Defender is WPMU Dev’s security layer, and its design bet is integration: if you run other WPMU Dev plugins – Smush, Hummingbird, SmartCrawl – Defender shares their management surface, and the whole stack reports into one Hub dashboard. Standalone, it covers the standard hardening surface: malware scanning against WordPress.org checksums plus the WPMU Dev vulnerability database, firewall rules for injections and suspicious requests, TOTP and email two-factor authentication, and an activity log detailed enough to restore content changed during a specific window. The guided security checklist walks through the unglamorous hardening steps – disable file editing, hide version strings, secure wp-config.php – that most sites skip. Against checklist-driven rivals like All In One WP Security Pro, Defender’s counterargument is the restorable audit log and ecosystem consolidation.
Its honest position against specialists like Cerber Security Pro: Defender lacks per-page admin access control and live traffic viewing, but its audit UI is cleaner, 2FA ships free without gating, and the 6.2.x line’s audit improvements (sync to Hub, better event context labels) show active maintenance on the logging side – which is the feature most security plugins treat as an afterthought.
Competitive Features
- Checksum + vulnerability dual scanning – core files against WordPress.org, plugins/themes against WPMU Dev’s database
- Free full 2FA – TOTP apps, email codes, and backup codes with no premium gate
- Restore-capable activity log – tracked content changes can be rolled back from the log
- Guided hardening checklist – prioritized actions with explanations, not just toggles
- 404 threshold blocking – IPs generating scanner-style 404 storms get blocked automatically
- Hub integration – multi-site security reporting for WPMU Dev members
- Scheduled audit reports – email digests of security events and scan outcomes
Key Features
- Firewall protection – SQL injection, XSS, and path traversal request filtering
- File integrity monitoring – comparisons against official repository checksums
- Login protection – attempt limits, lockouts, strong password enforcement
- reCAPTCHA v3 – on login, registration, and password reset forms
- IP management – automated blocklist plus manual whitelist/blacklist control
- Security recommendations – prioritized fixes derived from scan results
- Configurable log retention – audit history up to 6 months
Comparison with Competitors
Defender vs Solid Security
| Aspect | Defender | Solid Security |
|---|---|---|
| Malware scanning | Checksums + vulnerability DB | Checksum-based |
| Two-factor auth | Free (TOTP + email) | Free (TOTP) |
| Activity logging | Detailed, restorable | Standard |
| Password policy | No | Yes |
| Version management | No | Yes |
| Multi-site reporting | Via WPMU Dev Hub | Per-site |
Bottom line: Solid Security adds password policy and version management that Defender lacks; Defender answers with restorable audit logs, free email-based 2FA, and the Hub for managing many sites. The WPMU Dev ecosystem lock-in is either the selling point or the dealbreaker.
Defender vs All In One WP Security Pro
| Aspect | Defender | All In One WP Security Pro |
|---|---|---|
| Interface polish | Modern, Hub-connected | Functional, denser |
| Malware scanning | Vulnerability DB integrated | Signature-based |
| Traffic-light checklist | Yes | Yes |
| 2FA | TOTP + email free | TOTP + CAPTCHA |
| Audit log | Restorable | Standard |
| Ecosystem | WPMU Dev suite | Standalone |
Bottom line: All In One WP Security Pro matches most features standalone with its traffic-light audit; Defender’s advantages are the vulnerability database, restorable logs, and multi-site Hub. Both are free-tier friendly – pick by whether you live in the WPMU Dev ecosystem.
Recommended Stack – security detects and blocks; backup recovers. Pair Defender with WPMU Dev Backup for ecosystem-consistent recovery – same dashboard, same support channel, same retention logic.
Official Changelog
Version 6.2.4
Release Date: September 1, 2026
- Fix: Username not appearing in some Audit Log events.
- Fix: Audit module storing un-interpolated
{{user_login}}in some log entries. - Fix: Minor improvements in vulnerability detection.
Version 6.2.3
Release Date: August 31, 2026
- Enhancement: Improved Audit Log UI across Dashboard and Audit Log pages.
- Enhancement: Added a “Save your API keys to load” preview state for Bot Protection CAPTCHA settings.
- Enhancement: Updated the event type label in the detailed Audit Log view from ‘Content’ to ‘Context’.
- Fix: Resolved an issue where audit log events from multi-event requests were not synchronizing to the Hub.
- Fix: Fixed a UI layout issue when editing Nginx configuration under Hardening > Prevent Information Disclosure.
- Fix: Addressed a deprecation notice for
Webauthn::verify_response(). - Fix: Fixed a visual bug where the “Learn how we detect your IP” link overlapped the background border at 1280px screen widths.
Version 6.2.2
Release Date: August 24, 2026
- Fix: Streamlined schema method by removing bootstrap trait.
Frequently Asked Questions
Does Defender replace Wordfence?
It covers the same core surface – malware scanning, firewall, login protection – but not Wordfence’s kernel-level WAF with live traffic view. Defender’s case is the free 2FA, restorable activity logs, and WPMU Dev Hub integration rather than raw firewall depth.
How does the activity log work?
Every user action is logged: content edits, plugin installs, settings changes, login attempts. Filtering by user, date, and action type, with retention up to six months. Content changes tracked in the log can be restored directly – the feature that separates auditing from forensics.
Is two-factor authentication free?
Yes. TOTP via any authenticator app, email-based codes, and backup codes are all included without premium gating – an area where Defender is more generous than several competitors.
What’s the difference between free and Pro?
Core protections – scanning, firewall, 2FA, audit logging – are free. The WPMU Dev membership adds white-label client reporting, advanced scheduling, Hub multi-site management, and support.
How does the malware scanner detect threats?
Three layers: core files verified against WordPress.org checksums, plugin and theme code checked against the WPMU Dev vulnerability database, and pattern scanning for suspicious constructs like eval() with encoded payloads or large base64_decode() strings.

Leave a Reply