Ghostables Defender · WordPress Security

Active defence for
every WordPress site.

Ghostables Defender is the security plugin built by the team behind Ghostables. Malware scanning, firewall, login defence, hardening, and a tamper-evident audit chain — all in one drop-in install. Free on wp.org. Pro tiers for sites that need more.

wp.org free tier WooCommerce-aware Pairs with Ghostables for WordPress 14-day refund

Every layer of WordPress
security, in one plugin.

Defender is the practical, operator-friendly security stack we wish was available when we built Ghostables for WordPress. Seven module groups, every event written to a tamper-evident audit chain, sensible defaults that you can flip into hardened mode in one click.

01 / Threat detection

Scanning & integrity

Continuously watches your installed software and the files on disk for known threats and unexpected change.

  • CVE scanner (Patchstack + WPScan databases)
  • Cryptographic file-integrity baseline
  • Malware engine — pattern + ClamAV signatures
  • WordPress core + plugin checksum verification
  • Plugin reputation & abandonment signals
  • Quarantine for suspicious files
02 / Perimeter

Firewall & WAF

Stops bad traffic before it reaches WordPress. Manual rules, country blocking, threat-intel feeds, and a managed WAF on Business+.

  • Manual IP allow / block (CIDR-aware)
  • Country & region blocking
  • AbuseIPDB threat-intel sync (Business+)
  • Managed WAF ruleset (Business+)
  • Bot verification (Googlebot, Bingbot, etc.)
  • Proxy / VPN detection
  • Community shared blocklist
03 / Account security

Login & identity

Login is the most-attacked surface on WordPress. Defender layers controls so credential stuffing, brute force, and replay don't get through.

  • Login lockouts + 404 lockouts
  • Custom login URL masking
  • Two-factor authentication (TOTP + WebAuthn)
  • 2FA enforcement for admin roles (Business+)
  • Pwned-password check (Have I Been Pwned)
  • Login CAPTCHA on threshold
  • Per-country login geo-blocking
  • Active session viewer + force-revoke
04 / Hardening

Hardening checklist

A live checklist of WordPress hardening best-practice. Solo and above gets one-click fixes for each row.

  • 20+ hardening recommendations
  • One-click fixes (Solo+)
  • HTTPS-only enforcement
  • XML-RPC kill switch
  • wp-config.php integrity watcher
  • Security headers (CSP, HSTS, X-Frame, Referrer)
  • Disable PHP execution in /uploads
  • WooCommerce order integrity (Business+)
05 / Backup & recovery

Backups & data export

If something does get through, you want a clean known-good restore point and the paper trail to prove what happened.

  • Encrypted database backups (Solo+)
  • Backup encryption with operator-only key (Business+)
  • Offsite backup destinations (Business+)
  • GDPR data-export pipeline
  • Compliance report pack (Business+)
  • Audit log redacted export (Business+)
06 / Monitoring

Monitoring & audit

Every admin action, every defensive event, and every login attempt is logged to a tamper-evident chain. The dashboard shows you what matters today.

  • Tamper-evident audit chain
  • 14-day rolling baseline anomaly detection
  • Operator activity feed
  • Uptime monitor with multi-region pings (Solo+)
  • Weekly digest email (Business+)
  • Forensic PDF incident report (Business+)
  • Live dashboard widget
07 / Operator controls

Operator gate

An extra security layer above wp-admin so that even a compromised admin account can't drop Defender, disable scans, or delete the audit trail.

  • Operator PIN + dedicated 2FA
  • Per-operator action throttling
  • Webhook integrations (Solo+)
  • Cloudflare rule sync (Business+)
  • Plugin allowlist (Enterprise)
  • One-click site lockdown (Enterprise)
  • White-label trust badge (Business+)

Defence in depth.
One licence covers both.

Defender keeps attackers off the site. Ghostables for WordPress makes sure that if they ever do get in, the customer database they walk away with is unreadable. Together you have prevention and contained-impact. Buy a Ghostables for WordPress plan and the matching Defender tier is included automatically — one licence, both plugins, no double payment.

Bundled with every paid Ghostables for WordPress licence.

If you own Ghostables for WordPress at any paid tier, Defender activates against the same licence key. The Defender plugin detects the licence automatically and unlocks the matching tier — no extra checkout, no extra invoice.

You can still install Defender on its own — that's the wp.org free tier and the standalone Pro tiers on this page. But if you're going to encrypt your customer database anyway, the bundle is cheaper than buying both products separately.

See Ghostables for WordPress →
// Bundle map

What each Ghostables for WordPress tier unlocks

Solo · £149/yr+ Defender Free
Business · £499/yr+ Defender Business
Agency · £1,499/yr+ Defender Enterprise
Buy Ghostables for WordPress →

Four tiers.
Pick what you need.

Already have Ghostables for WordPress? You don't need to buy Defender separately — your existing licence unlocks it. These prices are for sites running Defender on its own.

Free
£0 / forever

wp.org download · 1 site · community support

  • CVE scanner (Patchstack)
  • File-integrity baseline
  • Pattern malware scanner
  • Hardening checklist (manual fixes)
  • Two-factor authentication
  • Activity audit log
  • Audit log retained 30 days
  • Best for solo blogs, small business sites
Download free →
Solo
£59 / year

or £6/month · 1 site · email support

  • Everything in Free, plus —
  • "Protected by Ghostables" trust mark
  • ClamAV malware engine + quarantine
  • Login URL masking + lockouts
  • Country & region firewall rules
  • One-click hardening fixes
  • Encrypted database backups
  • Uptime monitor (multi-region)
  • Plugin checksum verification
  • Audit-log tail viewer
  • Best for serious solo operators
Choose Solo →
Enterprise
£549 / year

or £59/month · unlimited sites · SLA support

  • Everything in Business, plus —
  • Plugin allowlist (only signed plugins run)
  • One-click site lockdown
  • Custom YARA rule import
  • Hedera HCS audit anchoring
  • Cross-site threat-intel network
  • Compliance pack export (SOC 2 / ISO)
  • Direct support SLA
  • Best for regulated industries, large estates
Choose Enterprise →

All paid tiers include automatic updates, secure recovery, and a 14-day refund. VAT calculated at checkout. Cancel any time from your dashboard.

Tier comparison.

The full feature matrix. Everything in the table works in every tier marked ✓ — no hidden caps or "lite" versions.

Feature Free Solo Business Enterprise
Threat detection
CVE scanner (Patchstack)
CVE scanner (WPScan)
File integrity baseline
Pattern malware scanner
ClamAV signatures
Quarantine
Core + plugin checksums
Custom YARA rules
Perimeter
Manual IP allow / block
Geo / country blocking
AbuseIPDB threat-intel
Managed WAF ruleset
Bot verification
Community blocklist sync
Cross-site threat-intel network
Account security
Login lockouts
Custom login URL
Two-factor authentication
Enforced 2FA for admins
Pwned-password check
Per-country login geo-block
Hardening
Hardening recommendations
One-click fixes
HTTPS-only enforcement
wp-config watcher
WooCommerce order integrity
Backup & recovery
Encrypted database backups
Backup encryption (operator key)
Offsite backup destinations
GDPR data export
Compliance pack export
Monitoring & audit
Tamper-evident audit chain
Anomaly detection (14-day baseline)
Uptime monitor
Weekly digest email
Forensic PDF incident report
Hedera HCS audit anchoring
Operator controls
Operator PIN + dedicated 2FA
Per-operator action throttling
Webhook integrations
Cloudflare rule sync
"Protected by Ghostables" trust mark
White-label trust mark
Plugin allowlist (signed-only)
One-click site lockdown
Support & coverage
Sites11Unlimited
Support channelCommunityEmailSLA
Auto-update with rollback

FAQ

Do I need Defender if I already have Ghostables for WordPress?

You already have it. The two plugins talk to each other — install Defender on the same site and it picks up the Ghostables for WordPress licence and runs at the matching tier automatically. You don't pay twice. The standalone Pro prices on this page are for sites that don't have Ghostables for WordPress and just want the security plugin on its own.

Is the wp.org free tier actually useful, or is it a tease?

It's useful. The free tier includes CVE scanning, file-integrity baselines, the pattern malware scanner, the hardening checklist, two-factor authentication, and the audit log. That's already more than most paid competitors offer for free. Pro tiers add deeper scanning (ClamAV), the perimeter layer (firewall + WAF + threat-intel), one-click fixes, the reporting / compliance bits agencies need, and the "Protected by Ghostables" trust mark — the public mark is paid-only because it represents accreditation, and an accreditation that anyone can claim for free isn't an accreditation.

Will Defender break my site?

Defender ships with a "Lite Mode" that disables everything except scanning, so you can install on a fragile / legacy site and turn modules on one at a time. The hardening checklist tells you exactly what each fix will change before you apply it. Every action is reversible from the audit log. And there's a one-click "Pause Defender" toggle if you ever need to take it out of the request path.

How does Defender's audit chain work?

Every defensive action — every block, every quarantine, every operator login, every settings change — is written to a tamper-evident chain. Each entry's hash is bound to the previous one, so removing or altering an entry breaks the chain visibly. The Enterprise tier can anchor that chain to the Hedera public ledger so the proof is verifiable independently of your server. The free tier already includes the chain itself; anchoring is the only Enterprise-only piece.

What's the operator gate?

An extra security layer on top of wp-admin. Even if an admin account is compromised (stolen password, malicious plugin code), the attacker can't disable Defender, delete scan results, or alter the audit chain without separately knowing the operator PIN and passing the dedicated operator 2FA. It's the difference between an attacker who got in and an attacker who can clean up after themselves.

How does activation work?

You buy a subscription, we email a licence key. Paste it into the plugin's settings page. The plugin checks in daily — if your subscription lapses, the plugin degrades gracefully to the free tier rather than going offline. Customer data, audit history, and scan baselines all remain intact.

What if I want a refund?

14 days, no questions. Cancel from your dashboard or email hello@ghostables.io. You keep access until the end of the current billing cycle and the plugin then steps down to the free tier.

Active defence,
built by Ghostables.

Start free, or pick a Pro tier and get everything. If you already own Ghostables for WordPress, install Defender — it activates against your existing licence.