plugin-icon

Defen.so Connector

Par defenso·
Official Defen.so connector. One-click connect: managed WAF, upload scan, uptime monitor, brute-force signal, attack log. No config file.
Évaluations
Version
1.1.8
Mis à jour récemment
Jul 31, 2026
Defen.so Connector

Defen.so is a developer-first web application security SaaS. This plugin gives your WordPress site real, local protection out of the box, and connects to Defen.so in one click for a managed cloud layer on top — no API key to paste, no config file.

Works standalone — no account required

You do not need a Defen.so account to use the plugin. These features run entirely on your own server, for free, with no sign-up and no limits:

  • Upload scanning — every uploaded file is checked for dangerous extensions and polyglots (magic bytes that disagree with the declared type). Runs on every upload for everyone.
  • Login hardening — per-IP brute-force rate limiting with adjustable attempt count + window, optional reCAPTCHA v3, optional TOTP 2FA.
  • Geo-block — reject requests from any list of countries.
  • Local malware scan — heuristic sweep of your PHP/JS files for common webshell / obfuscation patterns.
  • File-integrity baseline — snapshot your files and compare for changes.
  • Activity log — records the last 100 high-value admin actions locally.

Better when connected (optional)

Connecting a free Defen.so account adds the managed cloud layer — none of it takes anything away from the standalone features above:

  • Managed WAF — blocks SQL injection, XSS, path traversal, bot scanners, mass assignment, using the rule set + custom rules from your Defen.so dashboard.
  • Attack log + uptime monitor — blocked events (including upload blocks) streamed to your dashboard; edge uptime checks.
  • CVE vulnerability lookup — checks your installed plugins/themes against the live CVE feed.

Paid plans (Pro $29/mo, Business $69/mo per site) increase the server-side quotas — monitor interval, log retention, custom-rule count, scan frequency — all of which run on Defen.so infrastructure, not by unlocking code in this plugin.

One-click connect

Click « Connect to Defen.so ». A popup opens at app.defen.so, you sign in (or sign up), authorize the connection, and the popup postMessages a scoped API key back — origin-locked to app.defen.so so no third party can intercept.

Fails-open: if Defen.so is unreachable at request time, the plugin allows the request and ships the log later.

External services

This plugin connects to external services. Here is exactly what is sent, when, and to whom.

1. Defen.so API (app.defen.so) — the plugin’s core service.

  • What it is: the managed WAF, uptime monitoring, and attack-log backend the plugin connects your site to.
  • When data is sent: when you connect your site (one-time OAuth handshake), when the plugin refreshes its cached rule policy, and when a request is blocked/challenged/deceived (attack-log events are batched and sent on shutdown).
  • What is sent: your scoped API token, your site URL, and per-event metadata — HTTP method, URL path, visitor IP, User-Agent, matched rule ID, and the action taken. No request bodies, no cookies, no personal content.
  • Terms: https://defen.so/tos — Privacy: https://defen.so/privacy

2. Google reCAPTCHA (google.com/recaptcha) — optional, only if you enable login hardening with a reCAPTCHA site key.

  • What it is: Google’s bot-detection service, used to score login attempts on wp-login.php.
  • When data is sent: only on the login page, and only if you have entered a reCAPTCHA site key in the plugin settings. If you leave it blank, no request is ever made to Google.
  • What is sent: the reCAPTCHA token and the data Google’s script collects from the login page (per Google’s terms).
  • Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy

3. ip-api.com — optional, only if you enable the geo-block feature.

  • What it is: a free IP-to-country geolocation lookup, used to find the country of a visitor so the geo-block rule can allow or deny it.
  • When data is sent: only when geo-block is enabled and a visitor’s country is not already supplied by your host (e.g. Cloudflare’s country header). The visitor’s IP address is sent for the lookup.
  • What is sent: the visitor’s IP address only.
  • Terms: https://ip-api.com/docs/legal — Privacy: https://ip-api.com/docs/legal
Gratuitsur les plans payants
En procédant à l’installation, vous acceptez les Conditions d’utilisation de WordPress.com ainsi que les Conditions de l’extension tierce.
Testé jusqu’à version
WordPress 7.0.2
Cette extension est disponible en téléchargement pour votre site .