{"id":357924,"date":"2026-09-09T13:25:48","date_gmt":"2026-09-09T13:25:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/banana-defender\/"},"modified":"2026-09-18T05:43:06","modified_gmt":"2026-09-18T05:43:06","slug":"banana-defender","status":"publish","type":"plugin","link":"https:\/\/lo.wordpress.org\/plugins\/banana-defender\/","author":23554040,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2026.9.174","stable_tag":"2026.9.174","tested":"7.1.1","requires":"5.6","requires_php":"7.4","requires_plugins":null,"header_name":"Banana Defender","header_author":"flexxDEV, Bastian Ranft","header_description":"WordPress Security \u2014 Made in Germany. Virtual Patching, Attack Surface Reduction, Malware Scanner & more.","assets_banners_color":"f4f1fa","last_updated":"2026-09-18 05:43:06","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/flexx-hosting.de","header_author_uri":"https:\/\/flexx-dev.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":275,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2026.9.100":{"tag":"2026.9.100","author":"flexxdev","date":"2026-09-09 13:25:19","revision":3688360},"2026.9.111":{"tag":"2026.9.111","author":"flexxdev","date":"2026-09-11 15:28:17","revision":3691668},"2026.9.153":{"tag":"2026.9.153","author":"flexxdev","date":"2026-09-16 14:33:08","revision":3698789},"2026.9.171":{"tag":"2026.9.171","author":"flexxdev","date":"2026-09-17 20:28:45","revision":3700944},"2026.9.172":{"tag":"2026.9.172","author":"flexxdev","date":"2026-09-17 20:46:28","revision":3700964},"2026.9.174":{"tag":"2026.9.174","author":"flexxdev","date":"2026-09-18 05:43:06","revision":3701352}},"upgrade_notice":{"2026.8.88":"<p>Feature tiers restructured: Free, Pro, and Agency. 2FA in free version now admin-only.<\/p>","2026.8.87":"<p>Removed style tags from email templates per review feedback.<\/p>","2026.8.86":"<p>WordPress.org review compliance: prefix rename, enqueue fixes, update checker removed.<\/p>","2026.8.82":"<p>Major update: Virtual Patching, File Integrity Monitoring, and Attack Surface Reduction added.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697191,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697191,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3688360,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3688360,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2026.9.100","2026.9.111","2026.9.153","2026.9.171","2026.9.172","2026.9.174"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3697191,"resolution":"1","location":"assets","locale":"","width":1434,"height":840},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3697191,"resolution":"2","location":"assets","locale":"","width":1434,"height":840},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3697191,"resolution":"3","location":"assets","locale":"","width":1434,"height":840},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3697191,"resolution":"4","location":"assets","locale":"","width":1434,"height":840},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3697191,"resolution":"5","location":"assets","locale":"","width":1434,"height":840},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3697191,"resolution":"6","location":"assets","locale":"","width":1434,"height":840}},"screenshots":{"1":"Dashboard Overview \u2014 Setup Wizard and Security Score at a glance","2":"Security Overview \u2014 Threat statistics, system checks and module status grid","3":"Security Settings \u2014 Login Protection with Brute-Force thresholds, 2FA and IP Blacklist","4":"Scanner &amp; Reports \u2014 File Integrity Monitoring with scan results and change detection","5":"License &amp; Support \u2014 Pro license management with account and support access","6":"Virtual Patching \u2014 WAF with SQL Injection, XSS and exploit protection rules"}},"plugin_section":[262246],"plugin_tags":[1174,602,1184,1178,600],"plugin_category":[38,54],"plugin_contributors":[279938],"plugin_business_model":[],"class_list":["post-357924","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-firewall","plugin_tags-login","plugin_tags-malware","plugin_tags-protection","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-flexxdev","plugin_committers-flexxdev"],"banners":{"banner":"https:\/\/ps.w.org\/banana-defender\/assets\/banner-772x250.png?rev=3688360","banner_2x":"https:\/\/ps.w.org\/banana-defender\/assets\/banner-1544x500.png?rev=3688360","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/banana-defender\/assets\/icon-128x128.png?rev=3697191","icon_2x":"https:\/\/ps.w.org\/banana-defender\/assets\/icon-256x256.png?rev=3697191","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/banana-defender\/assets\/screenshot-1.png?rev=3697191","caption":"Dashboard Overview \u2014 Setup Wizard and Security Score at a glance"},{"src":"https:\/\/ps.w.org\/banana-defender\/assets\/screenshot-2.png?rev=3697191","caption":"Security Overview \u2014 Threat statistics, system checks and module status grid"},{"src":"https:\/\/ps.w.org\/banana-defender\/assets\/screenshot-3.png?rev=3697191","caption":"Security Settings \u2014 Login Protection with Brute-Force thresholds, 2FA and IP Blacklist"},{"src":"https:\/\/ps.w.org\/banana-defender\/assets\/screenshot-4.png?rev=3697191","caption":"Scanner &amp; Reports \u2014 File Integrity Monitoring with scan results and change detection"},{"src":"https:\/\/ps.w.org\/banana-defender\/assets\/screenshot-5.png?rev=3697191","caption":"License &amp; Support \u2014 Pro license management with account and support access"},{"src":"https:\/\/ps.w.org\/banana-defender\/assets\/screenshot-6.png?rev=3697191","caption":"Virtual Patching \u2014 WAF with SQL Injection, XSS and exploit protection rules"}],"raw_content":"<!--section=description-->\n<p>Most WordPress security plugins are built for the US market, phone home to external clouds, and drop tracking cookies on your visitors. Banana Defender does none of that.<\/p>\n\n<p><strong>Install the plugin. Launch the wizard. Done in 2 minutes.<\/strong> Your firewall, malware scanner, login protection, and virtual patching are configured \u2014 no cybersecurity degree required. Easy for beginners, fully flexible for pros.<\/p>\n\n<p>Banana Defender runs entirely on your server. No data leaves your site, no cloud dependency, no AV contract needed. 33,000+ known vulnerabilities are blocked automatically through Virtual Patching \u2014 for free. GDPR-compliant and cookie-free from the moment you activate it.<\/p>\n\n<p>Built in Germany by <a href=\"https:\/\/flexx-dev.com\">flexxDEV<\/a>. Because your website's security shouldn't depend on a data center in Virginia.<\/p>\n\n<h4>Why Banana Defender?<\/h4>\n\n<ul>\n<li><strong>Zero Cloud, Zero Tracking, Zero Cookies<\/strong> \u2014 Your data stays on your server. Period. No external connections, no visitor tracking, no cookie banners needed.<\/li>\n<li><strong>Virtual Patching (Free)<\/strong> \u2014 33,000+ known plugin and theme vulnerabilities blocked automatically \u2014 even before the developer releases a fix.<\/li>\n<li><strong>2-Minute Setup Wizard<\/strong> \u2014 Firewall, scanner, login protection \u2014 configured, not complicated. Works for site owners and developers alike.<\/li>\n<li><strong>GDPR-Compliant by Design<\/strong> \u2014 Built with DSGVO compliance as a core principle, not bolted on as an afterthought.<\/li>\n<li><strong>Made in Germany<\/strong> \u2014 Developed by flexxDEV. German engineering for WordPress security.<\/li>\n<li><strong>Lightweight<\/strong> \u2014 No bloat, no performance drag. Your visitors won't notice it. Attackers will.<\/li>\n<\/ul>\n\n<h4>Free Features<\/h4>\n\n<ul>\n<li><strong>Banana Shield (Virtual Patching)<\/strong> \u2014 WAF that automatically blocks exploits for 33,000+ known vulnerabilities<\/li>\n<li><strong>Attack Surface Reduction<\/strong> \u2014 7 hardening rules to lock down your WordPress installation<\/li>\n<li><strong>Malware Scanner<\/strong> \u2014 Detect suspicious files and code patterns before they cause damage<\/li>\n<li><strong>Login Protection<\/strong> \u2014 Brute-force blocking with configurable lockout thresholds<\/li>\n<li><strong>Two-Factor Authentication<\/strong> \u2014 TOTP-based 2FA for administrators<\/li>\n<li><strong>Math CAPTCHA<\/strong> \u2014 Lightweight bot protection for your login form<\/li>\n<li><strong>Custom Login URL<\/strong> \u2014 Hide wp-login.php from automated attacks. Recovery via WP-CLI or wp-config.php constant<\/li>\n<li><strong>Security Headers<\/strong> \u2014 Recommended HTTP security headers, automatically configured<\/li>\n<li><strong>File Integrity Monitoring<\/strong> \u2014 Detect unauthorized changes to WordPress core files<\/li>\n<li><strong>IP Blacklist &amp; Whitelist<\/strong> \u2014 Manual IP access control<\/li>\n<li><strong>Security Score Dashboard<\/strong> \u2014 Your site's security posture at a glance<\/li>\n<li><strong>WP-CLI Support<\/strong> \u2014 Manage Banana Defender from the command line (status, login URL reset)<\/li>\n<li><strong>Setup Wizard<\/strong> \u2014 From zero to protected in under 2 minutes<\/li>\n<\/ul>\n\n<h4>Pro Features (Single License)<\/h4>\n\n<p>Everything in Free, plus:<\/p>\n\n<ul>\n<li><strong>E-Mail Security Alerts<\/strong> \u2014 Instant notifications for attacks, malware findings, and file changes<\/li>\n<li><strong>Scheduled Automatic Scans<\/strong> \u2014 Daily or weekly malware and integrity scans on autopilot<\/li>\n<li><strong>Audit Log<\/strong> \u2014 Complete security event log with 365-day retention<\/li>\n<li><strong>2FA for All User Roles<\/strong> \u2014 Extend two-factor authentication to editors, authors, and all roles<\/li>\n<li><strong>Hourly Vulnerability DB<\/strong> \u2014 Vulnerability database updated every hour instead of only on plugin updates<\/li>\n<li><strong>Vulnerability Auto-Updates<\/strong> \u2014 Automatically update plugins and themes when a security flaw is detected<\/li>\n<li><strong>Auto-Repair &amp; Cleanup<\/strong> \u2014 Automatic malware removal and file restoration<\/li>\n<li><strong>Plugin &amp; Theme Integrity Check<\/strong> \u2014 Verify plugins and themes against their originals<\/li>\n<li><strong>Rate Limiting<\/strong> \u2014 Anti-DoS protection with configurable request limits<\/li>\n<li><strong>Priority Support<\/strong> \u2014 Direct email support from the developer<\/li>\n<\/ul>\n\n<h4>Agency Features (Multi-Site License)<\/h4>\n\n<p>Everything in Pro, plus tools built for professionals managing client sites:<\/p>\n\n<ul>\n<li><strong>Geo-Blocking<\/strong> \u2014 Block traffic from countries with no legitimate visitors<\/li>\n<li><strong>Advanced Bot Detection<\/strong> \u2014 Distinguish real visitors from automated attacks<\/li>\n<li><strong>Passkeys \/ WebAuthn<\/strong> \u2014 Passwordless biometric authentication<\/li>\n<li><strong>Session Management<\/strong> \u2014 Monitor and control active user sessions<\/li>\n<li><strong>CSP Builder<\/strong> \u2014 Visual Content Security Policy configuration<\/li>\n<li><strong>Custom Firewall Rules<\/strong> \u2014 Create your own WAF rules<\/li>\n<li><strong>Live Traffic Viewer<\/strong> \u2014 Real-time traffic monitoring and analysis<\/li>\n<li><strong>PDF Security Reports<\/strong> \u2014 Exportable security reports for your clients<\/li>\n<li><strong>Syslog \/ Fail2Ban Integration<\/strong> \u2014 Connect to external security infrastructure<\/li>\n<li><strong>Salt &amp; Key Rotation<\/strong> \u2014 Automated WordPress security key rotation<\/li>\n<li><strong>Advanced Activity Log<\/strong> \u2014 Extended logging with CSV export and filtering<\/li>\n<li><strong>White-Label<\/strong> \u2014 Custom branding for agencies<\/li>\n<li><strong>WP-CLI Import\/Export<\/strong> \u2014 Configuration portability for bulk deployments<\/li>\n<\/ul>\n\n<h4>Privacy &amp; GDPR<\/h4>\n\n<p>Banana Defender was built with privacy as a non-negotiable. No data leaves your server unless you explicitly opt in to usage analytics via Freemius. All security features work entirely offline. Zero cookies for your visitors.<\/p>\n\n<p>Made in Germany by <a href=\"https:\/\/flexx-dev.com\">flexxDEV<\/a>.<\/p>\n\n<h4>Legal<\/h4>\n\n<ul>\n<li><a href=\"https:\/\/flexx-dev.com\/terms-agb\/\">Terms of Service \/ AGB \/ EULA<\/a><\/li>\n<li><a href=\"https:\/\/flexx-dev.com\/privacy-policy\/\">Privacy Policy \/ Datenschutzerkl\u00e4rung<\/a><\/li>\n<li><a href=\"https:\/\/flexx-dev.com\/impressum\/\">Impressum<\/a><\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin optionally connects to the following external services:<\/p>\n\n<h4>Freemius<\/h4>\n\n<p>When activated, Banana Defender uses the <a href=\"https:\/\/freemius.com\/\">Freemius<\/a> SDK for license management and optional usage analytics. <strong>No data is transmitted without explicit user consent<\/strong> \u2014 an opt-in screen is shown after plugin activation.<\/p>\n\n<p>Data sent after opt-in: site URL, WordPress version, PHP version, plugin version, user email and name.<\/p>\n\n<ul>\n<li><a href=\"https:\/\/freemius.com\/terms\/\">Freemius Terms of Service<\/a><\/li>\n<li><a href=\"https:\/\/freemius.com\/privacy\/\">Freemius Privacy Policy<\/a><\/li>\n<\/ul>\n\n<h4>Vulnerability Database<\/h4>\n\n<p>Banana Defender downloads vulnerability data from the flexxDEV update server to power the virtual patching engine. This connection transmits only the plugin version and WordPress version. No personal or site-identifying data is sent.<\/p>\n\n<ul>\n<li>Server: flexx-hosting.de<\/li>\n<li><a href=\"https:\/\/flexx-dev.com\/privacy-policy\/\">flexxDEV Privacy Policy<\/a><\/li>\n<\/ul>\n\n<h4>WordPress.org API<\/h4>\n\n<p>The File Integrity Monitoring feature retrieves checksums from api.wordpress.org to verify WordPress core files. This transmits your WordPress version and locale. No personal data is sent.<\/p>\n\n<ul>\n<li><a href=\"https:\/\/wordpress.org\/about\/privacy\/\">WordPress.org Privacy Policy<\/a><\/li>\n<\/ul>\n\n<h3>Advanced Configuration<\/h3>\n\n<h4>WP-CLI Commands<\/h4>\n\n<p>Banana Defender registers WP-CLI commands for server-side management. Useful for locked-out situations, automated deployments, and headless administration.<\/p>\n\n\n\n\n  Command\n  Description\n\n\n\n\n  <code>wp banana-defender status<\/code>\n  Show plugin version and module status (enabled\/disabled)\n\n\n  <code>wp banana-defender login-url<\/code>\n  Display the current custom login URL\n\n\n  <code>wp banana-defender reset-login-url<\/code>\n  Disable the custom login URL and restore wp-login.php access\n\n\n\n\n<p>Example \u2014 recover from a forgotten custom login URL:<\/p>\n\n<pre><code>wp banana-defender reset-login-url\n<\/code><\/pre>\n\n<h4>wp-config.php Constants<\/h4>\n\n<p>You can override certain Banana Defender behaviors by defining constants in your <code>wp-config.php<\/code>. Add them <strong>before<\/strong> the <code>\/* That's all, stop editing! *\/<\/code> line.<\/p>\n\n\n\n\n  Constant\n  Value\n  Effect\n\n\n\n\n  <code>BANADE_DISABLE_LOGIN_URL<\/code>\n  <code>true<\/code>\n  Disables the custom login URL feature entirely. wp-login.php becomes accessible again without changing any plugin settings. Use this as an emergency recovery when you forgot your custom login URL and cannot access WP-CLI.\n\n\n\n\n<p>Example \u2014 restore login access via wp-config.php:<\/p>\n\n<pre><code>define( 'BANADE_DISABLE_LOGIN_URL', true );\n<\/code><\/pre>\n\n<p>After regaining access, disable the custom login URL in the plugin settings and remove the constant from wp-config.php.<\/p>\n\n<h3>Haftungsausschluss \/ Disclaimer<\/h3>\n\n<h4>Deutsch<\/h4>\n\n<p>HAFTUNGSAUSSCHLUSS \u2014 BITTE SORGFAELTIG LESEN<\/p>\n\n<p>Dieses Plugin wird \"wie besehen\" (\"as is\") zur Verfuegung gestellt. Die Nutzung erfolgt ausschliesslich auf eigene Gefahr und Verantwortung des Website-Betreibers.<\/p>\n\n<ol>\n<li><p>KEINE GARANTIE FUER ABSOLUTE SICHERHEIT\nKein Sicherheits-Plugin kann einen vollstaendigen oder absoluten Schutz vor Cyberangriffen, Datenverlust, Malware-Infektionen, unbefugtem Zugriff oder sonstigen Sicherheitsvorfaellen garantieren. Banana Defender ist eine ergaenzende Sicherheitsmassnahme und kein Ersatz fuer ein umfassendes Sicherheitskonzept, regelmaessige Backups, sichere Passwoerter, aktualisierte Software und professionelle Sicherheitsberatung.<\/p><\/li>\n<li><p>HAFTUNGSBESCHRAENKUNG\nIm Rahmen der gesetzlich zulaessigen Grenzen uebernimmt der Herausgeber (flexxDEV \/ Bastian Ranft) keine Haftung fuer:<\/p><\/li>\n<\/ol>\n\n<ul>\n<li>Schaeden durch Sicherheitsvorfaelle trotz aktiviertem Plugin, einschliesslich Datenverlust, Datendiebstahl, Website-Defacement, Malware-Infektionen oder Betriebsunterbrechungen;<\/li>\n<li>Schaeden durch falsch-positive oder falsch-negative Ergebnisse der Malware- oder Datei-Integritaetspruefung;<\/li>\n<li>Schaeden durch fehlerhafte, unvollstaendige oder unterlassene Konfiguration durch den Website-Betreiber;<\/li>\n<li>Inkompatibilitaeten mit anderen Plugins, Themes, Hosting-Umgebungen oder Server-Konfigurationen;<\/li>\n<li>Schaeden durch Ausfall, Verzoegerung oder Nichtzustellung von Sicherheitsbenachrichtigungen;<\/li>\n<li>Mittelbare oder unmittelbare Folgeschaeden jeglicher Art, einschliesslich entgangener Gewinne, Umsatzverluste oder Reputationsschaeden.<\/li>\n<\/ul>\n\n<ol>\n<li>VERANTWORTUNG DES NUTZERS\nDer Website-Betreiber ist allein verantwortlich fuer:<\/li>\n<\/ol>\n\n<ul>\n<li>Die ordnungsgemaesse Konfiguration und Wartung des Plugins;<\/li>\n<li>Die regelmaessige Erstellung und Ueberpruefung von Backups;<\/li>\n<li>Die zeitnahe Aktualisierung aller Software-Komponenten (WordPress, Plugins, Themes, PHP);<\/li>\n<li>Die angemessene Reaktion auf Sicherheitswarnungen und Scan-Ergebnisse;<\/li>\n<li>Die Einhaltung geltender Datenschutzgesetze (DSGVO, BDSG) im Zusammenhang mit den vom Plugin verarbeiteten Daten;<\/li>\n<li>Die Einholung professioneller Sicherheitsberatung bei erhoehtem Schutzbedarf.<\/li>\n<\/ul>\n\n<ol>\n<li><p>KEINE RECHTSBERATUNG\nInformationen und Empfehlungen innerhalb des Plugins stellen keine Rechts-, Sicherheits- oder IT-Beratung dar. Bei rechtlichen Fragen oder konkreten Sicherheitsvorfaellen wenden Sie sich an qualifizierte Fachleute.<\/p><\/li>\n<li><p>GEWAEHRLEISTUNGSAUSSCHLUSS\nSoweit gesetzlich zulaessig, wird jede ausdrueckliche oder stillschweigende Gewaehrleistung ausgeschlossen, einschliesslich, aber nicht beschraenkt auf die Gewaehrleistung der Marktgaengigkeit, Eignung fuer einen bestimmten Zweck und Nichtverletzung von Rechten Dritter.<\/p><\/li>\n<li><p>GESETZLICH ZWINGENDE HAFTUNG\nDieser Haftungsausschluss beruehrt nicht die gesetzlich zwingende Haftung, insbesondere nicht die Haftung fuer Vorsatz, grobe Fahrlaessigkeit, Verletzung wesentlicher Vertragspflichten (Kardinalpflichten) sowie die Haftung nach dem Produkthaftungsgesetz und fuer Schaeden aus der Verletzung des Lebens, des Koerpers oder der Gesundheit.<\/p><\/li>\n<\/ol>\n\n<h4>English<\/h4>\n\n<p>DISCLAIMER \u2014 PLEASE READ CAREFULLY<\/p>\n\n<p>This plugin is provided \"as is\" without warranty of any kind. Use is entirely at the website operator's own risk and responsibility.<\/p>\n\n<ol>\n<li><p>NO GUARANTEE OF ABSOLUTE SECURITY\nNo security plugin can guarantee complete or absolute protection against cyber attacks, data loss, malware infections, unauthorized access, or other security incidents. Banana Defender is a supplementary security measure and not a substitute for a comprehensive security concept, regular backups, strong passwords, updated software, and professional security consulting.<\/p><\/li>\n<li><p>LIMITATION OF LIABILITY\nTo the fullest extent permitted by applicable law, the publisher (flexxDEV \/ Bastian Ranft) shall not be liable for:<\/p><\/li>\n<\/ol>\n\n<ul>\n<li>Damages resulting from security incidents despite the plugin being active, including data loss, data theft, website defacement, malware infections, or business interruption;<\/li>\n<li>Damages resulting from false positive or false negative results of malware or file integrity scans;<\/li>\n<li>Damages resulting from incorrect, incomplete, or omitted configuration by the website operator;<\/li>\n<li>Incompatibilities with other plugins, themes, hosting environments, or server configurations;<\/li>\n<li>Damages resulting from failure, delay, or non-delivery of security notifications;<\/li>\n<li>Any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to loss of profits, revenue, or reputation.<\/li>\n<\/ul>\n\n<ol>\n<li>USER RESPONSIBILITY\nThe website operator is solely responsible for:<\/li>\n<\/ol>\n\n<ul>\n<li>Proper configuration and maintenance of the plugin;<\/li>\n<li>Regular creation and verification of backups;<\/li>\n<li>Timely updates of all software components (WordPress, plugins, themes, PHP);<\/li>\n<li>Appropriate response to security warnings and scan results;<\/li>\n<li>Compliance with applicable data protection laws (GDPR) in connection with data processed by the plugin;<\/li>\n<li>Obtaining professional security advice where enhanced protection is required.<\/li>\n<\/ul>\n\n<ol>\n<li><p>NO PROFESSIONAL ADVICE\nInformation and recommendations within the plugin do not constitute legal, security, or IT consulting advice. For legal questions or specific security incidents, consult qualified professionals.<\/p><\/li>\n<li><p>WARRANTY DISCLAIMER\nTo the maximum extent permitted by applicable law, all express or implied warranties are disclaimed, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.<\/p><\/li>\n<li><p>MANDATORY STATUTORY LIABILITY\nThis disclaimer does not affect mandatory statutory liability, in particular liability for intent, gross negligence, breach of essential contractual obligations, liability under product liability law, and liability for damages arising from injury to life, body, or health.<\/p><\/li>\n<\/ol>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>banana-defender<\/code> folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>Navigate to <strong>Banana Defender<\/strong> in the admin sidebar<\/li>\n<li>Follow the Setup Wizard to configure your security settings<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20banana%20defender%20slow%20down%20my%20website%3F\"><h3>Does Banana Defender slow down my website?<\/h3><\/dt>\n<dd><p>No. Banana Defender is built to be invisible to your visitors. All security checks run efficiently with minimal impact on page load times. No external API calls, no cloud roundtrips \u2014 everything happens locally on your server.<\/p><\/dd>\n<dt id=\"is%20banana%20defender%20gdpr-compliant%3F\"><h3>Is Banana Defender GDPR-compliant?<\/h3><\/dt>\n<dd><p>From the moment you activate it. Banana Defender was designed in Germany with GDPR\/DSGVO as a core architecture principle \u2014 not a checkbox added later. No data is sent to external servers without your explicit opt-in. No cookies are set for your visitors. No consent banner needed.<\/p><\/dd>\n<dt id=\"what%20is%20virtual%20patching%3F\"><h3>What is Virtual Patching?<\/h3><\/dt>\n<dd><p>When a vulnerability is discovered in a WordPress plugin or theme, it can take days or weeks until the developer releases a fix. Virtual Patching closes that gap: Banana Defender automatically blocks known exploit patterns at the firewall level \u2014 protecting your site even before an update is available. This covers 33,000+ known vulnerabilities and is included for free.<\/p><\/dd>\n<dt id=\"do%20i%20need%20the%20pro%20or%20agency%20version%3F\"><h3>Do I need the Pro or Agency version?<\/h3><\/dt>\n<dd><p>The free version covers all essential security features, including Virtual Patching, malware scanning, login protection, and 2FA. That's more than most plugins offer in their paid tier. Pro adds automation: scheduled scans, email alerts, audit logging, auto-repair, and hourly vulnerability updates \u2014 set it and forget it. Agency is built for professionals managing client sites: geo-blocking, bot detection, white-label, PDF reports, and WP-CLI support.<\/p><\/dd>\n<dt id=\"can%20i%20use%20banana%20defender%20alongside%20other%20security%20plugins%3F\"><h3>Can I use Banana Defender alongside other security plugins?<\/h3><\/dt>\n<dd><p>We recommend running one security plugin at a time. Multiple firewalls and scanners competing for the same requests create conflicts and false positives. Banana Defender covers firewall, scanner, login protection, 2FA, file integrity, and hardening \u2014 a second security plugin would be redundant.<\/p><\/dd>\n<dt id=\"where%20can%20i%20get%20support%3F\"><h3>Where can I get support?<\/h3><\/dt>\n<dd><p>Free users: <a href=\"https:\/\/wordpress.org\/support\/plugin\/banana-defender\/\">WordPress.org support forum<\/a>. Pro and Agency: priority email support directly from the developer \u2014 typically same-day response.<\/p><\/dd>\n<dt id=\"why%20should%20i%20trust%20a%20new%20security%20plugin%3F\"><h3>Why should I trust a new security plugin?<\/h3><\/dt>\n<dd><p>Fair question. Banana Defender's Virtual Patching engine covers the same vulnerability database that established players use. The firewall rules are updated in real-time. The codebase follows WordPress coding standards and has passed WordPress.org review. And unlike many competitors, we don't require a cloud connection \u2014 which means fewer attack vectors, not more.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2026.9.174<\/h4>\n\n<ul>\n<li>Fix: Fatal Error bei aktiviertem Rate Limiting \u2014 fehlender IP-Parameter bei Whitelist-Pr\u00fcfung behoben<\/li>\n<\/ul>\n\n<h4>2026.9.173<\/h4>\n\n<ul>\n<li>Feature: Rate Limiting \u2014 Anti-DoS-Schutz mit konfigurierbaren Anfragelimits pro Endpunkt (Pro)<\/li>\n<li>Feature: Separate Limits f\u00fcr Login, XML-RPC, REST API und allgemeine Anfragen<\/li>\n<li>Feature: Automatische IP-Sperre bei \u00dcberschreitung mit konfigurierbarer Sperrdauer<\/li>\n<li>Feature: 429 Too Many Requests mit Retry-After Header (HTTP-konform)<\/li>\n<li>Feature: Rate-Limit-Log mit letzten Sperrungen im Admin-Dashboard<\/li>\n<li>Feature: Security Score um Rate Limiting erweitert<\/li>\n<li>UI: Neues Rate Limiting Modul im Sicherheit-Tab mit Master-Detail-Navigation<\/li>\n<li>UI: Dashboard-Modul zeigt echten Rate-Limiting-Status und 24h-Sperrungen<\/li>\n<\/ul>\n\n<h4>2026.9.172<\/h4>\n\n<ul>\n<li>UI: Fehlende PRO-Badges bei 2FA Rollen-Konfiguration, Passkeys\/WebAuthn und Quarantine erg\u00e4nzt<\/li>\n<\/ul>\n\n<h4>2026.9.171<\/h4>\n\n<ul>\n<li>DSGVO: Passkey-Datenschutztext in Datenschutzerkl\u00e4rung erg\u00e4nzt (DE + EN) \u2014 beschreibt gespeicherte Daten, dass Biometrie auf dem Ger\u00e4t verbleibt, und Betroffenenrechte<\/li>\n<li>DSGVO: Rechtsgrundlage korrigiert \u2014 Art. 6(1)(f) berechtigtes Interesse (Erw\u00e4gungsgrund 49) statt Art. 6(1)(a) Einwilligung, konsistent mit allen anderen Sicherheitsfeatures<\/li>\n<li>DSGVO: Klarstellung zu Art. 9 \u2014 biometrische Daten verlassen das Endger\u00e4t nie (vgl. FIDO Alliance GDPR White Paper)<\/li>\n<li>DSGVO: WordPress Privacy Data Exporter um Passkey-Daten erweitert (Name, Erstellungsdatum, letzte Nutzung)<\/li>\n<li>DSGVO: WordPress Privacy Data Eraser l\u00f6scht jetzt auch Passkey-Daten bei L\u00f6schanfrage<\/li>\n<li>DSGVO: delete_user Hook \u2014 Passkey-Daten werden bei Kontol\u00f6schung automatisch entfernt<\/li>\n<li>DSGVO: Speicherdauer f\u00fcr Passkeys im Datenschutztext dokumentiert<\/li>\n<li>Security: Informations-Leaks in Fehlermeldungen entfernt (Origin, DB-Error, Dateipfade, PHP-Typen)<\/li>\n<li>Security: sanitize_text_field() aus auth_verify-Endpunkt entfernt (konsistent mit register_verify)<\/li>\n<li>UI: Passkey-Beschreibung auf Settings-Karte erweitert \u2014 erkl\u00e4rt WebAuthn\/FIDO2-Standard und Ger\u00e4tespeicherung<\/li>\n<li>UI: Button \u201eWeiteren Passkey registrieren\" auf Settings-Karte bei vorhandenen Passkeys<\/li>\n<\/ul>\n\n<h4>2026.9.160<\/h4>\n\n<ul>\n<li>Pro: Passkeys \/ WebAuthn \u2014 Passwortloses Login per Fingerabdruck, Gesichtserkennung oder Hardware-Key<\/li>\n<li>Pro: Mehrere Passkeys pro Benutzer registrierbar mit Verwaltung (Umbenennen\/L\u00f6schen)<\/li>\n<li>Pro: Passkey-Login-Button auf der WordPress-Anmeldeseite<\/li>\n<li>Pro: FIDO2-konforme Implementierung mit CBOR-Decoder und ES256-Signaturverifizierung<\/li>\n<li>Pro: Dashboard-Tile und Security Score (+10 Punkte) f\u00fcr Passkeys<\/li>\n<li>Pro: Audit-Log-Integration f\u00fcr Passkey-Registrierung, -Login und -L\u00f6schung<\/li>\n<\/ul>\n\n<h4>2026.9.159<\/h4>\n\n<ul>\n<li>Pro: 2FA f\u00fcr alle Benutzerrollen \u2014 Rollen-basierte Konfiguration (Aus\/Verf\u00fcgbar\/Erforderlich)<\/li>\n<li>Pro: Administrator-Rolle in 2FA-Konfiguration mit Verf\u00fcgbar\/Erforderlich (kein Aus)<\/li>\n<li>Pro: 2FA-Pflicht mit automatischer Weiterleitung zur Einrichtung beim Login<\/li>\n<li>Pro: Dashboard-Tile \u201e2FA alle Rollen\" zeigt jetzt den tats\u00e4chlichen Status<\/li>\n<\/ul>\n\n<h4>2026.9.157<\/h4>\n\n<ul>\n<li>UI: Audit-Log Aufbewahrung als Segmented Control (Pill-Buttons) statt Dropdown<\/li>\n<li>UI: CSV-Export-Button direkt in der Audit-Log Feature-Karte<\/li>\n<li>UI: Login-Log und Firewall-Log Buttons rechts ausgerichtet<\/li>\n<\/ul>\n\n<h4>2026.9.156<\/h4>\n\n<ul>\n<li>Pro: Audit-Log erweitert \u2014 365 Tage Aufbewahrung (konfigurierbar: 90\/180\/365 Tage)<\/li>\n<li>Pro: Audit-Log Filter \u2014 Nach Ereignis, Benutzer und Datumsbereich filtern<\/li>\n<li>Pro: Audit-Log Pagination \u2014 AJAX-basierte Bl\u00e4tterfunktion (50 Eintr\u00e4ge pro Seite)<\/li>\n<li>Pro: Audit-Log CSV-Export \u2014 Gefilterte Eintr\u00e4ge als CSV herunterladen<\/li>\n<li>Pro: Neue Audit-Events \u2014 Beitr\u00e4ge, Seiten, Medien, Kommentare, Permalinks und weitere Einstellungen<\/li>\n<li>Pro: Audit-Log DB-Index auf user_id f\u00fcr bessere Filter-Performance<\/li>\n<\/ul>\n\n<h4>2026.9.155<\/h4>\n\n<ul>\n<li>Pro: Auto-Update bei Sicherheitsl\u00fccken \u2014 Verwundbare Plugins und Themes automatisch aktualisieren<\/li>\n<li>Pro: UI-Sektion mit Toggle, Status, Verlauf und manueller Ausl\u00f6sung<\/li>\n<li>Pro: Audit-Log-Integration f\u00fcr alle Auto-Updates<\/li>\n<\/ul>\n\n<h4>2026.9.154<\/h4>\n\n<ul>\n<li>Fix: Admin-Hinweise anderer Plugins erscheinen nicht mehr innerhalb der Einrichtungsassistent-Karte<\/li>\n<li>Changelog nachgepflegt f\u00fcr alle Versionen seit 2026.9.138<\/li>\n<\/ul>\n\n<h4>2026.9.153<\/h4>\n\n<ul>\n<li>Pro: E-Mail Security Alerts \u2014 Sofortige Benachrichtigungen bei Angriffen, Malware und Datei\u00e4nderungen<\/li>\n<li>Pro: Automatische Scans \u2014 T\u00e4gliche oder w\u00f6chentliche Malware- und Integrit\u00e4tsscans auf Autopilot<\/li>\n<li>Pro: Auto-Repair &amp; Cleanup \u2014 Automatische Malware-Entfernung und Dateiwiederherstellung<\/li>\n<li>Pro: St\u00fcndliche Vulnerability DB \u2014 Vulnerability-Datenbank mit konfigurierbarem Sync-Intervall (st\u00fcndlich bis t\u00e4glich)<\/li>\n<li>Vulnerability DB: Aktivieren\/Deaktivieren Toggle und w\u00e4hlbares Sync-Intervall<\/li>\n<li>Freemius Opt-in Dialog: Deutsche \u00dcbersetzung f\u00fcr Erst-Installation und Updates<\/li>\n<li>Fix: GET\u2192POST Konvertierung f\u00fcr Freemius Pricing bei Hostern mit ModSecurity<\/li>\n<li>Fix: Stable Tag Warnung auf WordPress.org behoben<\/li>\n<\/ul>\n\n<h4>2026.9.138<\/h4>\n\n<ul>\n<li>WP-CLI support: <code>wp banana-defender status<\/code>, <code>login-url<\/code>, <code>reset-login-url<\/code><\/li>\n<li>Setup wizard button now shows \"Run Wizard Again\" after first completion<\/li>\n<li>Added Advanced Configuration section with WP-CLI commands and wp-config.php constants reference<\/li>\n<\/ul>\n\n<h4>2026.9.106<\/h4>\n\n<ul>\n<li>Admin UI: All tabs now use consistent master-detail sidebar layout<\/li>\n<li>License &amp; Support tab with Account, Plans &amp; Pricing, Support navigation<\/li>\n<li>Scanner &amp; Reports tab with Scanner, Log, Notifications navigation<\/li>\n<li>Freemius sidebar items (Konto, Kontakt, Preise) removed from WordPress admin menu<\/li>\n<li>Plans &amp; Pricing links to flexx-dev.com website instead of Freemius pricing page<\/li>\n<li>VP log table: fixed URL column display on narrow screens<\/li>\n<li>Tab \"Sicherheits\u00fcbersicht\" renamed to \"\u00dcbersicht\"<\/li>\n<\/ul>\n\n<h4>2026.9.100<\/h4>\n\n<ul>\n<li>Setup wizard no longer opens automatically on page load<\/li>\n<\/ul>\n\n<h4>2026.9.99<\/h4>\n\n<ul>\n<li>Fix: Freemius pricing page on hosts with ModSecurity (GET\u2192POST conversion)<\/li>\n<li>Default currency set to EUR<\/li>\n<\/ul>\n\n<h4>2026.9.97<\/h4>\n\n<ul>\n<li>Pro upgrade banner with sliding feature highlights above tab navigation<\/li>\n<\/ul>\n\n<h4>2026.9.96<\/h4>\n\n<ul>\n<li>OPcache invalidation for reliable deployment<\/li>\n<\/ul>\n\n<h4>2026.9.95<\/h4>\n\n<ul>\n<li>Freemius SDK integration for Pro licensing and updates<\/li>\n<li>Pro features (Notifications, Audit Log, 2FA all roles) now use Freemius __premium_only code stripping<\/li>\n<li>Added Pro badges, upgrade CTAs, and lock icons for premium features in admin UI<\/li>\n<li>All premium class references wrapped in class_exists() guards for free build safety<\/li>\n<li>Removed self-hosted updater (replaced by WordPress.org + Freemius update system)<\/li>\n<li>Renamed Ultimate branding to Pro throughout<\/li>\n<\/ul>\n\n<h4>2026.9.93<\/h4>\n\n<ul>\n<li>Added Legal section with links to Terms\/AGB\/EULA, Privacy Policy, and Impressum<\/li>\n<li>Added WordPress.org API disclosure for File Integrity Monitoring checksums<\/li>\n<li>Updated tier naming from \"Ultimate\" to \"Pro \/ Agency\"<\/li>\n<\/ul>\n\n<h4>2026.8.88<\/h4>\n\n<ul>\n<li>Restructured feature tiers: Free, Pro (Single License), Agency (Multi-Site License)<\/li>\n<li>Moved Audit Log, E-Mail Notifications, and full-role 2FA to Pro tier<\/li>\n<li>Free version 2FA now limited to administrators only<\/li>\n<\/ul>\n\n<h4>2026.8.87<\/h4>\n\n<ul>\n<li>Removed email template style tags (review compliance)<\/li>\n<\/ul>\n\n<h4>2026.8.86<\/h4>\n\n<ul>\n<li>Prefix renamed from bd_ to banade_ for WordPress.org compliance<\/li>\n<li>Removed self-hosted update checker<\/li>\n<li>Inline scripts and styles converted to wp_enqueue<\/li>\n<li>File paths updated to use WP_PLUGIN_DIR<\/li>\n<li>Fixed privacy policy URL<\/li>\n<li>Shortened readme short description to under 150 characters<\/li>\n<li>Removed exclusivity claims from readme<\/li>\n<li>Unified log retention to 90 days for all users<\/li>\n<\/ul>\n\n<h4>2026.8.82<\/h4>\n\n<ul>\n<li>Virtual Patching engine with automatic vulnerability protection<\/li>\n<li>File Integrity Monitoring for WordPress core files<\/li>\n<li>Attack Surface Reduction with 7 configurable rules<\/li>\n<li>Freemius SDK integration for premium licensing<\/li>\n<\/ul>\n\n<h4>2026.8.69<\/h4>\n\n<ul>\n<li>Header: Original horizontal Banana Defender logo<\/li>\n<li>Wizard section: Icon and button aligned to top<\/li>\n<\/ul>\n\n<h4>2026.8.68<\/h4>\n\n<ul>\n<li>Wizard colors changed from green to purple (matching BD logo)<\/li>\n<li>Banana Defender logo integrated in header, wizard section and footer<\/li>\n<\/ul>\n\n<h4>2026.8.67<\/h4>\n\n<ul>\n<li>Fix: Email field in Wizard Step 5 no longer overflows on mobile<\/li>\n<\/ul>\n\n<h4>2026.8.66<\/h4>\n\n<ul>\n<li>Wizard texts completely rewritten for less experienced admins<\/li>\n<li>Enable all button moved to section headers<\/li>\n<li>Comprehensive mobile responsivity for the entire plugin<\/li>\n<\/ul>\n\n<h4>2026.8.3<\/h4>\n\n<ul>\n<li>Fix: DB migration now runs on plugin update (not just first activation)<\/li>\n<\/ul>\n\n<h4>2026.8.2<\/h4>\n\n<ul>\n<li>Login Protection \u2014 Brute-Force protection with IP lockout<\/li>\n<\/ul>\n\n<h4>2026.8.1<\/h4>\n\n<ul>\n<li>Initial release \u2014 Plugin skeleton with admin UI<\/li>\n<\/ul>","raw_excerpt":"WordPress Security \u2014 Made in Germany. Firewall, Virtual Patching, Malware Scanner &amp; Login Protection. GDPR-compliant, cookie-free, no cloud.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/357924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=357924"}],"author":[{"embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/flexxdev"}],"wp:attachment":[{"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=357924"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=357924"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=357924"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=357924"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=357924"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=357924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}