Alternatives

Defender's free malware scan turns on after you connect an account

A free Defender install with no WPMU DEV account checks your core and plugin files against WordPress.org and flags outdated plugins. Connect a free account and vulnerability lookup and suspicious-code scanning turn on. Segurium scans in full from the first run, then cleans the infected file and leaves it working. Free covers 3 cleanups every 30 days.

Install the free plugin from WordPress.org

No card, no account to connect, no trial clock.

What you get here that they do not ship at any price

Defender Free costs nothing, so this block is not about price.

Where Defender is ahead, and it is ahead in places: login masking, breached-password checks, WebAuthn and hardware-key two-factor, CAPTCHA with three providers, and a curated bot blocklist all ship free and we have none of them. Every Defender figure on this page was checked against their pricing page, their documentation and the free 6.1.0 ZIP on WordPress.org on 19 August 2026.

What it costs over three years

Product Year one Three years
Defender Pro, Pro Basic, one site $60 $180
Segurium Pro, one site $79 $237
Segurium Free $0 $0

Segurium Pro is the dearer of the two by $57 over three years. The free plan is $180 cheaper than theirs over the same period and reads the same detection feed Pro does. Segurium Pro at $79 lifts the cleanup ceiling above 3 files per 30 days and turns on unattended fixing, so a scheduled scan cleans without you opening the dashboard. Defender has no standalone price. $60 is the list price for Pro Basic on one site, promoted at $36 a year on 19 August 2026, and it buys the whole WPMU DEV Pro plugin suite plus scheduled scans, email alerts and audit logging rather than a different scan.

Install the free plugin from WordPress.org

Why people go looking

Three of their own surfaces disagree about the free scan. Their WordPress.org readme carries a heading called "Free Malware Scanner" and lists four things it covers: "Files that have changed unexpectedly / Known vulnerabilities / Suspicious code / Outdated & removed plugins". Their pricing page sells "Vulnerability detection" and "Suspicious code scanning" as things you get by upgrading to Pro. The free 6.1.0 code on WordPress.org adds those two steps to the scan only when a WPMU DEV Hub API key is present, and a free Hub account provides one. So the capability is free, the requirement is an account with them, and their pricing page will tell you it is a paid feature. All three checked on 19 August 2026. Their documentation also caps the scan itself: "the scanning feature will run for a maximum of 3 hours before timing out."

Every repair path ends at WordPress.org or at Delete. Their words on Safe Repair: "replace the modified plugin file with its latest copy fetched from the Official WordPress repository. This option is available only for the files of plugins downloaded from WordPress.org. When a file is repaired, any local changes made to the file are overridden". A theme file gets a Restore button. Custom code gets Ignore or Delete. That covers the common case well, where a wp.org plugin file was modified and you want the shipped version back. It runs out of moves the moment the infected file has no upstream copy.

Their quarantine is real and deserves credit. Defender can move a file into a quarantine directory under a hashed name with access forbidden by default, hold it for 30 days by default and up to a year if you raise the retention, and restore it on request. Most scanners in this market delete and keep nothing. The line to draw is narrower: a restorable copy of the infected file is not the same as a working cleaned file, and an overwrite that discards your edits is not the same either. Both leave you work to do afterwards.

How the cleanup actually works

Segurium hashes every file on your server and checks each hash against a cloud database of known-good and known-bad files. Around 94% of your files are settled by the hash alone and never leave the server. A lookup takes about 24 milliseconds, so a full scan does not sit on your CPU for an hour.

Detection is not a paid tier. Free and Pro read the same feed at the same moment. The only thing money changes is how many files you may clean.

When a file comes back infected, you click Fix. For an injection into an otherwise-working file, Segurium fetches a cleaned version of that exact file, so your theme keeps rendering and your plugin keeps loading. A file that is nothing but malware becomes zero bytes at the same path. When no clean version can be produced, the cleanup stops and leaves the file exactly as it found it.

The original goes into an encrypted backup on your own server before any of that happens, and one click puts it back. You can look at the malware it removed before you decide. That backup covers every file we touch, not only the ones WordPress.org happens to host.

Separately, an integrity scan compares every core, plugin and theme file against the canonical upstream copy of the exact version you have installed, and restores anything that drifted. While the file is clean that is unlimited on the free plan and never touches your cleanup count. Same job as Safe Repair, without the wp.org-plugins-only boundary.

Bulk Fix All ships on every install, free, with a preflight preview so you can see exactly what it will touch before it touches anything. Pro at $79 a year lifts the cleanup limit and turns on unattended fixing, so a scheduled scan cleans without you opening the dashboard.

Side by side

FeatureDefenderSegurium
Entry price Free, or $60/yr list for Pro Basic on one site Free, or $79/yr per site
Scanning on a free install with no account connected Core and plugin file integrity against WordPress.org, plus outdated and removed plugins Full malware scan, same detection feed as Pro
Scanning after you connect a free WPMU DEV account Adds vulnerability lookup and suspicious-code scanning of PHP and JavaScript No account to connect
An injection in a file with no WordPress.org copy Ignore or Delete. Safe Repair does not cover it Cleaned version of that exact file, 3 per 30 days on Free
Repairing a modified WordPress.org plugin file Safe Repair, free. Overwrites any local changes Restore to upstream content. Unlimited while the file is clean
Recovering the original after a fix Quarantine, WordPress.org plugin files only, 30 days to 1 year Encrypted copy on your own server, one-click restore
Unattended cleanup on a schedule Not offered. No in-place cleaning at any tier Pro, $79/yr
Country blocking Free, local GeoLite2 database refreshed weekly Free, with a confirm-or-revert step so a mistake cannot lock you out
Security headers Free, one of twelve hardening recommendations Free, three presets plus custom
Two-factor authentication Free: TOTP, WebAuthn, hardware keys, backup codes, WooCommerce Free: TOTP, email fallback, backup codes, trusted devices
Firewall AntiBot bot filter runs in PHP, free. The full WAF needs WPMU DEV hosting Runs inside WordPress, free: IP and CIDR rules, country filter
Curated IP blocklist Free, synced every 12 hours from over 750,000 sites None. Your own rules only
Hiding the login URL Free, login masking Not shipped
Vulnerability scanning against a CVE database Free once a WPMU DEV account is connected Not shipped
Security audit log Pro in the shipped 6.1.0 release, announced as free in 6.2.0 Not shipped
Track record On WordPress.org since 2017, 96/100 across 334 ratings, 80,000 installs Listed since July 2026

Defender prices and capabilities checked at wpmudev.com, in their documentation, and in the free 6.1.0 ZIP on WordPress.org on 19 August 2026. Their changelog dated 18 August 2026 announces the audit log reaching free Hub and WordPress.org users in 6.2.0, which had not landed in the directory when we checked. Check both again before you decide.

What Segurium does not do

Six things, and Defender gives four of them away.

Who should switch, and who should not

Most readers should run both, and it costs nothing. Defender Free in front for login masking, breached-password checks, hardware-key two-factor and the bot blocklist. Segurium behind it for detection and cleanup. Turn one of the two malware scanners off so the same files are not scanned twice, and enrol your users in one two-factor system rather than two, because two competing 2FA plugins is a common way to lock yourself out of your own admin.

Switch outright if the last infection landed in a custom theme or a paid plugin and Delete was the only button that applied, or if you would rather not connect a WPMU DEV account to get the scan their listing advertises.

Do not switch if the curated bot blocklist, the vulnerability lookup or the audit log is what keeps you on Defender, or if you want the rest of the WPMU DEV plugin suite that a Pro plan bundles in.

One practical note whichever way you go. Defender 6.0.0 shipped a full UI rewrite in July 2026, followed by a 6.0.1 hotfix the next day for a fatal error, and their own changelogs for 6.1.0 and 6.2.0 record two-factor and notification settings being incorrectly reset or disabled on upgrade. Check your two-factor enrolment after a Defender update.

What moving across involves

Nothing imports. Segurium has migration adapters for some plugins and Defender is not one of them, so there is no settings transfer and no importer tab to open. On one site the manual setup takes a few minutes.

You set these by hand:

  1. Install Segurium from WordPress.org.
  2. Accept the service disclosure. Nothing contacts our service before you do.
  3. Run a full scan and an integrity scan.
  4. Set your firewall rules, blocked countries and security headers.
  5. Decide about Defender. Keeping it for the login hardening is a reasonable answer, and if you do, turn its scanner off and pick one two-factor system.

Install the free plugin from WordPress.org

Nothing is deleted without a reversible backup on your own server.

What leaves your server, in plain terms

Scanning is opt-in. Until you accept the disclosure on the plugin page, Segurium does not contact our service and does not scan.

Files are checked by SHA-256 first. A file has its bytes sent in two cases: when its hash is one we have never seen, which in practice is about 6% of them, and when you clean it and we build the replacement. Everything else is settled by hash.

Both products send something off your server. Defender's vulnerability and suspicious-code steps call WPMU DEV servers, and their audit log is stored there with retention capped at 12 months. The difference is the account: Segurium needs no signup, and about 94% of your files are settled by hash without their bytes leaving the machine.

Samples we do receive are kept for up to 365 days and then deleted by an automated purge, and an analyst can delete one sooner once it has been triaged. Our privacy policy lists every retention period we hold to.

Our servers are in the European Economic Area and Segurium is run from Spain, so GDPR applies to us directly rather than reaching us through an adequacy decision. Two subprocessors sit outside the EEA, for payments and for support email. Both are covered by Standard Contractual Clauses and both are named in the privacy policy.

We do not track your visitors. Segurium looks at files and login attempts.

Questions

Does Defender's free scanner find malware or not?
Three of their own surfaces answer differently, so here is all three. Their WordPress.org readme has a heading called Free Malware Scanner and lists changed files, known vulnerabilities, suspicious code and outdated plugins. Their pricing page sells vulnerability detection and suspicious code scanning as reasons to upgrade to Pro. The free 6.1.0 code adds the vulnerability and suspicious-code steps to the scan only when a WPMU DEV Hub API key is present, and a free Hub account provides one. Read together on 19 August 2026: an unconnected free install checks file integrity against WordPress.org and flags outdated or removed plugins. Connect a free account and the other two turn on.
Defender Pro is $60 and Segurium Pro is $79. What is the difference for?
Defender Pro adds scheduled scans, email alerts, audit logging and the rest of the WPMU DEV plugin suite on top of the same scan. It does not change what happens to an infected file. Segurium Pro lifts the cleanup ceiling above three files per 30 days and runs the fix unattended on a scheduled scan. If you never expect to clean more than three files a month, take Segurium Free and pay nothing.
What happens to an infected file in each product?
Defender offers Ignore, Delete, or Safe Repair. Safe Repair fetches the latest copy from the WordPress.org repository, so the file has to have come from there, and their documentation says any local changes to the file are overridden. Segurium asks for a cleaned version of that exact file, writes it back, and the theme keeps rendering. When no clean version can be produced, the cleanup stops and leaves the file exactly as it found it.
Is Defender's quarantine a backup?
It is a copy of the infected file, held for 30 days by default and up to a year if you raise the setting. That is more than most scanners in this market keep and it is worth having. It covers plugin files from WordPress.org and nothing else, so a theme file, a paid plugin or your own code is deleted with no copy retained. Segurium writes the original into an encrypted backup on your own server for any file it touches, and one click puts it back.
Can I run both?
Yes, and most readers should. Defender Free covers login masking, breached-password checks, hardware-key two-factor and a curated bot blocklist that we do not ship. Segurium covers detection and cleanup. Turn one of the two malware scanners off so the same files are not scanned twice, and enrol your users in one two-factor system rather than two.
Will my Defender settings come across?
No. There is no importer for Defender, so you set your firewall rules, blocked countries and two-factor enrolment again by hand. It takes a few minutes on one site. Keeping Defender installed for the login hardening avoids most of that work.

Comparing something else?

Run one scan against your own site

Install the free plugin and scan alongside Defender. If the two agree, you have spent twenty minutes and confirmed your site is clean. If they do not, you found out for nothing and you can clean it in the same screen.