Integrations for every stack & editor.
Scanning and monitoring start the moment you add a site, no code needed. Add one line and the firewall turns on too. Your AI editor gets the whole platform through the MCP tools and Skills, and alerts land wherever you already work.
- Ten framework SDKs
- MCP & AI Skills
- CLI & WordPress
- Slack, Discord, Telegram
Security that fits the stack you already run.
Defenso is not another dashboard to babysit. It drops into the tools you already use. One SDK line in your framework, a plugin for WordPress, MCP tools inside your AI editor, and alerts routed to the channels your team already lives in. No DNS migration, no agent, no rip-and-replace. Here is how it connects to the rest of your stack.
Every way to plug Defenso in.
Built to slot into modern stacks, not fight them.
The SDK installs in one line on Node, PHP, Python, Go, Ruby, Rust, Java and .NET, with framework-aware wiring for Next.js, Nuxt, SvelteKit, Astro, Express, Fastify, FastAPI, Django, Laravel, Symfony, Rails, chi, gin, axum, Spring and ASP.NET. It runs inside your app, so there is no DNS change and nothing to route through a proxy. Deploy on Vercel, Netlify, Fly, Railway or your own box; Defenso does not care where your code lives.
It coexists with the platforms you already trust. Keep Cloudflare in front for CDN and DDoS; Defenso adds the application-layer WAF, pentest and monitoring behind it. Supabase and Auth0 and Clerk handle your auth; Defenso plugs into the login flow for credential-stuffing and account-takeover protection, and works even when row-level security is not fully configured. WordPress connects with a one-click plugin, and there is a CNAME edge option for sites you cannot add code to.
Alerts reach you where you already work. Every finding and every outage fans out to email, Slack, Discord, Telegram, PagerDuty and signed webhooks, plus the Defenso Alerts phone app with its call-style alarm. AI editors (Claude Code, Cursor, Windsurf and VS Code) get real security tools through the MCP server and agent skills, so "add security to this app" does the right thing without leaving your editor. One layer, wired into the tools you already run.
Frequently asked questions.
Everything people ask before they start. Still unsure? We are one message away.
The SDK supports Node, PHP, Python, Go, Ruby, Rust, Java and .NET, with framework-aware wiring for Next.js, Nuxt, SvelteKit, Astro, Express, Fastify, FastAPI, Django, Laravel, Symfony, Rails, chi, gin, axum, Spring and ASP.NET. It runs on any host (Vercel, Netlify, Fly, Railway, your own server), connects to WordPress via a plugin, and offers a CNAME edge option for no-code sites.
No, it complements them. Keep Cloudflare for CDN and DDoS and Defenso adds the application-layer WAF, pentest and monitoring behind it. Your auth provider (Supabase, Auth0, Clerk) keeps handling sign-in; Defenso plugs into that flow for credential-stuffing and account-takeover protection, and works even if row-level security is not fully set up.
Email, Slack, Discord, Telegram, PagerDuty and signed webhooks, plus the Defenso Alerts phone app whose call-style alarm rings through silent mode and Do Not Disturb. You pick per site which channels fire for security findings versus downtime, and you can add teammates and their devices.
The Defenso MCP server gives Claude Code, Cursor, Windsurf and VS Code real security tools (scan a site, review code you just wrote, catch leaked secrets and explain a WAF verdict) right inside the editor. Agent skills teach the assistant when to scan and how to wire the SDK, so security happens during development, not after.
No. The SDK runs inside your app in one line with no DNS change and no agent to install. WordPress uses a plugin, and there is an optional CNAME edge mode for sites you cannot add code to. Nothing routes through a mandatory proxy, and the SDK fails open so it never becomes a single point of failure.
Plug it into whatever you build with.
Free to start. Add a site for scanning and monitoring, or one line for the firewall, and your editor gets it all.