Defender Pro by WPMU DEV is a premium all-in-one WordPress security plugin built to protect your website from hackers, malware, and other online threats. Designed for ease of use, it combines powerful automated tools with intelligent recommendations to help you identify and fix vulnerabilities before they become a problem. Whether you’re managing a single site or an entire client portfolio, Defender Pro delivers enterprise-grade protection in a simple, user-friendly interface.
What makes Defender Pro stand out is its proactive multilayered defense system, featuring scheduled malware scans, firewall protection, vulnerability detection, and secure repair options. Integrated seamlessly with the WPMU DEV ecosystem, it allows centralized management of multiple sites through a single dashboard — ideal for developers, freelancers, and agencies. With its combination of automation, analytics, and real-time alerts, Defender Pro keeps your WordPress installation fast, safe, and compliant at all times.
What makes Defender Pro stand out is its proactive multilayered defense system, featuring scheduled malware scans, firewall protection, vulnerability detection, and secure repair options. Integrated seamlessly with the WPMU DEV ecosystem, it allows centralized management of multiple sites through a single dashboard — ideal for developers, freelancers, and agencies. With its combination of automation, analytics, and real-time alerts, Defender Pro keeps your WordPress installation fast, safe, and compliant at all times.
Key Features
- Malware Scanning – Perform scheduled or on-demand scans to detect and remove malicious code.
- Global Firewall – Block malicious traffic and safeguard your website from brute-force and DDoS attacks.
- Two-Factor Authentication (2FA) – Add an extra layer of security to user logins.
- Vulnerability Detection – Instantly identify outdated plugins, themes, or core files that may pose security risks.
- Patchstack-Powered Protection – Access an extensive vulnerability database for enhanced threat prevention.
- AntiBot Global Firewall – Automatically block known bots and IPs attempting unauthorized access.
- Login Security & IP Blocking – Limit login attempts, enforce password policies, and block suspicious users.
- Google Blocklist Monitoring – Get notified if your domain is blacklisted by Google or other major authorities.
- Security Recommendations – Receive actionable suggestions to improve your overall site protection.
- Centralized Management – Manage multiple websites and security reports from a single WPMU DEV dashboard.
Technical Details
- Plugin Type: WordPress Security & Malware Protection Plugin
- Compatibility: WordPress 6.0+ and PHP 7.4+
- Integrations: Fully compatible with WPMU DEV suite and major caching/CDN plugins
- Performance: Lightweight, optimized for speed, and compliant with WordPress coding standards
Defender Pro by WPMU DEV is a complete WordPress security plugin offering malware scanning, firewall protection, two-factor authentication, and vulnerability monitoring — keeping your website secure and optimized around the clock.Why choose NulledFire?
- ✅ Original GPL files
- 🛡️ Malware scanned
- 🔄 Updated daily
- 🌐 Unlimited websites
- 🔔 Email notifications
- 🚀 Fast CDN download
What's new in Version 6.2.3
- Enhancement: Improved Audit Log UI across Dashboard and Audit Log pages
- Enhancement: Added a "Save your API keys to load" preview state for Bot Protection CAPTCHA settings
- Enhancement: Updated the event type label in the detailed Audit Log view from 'Content' to 'Context'
- Fix: Resolved an issue where audit log events from multi-event requests were not synchronizing to the Hub
- Fix: Fixed a UI layout issue when editing Nginx configuration under Hardening > Prevent Information Disclosure
- Fix: Addressed a deprecation notice for Webauthn::verify_response()
- Fix: Fixed a visual bug where the "Learn how we detect your IP" link overlapped the background border at 1280px screen widths
- Fix: Minor code improvements
- Enhancement: Added a "Save your API keys to load" preview state for Bot Protection CAPTCHA settings
- Enhancement: Updated the event type label in the detailed Audit Log view from 'Content' to 'Context'
- Fix: Resolved an issue where audit log events from multi-event requests were not synchronizing to the Hub
- Fix: Fixed a UI layout issue when editing Nginx configuration under Hardening > Prevent Information Disclosure
- Fix: Addressed a deprecation notice for Webauthn::verify_response()
- Fix: Fixed a visual bug where the "Learn how we detect your IP" link overlapped the background border at 1280px screen widths
- Fix: Minor code improvements
What's new in Version 6.2.0
- New: Audit Log for Free Hub and WP.org users
- Enhancement: Compatibility with WordPress 7.1
- Enhancement: Replace PHP-DI third-party package with custom lightweight DI Container
- Enhancement: Display the Audit Log Storage retention setting
- Enhancement: Handle UI state when all scan types are disabled on the Settings page
- Enhancement: Update WPMU DEV domain in Audit service codebase
- Enhancement: Validate secret-key API response before writing to wp-config.php
- Enhancement: Improve toast message when attempting to disable the last enabled Malware Scan type
- Enhancement: Remove dash-notice submodule
- Enhancement: Ensure all scan status messages are displayed during scan progress
- Enhancement: Improving user communication while the site is connecting to the Hub
- Fix: Clicking on 'View Logs' link does not filter Firewall Logs after the redirect
- Fix: Security improvements on Hub-Connector (props: Jakub Herman)
- Fix: Prevent adding duplicate recipient email addresses in Reports and Alerts
- Fix: Changing the default report template should not affect existing recipient(s) preferences
- Fix: Fix responsive layout issues on Dashboard, Two-Factor Auth and Other Settings plugin pages
- Fix: Reverting to Defender 5 causes JavaScript errors on the Notifications page
- Fix: Recipients don't receive email for all types of 'Firewall Alert' when a firewall lockout is enabled and triggered for XSS, Fake Bot, or 'Non-installed plugin lockout'
- Fix: Logs are displayed without timezone on Audit and Firewall log pages
- Fix: Improve Malware Alert and Report flow for 'always_send' and 'error_send' params
- Fix: Email notifications title issue with apostrophes
- Fix: The scheduled time notice does not show after the Free upgrade
- Fix: Defender Welcome Modal is displayed in wrong version
- Fix: 3 strings were not imported for translation due to emoji
- Fix: Unable to access the Custom Rules page
- Fix: Force Authentication is not restricted to roles enabled under User Roles
- Fix: Settings page layout breaks at 1280px with horizontal scrollbar
- Fix: Incorrect 'Enable Bot Protection' modal on disabled reCAPTCHA toggles
- Fix: Pagination remains visible after ignoring all files and only disappears after clicking a page
- Fix: Defender Audit Logs creates incorrect and duplicate entries when updating General Settings
- Fix: Minor code improvements
- Enhancement: Compatibility with WordPress 7.1
- Enhancement: Replace PHP-DI third-party package with custom lightweight DI Container
- Enhancement: Display the Audit Log Storage retention setting
- Enhancement: Handle UI state when all scan types are disabled on the Settings page
- Enhancement: Update WPMU DEV domain in Audit service codebase
- Enhancement: Validate secret-key API response before writing to wp-config.php
- Enhancement: Improve toast message when attempting to disable the last enabled Malware Scan type
- Enhancement: Remove dash-notice submodule
- Enhancement: Ensure all scan status messages are displayed during scan progress
- Enhancement: Improving user communication while the site is connecting to the Hub
- Fix: Clicking on 'View Logs' link does not filter Firewall Logs after the redirect
- Fix: Security improvements on Hub-Connector (props: Jakub Herman)
- Fix: Prevent adding duplicate recipient email addresses in Reports and Alerts
- Fix: Changing the default report template should not affect existing recipient(s) preferences
- Fix: Fix responsive layout issues on Dashboard, Two-Factor Auth and Other Settings plugin pages
- Fix: Reverting to Defender 5 causes JavaScript errors on the Notifications page
- Fix: Recipients don't receive email for all types of 'Firewall Alert' when a firewall lockout is enabled and triggered for XSS, Fake Bot, or 'Non-installed plugin lockout'
- Fix: Logs are displayed without timezone on Audit and Firewall log pages
- Fix: Improve Malware Alert and Report flow for 'always_send' and 'error_send' params
- Fix: Email notifications title issue with apostrophes
- Fix: The scheduled time notice does not show after the Free upgrade
- Fix: Defender Welcome Modal is displayed in wrong version
- Fix: 3 strings were not imported for translation due to emoji
- Fix: Unable to access the Custom Rules page
- Fix: Force Authentication is not restricted to roles enabled under User Roles
- Fix: Settings page layout breaks at 1280px with horizontal scrollbar
- Fix: Incorrect 'Enable Bot Protection' modal on disabled reCAPTCHA toggles
- Fix: Pagination remains visible after ignoring all files and only disappears after clicking a page
- Fix: Defender Audit Logs creates incorrect and duplicate entries when updating General Settings
- Fix: Minor code improvements