked events (including upload blocks) streamed to your dashboard; edge uptime checks.<\/li>\n<li><strong>CVE vulnerability lookup<\/strong> \u2014 checks your installed plugins\/themes against the live CVE feed.<\/li>\n<\/ul>\n\n<p>Paid plans (Pro $29\/mo, Business $69\/mo per site) increase the server-side quotas \u2014 monitor interval, log retention, custom-rule count, scan frequency \u2014 all of which run on Defen.so infrastructure, not by unlocking code in this plugin.<\/p>\n\n<p><strong>One-click connect<\/strong><\/p>\n\n<p>Click \"Connect to Defen.so\". A popup opens at <code>app.defen.so<\/code>, you sign in (or sign up), authorize the connection, and the popup postMessages a scoped API key back \u2014 origin-locked to <code>app.defen.so<\/code> so no third party can intercept.<\/p>\n\n<p>Fails-open: if Defen.so is unreachable at request time, the plugin allows the request and ships the log later.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to external services. Here is exactly what is sent, when, and to whom.<\/p>\n\n<p><strong>1. Defen.so API (app.defen.so)<\/strong> \u2014 the plugin's core service.<\/p>\n\n<ul>\n<li>What it is: the managed WAF, uptime monitoring, and attack-log backend the plugin connects your site to.<\/li>\n<li>When data is sent: when you connect your site (one-time OAuth handshake), when the plugin refreshes its cached rule policy, and when a request is blocked\/challenged\/deceived (attack-log events are batched and sent on <code>shutdown<\/code>).<\/li>\n<li>What is sent: your scoped API token, your site URL, and per-event metadata \u2014 HTTP method, URL path, visitor IP, User-Agent, matched rule ID, and the action taken. No request bodies, no cookies, no personal content.<\/li>\n<li>Terms: https:\/\/defen.so\/tos \u2014 Privacy: https:\/\/defen.so\/privacy<\/li>\n<\/ul>\n\n<p><strong>2. Google reCAPTCHA (google.com\/recaptcha)<\/strong> \u2014 optional, only if you enable login hardening with a reCAPTCHA site key.<\/p>\n\n<ul>\n<li>What it is: Google's bot-detection service, used to score login attempts on <code>wp-login.php<\/code>.<\/li>\n<li>When data is sent: only on the login page, and only if you have entered a reCAPTCHA site key in the plugin settings. If you leave it blank, no request is ever made to Google.<\/li>\n<li>What is sent: the reCAPTCHA token and the data Google's script collects from the login page (per Google's terms).<\/li>\n<li>Terms: https:\/\/policies.google.com\/terms \u2014 Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<p><strong>3. ip-api.com<\/strong> \u2014 optional, only if you enable the geo-block feature.<\/p>\n\n<ul>\n<li>What it is: a free IP-to-country geolocation lookup, used to find the country of a visitor so the geo-block rule can allow or deny it.<\/li>\n<li>When data is sent: only when geo-block is enabled and a visitor's country is not already supplied by your host (e.g. Cloudflare's country header). The visitor's IP address is sent for the lookup.<\/li>\n<li>What is sent: the visitor's IP address only.<\/li>\n<li>Terms: https:\/\/ip-api.com\/docs\/legal \u2014 Privacy: https:\/\/ip-api.com\/docs\/legal<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload <code>defen-so-connector<\/code> to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate through the \"Plugins\" menu.<\/li>\n<li>You'll be redirected to the Defen.so setup page. Click \"Connect to Defen.so\" and follow the popup.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20slow%20down%20my%20site%3F\"><h3>Does the plugin slow down my site?<\/h3><\/dt>\n<dd><p>No. The WAF check on <code>init<\/code> reads a locally-cached policy (10-min TTL, stale-while-revalidate) \u2014 no external HTTP call on the hot path. Attack logs ship in a batched, non-blocking <code>wp_remote_post<\/code> on <code>shutdown<\/code>.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20defen.so%20is%20down%3F\"><h3>What happens if Defen.so is down?<\/h3><\/dt>\n<dd><p>Fails open. The cached policy stays live for 24 h so protection continues even during an outage. If the cache is also gone, requests are allowed.<\/p><\/dd>\n<dt id=\"is%20my%20data%20safe%3F\"><h3>Is my data safe?<\/h3><\/dt>\n<dd><p>Only attack-log metadata leaves your site: method, URL path, IP, User-Agent, matched rule ID, action. No request bodies, no cookies, no PII.<\/p><\/dd>\n<dt id=\"can%20i%20self-host%3F\"><h3>Can I self-host?<\/h3><\/dt>\n<dd><p>Not today. The plugin is the SDK; the classifier, rule store, and dashboard live on Defen.so infra.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.8<\/h4>\n\n<ul>\n<li>Plugin URI updated to the plugin's page (previous URL now redirects).<\/li>\n<li>No functional changes from 1.1.7.<\/li>\n<\/ul>\n\n<h4>1.1.7<\/h4>\n\n<ul>\n<li>All local tools (malware scan, file integrity, vulnerability listing UI, geo-block, login hardening, activity log) now render and work without connecting an account, per directory Guideline 5. Connection only adds the external Defen.so service (WAF policy, uptime, attack log, CVE lookups), documented per Guideline 6.<\/li>\n<li>Admin menu slug renamed from defen-so to defenso for a consistent unique prefix.<\/li>\n<\/ul>\n\n<h4>1.1.6<\/h4>\n\n<ul>\n<li>Sanitize REQUEST_URI and QUERY_STRING with sanitize_text_field() on receipt; raw copies are used only for in-memory WAF pattern matching, never stored.<\/li>\n<\/ul>\n\n<h4>1.1.5<\/h4>\n\n<ul>\n<li>Upload scanning (dangerous extensions + polyglot detection) now runs for everyone, always \u2014 it no longer required a connected account, since it's fully local.<\/li>\n<li>Sanitized the request path before it's stored in the local attack-log queue.<\/li>\n<li>Fixed the Plugin URI and readme Terms link; documented the optional ip-api.com geo-lookup service.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Plugin Check: set an explicit version arg on the reCAPTCHA script enqueue (false, since Google hosts it) to silence the MissingVersion warning.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Plugin Check cleanup: reCAPTCHA now loads via wp_enqueue_script; prefixed admin-view variables; trimmed tags to 5; documented the WAF's raw-input reads.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Compatibility: tested up to WordPress 7.0.<\/li>\n<li>Housekeeping: shortened the plugin name so the text domain matches the slug.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>All in-plugin features (login hardening, geo-block, local malware scan, file-integrity, activity log) now work fully for everyone, with no account and no plan limits. Plan tiers only affect the optional server-side cloud services.<\/li>\n<li>Every AJAX handler now verifies a nonce; sanitized all request\/server inputs.<\/li>\n<li>Documented external services (Defen.so API, optional Google reCAPTCHA) in the readme.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added login hardening, geo-block, file-integrity, activity log, and vulnerability + malware scanning modules.<\/li>\n<li>Cleaner admin page and connect flow.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release. WAF, upload scan, brute-force signal, uptime monitor, attack log.<\/li>\n<\/ul>","raw_excerpt":"Official Defen.so connector. One-click connect: managed WAF, upload scan, uptime monitor, brute-force signal, attack log. No config file.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/344919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=344919"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/defenso"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=344919"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=344919"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=344919"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=344919"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=344919"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=344919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}