BACK TO DIRECTORY

Banana Defender – GDPR-Compliant Firewall, Scanner & Virtual Patching for WordPress

by flexxdev

0.0
(0 ratings)

Most WordPress security plugins are built for the US market, phone home to external clouds, and drop tracking cookies on your visitors. Banana Defender does none of that.

Install the plugin. Launch the wizard. Done in 2 minutes. Your firewall, malware scanner, login protection, and virtual patching are configured — no cybersecurity degree required. Easy for beginners, fully flexible for pros.

Banana Defender runs entirely on your server. No data leaves your site, no cloud dependency, no AV contract needed. 33,000+ known vulnerabilities are blocked automatically through Virtual Patching — for free. GDPR-compliant and cookie-free from the moment you activate it.

Built in Germany by flexxDEV. Because your website’s security shouldn’t depend on a data center in Virginia.

Why Banana Defender?

  • Zero Cloud, Zero Tracking, Zero Cookies — Your data stays on your server. Period. No external connections, no visitor tracking, no cookie banners needed.
  • Virtual Patching (Free) — 33,000+ known plugin and theme vulnerabilities blocked automatically — even before the developer releases a fix.
  • 2-Minute Setup Wizard — Firewall, scanner, login protection — configured, not complicated. Works for site owners and developers alike.
  • GDPR-Compliant by Design — Built with DSGVO compliance as a core principle, not bolted on as an afterthought.
  • Made in Germany — Developed by flexxDEV. German engineering for WordPress security.
  • Lightweight — No bloat, no performance drag. Your visitors won’t notice it. Attackers will.

Free Features

  • Banana Shield (Virtual Patching) — WAF that automatically blocks exploits for 33,000+ known vulnerabilities
  • Attack Surface Reduction — 7 hardening rules to lock down your WordPress installation
  • Malware Scanner — Detect suspicious files and code patterns before they cause damage
  • Login Protection — Brute-force blocking with configurable lockout thresholds
  • Two-Factor Authentication — TOTP-based 2FA for administrators
  • Math CAPTCHA — Lightweight bot protection for your login form
  • Custom Login URL — Hide wp-login.php from automated attacks. Recovery via WP-CLI or wp-config.php constant
  • Security Headers — Recommended HTTP security headers, automatically configured
  • File Integrity Monitoring — Detect unauthorized changes to WordPress core files
  • IP Blacklist & Whitelist — Manual IP access control
  • Security Score Dashboard — Your site’s security posture at a glance
  • WP-CLI Support — Manage Banana Defender from the command line (status, login URL reset)
  • Setup Wizard — From zero to protected in under 2 minutes

Pro Features (Single License)

Everything in Free, plus:

  • E-Mail Security Alerts — Instant notifications for attacks, malware findings, and file changes
  • Scheduled Automatic Scans — Daily or weekly malware and integrity scans on autopilot
  • Audit Log — Complete security event log with 365-day retention
  • 2FA for All User Roles — Extend two-factor authentication to editors, authors, and all roles
  • Hourly Vulnerability DB — Vulnerability database updated every hour instead of only on plugin updates
  • Real-time WAF Rules — WAF rule updates pushed to your site in real-time
  • Auto-Repair & Cleanup — Automatic malware removal and file restoration
  • Plugin & Theme Integrity Check — Verify plugins and themes against their originals
  • Rate Limiting — Anti-DoS protection with configurable request limits
  • Priority Support — Direct email support from the developer

Agency Features (Multi-Site License)

Everything in Pro, plus tools built for professionals managing client sites:

  • Geo-Blocking — Block traffic from countries with no legitimate visitors
  • Advanced Bot Detection — Distinguish real visitors from automated attacks
  • Passkeys / WebAuthn — Passwordless biometric authentication
  • Session Management — Monitor and control active user sessions
  • CSP Builder — Visual Content Security Policy configuration
  • Custom Firewall Rules — Create your own WAF rules
  • Live Traffic Viewer — Real-time traffic monitoring and analysis
  • PDF Security Reports — Exportable security reports for your clients
  • Syslog / Fail2Ban Integration — Connect to external security infrastructure
  • Salt & Key Rotation — Automated WordPress security key rotation
  • Advanced Activity Log — Extended logging with CSV export and filtering
  • White-Label — Custom branding for agencies
  • WP-CLI Import/Export — Configuration portability for bulk deployments

Privacy & GDPR

Banana Defender was built with privacy as a non-negotiable. No data leaves your server unless you explicitly opt in to usage analytics via Freemius. All security features work entirely offline. Zero cookies for your visitors.

Made in Germany by flexxDEV.

Legal

External Services

This plugin optionally connects to the following external services:

Freemius

When activated, Banana Defender uses the Freemius SDK for license management and optional usage analytics. No data is transmitted without explicit user consent — an opt-in screen is shown after plugin activation.

Data sent after opt-in: site URL, WordPress version, PHP version, plugin version, user email and name.

Vulnerability Database

Banana Defender downloads vulnerability data from the flexxDEV update server to power the virtual patching engine. This connection transmits only the plugin version and WordPress version. No personal or site-identifying data is sent.

WordPress.org API

The File Integrity Monitoring feature retrieves checksums from api.wordpress.org to verify WordPress core files. This transmits your WordPress version and locale. No personal data is sent.

Advanced Configuration

WP-CLI Commands

Banana Defender registers WP-CLI commands for server-side management. Useful for locked-out situations, automated deployments, and headless administration.

Command
Description

wp banana-defender status
Show plugin version and module status (enabled/disabled)

wp banana-defender login-url
Display the current custom login URL

wp banana-defender reset-login-url
Disable the custom login URL and restore wp-login.php access

Example — recover from a forgotten custom login URL:

wp banana-defender reset-login-url

wp-config.php Constants

You can override certain Banana Defender behaviors by defining constants in your wp-config.php. Add them before the /* That's all, stop editing! */ line.

Constant
Value
Effect

BANADE_DISABLE_LOGIN_URL
true
Disables the custom login URL feature entirely. wp-login.php becomes accessible again without changing any plugin settings. Use this as an emergency recovery when you forgot your custom login URL and cannot access WP-CLI.

Example — restore login access via wp-config.php:

define( 'BANADE_DISABLE_LOGIN_URL', true );

After regaining access, disable the custom login URL in the plugin settings and remove the constant from wp-config.php.

Haftungsausschluss / Disclaimer

Deutsch

HAFTUNGSAUSSCHLUSS — BITTE SORGFAELTIG LESEN

Dieses Plugin wird “wie besehen” (“as is”) zur Verfuegung gestellt. Die Nutzung erfolgt ausschliesslich auf eigene Gefahr und Verantwortung des Website-Betreibers.

  1. KEINE GARANTIE FUER ABSOLUTE SICHERHEIT
    Kein Sicherheits-Plugin kann einen vollstaendigen oder absoluten Schutz vor Cyberangriffen, Datenverlust, Malware-Infektionen, unbefugtem Zugriff oder sonstigen Sicherheitsvorfaellen garantieren. Banana Defender ist eine ergaenzende Sicherheitsmassnahme und kein Ersatz fuer ein umfassendes Sicherheitskonzept, regelmaessige Backups, sichere Passwoerter, aktualisierte Software und professionelle Sicherheitsberatung.

  2. HAFTUNGSBESCHRAENKUNG
    Im Rahmen der gesetzlich zulaessigen Grenzen uebernimmt der Herausgeber (flexxDEV / Bastian Ranft) keine Haftung fuer:

  • Schaeden durch Sicherheitsvorfaelle trotz aktiviertem Plugin, einschliesslich Datenverlust, Datendiebstahl, Website-Defacement, Malware-Infektionen oder Betriebsunterbrechungen;
  • Schaeden durch falsch-positive oder falsch-negative Ergebnisse der Malware- oder Datei-Integritaetspruefung;
  • Schaeden durch fehlerhafte, unvollstaendige oder unterlassene Konfiguration durch den Website-Betreiber;
  • Inkompatibilitaeten mit anderen Plugins, Themes, Hosting-Umgebungen oder Server-Konfigurationen;
  • Schaeden durch Ausfall, Verzoegerung oder Nichtzustellung von Sicherheitsbenachrichtigungen;
  • Mittelbare oder unmittelbare Folgeschaeden jeglicher Art, einschliesslich entgangener Gewinne, Umsatzverluste oder Reputationsschaeden.
  1. VERANTWORTUNG DES NUTZERS
    Der Website-Betreiber ist allein verantwortlich fuer:
  • Die ordnungsgemaesse Konfiguration und Wartung des Plugins;
  • Die regelmaessige Erstellung und Ueberpruefung von Backups;
  • Die zeitnahe Aktualisierung aller Software-Komponenten (WordPress, Plugins, Themes, PHP);
  • Die angemessene Reaktion auf Sicherheitswarnungen und Scan-Ergebnisse;
  • Die Einhaltung geltender Datenschutzgesetze (DSGVO, BDSG) im Zusammenhang mit den vom Plugin verarbeiteten Daten;
  • Die Einholung professioneller Sicherheitsberatung bei erhoehtem Schutzbedarf.
  1. KEINE RECHTSBERATUNG
    Informationen und Empfehlungen innerhalb des Plugins stellen keine Rechts-, Sicherheits- oder IT-Beratung dar. Bei rechtlichen Fragen oder konkreten Sicherheitsvorfaellen wenden Sie sich an qualifizierte Fachleute.

  2. GEWAEHRLEISTUNGSAUSSCHLUSS
    Soweit gesetzlich zulaessig, wird jede ausdrueckliche oder stillschweigende Gewaehrleistung ausgeschlossen, einschliesslich, aber nicht beschraenkt auf die Gewaehrleistung der Marktgaengigkeit, Eignung fuer einen bestimmten Zweck und Nichtverletzung von Rechten Dritter.

  3. GESETZLICH ZWINGENDE HAFTUNG
    Dieser Haftungsausschluss beruehrt nicht die gesetzlich zwingende Haftung, insbesondere nicht die Haftung fuer Vorsatz, grobe Fahrlaessigkeit, Verletzung wesentlicher Vertragspflichten (Kardinalpflichten) sowie die Haftung nach dem Produkthaftungsgesetz und fuer Schaeden aus der Verletzung des Lebens, des Koerpers oder der Gesundheit.

English

DISCLAIMER — PLEASE READ CAREFULLY

This plugin is provided “as is” without warranty of any kind. Use is entirely at the website operator’s own risk and responsibility.

  1. NO GUARANTEE OF ABSOLUTE SECURITY
    No security plugin can guarantee complete or absolute protection against cyber attacks, data loss, malware infections, unauthorized access, or other security incidents. Banana Defender is a supplementary security measure and not a substitute for a comprehensive security concept, regular backups, strong passwords, updated software, and professional security consulting.

  2. LIMITATION OF LIABILITY
    To the fullest extent permitted by applicable law, the publisher (flexxDEV / Bastian Ranft) shall not be liable for:

  • Damages resulting from security incidents despite the plugin being active, including data loss, data theft, website defacement, malware infections, or business interruption;
  • Damages resulting from false positive or false negative results of malware or file integrity scans;
  • Damages resulting from incorrect, incomplete, or omitted configuration by the website operator;
  • Incompatibilities with other plugins, themes, hosting environments, or server configurations;
  • Damages resulting from failure, delay, or non-delivery of security notifications;
  • Any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to loss of profits, revenue, or reputation.
  1. USER RESPONSIBILITY
    The website operator is solely responsible for:
  • Proper configuration and maintenance of the plugin;
  • Regular creation and verification of backups;
  • Timely updates of all software components (WordPress, plugins, themes, PHP);
  • Appropriate response to security warnings and scan results;
  • Compliance with applicable data protection laws (GDPR) in connection with data processed by the plugin;
  • Obtaining professional security advice where enhanced protection is required.
  1. NO PROFESSIONAL ADVICE
    Information and recommendations within the plugin do not constitute legal, security, or IT consulting advice. For legal questions or specific security incidents, consult qualified professionals.

  2. WARRANTY DISCLAIMER
    To the maximum extent permitted by applicable law, all express or implied warranties are disclaimed, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

  3. MANDATORY STATUTORY LIABILITY
    This disclaimer does not affect mandatory statutory liability, in particular liability for intent, gross negligence, breach of essential contractual obligations, liability under product liability law, and liability for damages arising from injury to life, body, or health.

Screenshots

Dashboard Overview — Setup Wizard and Security Score at a glance

Dashboard Overview — Setup Wizard and Security Score at a glance

Security Overview — Threat statistics, system checks and module status grid

Security Overview — Threat statistics, system checks and module status grid

Security Settings — Login Protection with Brute-Force thresholds, 2FA and IP Blacklist

Security Settings — Login Protection with Brute-Force thresholds, 2FA and IP Blacklist

Scanner & Reports — File Integrity Monitoring with scan results and change detection

Scanner & Reports — File Integrity Monitoring with scan results and change detection

License & Support — Pro license management with account and support access

License & Support — Pro license management with account and support access

Virtual Patching — WAF with SQL Injection, XSS and exploit protection rules

Virtual Patching — WAF with SQL Injection, XSS and exploit protection rules

Plugin Details

Active Installs
0
Total Downloads
154
Version
2026.9.153
Requires WP
5.6
Requires PHP
7.4
Tested Up To
7.1
Added
2026-09-09
Last Updated
2026-09-16 2:33pm GMT

Ratings

5
0
4
0
3
0
2
0
1
0