[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGbHDSVvrG0iPmM0yz1NxdBCdlKLYFM3sOk17nYEDm6w":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"defyndigital","Defyn","https:\u002F\u002Fprofiles.wordpress.org\u002Fdefyndigital\u002F",2,20,100,30,94,"2026-08-24T02:54:01.476Z",[14,36],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":21,"num_ratings":21,"last_updated":22,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":26,"homepage":32,"download_link":33,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"defyn-security-manager","Defyn Security Manager – Hide Login, 2FA & Brute-Force Protection","1.2.1","\u003Cp>\u003Cstrong>Defyn Security Manager is a lightweight WordPress security plugin that hides your login page and locks down the back end.\u003C\u002Fstrong> Most attacks on WordPress start at one predictable place: \u003Ccode>\u002Fwp-admin\u003C\u002Fcode> and \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode>. Defyn Security Manager moves that door, throttles attackers, adds two-factor authentication, and records every attempt so you always know who is knocking.\u003C\u002Fp>\n\u003Cp>No bloat, no upsell walls, and no account required. Install it, choose a secret login slug, and your login page disappears from bots and scanners.\u003C\u002Fp>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hide the WordPress login URL.\u003C\u002Fstrong> Replace \u003Ccode>\u002Fwp-admin\u003C\u002Fcode> and \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> with any custom login URL you choose, so automated bots and brute-force scripts hit a dead end.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Decoy or 404 the old URLs.\u003C\u002Fstrong> Decide what attackers see at the original login addresses: a 404, a redirect, or a decoy login screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force protection.\u003C\u002Fstrong> Limit login attempts and automatically lock out IP addresses after repeated failures, with a one-click control to clear active lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-factor authentication (2FA).\u003C\u002Fstrong> Add TOTP-based two-factor authentication using Google Authenticator, Authy, 1Password, Microsoft Authenticator or Bitwarden, complete with backup codes and per-role enforcement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API and XML-RPC protection.\u003C\u002Fstrong> Extend two-factor enforcement to the REST API and XML-RPC, with optional API hiding to shrink your attack surface.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Time-window access control.\u003C\u002Fstrong> Only allow logins during the hours and days you actually work, and block everything else.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP allowlisting.\u003C\u002Fstrong> Optionally restrict back-end access to trusted IP addresses or CIDR ranges.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity log and audit trail.\u003C\u002Fstrong> See login attempts, lockouts, scans of your old login URLs, and settings changes in one searchable log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email alerts.\u003C\u002Fstrong> Get notified about lockouts, scans, and logins from new IP addresses.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why choose Defyn Security Manager\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Fast and focused.\u003C\u002Fstrong> A purpose-built login-security and login-hardening plugin, not a heavyweight suite that slows your site down.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recovery built in.\u003C\u002Fstrong> A documented emergency kill switch means you can never permanently lock yourself out.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy friendly.\u003C\u002Fstrong> Your data stays on your site. Nothing is sent to a third-party service.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built by an agency.\u003C\u002Fstrong> Maintained by \u003Ca href=\"https:\u002F\u002Fdefyn.com.au\" rel=\"nofollow ugc\">Defyn\u003C\u002Fa>, an Australian web design and development studio that runs this plugin on client sites every day.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Defyn Security Manager is ideal for anyone who wants to hide wp-admin, stop brute-force login attempts, limit login attempts, add 2FA to WordPress, and keep a clear security audit trail.\u003C\u002Fp>\n","Hide wp-admin behind a custom login URL and stop brute-force attacks with two-factor authentication, login limits, IP rules and an activity log.",202,0,"2026-07-17T04:48:00.000Z","6.8.6","5.8","7.4",[27,28,29,30,31],"brute-force","hide-login","login","security","two-factor","https:\u002F\u002Fdefyn.com.au\u002Fplugins\u002Fdefyn-security-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefyn-security-manager.1.2.1.zip",null,"2026-07-22T17:31:50.256Z",{"slug":37,"name":38,"version":39,"author":5,"author_profile":6,"description":40,"short_description":41,"active_installs":21,"downloaded":42,"rating":21,"num_ratings":21,"last_updated":43,"tested_up_to":44,"requires_at_least":45,"requires_php":46,"tags":47,"homepage":53,"download_link":54,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"defyn-media-offload","Defyn Media Offload","1.0.0","\u003Cp>Defyn Media Offload moves your WordPress media library to S3-compatible object storage and serves every image, video and document from a fast content delivery network (CDN), then optionally deletes the local copies so your site fits within strict host disk and storage limits.\u003C\u002Fp>\n\u003Cp>It works with Amazon S3, DigitalOcean Spaces, Cloudflare R2, Wasabi, Backblaze B2, Google Cloud Storage (in S3 mode), MinIO and any other S3-compatible object store. Offloading your uploads to cloud storage frees up server disk space, shrinks your backups, lowers bandwidth costs, and lets a global CDN deliver your images faster.\u003C\u002Fp>\n\u003Cp>It was built for a large WooCommerce and multi-vendor marketplace on managed WordPress (where Jetpack’s image CDN virtualises some thumbnail sizes), so it is hardened against the edge cases that break naive media offload plugins.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatic offload on upload, after all thumbnail sizes are generated, including front-end (vendor) uploads.\u003C\u002Fli>\n\u003Cli>Serves product images, galleries, variation images, responsive \u003Ccode>srcset\u003C\u002Fcode>, REST API URLs and content-embedded images from the CDN.\u003C\u002Fli>\n\u003Cli>Resumable, cursor-based bulk migration for very large libraries (survives dropped SSH sessions). WP-CLI is the supported path; a browser-driven runner and Action Scheduler background runner are also provided.\u003C\u002Fli>\n\u003Cli>Optional, decoupled “remove local” pass so migration and deletion stay safe and reversible.\u003C\u002Fli>\n\u003Cli>Optional mirror-delete: removing an attachment removes its objects from the store.\u003C\u002Fli>\n\u003Cli>Handles Jetpack “virtual” thumbnail sizes (skip-and-log, never stalls).\u003C\u002Fli>\n\u003Cli>WooCommerce downloadable\u002Fprotected files are stored privately and never made public-read.\u003C\u002Fli>\n\u003Cli>Works with the AWS SDK for PHP v3, namespace-isolated with php-scoper so it never conflicts with other plugins’ bundled AWS SDK.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Configuration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>For best security, define credentials as constants in \u003Ccode>wp-config.php\u003C\u002Fcode>:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define( 'OSMO_KEY',      'your-access-key' );\ndefine( 'OSMO_SECRET',   'your-secret-key' );\ndefine( 'OSMO_BUCKET',   'your-bucket' );\ndefine( 'OSMO_REGION',   'syd1' );\ndefine( 'OSMO_ENDPOINT', 'https:\u002F\u002Fsyd1.digitaloceanspaces.com' );\ndefine( 'OSMO_CDN',      'https:\u002F\u002Fcdn.example.com' );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Otherwise enter them on \u003Cstrong>Media \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Media Offload\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to one external service: the S3-compatible object storage\u003Cbr \u002F>\nendpoint that \u003Cstrong>you\u003C\u002Fstrong> configure (for example DigitalOcean Spaces, Amazon S3,\u003Cbr \u002F>\nWasabi, or a self-hosted MinIO server). It is used to store and serve your media\u003Cbr \u002F>\nfiles.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>What is sent, and when: when you upload media (or run a migration), the media\u003Cbr \u002F>\nfiles and their object keys (the uploads-relative path, e.g.\u003Cbr \u002F>\n  2026\u002F06\u002Fimage.jpg) are uploaded to the bucket you configured, using the\u003Cbr \u002F>\naccess key and secret you provide. URL rewriting and verification read object\u003Cbr \u002F>\nkeys back from the same bucket.\u003C\u002Fli>\n\u003Cli>The plugin does not contact any other server. It does not collect analytics,\u003Cbr \u002F>\ntelemetry, or usage data, and it never “phones home” to the author.\u003C\u002Fli>\n\u003Cli>You must supply your own credentials and accept the terms and privacy policy\u003Cbr \u002F>\nof whichever storage provider you choose. DigitalOcean Spaces:\u003Cbr \u002F>\nhttps:\u002F\u002Fwww.digitalocean.com\u002Flegal\u002Fterms-of-service-agreement \u002F\u003Cbr \u002F>\nhttps:\u002F\u002Fwww.digitalocean.com\u002Flegal\u002Fprivacy-policy . Amazon S3:\u003Cbr \u002F>\nhttps:\u002F\u002Faws.amazon.com\u002Fservice-terms\u002F \u002F https:\u002F\u002Faws.amazon.com\u002Fprivacy\u002F .\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Third-party libraries\u003C\u002Fh3>\n\u003Cp>This plugin bundles the AWS SDK for PHP v3 (Apache License 2.0, GPL-compatible)\u003Cbr \u002F>\nand its dependencies (Guzzle, PSR interfaces, JMESPath, Symfony polyfills). The\u003Cbr \u002F>\nSDK is namespace-isolated under \u003Ccode>OSMO\\Vendor\\\u003C\u002Fcode> using php-scoper so it never\u003Cbr \u002F>\nconflicts with an AWS SDK bundled by another plugin. This is namespacing, not\u003Cbr \u002F>\nobfuscation, and the bundled PHP remains fully human-readable.\u003C\u002Fp>\n\u003Cp>The full source code and the build tooling (composer.json, scoper.inc.php,\u003Cbr \u002F>\nbuild.sh, and the post-scope patch helpers in bin\u002F) are available so the bundled\u003Cbr \u002F>\n    vendor\u002F directory can be reproduced from scratch with \u003Ccode>bash build.sh\u003C\u002Fcode>.\u003C\u002Fp>\n","Offload WordPress media to Amazon S3, DigitalOcean Spaces, Wasabi, Cloudflare R2 or MinIO, serve images from a CDN, and reclaim server disk space.",170,"2026-06-26T11:48:00.000Z","7.0.2","6.0","8.1",[48,49,50,51,52],"cdn","cloud-storage","digitalocean-spaces","media-offload","s3","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefyn-media-offload.1.0.0.zip"]