BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Ghostables Defender Lite icon
Maintained Tested up to 7.0.6 #9 in File Integrity

Ghostables Defender Lite

Active security for WordPress: vulnerability scanning, file integrity, hardening checklist, two-factor authentication, and a tamper-evident audit log.

Active installs<10New
Downloads · 30d56▲ +43.6% vs prev. 30d
Rating—0 reviews
Health score49/100Fair
All-time downloads197Since Jun 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d12• 0% week over week
Our verdict

Use with caution

Ghostables Defender Lite works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 49/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

134Jul 2Aug 15Sep 29
Yesterday1
Daily average (1y)2
Peak day31Jun 23, 2026
Last 12 months206

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Ghostables Defender Lite stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
File Integrity >100 670 Best File Integrity plugins →
hardening >100 2,103 Best hardening plugins →
security >100 10,000 Best security plugins →
two factor authentication >100 423 Best two factor authentication plugins →
vulnerability scanner >100 282 Best vulnerability scanner plugins →

About Ghostables Defender Lite

From the official readme · v0.1.6

Description

Ghostables Defender Lite is a free, fully functional security plugin for WordPress. Nothing in it is locked, limited, or gated behind a licence — every feature below works out of the box:

  • Continuous vulnerability scanning against installed plugins, themes, and WordPress core
  • Cryptographic file integrity baseline with daily drift detection
  • WordPress hardening checklist with one-click safe fixes
  • Per-user TOTP two-factor authentication (Google Authenticator, Authy, 1Password)
  • Tamper-evident audit log — events are linked together so any deletion is detectable, with a free, user-configurable retention period
  • Operator gate — a PIN above WordPress admin so a compromised super-admin cannot silently disable the plugin

Built by Ghostables Ltd. Opinionated about defaults. Honest about what each setting actually does.

Is anything locked or limited?

No. Defender Lite is free and complete — no nag screens, no crippled features, no trial period, no usage quota. The audit-log retention period is a setting you control (default 90 days; set it to keep everything forever). Every feature listed above is the real thing.

Is there a more advanced version?

Yes — Ghostables Defender is a separate, more advanced plugin distributed from ghostables.io. It is not part of this plugin and is not required to use Defender Lite. It adds capabilities such as a behavioural firewall, malware quarantine, Cloudflare edge sync, webhook alerts, encrypted backups, and more. The “More Security” page inside Defender Lite lists what it adds, purely for information.

Coexistence with the separate plugin

If you install the separate Ghostables Defender plugin, Defender Lite steps aside automatically so the two don’t run side by side. Your settings (Operator PIN, hardening fixes, baseline, audit chain) are preserved across the handover. Defender Lite remains free and fully functional whether or not you ever install it.

External services

This plugin connects to one external service: the public WordPress Vulnerability Database operated by the WPVulnerability project at https://www.wpvulnerability.net/.

  • What is sent: an HTTP GET request to https://www.wpvulnerability.net/plugin/{slug}/, https://www.wpvulnerability.net/theme/{slug}/, or https://www.wpvulnerability.net/core/{wp-version}/ — one URL per installed component being checked. The request body is empty. The only request headers are Accept: application/json and a User-Agent of the form GhostablesDefenderLite/<plugin version>. No site URL, no admin email, no IP-derived identifier — only the slug of the component being queried and the User-Agent itself.
  • What is received: a JSON record listing publicly disclosed vulnerabilities affecting that single component, with affected version ranges and severity scores. The plugin compares this against the locally-installed version and stores any open findings in the plugin’s own database table.
  • When it is sent: at most once per installed component per 24 hours. Each per-slug response is cached locally in a WordPress transient, so the twice-daily scan cron only triggers fresh HTTP requests when the cache has expired.
  • Service provider: The WPVulnerability Project (operated by ROBOTSTXT and contributors). Service licence (EUPL v1.2, GPL-compatible): https://www.wpvulnerability.com/license/. Privacy policy: https://www.wpvulnerability.com/privacy/.

No other outbound network traffic originates from this plugin. The two-factor QR code is rendered locally in the operator’s browser using a vendored MIT-licensed JavaScript library — the TOTP secret is never transmitted to any third party.

Installation

  1. Upload ghostables-defender-lite to /wp-content/plugins/ (or install via Plugins → Add New)
  2. Activate
  3. Follow the 4-step setup wizard. The first administrator to complete it becomes the founding Operator — sets a 6–10 digit PIN and receives 10 single-use recovery codes.
  4. The wizard takes the first file-integrity baseline and runs the first vulnerability scan automatically.

Frequently asked questions

Does Defender Lite phone home?

Lite calls one external service: the public WordPress Vulnerability Database at wpvulnerability.net, to look up disclosed vulnerabilities for each installed plugin, theme, and your WordPress core version. No API key, no site URL, no admin email — only the slug being queried and a User-Agent identifying the plugin version. Each lookup is cached locally for 24 hours. See the “External services” section above for the full disclosure. The two-factor QR code is rendered locally in your browser; the TOTP secret never leaves your WordPress install.

Will Lite slow my site down?

The scans run on cron (twice-daily CVE check, daily integrity scan). Runtime hardening is a handful of cheap filter hooks. No page-load impact you’ll measure.

Will Lite break my site?

The hardening checklist tells you what each fix does before you click it. Every one-click fix is reversible by editing wp-config.php or unchecking the option. Defaults are conservative — nothing is enforced site-wide on first install except the Operator gate, which only restricts Defender’s own settings.

Does it work alongside Wordfence / iThemes / Sucuri?

Technically yes, but running multiple security plugins is usually counterproductive — they fight over the same hooks. Run one, run it well.

Is the audit log really tamper-evident?

Each row’s row_hash is an HMAC-SHA-256 over the previous row’s hash plus the row’s own fields, keyed with a 32-byte chain key. The chain key is either (a) the GDEF_LITE_AUDIT_KEY constant in your wp-config.php, or (b) auto-generated and stored as a WordPress option on first use. An attacker with database write access can delete or modify a row, but cannot quietly recompute the following row’s HMAC without the key — so the next row’s stored hash will no longer match, and the break is visible from Settings → Operator → Chain status. For the strongest guarantee, set GDEF_LITE_AUDIT_KEY in…

How do I get the separate Ghostables Defender plugin?

It’s distributed from ghostables.io. Install it alongside Defender Lite and Lite steps aside automatically; every setting you’ve configured here carries over. You never need it to keep using Defender Lite, which is free and fully functional on its own.

What happens if I uninstall?

Uninstalling (not just deactivating) drops Defender’s three tables and clears its options. Your audit log goes with it. This is intentional — uninstall means uninstall.

Changelog

Fixes the scan progress modal appearing hidden behind its backdrop. No functional changes.

0.1.6

  • Fix: on the Scan page, the vulnerability and file-integrity scan progress modal could appear hidden behind its own backdrop. The modal is mounted on the page body — outside the plugin’s styling scope — so its brand colour variables weren’t resolving and the card rendered transparent. The modal now carries its own tokens and displays correctly. No change to scanning behaviour.

0.1.5

  • Authorisation: the integrity scan-control endpoints (start, tick, cancel) and the baseline and finding-resolve endpoints now enforce the Operator gate directly in their REST permission_callback — administrator capability plus an unlocked Operator session — because advancing a baseline rewrites the trusted file fingerprint (a security-state change). Read-only endpoints (CVE scan, scan status, audit verify) continue to require the administrator capability only. Locked requests return a clear, actionable 403.
  • Removed remaining “free tier / upgrade” wording from the plugin header description to match the rest of the plugin: Defender Lite is free and fully functional, with the separate plugin described for information only.

0.1.4

  • Guidelines compliance. Audit-log retention is now a free, user-configurable setting (default 90 days, set to 0 to keep everything forever) — it is no longer presented as a paid limit. Nothing in the plugin is gated behind a licence, tier, quota, or time limit; every feature is free and fully functional.
  • The “More Security” page now describes Ghostables Defender purely as a separate, more advanced plugin available from ghostables.io — no locked tiles, no “unlock”, no in-plugin upsell or licence-key entry.
  • All JavaScript and CSS is now loaded through wp_enqueue_*. The previous inline and blocks (the REST helper, scan modal, onboarding wizard) moved to enqueued assets/js/admin.js, assets/js/onboard.js, assets/css/onboard.css, and assets/css/login.css. Inline onclick handlers and inline style attributes were replaced with delegated event listeners and CSS classes.
  • No change to the actual security features: vulnerability scanning, file integrity, hardening, two-factor authentication, Operator gate, and the tamper-evident audit log all work exactly as before.

0.1.3

  • Plugin Check round-2 cleanup. Fixed the only remaining ERROR (a $wpdb->prepare() call in the CVE scanner that concatenated time() into the SQL — now bound as %d), collapsed two multi-line $wpdb->prepare() calls onto single lines so the phpcs:ignore directive actually lands on the offending line, suppressed the PrefixAllGlobals sniff on view templates (they are require()’d inside controller methods, so their variables are method-local at runtime even though PHPCS sees them as global), and wrapped uninstall.php’s body in an immediately-invoked closure so its working variables are genuinely function-scoped. No functional or behavioural changes.

0.1.2

  • Plugin Check cleanup: switched all filesystem operations to WP_Filesystem; sanitised every superglobal read with wp_unslash() + sanitize_text_field() / esc_url_raw(); annotated every deliberate direct $wpdb query with the rationale; prefixed all view-file local variables with gdef_ to satisfy the PrefixAllGlobals rule.
  • No functional changes — all behaviour, option keys, DB schemas, REST routes, and admin UI are unchanged.

0.1.1

  • Vulnerability feed switched from Wordfence Intelligence to the public WordPress Vulnerability Database (wpvulnerability.net). Same coverage, GPL-compatible licensing, per-component 24h cache.
  • Two-factor QR code is now rendered locally in the operator’s browser using a bundled MIT-licensed library. The TOTP secret is no longer transmitted to a third party.
  • Two-factor authentication now blocks XML-RPC and application-password channels for any user with 2FA enabled, closing the previous bypass.
  • Two-factor recovery codes are stored as password_hash() values rather than plaintext.
  • Brute-force throttle added to the Operator PIN, the Operator recovery code, and the 2FA challenge — 5 failures in 5 minutes triggers a lockout with exponential backoff up to 1 hour.
  • Audit chain upgraded from unkeyed SHA-256 to HMAC-SHA-256 with a chain key. The key is read from a GDEF_LITE_AUDIT_KEY wp-config constant when present, otherwise auto-generated and stored as an option. Existing pre-upgrade rows remain verifiable under the legacy scheme.
  • The audit log no longer trusts X-Forwarded-For or CF-Connecting-IP headers by default — opt in via the GDEF_LITE_TRUST_PROXY wp-config constant or the gdef_lite_trust_proxy filter when the site genuinely sits behind a reverse proxy.
  • Hardening: nginx server-block snippet for blocking PHP execution in /uploads is now generated on the Hardening page (Apache .htaccess output unchanged).
  • Admin pages no longer fetch Google Fonts from a CDN — system font stack is used instead.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Ghostables Defender Lite alternatives

All File Integrity plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Guardian Gaze Security – Malware & Database Scanner, File Integrity Monitoring, IP Blocking Guardian Gaze Security WordPress malware and database scanner that detects and helps you remove malware, hidden… by REDSECLABS 20+ ★★★★★★★★★★ No reviews 3 weeks ago 67
2 File Change Monitor File Change Monitor Detects file changes in WordPress core, themes, and plugins. Sends email alerts to the site… by Osman 20+ ★★★★★★★★★★ No reviews 5 months ago 45
3 InTouch Integrity Guard InTouch Integrity Guard A lightweight file integrity checker, hardening toggles and opt-in known-vulnerability… by intouchdesigndev 10+ ★★★★★★★★★★ 5 (1) 3 weeks ago 73
4 FirePhage Security FirePhage Security WordPress security plugin with malware scanning, file integrity checks, login protection… by Nikola (FirePhage) 10+ ★★★★★★★★★★ No reviews 2 months ago 57
5 Nova Scan Lite – Malware Scanner, Backdoor & File Integrity Nova Scan Lite – Malware Scanner, Backdoor & File Integrity Lightweight WordPress malware scanner. Detects PHP backdoors, webshells, and injections… by SephX <10 ★★★★★★★★★★ No reviews 1 month ago 60
6 FileOps Monitor FileOps Monitor Find added, modified and deleted WordPress files with a local SHA-256 baseline and manual… by iamgsbala <10 ★★★★★★★★★★ No reviews 2 weeks ago 64
7 FortressX Security – Firewall, Security Scan & Hardening FortressX Security – Firewall, Security Scan & Hardening FortressX Security helps protect WordPress with login protection, firewall tools, security… by Fortressx <10 ★★★★★★★★★★ No reviews 1 month ago 60
8 Ensomedia Security powered by shieldwave.io Ensomedia Security powered by shieldwave.io Finds malware, tampered files, known vulnerabilities, injected content and risky settings… by shieldwave <10 ★★★★★★★★★★ No reviews 13 hours ago 64
10 Neksio Login & File Security Neksio Login & File Security Protect WordPress logins with two-factor authentication, monitor critical file changes, and… by Neksio Tool <10 ★★★★★★★★★★ No reviews 3 weeks ago 64
11 MadTek Entrusans ™ IDS client MadTek Entrusans ™ IDS client Effective website security requires a combination of tools and best practices to operate… by jee@madtek.com <10 ★★★★★★★★★★ No reviews 7 years ago 21

FAQ

Ghostables Defender Lite: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 30, 2026

Is Ghostables Defender Lite free?

Yes. Ghostables Defender Lite is free to download and use from the official WordPress.org plugin directory.

Is Ghostables Defender Lite safe to use in 2026?

Ghostables Defender Lite works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 49/100 on our health check.

How many websites use Ghostables Defender Lite?

Ghostables Defender Lite is active on <10 WordPress websites and has been downloaded 197 times since it launched in June 2026. It was downloaded 56 times in the last 30 days.

Does Ghostables Defender Lite work with WordPress 7.1?

Ghostables Defender Lite is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does Ghostables Defender Lite need?

Ghostables Defender Lite requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Ghostables Defender Lite last updated?

The latest version, 0.1.6, was released on June 23, 2026 (3 months ago).

Who makes Ghostables Defender Lite?

Ghostables Defender Lite is developed and maintained by ghostables.

What are the best alternatives to Ghostables Defender Lite?

The most popular alternatives to Ghostables Defender Lite are Guardian Gaze Security (20+ installs), File Change Monitor (20+ installs) and InTouch Integrity Guard (10+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.