Description
WP Defender Pro – Malware Scanner, Login Security & Firewall scans core, plugin, and theme files for suspicious signatures, compares hashes against the official WordPress repository, and blocks brute-force login attempts using attempt limits, automatic lockout, and two-factor authentication via app. It combines a firewall with a blocked IP list, login URL masking, and scheduled email reports for administrators who need to keep site integrity under continuous control.
Key Features
- Malware scanning
Inspects WordPress files against official hashes and detects injected code in plugins and themes. - Two-factor authentication
Adds a second login step via TOTP-compatible authenticator apps. - Brute-force protection
Limits login attempts per IP and applies temporary lockouts after repeated failures. - Login masking
Replaces the default wp-login.php URL with a custom address, hiding administrative access. - Scheduled reports and logs
Sends periodic summaries of scans, blocked attempts, and security events by email.
Benefits of WP Defender Pro – Malware Scanner, Login Security & Firewall
- Fast threat response
Identifies compromised files before they affect visitors or hurt your Google ranking. - A more discreet admin panel
Reduces exposure of the login screen to bots and automated scanners crawling the internet. - Visibility into incidents
Keeps the person in charge informed about suspicious attempts without needing to manually check the dashboard. - Hardening without complex setup
Applies WordPress security recommendations with direct activation from the plugin interface.
Who Is It For?
- Administrators of institutional sites and stores that handle sensitive customer data.
- Agencies and freelancers responsible for maintaining multiple WordPress sites.
- Bloggers and content creators dealing with constant intrusion attempts on wp-login.
The goal of WP Defender Pro is to centralize malware scanning, brute-force blocking, and WordPress hardening in a single dashboard, eliminating the need to combine several separate tools. The result is a defense layer covering everything from login to file integrity, with automations that reduce the time spent on manual security routines.
Frequently asked questions
Is WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall GPL-licensed?
Yes. WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall on multiple sites?
Yes. You can install WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall cost at Ultrapack?
WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall include updates?
Yes. The current version of WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall is 6.3.0, published at Ultrapack on Sep 22, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall scanned before publication?
Yes. Every version of WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin WPMUDEV WP Defender Pro – Malware Scanner, Login Security & Firewall?
Requires WordPress 6.4 or higher and PHP 8.0.0 or higher.
What changed in this version
Version 6.3.0 2026-09-22
- Enhancement: Update malware signatures
- Enhancement: Make Scan settings uneditable while scanning is in progress
- Enhancement: Upgrade node packages
- Enhancement: Display country name tooltip on country flag hover in Firewall Logs
- Enhancement: Reduce the plugin archive size by removing legacy code in some files
- Enhancement: Translation improvements
- Enhancement: Display scan details of issue with a suspicious code with automatic scrolling
- Enhancement: Update support and product roadmap links
- Enhancement: DOM improvements when Pwned/Strong passwords are enabled
- Enhancement: Style improvements on Issues page
- Enhancement: Scan progress bar improvements
- Enhancement: Placeholder copy for Files, folders and file types field
- Enhancement: Show count of lockouts in the notice within Malicious Bot detector
- Enhancement: Improve config applying message
- Fix: Unlock Pro features on free plan for sites hosted by WPMU DEV
- Fix: Passing null to parameter #1 on class-malicious-bot.php
- Fix: Audit logs are causing an error when updating menu items
- Fix: Defender blocking entire America if Armenia is blocked in geoblocking
- Fix: Messaging missing for the config file imports
- Fix: Defender > Strong passwords option breaks the WP Application Password
- Fix: Dropdown scroll issue in smaller screens
- Fix: Overlapping modals on Dashboard page
- Fix: Minor code improvements
Version 6.2.4 2026-09-01
- Fix: Username does not appear in some Audit Log events
- Fix: Audit module stores un-interpolated {{user_login}} in some logs
- Fix: Minor improvements in vulnerability detection
Version 6.2.3 2026-08-31
- Enhancement: Improved Audit Log UI across Dashboard and Audit Log pages
- Enhancement: Added a "Save your API keys to load" preview state for Bot Protection CAPTCHA settings
- Enhancement: Updated the event type label in the detailed Audit Log view from 'Content' to 'Context'
- Fix: Resolved an issue where audit log events from multi-event requests were not synchronizing to the Hub
- Fix: Fixed a UI layout issue when editing Nginx configuration under Hardening > Prevent Information Disclosure
- Fix: Addressed a deprecation notice for Webauthn::verify_response
- Fix: Fixed a visual bug where the "Learn how we detect your IP" link overlapped the background border at 1280px screen widths
- Fix: Minor code improvements
Version 6.2.2 2026-08-24
- Fix: Streamlined schema method by removing bootstrap trait
Version 6.2.1 2026-08-20
- Fix: 2FA > Web Authentication method binds credential verification to the target user (props: Tai)
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
wp-defender-pro.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
wp-defender-pro.zipand click Install Now. - Click Activate.
Requirements: Requires WordPress 6.4 or higher and PHP 8.0.0 or higher.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready