Deskripzioa
Most WordPress security plugins are built for the US market, phone home to external clouds, and drop tracking cookies on your visitors. Banana Defender does none of that.
Install the plugin. Launch the wizard. Done in 2 minutes. Your firewall, malware scanner, login protection, and virtual patching are configured — no cybersecurity degree required. Easy for beginners, fully flexible for pros.
Banana Defender runs entirely on your server. No data leaves your site, no cloud dependency, no AV contract needed. 33,000+ known vulnerabilities are blocked automatically through Virtual Patching — for free. GDPR-compliant and cookie-free from the moment you activate it.
Built in Germany by flexxDEV. Because your website’s security shouldn’t depend on a data center in Virginia.
Why Banana Defender?
- Zero Cloud, Zero Tracking, Zero Cookies — Your data stays on your server. Period. No external connections, no visitor tracking, no cookie banners needed.
- Virtual Patching (Free) — 33,000+ known plugin and theme vulnerabilities blocked automatically — even before the developer releases a fix.
- 2-Minute Setup Wizard — Firewall, scanner, login protection — configured, not complicated. Works for site owners and developers alike.
- GDPR-Compliant by Design — Built with DSGVO compliance as a core principle, not bolted on as an afterthought.
- Made in Germany — Developed by flexxDEV. German engineering for WordPress security.
- Lightweight — No bloat, no performance drag. Your visitors won’t notice it. Attackers will.
Free Features
- Banana Shield (Virtual Patching) — WAF that automatically blocks exploits for 33,000+ known vulnerabilities
- Attack Surface Reduction — 7 hardening rules to lock down your WordPress installation
- Malware Scanner — Detect suspicious files and code patterns before they cause damage
- Login Protection — Brute-force blocking with configurable lockout thresholds
- Two-Factor Authentication — TOTP-based 2FA for administrators
- Math CAPTCHA — Lightweight bot protection for your login form
- Custom Login URL — Hide wp-login.php from automated attacks. Recovery via WP-CLI or wp-config.php constant
- Security Headers — Recommended HTTP security headers, automatically configured
- File Integrity Monitoring — Detect unauthorized changes to WordPress core files
- IP Blacklist & Whitelist — Manual IP access control
- Security Score Dashboard — Your site’s security posture at a glance
- WP-CLI Support — Manage Banana Defender from the command line (status, login URL reset)
- Setup Wizard — From zero to protected in under 2 minutes
Pro Features (Single License)
Everything in Free, plus:
- E-Mail Security Alerts — Instant notifications for attacks, malware findings, and file changes
- Scheduled Automatic Scans — Daily or weekly malware and integrity scans on autopilot
- Audit Log — Complete security event log with 365-day retention
- 2FA for All User Roles — Extend two-factor authentication to editors, authors, and all roles
- Hourly Vulnerability DB — Vulnerability database updated every hour instead of only on plugin updates
- Vulnerability Auto-Updates — Automatically update plugins and themes when a security flaw is detected
- Auto-Repair & Cleanup — Automatic malware removal and file restoration
- Plugin & Theme Integrity Check — Verify plugins and themes against their originals
- Rate Limiting — Anti-DoS protection with configurable request limits
- Priority Support — Direct email support from the developer
Agency Features (Multi-Site License)
Everything in Pro, plus tools built for professionals managing client sites:
- Geo-Blocking — Block traffic from countries with no legitimate visitors
- Advanced Bot Detection — Distinguish real visitors from automated attacks
- Passkeys / WebAuthn — Passwordless biometric authentication
- Session Management — Monitor and control active user sessions
- CSP Builder — Visual Content Security Policy configuration
- Custom Firewall Rules — Create your own WAF rules
- Live Traffic Viewer — Real-time traffic monitoring and analysis
- PDF Security Reports — Exportable security reports for your clients
- Syslog / Fail2Ban Integration — Connect to external security infrastructure
- Salt & Key Rotation — Automated WordPress security key rotation
- Advanced Activity Log — Extended logging with CSV export and filtering
- White-Label — Custom branding for agencies
- WP-CLI Import/Export — Configuration portability for bulk deployments
Privacy & GDPR
Banana Defender was built with privacy as a non-negotiable. No data leaves your server unless you explicitly opt in to usage analytics via Freemius. All security features work entirely offline. Zero cookies for your visitors.
Made in Germany by flexxDEV.
Legal
External Services
This plugin optionally connects to the following external services:
Freemius
When activated, Banana Defender uses the Freemius SDK for license management and optional usage analytics. No data is transmitted without explicit user consent — an opt-in screen is shown after plugin activation.
Data sent after opt-in: site URL, WordPress version, PHP version, plugin version, user email and name.
Vulnerability Database
Banana Defender downloads vulnerability data from the flexxDEV update server to power the virtual patching engine. This connection transmits only the plugin version and WordPress version. No personal or site-identifying data is sent.
- Server: flexx-hosting.de
- flexxDEV Privacy Policy
WordPress.org API
The File Integrity Monitoring feature retrieves checksums from api.wordpress.org to verify WordPress core files. This transmits your WordPress version and locale. No personal data is sent.
Advanced Configuration
WP-CLI Commands
Banana Defender registers WP-CLI commands for server-side management. Useful for locked-out situations, automated deployments, and headless administration.
Command
Description
wp banana-defender status
Show plugin version and module status (enabled/disabled)
wp banana-defender login-url
Display the current custom login URL
wp banana-defender reset-login-url
Disable the custom login URL and restore wp-login.php access
Example — recover from a forgotten custom login URL:
wp banana-defender reset-login-url
wp-config.php Constants
You can override certain Banana Defender behaviors by defining constants in your wp-config.php. Add them before the /* That's all, stop editing! */ line.
Constant
Value
Effect
BANADE_DISABLE_LOGIN_URL
true
Disables the custom login URL feature entirely. wp-login.php becomes accessible again without changing any plugin settings. Use this as an emergency recovery when you forgot your custom login URL and cannot access WP-CLI.
Example — restore login access via wp-config.php:
define( 'BANADE_DISABLE_LOGIN_URL', true );
After regaining access, disable the custom login URL in the plugin settings and remove the constant from wp-config.php.
Haftungsausschluss / Disclaimer
Deutsch
HAFTUNGSAUSSCHLUSS — BITTE SORGFAELTIG LESEN
Dieses Plugin wird “wie besehen” (“as is”) zur Verfuegung gestellt. Die Nutzung erfolgt ausschliesslich auf eigene Gefahr und Verantwortung des Website-Betreibers.
-
KEINE GARANTIE FUER ABSOLUTE SICHERHEIT
Kein Sicherheits-Plugin kann einen vollstaendigen oder absoluten Schutz vor Cyberangriffen, Datenverlust, Malware-Infektionen, unbefugtem Zugriff oder sonstigen Sicherheitsvorfaellen garantieren. Banana Defender ist eine ergaenzende Sicherheitsmassnahme und kein Ersatz fuer ein umfassendes Sicherheitskonzept, regelmaessige Backups, sichere Passwoerter, aktualisierte Software und professionelle Sicherheitsberatung. -
HAFTUNGSBESCHRAENKUNG
Im Rahmen der gesetzlich zulaessigen Grenzen uebernimmt der Herausgeber (flexxDEV / Bastian Ranft) keine Haftung fuer:
- Schaeden durch Sicherheitsvorfaelle trotz aktiviertem Plugin, einschliesslich Datenverlust, Datendiebstahl, Website-Defacement, Malware-Infektionen oder Betriebsunterbrechungen;
- Schaeden durch falsch-positive oder falsch-negative Ergebnisse der Malware- oder Datei-Integritaetspruefung;
- Schaeden durch fehlerhafte, unvollstaendige oder unterlassene Konfiguration durch den Website-Betreiber;
- Inkompatibilitaeten mit anderen Plugins, Themes, Hosting-Umgebungen oder Server-Konfigurationen;
- Schaeden durch Ausfall, Verzoegerung oder Nichtzustellung von Sicherheitsbenachrichtigungen;
- Mittelbare oder unmittelbare Folgeschaeden jeglicher Art, einschliesslich entgangener Gewinne, Umsatzverluste oder Reputationsschaeden.
- VERANTWORTUNG DES NUTZERS
Der Website-Betreiber ist allein verantwortlich fuer:
- Die ordnungsgemaesse Konfiguration und Wartung des Plugins;
- Die regelmaessige Erstellung und Ueberpruefung von Backups;
- Die zeitnahe Aktualisierung aller Software-Komponenten (WordPress, Plugins, Themes, PHP);
- Die angemessene Reaktion auf Sicherheitswarnungen und Scan-Ergebnisse;
- Die Einhaltung geltender Datenschutzgesetze (DSGVO, BDSG) im Zusammenhang mit den vom Plugin verarbeiteten Daten;
- Die Einholung professioneller Sicherheitsberatung bei erhoehtem Schutzbedarf.
-
KEINE RECHTSBERATUNG
Informationen und Empfehlungen innerhalb des Plugins stellen keine Rechts-, Sicherheits- oder IT-Beratung dar. Bei rechtlichen Fragen oder konkreten Sicherheitsvorfaellen wenden Sie sich an qualifizierte Fachleute. -
GEWAEHRLEISTUNGSAUSSCHLUSS
Soweit gesetzlich zulaessig, wird jede ausdrueckliche oder stillschweigende Gewaehrleistung ausgeschlossen, einschliesslich, aber nicht beschraenkt auf die Gewaehrleistung der Marktgaengigkeit, Eignung fuer einen bestimmten Zweck und Nichtverletzung von Rechten Dritter. -
GESETZLICH ZWINGENDE HAFTUNG
Dieser Haftungsausschluss beruehrt nicht die gesetzlich zwingende Haftung, insbesondere nicht die Haftung fuer Vorsatz, grobe Fahrlaessigkeit, Verletzung wesentlicher Vertragspflichten (Kardinalpflichten) sowie die Haftung nach dem Produkthaftungsgesetz und fuer Schaeden aus der Verletzung des Lebens, des Koerpers oder der Gesundheit.
English
DISCLAIMER — PLEASE READ CAREFULLY
This plugin is provided “as is” without warranty of any kind. Use is entirely at the website operator’s own risk and responsibility.
-
NO GUARANTEE OF ABSOLUTE SECURITY
No security plugin can guarantee complete or absolute protection against cyber attacks, data loss, malware infections, unauthorized access, or other security incidents. Banana Defender is a supplementary security measure and not a substitute for a comprehensive security concept, regular backups, strong passwords, updated software, and professional security consulting. -
LIMITATION OF LIABILITY
To the fullest extent permitted by applicable law, the publisher (flexxDEV / Bastian Ranft) shall not be liable for:
- Damages resulting from security incidents despite the plugin being active, including data loss, data theft, website defacement, malware infections, or business interruption;
- Damages resulting from false positive or false negative results of malware or file integrity scans;
- Damages resulting from incorrect, incomplete, or omitted configuration by the website operator;
- Incompatibilities with other plugins, themes, hosting environments, or server configurations;
- Damages resulting from failure, delay, or non-delivery of security notifications;
- Any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to loss of profits, revenue, or reputation.
- USER RESPONSIBILITY
The website operator is solely responsible for:
- Proper configuration and maintenance of the plugin;
- Regular creation and verification of backups;
- Timely updates of all software components (WordPress, plugins, themes, PHP);
- Appropriate response to security warnings and scan results;
- Compliance with applicable data protection laws (GDPR) in connection with data processed by the plugin;
- Obtaining professional security advice where enhanced protection is required.
-
NO PROFESSIONAL ADVICE
Information and recommendations within the plugin do not constitute legal, security, or IT consulting advice. For legal questions or specific security incidents, consult qualified professionals. -
WARRANTY DISCLAIMER
To the maximum extent permitted by applicable law, all express or implied warranties are disclaimed, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement. -
MANDATORY STATUTORY LIABILITY
This disclaimer does not affect mandatory statutory liability, in particular liability for intent, gross negligence, breach of essential contractual obligations, liability under product liability law, and liability for damages arising from injury to life, body, or health.
Pantaila-argazkiak






Instalazioa
- Upload the
banana-defenderfolder to/wp-content/plugins/ - Activate the plugin through the ‘Plugins’ menu in WordPress
- Navigate to Banana Defender in the admin sidebar
- Follow the Setup Wizard to configure your security settings
MEG
-
Does Banana Defender slow down my website?
-
No. Banana Defender is built to be invisible to your visitors. All security checks run efficiently with minimal impact on page load times. No external API calls, no cloud roundtrips — everything happens locally on your server.
-
Is Banana Defender GDPR-compliant?
-
From the moment you activate it. Banana Defender was designed in Germany with GDPR/DSGVO as a core architecture principle — not a checkbox added later. No data is sent to external servers without your explicit opt-in. No cookies are set for your visitors. No consent banner needed.
-
What is Virtual Patching?
-
When a vulnerability is discovered in a WordPress plugin or theme, it can take days or weeks until the developer releases a fix. Virtual Patching closes that gap: Banana Defender automatically blocks known exploit patterns at the firewall level — protecting your site even before an update is available. This covers 33,000+ known vulnerabilities and is included for free.
-
Do I need the Pro or Agency version?
-
The free version covers all essential security features, including Virtual Patching, malware scanning, login protection, and 2FA. That’s more than most plugins offer in their paid tier. Pro adds automation: scheduled scans, email alerts, audit logging, auto-repair, and hourly vulnerability updates — set it and forget it. Agency is built for professionals managing client sites: geo-blocking, bot detection, white-label, PDF reports, and WP-CLI support.
-
Can I use Banana Defender alongside other security plugins?
-
We recommend running one security plugin at a time. Multiple firewalls and scanners competing for the same requests create conflicts and false positives. Banana Defender covers firewall, scanner, login protection, 2FA, file integrity, and hardening — a second security plugin would be redundant.
-
Where can I get support?
-
Free users: WordPress.org support forum. Pro and Agency: priority email support directly from the developer — typically same-day response.
-
Why should I trust a new security plugin?
-
Fair question. Banana Defender’s Virtual Patching engine covers the same vulnerability database that established players use. The firewall rules are updated in real-time. The codebase follows WordPress coding standards and has passed WordPress.org review. And unlike many competitors, we don’t require a cloud connection — which means fewer attack vectors, not more.
Berrikuspenak
Ez dago berrikuspenik plugin honentzat.
Laguntzaileak eta Garatzaileak
“Banana Defender – GDPR-Compliant Firewall, Scanner & Virtual Patching for WordPress” software librea da. Ondoko pertsonek egin dizkiote ekarpenak plugin honi.
LaguntzaileakGarapena interesatzen zaizu?
Araka kodea, begiratu SVN biltegia edo harpidetu garapen erregistrora RSS bidez.
Aldaketen loga
2026.9.174
- Fix: Fatal Error bei aktiviertem Rate Limiting — fehlender IP-Parameter bei Whitelist-Prüfung behoben
2026.9.173
- Feature: Rate Limiting — Anti-DoS-Schutz mit konfigurierbaren Anfragelimits pro Endpunkt (Pro)
- Feature: Separate Limits für Login, XML-RPC, REST API und allgemeine Anfragen
- Feature: Automatische IP-Sperre bei Überschreitung mit konfigurierbarer Sperrdauer
- Feature: 429 Too Many Requests mit Retry-After Header (HTTP-konform)
- Feature: Rate-Limit-Log mit letzten Sperrungen im Admin-Dashboard
- Feature: Security Score um Rate Limiting erweitert
- UI: Neues Rate Limiting Modul im Sicherheit-Tab mit Master-Detail-Navigation
- UI: Dashboard-Modul zeigt echten Rate-Limiting-Status und 24h-Sperrungen
2026.9.172
- UI: Fehlende PRO-Badges bei 2FA Rollen-Konfiguration, Passkeys/WebAuthn und Quarantine ergänzt
2026.9.171
- DSGVO: Passkey-Datenschutztext in Datenschutzerklärung ergänzt (DE + EN) — beschreibt gespeicherte Daten, dass Biometrie auf dem Gerät verbleibt, und Betroffenenrechte
- DSGVO: Rechtsgrundlage korrigiert — Art. 6(1)(f) berechtigtes Interesse (Erwägungsgrund 49) statt Art. 6(1)(a) Einwilligung, konsistent mit allen anderen Sicherheitsfeatures
- DSGVO: Klarstellung zu Art. 9 — biometrische Daten verlassen das Endgerät nie (vgl. FIDO Alliance GDPR White Paper)
- DSGVO: WordPress Privacy Data Exporter um Passkey-Daten erweitert (Name, Erstellungsdatum, letzte Nutzung)
- DSGVO: WordPress Privacy Data Eraser löscht jetzt auch Passkey-Daten bei Löschanfrage
- DSGVO: delete_user Hook — Passkey-Daten werden bei Kontolöschung automatisch entfernt
- DSGVO: Speicherdauer für Passkeys im Datenschutztext dokumentiert
- Security: Informations-Leaks in Fehlermeldungen entfernt (Origin, DB-Error, Dateipfade, PHP-Typen)
- Security: sanitize_text_field() aus auth_verify-Endpunkt entfernt (konsistent mit register_verify)
- UI: Passkey-Beschreibung auf Settings-Karte erweitert — erklärt WebAuthn/FIDO2-Standard und Gerätespeicherung
- UI: Button „Weiteren Passkey registrieren” auf Settings-Karte bei vorhandenen Passkeys
2026.9.160
- Pro: Passkeys / WebAuthn — Passwortloses Login per Fingerabdruck, Gesichtserkennung oder Hardware-Key
- Pro: Mehrere Passkeys pro Benutzer registrierbar mit Verwaltung (Umbenennen/Löschen)
- Pro: Passkey-Login-Button auf der WordPress-Anmeldeseite
- Pro: FIDO2-konforme Implementierung mit CBOR-Decoder und ES256-Signaturverifizierung
- Pro: Dashboard-Tile und Security Score (+10 Punkte) für Passkeys
- Pro: Audit-Log-Integration für Passkey-Registrierung, -Login und -Löschung
2026.9.159
- Pro: 2FA für alle Benutzerrollen — Rollen-basierte Konfiguration (Aus/Verfügbar/Erforderlich)
- Pro: Administrator-Rolle in 2FA-Konfiguration mit Verfügbar/Erforderlich (kein Aus)
- Pro: 2FA-Pflicht mit automatischer Weiterleitung zur Einrichtung beim Login
- Pro: Dashboard-Tile „2FA alle Rollen” zeigt jetzt den tatsächlichen Status
2026.9.157
- UI: Audit-Log Aufbewahrung als Segmented Control (Pill-Buttons) statt Dropdown
- UI: CSV-Export-Button direkt in der Audit-Log Feature-Karte
- UI: Login-Log und Firewall-Log Buttons rechts ausgerichtet
2026.9.156
- Pro: Audit-Log erweitert — 365 Tage Aufbewahrung (konfigurierbar: 90/180/365 Tage)
- Pro: Audit-Log Filter — Nach Ereignis, Benutzer und Datumsbereich filtern
- Pro: Audit-Log Pagination — AJAX-basierte Blätterfunktion (50 Einträge pro Seite)
- Pro: Audit-Log CSV-Export — Gefilterte Einträge als CSV herunterladen
- Pro: Neue Audit-Events — Beiträge, Seiten, Medien, Kommentare, Permalinks und weitere Einstellungen
- Pro: Audit-Log DB-Index auf user_id für bessere Filter-Performance
2026.9.155
- Pro: Auto-Update bei Sicherheitslücken — Verwundbare Plugins und Themes automatisch aktualisieren
- Pro: UI-Sektion mit Toggle, Status, Verlauf und manueller Auslösung
- Pro: Audit-Log-Integration für alle Auto-Updates
2026.9.154
- Fix: Admin-Hinweise anderer Plugins erscheinen nicht mehr innerhalb der Einrichtungsassistent-Karte
- Changelog nachgepflegt für alle Versionen seit 2026.9.138
2026.9.153
- Pro: E-Mail Security Alerts — Sofortige Benachrichtigungen bei Angriffen, Malware und Dateiänderungen
- Pro: Automatische Scans — Tägliche oder wöchentliche Malware- und Integritätsscans auf Autopilot
- Pro: Auto-Repair & Cleanup — Automatische Malware-Entfernung und Dateiwiederherstellung
- Pro: Stündliche Vulnerability DB — Vulnerability-Datenbank mit konfigurierbarem Sync-Intervall (stündlich bis täglich)
- Vulnerability DB: Aktivieren/Deaktivieren Toggle und wählbares Sync-Intervall
- Freemius Opt-in Dialog: Deutsche Übersetzung für Erst-Installation und Updates
- Fix: GETPOST Konvertierung für Freemius Pricing bei Hostern mit ModSecurity
- Fix: Stable Tag Warnung auf WordPress.org behoben
2026.9.138
- WP-CLI support:
wp banana-defender status,login-url,reset-login-url - Setup wizard button now shows “Run Wizard Again” after first completion
- Added Advanced Configuration section with WP-CLI commands and wp-config.php constants reference
2026.9.106
- Admin UI: All tabs now use consistent master-detail sidebar layout
- License & Support tab with Account, Plans & Pricing, Support navigation
- Scanner & Reports tab with Scanner, Log, Notifications navigation
- Freemius sidebar items (Konto, Kontakt, Preise) removed from WordPress admin menu
- Plans & Pricing links to flexx-dev.com website instead of Freemius pricing page
- VP log table: fixed URL column display on narrow screens
- Tab “Sicherheitsübersicht” renamed to “Übersicht”
2026.9.100
- Setup wizard no longer opens automatically on page load
2026.9.99
- Fix: Freemius pricing page on hosts with ModSecurity (GETPOST conversion)
- Default currency set to EUR
2026.9.97
- Pro upgrade banner with sliding feature highlights above tab navigation
2026.9.96
- OPcache invalidation for reliable deployment
2026.9.95
- Freemius SDK integration for Pro licensing and updates
- Pro features (Notifications, Audit Log, 2FA all roles) now use Freemius __premium_only code stripping
- Added Pro badges, upgrade CTAs, and lock icons for premium features in admin UI
- All premium class references wrapped in class_exists() guards for free build safety
- Removed self-hosted updater (replaced by WordPress.org + Freemius update system)
- Renamed Ultimate branding to Pro throughout
2026.9.93
- Added Legal section with links to Terms/AGB/EULA, Privacy Policy, and Impressum
- Added WordPress.org API disclosure for File Integrity Monitoring checksums
- Updated tier naming from “Ultimate” to “Pro / Agency”
2026.8.88
- Restructured feature tiers: Free, Pro (Single License), Agency (Multi-Site License)
- Moved Audit Log, E-Mail Notifications, and full-role 2FA to Pro tier
- Free version 2FA now limited to administrators only
2026.8.87
- Removed email template style tags (review compliance)
2026.8.86
- Prefix renamed from bd_ to banade_ for WordPress.org compliance
- Removed self-hosted update checker
- Inline scripts and styles converted to wp_enqueue
- File paths updated to use WP_PLUGIN_DIR
- Fixed privacy policy URL
- Shortened readme short description to under 150 characters
- Removed exclusivity claims from readme
- Unified log retention to 90 days for all users
2026.8.82
- Virtual Patching engine with automatic vulnerability protection
- File Integrity Monitoring for WordPress core files
- Attack Surface Reduction with 7 configurable rules
- Freemius SDK integration for premium licensing
2026.8.69
- Header: Original horizontal Banana Defender logo
- Wizard section: Icon and button aligned to top
2026.8.68
- Wizard colors changed from green to purple (matching BD logo)
- Banana Defender logo integrated in header, wizard section and footer
2026.8.67
- Fix: Email field in Wizard Step 5 no longer overflows on mobile
2026.8.66
- Wizard texts completely rewritten for less experienced admins
- Enable all button moved to section headers
- Comprehensive mobile responsivity for the entire plugin
2026.8.3
- Fix: DB migration now runs on plugin update (not just first activation)
2026.8.2
- Login Protection — Brute-Force protection with IP lockout
2026.8.1
- Initial release — Plugin skeleton with admin UI
