Defender Security – Malware Scanner, Login Security & Firewall

defender-security · by wpmudev · wordpress.org ↗ · SVN ↗
Acquired by WPMU DEV / Incsub. New committers from that team's naming convention are expected and will not fire takeover events. source ↗
Active installs
80k+
Current version
6.3.0
Added
2017-06-07
Last updated
2026-09-29 (12d ago)
First seen by beacon
5mo ago
Total downloads
4,357,147

Statistics

2024-06-17 → 2026-09-10 · 816 days
Downloads today
1,583
7-day total 35,336
Week over week
▲ +282%
vs prior 7 days
30-day trend
declining
▼ -4% MoM
Abandonment
○○○○○
healthy
Downloads/day Linear trend
29k21k14k7k02024-062024-102025-032025-072025-122026-04
23k17k11k6k02026-062026-062026-072026-072026-082026-08
17k12k8k4k02026-082026-082026-082026-082026-092026-09

Active versions

6.2other
6.2 · 44.4%other · 40.4%5.11 · 7.6%6.1 · 7.5%

Ratings

5★
305
4★
11
3★
5
2★
5
1★
8

Support: 4/4 resolved

Alerts (0)

No open alerts.

Show 1 resolved alert
Medium code_scan_delta Resolved · code_scan_fp_reviewed_benign 2026-09-21 16:42:07 (20d ago)
Slugdefender-security
Previous version6.2.4
Current version6.2.4
New findings
PatternKindFileLineSnippetConfidence
base64_decodebuiltinextra/hub-connector/inc/class-remote.php717$signature = base64_decode( $signed_data, true ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decodemedium
createfuncbuiltinlib/packages/Safe/generated/funchand.php17function create_function(string $args, string $code): stringmedium
createfuncbuiltinlib/packages/Safe/generated/funchand.php20$result = \create_function($args, $code);medium
base64_decodebuiltinlib/packages/Safe/generated/url.php20function base64_decode(string $data, bool $strict = false): stringmedium
base64_decodebuiltinlib/packages/Safe/generated/url.php23$result = \base64_decode($data, $strict);medium
gzinflatebuiltinlib/packages/Safe/generated/zlib.php340function gzinflate(string $data, int $length = 0): stringmedium
gzinflatebuiltinlib/packages/Safe/generated/zlib.php343$result = \gzinflate($data, $length);medium
base64_decodebuiltinlib/packages/Base64Url/Base64Url.php49$decoded = base64_decode(strtr($data, '-_', '+/'), true);medium
base64_decodebuiltinlib/packages/CBOR/Utils.php52$decoded = base64_decode(strtr($data, '-_', '+/'), true);medium
base64_decodebuiltinlib/packages/CBOR/Tag/Base64EncodingTag.php56$result = base64_decode($this->object->getNormalizedData($ignoreTags), true);medium
base64_decodebuiltinlib/packages/League/Uri/Uri.php697$userinfo = base64_decode(substr($server['HTTP_AUTHORIZATION'], 6), true);medium
base64_decodebuiltinlib/packages/League/Uri/Uri.php877$res = base64_decode($data, true);medium
hex_string_longbuiltinlib/packages/League/Uri/Uri.php199private const ASCII = "\x20\x65\x69\x61\x73\x6E\x74\x72\x6F\x6C\x75\x64\x5D\x5B\x63\x6D\x70\x27\x0A\x67\x7C\x68\x76\x2E\x66\x62\x2C\x3A\x3D\x2D\x71\x31\x30\x43\x32\x2A\x79\x78\x29\x28\x4C\x39\x41\medium
base64_decodebuiltinlib/packages/Assert/Assertion.php2,698if (false === \base64_decode($value, true)) {medium
base64_decodebuiltinlib/packages/Webauthn/PublicKeyCredentialUserEntity.php66$id = base64_decode($json['id'], true);medium
New finding count22
View raw JSON
{
    "slug": "defender-security",
    "previous_version": "6.2.4",
    "current_version": "6.2.4",
    "new_findings": [
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "extra/hub-connector/inc/class-remote.php",
            "line": 717,
            "snippet": "$signature = base64_decode( $signed_data, true ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode",
            "confidence": "medium"
        },
        {
            "pattern": "createfunc",
            "kind": "builtin",
            "file": "lib/packages/Safe/generated/funchand.php",
            "line": 17,
            "snippet": "function create_function(string $args, string $code): string",
            "confidence": "medium"
        },
        {
            "pattern": "createfunc",
            "kind": "builtin",
            "file": "lib/packages/Safe/generated/funchand.php",
            "line": 20,
            "snippet": "$result = \\create_function($args, $code);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/Safe/generated/url.php",
            "line": 20,
            "snippet": "function base64_decode(string $data, bool $strict = false): string",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/Safe/generated/url.php",
            "line": 23,
            "snippet": "$result = \\base64_decode($data, $strict);",
            "confidence": "medium"
        },
        {
            "pattern": "gzinflate",
            "kind": "builtin",
            "file": "lib/packages/Safe/generated/zlib.php",
            "line": 340,
            "snippet": "function gzinflate(string $data, int $length = 0): string",
            "confidence": "medium"
        },
        {
            "pattern": "gzinflate",
            "kind": "builtin",
            "file": "lib/packages/Safe/generated/zlib.php",
            "line": 343,
            "snippet": "$result = \\gzinflate($data, $length);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/Base64Url/Base64Url.php",
            "line": 49,
            "snippet": "$decoded = base64_decode(strtr($data, '-_', '+/'), true);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/CBOR/Utils.php",
            "line": 52,
            "snippet": "$decoded = base64_decode(strtr($data, '-_', '+/'), true);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/CBOR/Tag/Base64EncodingTag.php",
            "line": 56,
            "snippet": "$result = base64_decode($this->object->getNormalizedData($ignoreTags), true);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/League/Uri/Uri.php",
            "line": 697,
            "snippet": "$userinfo = base64_decode(substr($server['HTTP_AUTHORIZATION'], 6), true);",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/League/Uri/Uri.php",
            "line": 877,
            "snippet": "$res = base64_decode($data, true);",
            "confidence": "medium"
        },
        {
            "pattern": "hex_string_long",
            "kind": "builtin",
            "file": "lib/packages/League/Uri/Uri.php",
            "line": 199,
            "snippet": "private const ASCII = \"\\x20\\x65\\x69\\x61\\x73\\x6E\\x74\\x72\\x6F\\x6C\\x75\\x64\\x5D\\x5B\\x63\\x6D\\x70\\x27\\x0A\\x67\\x7C\\x68\\x76\\x2E\\x66\\x62\\x2C\\x3A\\x3D\\x2D\\x71\\x31\\x30\\x43\\x32\\x2A\\x79\\x78\\x29\\x28\\x4C\\x39\\x41\\",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/Assert/Assertion.php",
            "line": 2698,
            "snippet": "if (false === \\base64_decode($value, true)) {",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "lib/packages/Webauthn/PublicKeyCredentialUserEntity.php",
            "line": 66,
            "snippet": "$id = base64_decode($json['id'], true);",
            "confidence": "medium"
        }
    ],
    "new_finding_count": 22
}

SVN committers (10)

Accounts with actual commit access to defender-security on plugins.svn.wordpress.org, reconstructed from svn log. This is the list that matters for ownership changes — not the readme contributors.

Committer Member since Commits First commit Latest commit
Anton Shulga 2013-02-10 364 2020-02-03 · r2237723 2026-07-21 · r3617358
hoang1213 Young account 2017-06-07 95 2017-06-08 · r1673171 2020-08-26 · r2369388
jdailey 2013-02-28 22 2017-06-06 · r1672143 2020-03-19 · r2263944
Vijayan 2016-10-14 14 2022-04-25 · r2714366 2023-08-09 · r2950517
WPMU Dev – Paul Kevin Young account 2017-07-11 11 2017-07-11 · r1694372 2017-08-17 · r1714568
panoslyrakis 2017-11-19 5 2023-12-06 · r3005974 2026-07-20 · r3615306
rickjc89 2020-04-30 4 2020-09-01 · r2372666 2021-02-23 · r2480145
plugin-master 2007-03-09 1 2017-06-06 · r1672114 2017-06-06 · r1672114
Anton Vanyukov 2015-11-26 1 2021-03-11 · r2493740 2021-03-11 · r2493740
WPMU DEV - Your All-in-One WordPress Platform 2010-09-01 1 2017-07-03 · r1690097 2017-07-03 · r1690097

Readme contributors (1)

Names the plugin's readme declares as contributors. A soft signal — anyone can be listed. The SVN access column is the ground-truth cross-reference: does this contributor actually commit code?

Contributor Member since SVN access Status
WPMU DEV - Your All-in-One WordPress Platform 2010-09-01 1 commits Active

Versions (100 most recent)

Version Released Download
6.2.3 — zip
6.2.4 — zip
6.1.0 — zip
6.2.0 — zip
6.2.1 — zip
6.2.2 — zip
6.0.0 — zip
6.0.1 — zip
5.11.0 2026-04-07 · 6mo ago zip
5.10.0 2026-03-03 · 7mo ago zip
5.9.0 2026-02-02 · 8mo ago zip
5.8.1 2026-01-12 · 9mo ago zip
5.8.0 2026-01-12 · 9mo ago zip
5.7.2 2025-12-15 · 10mo ago zip
5.7.1 2025-11-24 · 10mo ago zip
5.7.0 2025-11-24 · 10mo ago zip
5.6.2 2025-11-20 · 10mo ago zip
5.6.1 2025-10-22 · 11mo ago zip
5.6.0 2025-10-13 · 12mo ago zip
5.5.1 2025-09-08 · 1y ago zip
5.5.0 2025-09-08 · 1y ago zip
5.4.1 2025-08-05 · 1y ago zip
5.4.0 2025-07-28 · 1y ago zip
5.3.1 2025-06-12 · 1y ago zip
5.3.0 2025-06-12 · 1y ago zip
5.2.2 2025-05-05 · 1y ago zip
5.2.1 2025-04-23 · 1y ago zip
5.2.0 2025-04-14 · 1y ago zip
5.1.1 2025-03-04 · 1y ago zip
5.1.0 2025-03-04 · 1y ago zip
5.0.2 2025-02-17 · 1y ago zip
5.0.1 2025-02-03 · 1y ago zip
5.0.0 2025-02-03 · 1y ago zip
4.12.0 2024-12-16 · 1y ago zip
4.11.0 2024-11-11 · 1y ago zip
4.10.1 2024-10-07 · 2y ago zip
4.10.0 2024-10-07 · 2y ago zip
4.9.0 2024-09-04 · 2y ago zip
4.8.2 2024-08-01 · 2y ago zip
4.8.1 2024-07-24 · 2y ago zip
4.8.0 2024-07-15 · 2y ago zip
4.7.4 2024-06-27 · 2y ago zip
4.7.3 2024-06-27 · 2y ago zip
4.7.2 2024-06-24 · 2y ago zip
4.7.1 2024-05-01 · 2y ago zip
4.7.0 2024-04-29 · 2y ago zip
4.6.0 2024-03-25 · 2y ago zip
4.5.1 2024-02-26 · 2y ago zip
4.5.0 2024-01-29 · 2y ago zip
4.4.2 2024-01-22 · 2y ago zip
4.4.1 2023-12-19 · 2y ago zip
4.4.0 2023-12-18 · 2y ago zip
4.3.1 2023-12-06 · 2y ago zip
4.3.0 2023-12-04 · 2y ago zip
4.2.1 2023-10-23 · 2y ago zip
4.2.0 2023-10-23 · 2y ago zip
4.1.0 2023-09-18 · 3y ago zip
4.0.2 2023-08-24 · 3y ago zip
4.0.1 2023-08-09 · 3y ago zip
4.0.0 2023-07-31 · 3y ago zip
3.12.0 2023-06-26 · 3y ago zip
3.11.1 2023-06-12 · 3y ago zip
3.11.0 2023-05-22 · 3y ago zip
3.10.1 2023-04-11 · 3y ago zip
3.10.0 2023-04-11 · 3y ago zip
3.9.1 2023-03-20 · 3y ago zip
3.9.0 2023-02-27 · 3y ago zip
3.8.2 2023-02-13 · 3y ago zip
3.8.1 2023-01-23 · 3y ago zip
3.8.0 2023-01-23 · 3y ago zip
3.7.0 2022-12-19 · 3y ago zip
3.6.0 2022-12-14 · 3y ago zip
3.5.0 2022-11-28 · 3y ago zip
3.4.1 2022-11-18 · 3y ago zip
3.4.0 2022-11-07 · 3y ago zip
3.3.3 2022-11-01 · 3y ago zip
3.3.2 2022-09-29 · 4y ago zip
3.3.1 2022-09-26 · 4y ago zip
3.3.0 2022-09-12 · 4y ago zip
3.2.0 2022-08-10 · 4y ago zip
3.1.2 2022-07-25 · 4y ago zip
3.1.1 2022-07-11 · 4y ago zip
3.1.0 2022-07-11 · 4y ago zip
3.0.0 2022-07-11 · 4y ago zip
3.0.1 2022-07-11 · 4y ago zip
2.8.3 2022-07-11 · 4y ago zip
2.8.2 2022-04-25 · 4y ago zip
2.8.1 2022-04-25 · 4y ago zip
2.8.0 2022-03-14 · 4y ago zip
2.7.1 2022-02-08 · 4y ago zip
2.7.0 2022-01-24 · 4y ago zip
2.6.5 2021-12-07 · 4y ago zip
2.6.4 2021-11-22 · 4y ago zip
2.6.3 2021-11-22 · 4y ago zip
2.6.2 2021-11-01 · 4y ago zip
2.6.1 2021-10-25 · 4y ago zip
2.6.0 2021-09-27 · 5y ago zip
2.5.7 2021-08-30 · 5y ago zip
2.5.6 2021-08-30 · 5y ago zip
2.5.5 2021-08-02 · 5y ago zip