Title: Banana Defender – GDPR-Compliant Firewall, Scanner &amp; Virtual Patching for WordPress
Author: flexxdev
Published: <strong>September 9, 2026</strong>
Last modified: September 29, 2026

---

Search plugins

![](https://ps.w.org/banana-defender/assets/banner-772x250.png?rev=3688360)

![](https://ps.w.org/banana-defender/assets/icon-256x256.png?rev=3697191)

# Banana Defender – GDPR-Compliant Firewall, Scanner & Virtual Patching for WordPress

 By [flexxdev](https://profiles.wordpress.org/flexxdev/)

[Download](https://downloads.wordpress.org/plugin/banana-defender.2026.9.199.zip)

 * [Details](https://pcd.wordpress.org/plugins/banana-defender/#description)
 * [Reviews](https://pcd.wordpress.org/plugins/banana-defender/#reviews)
 *  [Installation](https://pcd.wordpress.org/plugins/banana-defender/#installation)
 * [Development](https://pcd.wordpress.org/plugins/banana-defender/#developers)

 [Support](https://wordpress.org/support/plugin/banana-defender/)

## Description

Most WordPress security plugins are built for the US market, phone home to external
clouds, and drop tracking cookies on your visitors. Banana Defender does none of
that.

**Install the plugin. Launch the wizard. Done in 2 minutes.** Your firewall, malware
scanner, login protection, and virtual patching are configured — no cybersecurity
degree required. Easy for beginners, fully flexible for pros.

Banana Defender runs entirely on your server. No data leaves your site, no cloud
dependency, no AV contract needed. 33,000+ known vulnerabilities are blocked automatically
through Virtual Patching — for free. GDPR-compliant and cookie-free from the moment
you activate it.

Built in Germany by [flexxDEV](https://flexx-dev.com). Because your website’s security
shouldn’t depend on a data center in Virginia.

#### Why Banana Defender?

 * **Zero Cloud, Zero Tracking, Zero Cookies** — Your data stays on your server.
   Period. No external connections, no visitor tracking, no cookie banners needed.
 * **Virtual Patching (Free)** — 33,000+ known plugin and theme vulnerabilities 
   blocked automatically — even before the developer releases a fix.
 * **2-Minute Setup Wizard** — Firewall, scanner, login protection — configured,
   not complicated. Works for site owners and developers alike.
 * **GDPR-Compliant by Design** — Built with DSGVO compliance as a core principle,
   not bolted on as an afterthought.
 * **Made in Germany** — Developed by flexxDEV. German engineering for WordPress
   security.
 * **Lightweight** — No bloat, no performance drag. Your visitors won’t notice it.
   Attackers will.

#### Free Features

 * **Banana Shield (Virtual Patching)** — WAF that automatically blocks exploits
   for 33,000+ known vulnerabilities
 * **Attack Surface Reduction** — 7 hardening rules to lock down your WordPress 
   installation
 * **Malware Scanner** — Detect suspicious files and code patterns before they cause
   damage
 * **Login Protection** — Brute-force blocking with configurable lockout thresholds
 * **Two-Factor Authentication** — TOTP-based 2FA for administrators
 * **Math CAPTCHA** — Lightweight bot protection for your login form
 * **Custom Login URL** — Hide wp-login.php from automated attacks. Recovery via
   WP-CLI or wp-config.php constant
 * **Security Headers** — Recommended HTTP security headers, automatically configured
 * **File Integrity Monitoring** — Detect unauthorized changes to WordPress core
   files
 * **IP Blacklist & Whitelist** — Manual IP access control
 * **Security Score Dashboard** — Your site’s security posture at a glance
 * **WP-CLI Support** — Manage Banana Defender from the command line (status, login
   URL reset)
 * **Setup Wizard** — From zero to protected in under 2 minutes

#### Pro Features (Single License)

Everything in Free, plus:

 * **E-Mail Security Alerts** — Instant notifications for attacks, malware findings,
   and file changes
 * **Scheduled Automatic Scans** — Daily or weekly malware and integrity scans on
   autopilot
 * **Audit Log** — Complete security event log with 365-day retention
 * **2FA for All User Roles** — Extend two-factor authentication to editors, authors,
   and all roles
 * **Hourly Vulnerability DB** — Vulnerability database updated every hour instead
   of only on plugin updates
 * **Vulnerability Auto-Updates** — Automatically update plugins and themes when
   a security flaw is detected
 * **Auto-Repair & Cleanup** — Automatic malware removal and file restoration
 * **Plugin & Theme Integrity Check** — Verify plugins and themes against their 
   originals
 * **Rate Limiting** — Anti-DoS protection with configurable request limits
 * **Priority Support** — Direct email support from the developer

#### Agency Features (Multi-Site License)

Everything in Pro, plus tools built for professionals managing client sites:

 * **Geo-Blocking** — Block traffic from countries with no legitimate visitors
 * **Advanced Bot Detection** — Distinguish real visitors from automated attacks
 * **Passkeys / WebAuthn** — Passwordless biometric authentication
 * **Session Management** — Monitor and control active user sessions
 * **CSP Builder** — Visual Content Security Policy configuration
 * **Custom Firewall Rules** — Create your own WAF rules
 * **Live Traffic Viewer** — Real-time traffic monitoring and analysis
 * **PDF Security Reports** — Exportable security reports for your clients
 * **Syslog / Fail2Ban Integration** — Connect to external security infrastructure
 * **Salt & Key Rotation** — Automated WordPress security key rotation
 * **Advanced Activity Log** — Extended logging with CSV export and filtering
 * **WP-CLI Import/Export** — Configuration portability for bulk deployments

#### Privacy & GDPR

Banana Defender was built with privacy as a non-negotiable. No data leaves your 
server unless you explicitly opt in to usage analytics via Freemius. All security
features work entirely offline. Zero cookies for your visitors.

Made in Germany by [flexxDEV](https://flexx-dev.com).

#### Legal

 * [Terms of Service / AGB / EULA](https://flexx-dev.com/terms-agb/)
 * [Privacy Policy / Datenschutzerklärung](https://flexx-dev.com/privacy-policy/)
 * [Impressum](https://flexx-dev.com/impressum/)

### External Services

This plugin optionally connects to the following external services:

#### Freemius

When activated, Banana Defender uses the [Freemius](https://freemius.com/) SDK for
license management and optional usage analytics. **No data is transmitted without
explicit user consent** — an opt-in screen is shown after plugin activation.

Data sent after opt-in: site URL, WordPress version, PHP version, plugin version,
user email and name.

 * [Freemius Terms of Service](https://freemius.com/terms/)
 * [Freemius Privacy Policy](https://freemius.com/privacy/)

#### Vulnerability Database

Banana Defender downloads vulnerability data from the flexxDEV update server to 
power the virtual patching engine. This connection transmits only the plugin version
and WordPress version. No personal or site-identifying data is sent.

 * Server: flexx-hosting.de
 * [flexxDEV Privacy Policy](https://flexx-dev.com/privacy-policy/)

#### WordPress.org API

The File Integrity Monitoring feature retrieves checksums from api.wordpress.org
to verify WordPress core files. This transmits your WordPress version and locale.
No personal data is sent.

 * [WordPress.org Privacy Policy](https://wordpress.org/about/privacy/)

### Advanced Configuration

#### WP-CLI Commands

Banana Defender registers WP-CLI commands for server-side management. Useful for
locked-out situations, automated deployments, and headless administration.

 Command
 Description

 `wp banana-defender status`
 Show plugin version and module status (enabled/disabled)

 `wp banana-defender login-url`
 Display the current custom login URL

 `wp banana-defender reset-login-url`
 Disable the custom login URL and restore 
wp-login.php access

Example — recover from a forgotten custom login URL:

    ```
    wp banana-defender reset-login-url
    ```

#### wp-config.php Constants

You can override certain Banana Defender behaviors by defining constants in your`
wp-config.php`. Add them **before** the `/* That's all, stop editing! */` line.

 Constant
 Value Effect

 `BANADE_DISABLE_LOGIN_URL`
 `true` Disables the custom login URL feature entirely.
wp-login.php becomes accessible again without changing any plugin settings. Use 
this as an emergency recovery when you forgot your custom login URL and cannot access
WP-CLI.

Example — restore login access via wp-config.php:

    ```
    define( 'BANADE_DISABLE_LOGIN_URL', true );
    ```

After regaining access, disable the custom login URL in the plugin settings and 
remove the constant from wp-config.php.

### Haftungsausschluss / Disclaimer

#### Deutsch

HAFTUNGSAUSSCHLUSS — BITTE SORGFAELTIG LESEN

Dieses Plugin wird “wie besehen” (“as is”) zur Verfuegung gestellt. Die Nutzung 
erfolgt ausschliesslich auf eigene Gefahr und Verantwortung des Website-Betreibers.

 1. KEINE GARANTIE FUER ABSOLUTE SICHERHEIT
     Kein Sicherheits-Plugin kann einen vollstaendigen
    oder absoluten Schutz vor Cyberangriffen, Datenverlust, Malware-Infektionen, unbefugtem
    Zugriff oder sonstigen Sicherheitsvorfaellen garantieren. Banana Defender ist eine
    ergaenzende Sicherheitsmassnahme und kein Ersatz fuer ein umfassendes Sicherheitskonzept,
    regelmaessige Backups, sichere Passwoerter, aktualisierte Software und professionelle
    Sicherheitsberatung.
 2. HAFTUNGSBESCHRAENKUNG
     Im Rahmen der gesetzlich zulaessigen Grenzen uebernimmt 
    der Herausgeber (flexxDEV / Bastian Ranft) keine Haftung fuer:

 * Schaeden durch Sicherheitsvorfaelle trotz aktiviertem Plugin, einschliesslich
   Datenverlust, Datendiebstahl, Website-Defacement, Malware-Infektionen oder Betriebsunterbrechungen;
 * Schaeden durch falsch-positive oder falsch-negative Ergebnisse der Malware- oder
   Datei-Integritaetspruefung;
 * Schaeden durch fehlerhafte, unvollstaendige oder unterlassene Konfiguration durch
   den Website-Betreiber;
 * Inkompatibilitaeten mit anderen Plugins, Themes, Hosting-Umgebungen oder Server-
   Konfigurationen;
 * Schaeden durch Ausfall, Verzoegerung oder Nichtzustellung von Sicherheitsbenachrichtigungen;
 * Mittelbare oder unmittelbare Folgeschaeden jeglicher Art, einschliesslich entgangener
   Gewinne, Umsatzverluste oder Reputationsschaeden.

 1. VERANTWORTUNG DES NUTZERS
     Der Website-Betreiber ist allein verantwortlich fuer:

 * Die ordnungsgemaesse Konfiguration und Wartung des Plugins;
 * Die regelmaessige Erstellung und Ueberpruefung von Backups;
 * Die zeitnahe Aktualisierung aller Software-Komponenten (WordPress, Plugins, Themes,
   PHP);
 * Die angemessene Reaktion auf Sicherheitswarnungen und Scan-Ergebnisse;
 * Die Einhaltung geltender Datenschutzgesetze (DSGVO, BDSG) im Zusammenhang mit
   den vom Plugin verarbeiteten Daten;
 * Die Einholung professioneller Sicherheitsberatung bei erhoehtem Schutzbedarf.

 1. KEINE RECHTSBERATUNG
     Informationen und Empfehlungen innerhalb des Plugins stellen
    keine Rechts-, Sicherheits- oder IT-Beratung dar. Bei rechtlichen Fragen oder konkreten
    Sicherheitsvorfaellen wenden Sie sich an qualifizierte Fachleute.
 2. GEWAEHRLEISTUNGSAUSSCHLUSS
     Soweit gesetzlich zulaessig, wird jede ausdrueckliche
    oder stillschweigende Gewaehrleistung ausgeschlossen, einschliesslich, aber nicht
    beschraenkt auf die Gewaehrleistung der Marktgaengigkeit, Eignung fuer einen bestimmten
    Zweck und Nichtverletzung von Rechten Dritter.
 3. GESETZLICH ZWINGENDE HAFTUNG
     Dieser Haftungsausschluss beruehrt nicht die gesetzlich
    zwingende Haftung, insbesondere nicht die Haftung fuer Vorsatz, grobe Fahrlaessigkeit,
    Verletzung wesentlicher Vertragspflichten (Kardinalpflichten) sowie die Haftung
    nach dem Produkthaftungsgesetz und fuer Schaeden aus der Verletzung des Lebens,
    des Koerpers oder der Gesundheit.

#### English

DISCLAIMER — PLEASE READ CAREFULLY

This plugin is provided “as is” without warranty of any kind. Use is entirely at
the website operator’s own risk and responsibility.

 1. NO GUARANTEE OF ABSOLUTE SECURITY
     No security plugin can guarantee complete or
    absolute protection against cyber attacks, data loss, malware infections, unauthorized
    access, or other security incidents. Banana Defender is a supplementary security
    measure and not a substitute for a comprehensive security concept, regular backups,
    strong passwords, updated software, and professional security consulting.
 2. LIMITATION OF LIABILITY
     To the fullest extent permitted by applicable law, the
    publisher (flexxDEV / Bastian Ranft) shall not be liable for:

 * Damages resulting from security incidents despite the plugin being active, including
   data loss, data theft, website defacement, malware infections, or business interruption;
 * Damages resulting from false positive or false negative results of malware or
   file integrity scans;
 * Damages resulting from incorrect, incomplete, or omitted configuration by the
   website operator;
 * Incompatibilities with other plugins, themes, hosting environments, or server
   configurations;
 * Damages resulting from failure, delay, or non-delivery of security notifications;
 * Any direct, indirect, incidental, special, consequential, or exemplary damages,
   including but not limited to loss of profits, revenue, or reputation.

 1. USER RESPONSIBILITY
     The website operator is solely responsible for:

 * Proper configuration and maintenance of the plugin;
 * Regular creation and verification of backups;
 * Timely updates of all software components (WordPress, plugins, themes, PHP);
 * Appropriate response to security warnings and scan results;
 * Compliance with applicable data protection laws (GDPR) in connection with data
   processed by the plugin;
 * Obtaining professional security advice where enhanced protection is required.

 1. NO PROFESSIONAL ADVICE
     Information and recommendations within the plugin do not
    constitute legal, security, or IT consulting advice. For legal questions or specific
    security incidents, consult qualified professionals.
 2. WARRANTY DISCLAIMER
     To the maximum extent permitted by applicable law, all express
    or implied warranties are disclaimed, including but not limited to implied warranties
    of merchantability, fitness for a particular purpose, and non-infringement.
 3. MANDATORY STATUTORY LIABILITY
     This disclaimer does not affect mandatory statutory
    liability, in particular liability for intent, gross negligence, breach of essential
    contractual obligations, liability under product liability law, and liability for
    damages arising from injury to life, body, or health.

## Screenshots

[⌊Dashboard Overview — Setup Wizard and Security Score at a glance⌉⌊Dashboard Overview—
Setup Wizard and Security Score at a glance⌉[

Dashboard Overview — Setup Wizard and Security Score at a glance

[⌊Security Overview — Threat statistics, system checks and module status grid⌉⌊Security
Overview — Threat statistics, system checks and module status grid⌉[

Security Overview — Threat statistics, system checks and module status grid

[⌊Security Settings — Login Protection with Brute-Force thresholds, 2FA and IP Blacklist⌉⌊
Security Settings — Login Protection with Brute-Force thresholds, 2FA and IP Blacklist⌉[

Security Settings — Login Protection with Brute-Force thresholds, 2FA and IP Blacklist

[⌊Scanner & Reports — File Integrity Monitoring with scan results and change detection⌉⌊
Scanner & Reports — File Integrity Monitoring with scan results and change detection⌉[

Scanner & Reports — File Integrity Monitoring with scan results and change detection

[⌊License & Support — Pro license management with account and support access⌉⌊License&
Support — Pro license management with account and support access⌉[

License & Support — Pro license management with account and support access

[⌊Virtual Patching — WAF with SQL Injection, XSS and exploit protection rules⌉⌊Virtual
Patching — WAF with SQL Injection, XSS and exploit protection rules⌉[

Virtual Patching — WAF with SQL Injection, XSS and exploit protection rules

## Installation

 1. Upload the `banana-defender` folder to `/wp-content/plugins/`
 2. Activate the plugin through the ‘Plugins’ menu in WordPress
 3. Navigate to **Banana Defender** in the admin sidebar
 4. Follow the Setup Wizard to configure your security settings

## FAQ

### Does Banana Defender slow down my website?

No. Banana Defender is built to be invisible to your visitors. All security checks
run efficiently with minimal impact on page load times. No external API calls, no
cloud roundtrips — everything happens locally on your server.

### Is Banana Defender GDPR-compliant?

From the moment you activate it. Banana Defender was designed in Germany with GDPR/
DSGVO as a core architecture principle — not a checkbox added later. No data is 
sent to external servers without your explicit opt-in. No cookies are set for your
visitors. No consent banner needed.

### What is Virtual Patching?

When a vulnerability is discovered in a WordPress plugin or theme, it can take days
or weeks until the developer releases a fix. Virtual Patching closes that gap: Banana
Defender automatically blocks known exploit patterns at the firewall level — protecting
your site even before an update is available. This covers 33,000+ known vulnerabilities
and is included for free.

### Do I need the Pro or Agency version?

The free version covers all essential security features, including Virtual Patching,
malware scanning, login protection, and 2FA. That’s more than most plugins offer
in their paid tier. Pro adds automation: scheduled scans, email alerts, audit logging,
auto-repair, and hourly vulnerability updates — set it and forget it. Agency is 
built for professionals managing client sites: geo-blocking, bot detection, session
management, PDF reports, and WP-CLI support.

### Can I use Banana Defender alongside other security plugins?

We recommend running one security plugin at a time. Multiple firewalls and scanners
competing for the same requests create conflicts and false positives. Banana Defender
covers firewall, scanner, login protection, 2FA, file integrity, and hardening —
a second security plugin would be redundant.

### Where can I get support?

Free users: [WordPress.org support forum](https://wordpress.org/support/plugin/banana-defender/).
Pro and Agency: priority email support directly from the developer — typically same-
day response.

### Why should I trust a new security plugin?

Fair question. Banana Defender’s Virtual Patching engine covers the same vulnerability
database that established players use. The firewall rules are updated in real-time.
The codebase follows WordPress coding standards and has passed WordPress.org review.
And unlike many competitors, we don’t require a cloud connection — which means fewer
attack vectors, not more.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Banana Defender – GDPR-Compliant Firewall, Scanner & Virtual Patching for WordPress”
is open source software. The following people have contributed to this plugin.

Contributors

 *   [ flexxdev ](https://profiles.wordpress.org/flexxdev/)

[Translate “Banana Defender – GDPR-Compliant Firewall, Scanner & Virtual Patching for WordPress” into your language.](https://translate.wordpress.org/projects/wp-plugins/banana-defender)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/banana-defender/), 
check out the [SVN repository](https://plugins.svn.wordpress.org/banana-defender/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/banana-defender/)
by [RSS](https://plugins.trac.wordpress.org/log/banana-defender/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2026.9.199

 * Fix: Freemius premium_slug korrigiert (banana-defender-pro  banana-defender-premium)

#### 2026.9.198

 * Fix: Session Management — Audit-Log-Integration verwendet korrekte public API(
   log_event statt private log)
 * i18n: Neue Audit-Event-Labels für Session-Verwaltung (DE + EN)

#### 2026.9.197

 * Feature: Session Management — Aktive Sitzungen aller Benutzer einsehen und verwalten(
   Pro)
 * Feature: Einzelne Sitzungen oder alle Sitzungen eines Benutzers terminieren
 * Feature: Sitzungslimit — Maximale gleichzeitige Sessions pro Benutzer konfigurierbar(
   1–10)
 * Feature: Automatische Durchsetzung des Sitzungslimits bei neuem Login
 * Feature: Audit-Log-Integration für alle Session-Aktionen (Sitzung beendet, Limit
   durchgesetzt)
 * UI: Session-Karte im Sicherheit-Tab mit Benutzer-Übersicht und Session-Details

#### 2026.9.184

 * Feature: PDF Security Reports — Exportierbare Sicherheitsberichte als PDF (Pro)
 * Feature: Umfassender Bericht mit allen Modulen, Scan-Ergebnissen und Konfigurationsstatus
 * Feature: Professionelles Layout mit Logo, Zeitstempel und Seitennavigation
 * Bibliothek: TCPDF als PDF-Engine gebundelt

#### 2026.9.183

 * Feature: Live Traffic Viewer — Echtzeit-HTTP-Anfragen-Viewer (Pro)
 * Feature: Logging aller HTTP-Requests (ohne statische Assets) via shutdown-Hook
 * Feature: DSGVO-Stufenmodell: Standard anonymisiert, optional volle IP mit Auto-
   Anonymisierung nach 24/48/72h
 * Feature: Bot-Erkennung via User-Agent-Matching (40+ bekannte Bot-Patterns inkl.
   GPTBot, ClaudeBot)
 * Feature: 4 Filter: HTTP-Methode, Status-Code-Gruppen, Request-Typ (Mensch/Bot/
   Blockiert/Gedrosselt/404), Freitextsuche
 * Feature: 5-Sekunden-Live-Polling mit Page Visibility API (pausiert bei unsichtbarem
   Tab)
 * Feature: Konfigurierbare Retention (7/14/30 Tage) mit gebatchtem Cron-Cleanup
 * Feature: Integration mit Rate Limiting und Custom Firewall (blockiert/gedrosselt-
   Markierung)
 * Hinweis: Standard-IP-Modus ist anonymisiert (letztes Oktett genullt). Volle IPs
   nur nach Rechtsgrundlage-Bestätigung

#### 2026.9.180

 * Feature: CSP Builder — Content-Security-Policy Header-Verwaltung (Pro)
 * Feature: 8 konfigurierbare CSP-Direktiven (default-src, script-src, style-src,
   img-src, font-src, connect-src, frame-src, object-src)
 * Feature: Report-Only und Enforce Modus mit sicherem Default (Report-Only)
 * Feature: 3 Presets (Minimal, Standard, Strikt) als Startpunkt
 * Feature: Automatische Nonce-Injection für WordPress-Scripts via Hooks
 * Feature: Violation-Reporting mit eigenem AJAX-Endpoint und DB-Tabelle
 * Feature: Violations-Tab mit Pagination und Aufräumfunktion
 * Feature: Zusatzoptionen: upgrade-insecure-requests, block-all-mixed-content, 
   frame-ancestors
 * Hinweis: CSP gilt nur im Frontend, wp-admin ist ausgeschlossen
 * DB: Eigene Tabelle für CSP-Violation-Reports

#### 2026.9.179

 * Feature: Custom Firewall Rules — eigene Blockierregeln erstellen (Pro)
 * Feature: Regeln basierend auf URL-Pfad, Query-String, User-Agent, Referer, HTTP-
   Methode oder IP/IP-Range
 * Feature: Vergleichsoperatoren: enthält, beginnt mit, endet mit, exakt, Regex
 * Feature: AND-Logik für mehrere Bedingungen pro Regel
 * Feature: Block (403) oder Log-Only Modus pro Regel
 * Feature: Hit-Counter und Toggle für jede Regel
 * DB: Eigene Tabelle für Custom Firewall Rules

#### 2026.9.177

 * Feature: Plugin & Theme Integrity Check — vergleicht installierte Plugins/Themes
   gegen WordPress.org-Originale per SHA-256
 * Feature: Automatische Erkennung von WP.org-Plugins über Update-Transients
 * Feature: Repair-Funktion — manipulierte Dateien direkt von WordPress.org wiederherstellen
 * Feature: Theme-Verifizierung per ZIP-Download (Pro)
 * Feature: Info-Box erklärt dem User, was geprüft wird und was nicht (eigene/Premium-
   Plugins/Themes)
 * DB: Eigene Tabelle für Integrity-Scan-Ergebnisse

#### 2026.9.176

 * UI: Login-Schutz Eingabefelder auf kompaktes 2-Spalten Grid umgestellt (wie Rate
   Limiting)

#### 2026.9.175

 * UI: Rate Limiting Layout auf kompaktes 2×2 Grid umgestellt — bessere Platzausnutzung

#### 2026.9.174

 * Fix: Fatal Error bei aktiviertem Rate Limiting — fehlender IP-Parameter bei Whitelist-
   Prüfung behoben

#### 2026.9.173

 * Feature: Rate Limiting — Anti-DoS-Schutz mit konfigurierbaren Anfragelimits pro
   Endpunkt (Pro)
 * Feature: Separate Limits für Login, XML-RPC, REST API und allgemeine Anfragen
 * Feature: Automatische IP-Sperre bei Überschreitung mit konfigurierbarer Sperrdauer
 * Feature: 429 Too Many Requests mit Retry-After Header (HTTP-konform)
 * Feature: Rate-Limit-Log mit letzten Sperrungen im Admin-Dashboard
 * Feature: Security Score um Rate Limiting erweitert
 * UI: Neues Rate Limiting Modul im Sicherheit-Tab mit Master-Detail-Navigation
 * UI: Dashboard-Modul zeigt echten Rate-Limiting-Status und 24h-Sperrungen

#### 2026.9.172

 * UI: Fehlende PRO-Badges bei 2FA Rollen-Konfiguration, Passkeys/WebAuthn und Quarantine
   ergänzt

#### 2026.9.171

 * DSGVO: Passkey-Datenschutztext in Datenschutzerklärung ergänzt (DE + EN) — beschreibt
   gespeicherte Daten, dass Biometrie auf dem Gerät verbleibt, und Betroffenenrechte
 * DSGVO: Rechtsgrundlage korrigiert — Art. 6(1)(f) berechtigtes Interesse (Erwägungsgrund
   49) statt Art. 6(1)(a) Einwilligung, konsistent mit allen anderen Sicherheitsfeatures
 * DSGVO: Klarstellung zu Art. 9 — biometrische Daten verlassen das Endgerät nie(
   vgl. FIDO Alliance GDPR White Paper)
 * DSGVO: WordPress Privacy Data Exporter um Passkey-Daten erweitert (Name, Erstellungsdatum,
   letzte Nutzung)
 * DSGVO: WordPress Privacy Data Eraser löscht jetzt auch Passkey-Daten bei Löschanfrage
 * DSGVO: delete_user Hook — Passkey-Daten werden bei Kontolöschung automatisch 
   entfernt
 * DSGVO: Speicherdauer für Passkeys im Datenschutztext dokumentiert
 * Security: Informations-Leaks in Fehlermeldungen entfernt (Origin, DB-Error, Dateipfade,
   PHP-Typen)
 * Security: sanitize_text_field() aus auth_verify-Endpunkt entfernt (konsistent
   mit register_verify)
 * UI: Passkey-Beschreibung auf Settings-Karte erweitert — erklärt WebAuthn/FIDO2-
   Standard und Gerätespeicherung
 * UI: Button „Weiteren Passkey registrieren” auf Settings-Karte bei vorhandenen
   Passkeys

#### 2026.9.160

 * Pro: Passkeys / WebAuthn — Passwortloses Login per Fingerabdruck, Gesichtserkennung
   oder Hardware-Key
 * Pro: Mehrere Passkeys pro Benutzer registrierbar mit Verwaltung (Umbenennen/Löschen)
 * Pro: Passkey-Login-Button auf der WordPress-Anmeldeseite
 * Pro: FIDO2-konforme Implementierung mit CBOR-Decoder und ES256-Signaturverifizierung
 * Pro: Dashboard-Tile und Security Score (+10 Punkte) für Passkeys
 * Pro: Audit-Log-Integration für Passkey-Registrierung, -Login und -Löschung

#### 2026.9.159

 * Pro: 2FA für alle Benutzerrollen — Rollen-basierte Konfiguration (Aus/Verfügbar/
   Erforderlich)
 * Pro: Administrator-Rolle in 2FA-Konfiguration mit Verfügbar/Erforderlich (kein
   Aus)
 * Pro: 2FA-Pflicht mit automatischer Weiterleitung zur Einrichtung beim Login
 * Pro: Dashboard-Tile „2FA alle Rollen” zeigt jetzt den tatsächlichen Status

#### 2026.9.157

 * UI: Audit-Log Aufbewahrung als Segmented Control (Pill-Buttons) statt Dropdown
 * UI: CSV-Export-Button direkt in der Audit-Log Feature-Karte
 * UI: Login-Log und Firewall-Log Buttons rechts ausgerichtet

#### 2026.9.156

 * Pro: Audit-Log erweitert — 365 Tage Aufbewahrung (konfigurierbar: 90/180/365 
   Tage)
 * Pro: Audit-Log Filter — Nach Ereignis, Benutzer und Datumsbereich filtern
 * Pro: Audit-Log Pagination — AJAX-basierte Blätterfunktion (50 Einträge pro Seite)
 * Pro: Audit-Log CSV-Export — Gefilterte Einträge als CSV herunterladen
 * Pro: Neue Audit-Events — Beiträge, Seiten, Medien, Kommentare, Permalinks und
   weitere Einstellungen
 * Pro: Audit-Log DB-Index auf user_id für bessere Filter-Performance

#### 2026.9.155

 * Pro: Auto-Update bei Sicherheitslücken — Verwundbare Plugins und Themes automatisch
   aktualisieren
 * Pro: UI-Sektion mit Toggle, Status, Verlauf und manueller Auslösung
 * Pro: Audit-Log-Integration für alle Auto-Updates

#### 2026.9.154

 * Fix: Admin-Hinweise anderer Plugins erscheinen nicht mehr innerhalb der Einrichtungsassistent-
   Karte
 * Changelog nachgepflegt für alle Versionen seit 2026.9.138

#### 2026.9.153

 * Pro: E-Mail Security Alerts — Sofortige Benachrichtigungen bei Angriffen, Malware
   und Dateiänderungen
 * Pro: Automatische Scans — Tägliche oder wöchentliche Malware- und Integritätsscans
   auf Autopilot
 * Pro: Auto-Repair & Cleanup — Automatische Malware-Entfernung und Dateiwiederherstellung
 * Pro: Stündliche Vulnerability DB — Vulnerability-Datenbank mit konfigurierbarem
   Sync-Intervall (stündlich bis täglich)
 * Vulnerability DB: Aktivieren/Deaktivieren Toggle und wählbares Sync-Intervall
 * Freemius Opt-in Dialog: Deutsche Übersetzung für Erst-Installation und Updates
 * Fix: GETPOST Konvertierung für Freemius Pricing bei Hostern mit ModSecurity
 * Fix: Stable Tag Warnung auf WordPress.org behoben

#### 2026.9.138

 * WP-CLI support: `wp banana-defender status`, `login-url`, `reset-login-url`
 * Setup wizard button now shows “Run Wizard Again” after first completion
 * Added Advanced Configuration section with WP-CLI commands and wp-config.php constants
   reference

#### 2026.9.106

 * Admin UI: All tabs now use consistent master-detail sidebar layout
 * License & Support tab with Account, Plans & Pricing, Support navigation
 * Scanner & Reports tab with Scanner, Log, Notifications navigation
 * Freemius sidebar items (Konto, Kontakt, Preise) removed from WordPress admin 
   menu
 * Plans & Pricing links to flexx-dev.com website instead of Freemius pricing page
 * VP log table: fixed URL column display on narrow screens
 * Tab “Sicherheitsübersicht” renamed to “Übersicht”

#### 2026.9.100

 * Setup wizard no longer opens automatically on page load

#### 2026.9.99

 * Fix: Freemius pricing page on hosts with ModSecurity (GETPOST conversion)
 * Default currency set to EUR

#### 2026.9.97

 * Pro upgrade banner with sliding feature highlights above tab navigation

#### 2026.9.96

 * OPcache invalidation for reliable deployment

#### 2026.9.95

 * Freemius SDK integration for Pro licensing and updates
 * Pro features (Notifications, Audit Log, 2FA all roles) now use Freemius __premium_only
   code stripping
 * Added Pro badges, upgrade CTAs, and lock icons for premium features in admin 
   UI
 * All premium class references wrapped in class_exists() guards for free build 
   safety
 * Removed self-hosted updater (replaced by WordPress.org + Freemius update system)
 * Renamed Ultimate branding to Pro throughout

#### 2026.9.93

 * Added Legal section with links to Terms/AGB/EULA, Privacy Policy, and Impressum
 * Added WordPress.org API disclosure for File Integrity Monitoring checksums
 * Updated tier naming from “Ultimate” to “Pro / Agency”

#### 2026.8.88

 * Restructured feature tiers: Free, Pro (Single License), Agency (Multi-Site License)
 * Moved Audit Log, E-Mail Notifications, and full-role 2FA to Pro tier
 * Free version 2FA now limited to administrators only

#### 2026.8.87

 * Removed email template style tags (review compliance)

#### 2026.8.86

 * Prefix renamed from bd_ to banade_ for WordPress.org compliance
 * Removed self-hosted update checker
 * Inline scripts and styles converted to wp_enqueue
 * File paths updated to use WP_PLUGIN_DIR
 * Fixed privacy policy URL
 * Shortened readme short description to under 150 characters
 * Removed exclusivity claims from readme
 * Unified log retention to 90 days for all users

#### 2026.8.82

 * Virtual Patching engine with automatic vulnerability protection
 * File Integrity Monitoring for WordPress core files
 * Attack Surface Reduction with 7 configurable rules
 * Freemius SDK integration for premium licensing

#### 2026.8.69

 * Header: Original horizontal Banana Defender logo
 * Wizard section: Icon and button aligned to top

#### 2026.8.68

 * Wizard colors changed from green to purple (matching BD logo)
 * Banana Defender logo integrated in header, wizard section and footer

#### 2026.8.67

 * Fix: Email field in Wizard Step 5 no longer overflows on mobile

#### 2026.8.66

 * Wizard texts completely rewritten for less experienced admins
 * Enable all button moved to section headers
 * Comprehensive mobile responsivity for the entire plugin

#### 2026.8.3

 * Fix: DB migration now runs on plugin update (not just first activation)

#### 2026.8.2

 * Login Protection — Brute-Force protection with IP lockout

#### 2026.8.1

 * Initial release — Plugin skeleton with admin UI

## Meta

 *  Version **2026.9.199**
 *  Last updated **4 days ago**
 *  Active installations **10+**
 *  WordPress version ** 5.6 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/banana-defender/)
 * Tags
 * [firewall](https://pcd.wordpress.org/plugins/tags/firewall/)[login](https://pcd.wordpress.org/plugins/tags/login/)
   [malware](https://pcd.wordpress.org/plugins/tags/malware/)[protection](https://pcd.wordpress.org/plugins/tags/protection/)
   [security](https://pcd.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://pcd.wordpress.org/plugins/banana-defender/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/banana-defender/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/banana-defender/reviews/)

## Contributors

 *   [ flexxdev ](https://profiles.wordpress.org/flexxdev/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/banana-defender/)