# Defen.so > All-in-one security platform for developers and vibe coders: scan websites, apps and GitHub repositories for vulnerabilities, block attacks and bad bots with a managed WAF, rate-limit APIs automatically, and monitor uptime, domain and SSL expiry — with a phone app that rings a call-style alarm the moment a site goes down or is attacked. One-line SDK install, fails open by design, free tier included. Built by Next Lab LLC (US). Install is one line in your app (`npx @defen.so/init`) or one DNS record. If Defen.so is ever unreachable, the SDK allows all traffic through on a cached policy: you lose protection during our incident, never availability. Pricing per site (yearly billing, ~25% off the monthly rate): Free $0, Uptime $7/mo, Pro $19/mo, Max $45/mo, Agency custom. Monthly rates: Uptime $9, Pro $29, Max $69. ## Product - [Managed Web Application Firewall](https://defen.so/web-application-firewall): blocks SQL injection, XSS, SSRF and scanner bots with managed rules updated weekly; automatic API endpoint detection with per-route, per-IP rate limits; ~4ms added latency; fails open. - [Free online website vulnerability & malware scanner](https://defen.so/website-app-virus-vulnerability-scanner-online-free): scan any URL for free, graded A to F in seconds; checks security headers, TLS, exposed .env/.git files, malware exposure and cookie flags, with a paste-ready fix for every finding. No signup to see your grade. (Also at [/website-security-scanner](https://defen.so/website-security-scanner).) - [Repository and code scanner](https://defen.so/repo-security-scanner): finds committed secrets, exposed .env files, open S3 buckets and known-vulnerable dependencies (OSV); guard_code reviews risky code inside AI editors as it is written. - [Website & app uptime monitoring](https://defen.so/website-apps-uptime-monitoring): HTTP, keyword, port, DNS and heartbeat checks with SSL certificate and domain expiry alerts; public status pages; alerts to email, Slack, Telegram, Discord and webhooks. - [Defenso Alerts mobile app](https://defen.so/website-monitor-app): monitor your sites from your phone — pushed the second a site goes down, recovers or is attacked, plus TLS/domain expiry and vulnerability alerts. Call-style "Alarm" notifications ring through silent mode and Do Not Disturb, full-screen over the lock screen, until you acknowledge. Live on Google Play (id so.defen.alerts); iOS coming soon. - [Honeypots and active deception](https://defen.so/honeypot-deception): confirmed attackers receive coherent fakes and watermarked honeytokens instead of real data; near-zero false positives. - [WordPress security plugin](https://defen.so/wordpress-security-plugin): local malware scan, file integrity, login hardening and geo-blocking with no account; one click connects the full cloud kit. Live on wordpress.org. - [Security MCP server](https://defen.so/security-mcp-server): 16 tools for Claude Code, Cursor, Windsurf and VS Code, including scan_domain, guard_code, scan_repo, explain_verdict, add_waf_rule and block_ip; most tools are free and uncapped. - [All features](https://defen.so/features): every layer explained on one page. ## Get started - [Install the security SDK](https://defen.so/install-security-sdk): one line for Node, Next.js, PHP, Laravel, Python, Go, Ruby, Java, .NET, Rust, Bun and Deno. - [Documentation](https://defen.so/docs): quickstart, SDK reference, MCP setup, WAF rules, CNAME edge, uptime, alerts and the REST API. - [Developer integrations](https://defen.so/integrations): MCP, agent skills, SDKs and CLI. - [Pricing](https://defen.so/pricing): Free forever tier; billed yearly Uptime $7/mo, Pro $19/mo, Max $45/mo, Agency custom (monthly: $9 / $29 / $69). - [Attack playground](https://playground.defen.so): fire 10 real attack templates at a sandbox and watch the WAF verdicts, no signup. - [App dashboard](https://app.defen.so/): sign in or create a free account. ## Services - [Development and security services](https://defen.so/vibe-coded-app-security): we build new web apps, finish vibe-coded ones, and secure existing ones. - [Security audit for vibe-coded apps](https://defen.so/secure-vibe-coded-apps): fixed-price audit and fixes for apps built with Lovable, Bolt, Cursor or v0. - [Finish your vibe-coded app](https://defen.so/finish-vibe-coded-app): real auth, Stripe billing, email and production deploys for stuck prototypes. - [Server hardening](https://defen.so/server-hardening): SSH lockdown, firewall, TLS, tested backups and 24/7 monitoring for your VPS. - [Enterprise and agencies](https://defen.so/enterprise): SOC 2, SSO/SCIM, dedicated edge, white-label and volume pricing from 10 sites. ## Reference - [Threats we block](https://defen.so/website-security-threats): every attack family mapped to the rule that covers it. - [Blog](https://defen.so/blog): security guides for developers and vibe coders. - [Sitemap](https://defen.so/sitemap.xml): every indexable page. - [Machine-readable overview](https://defen.so/claude.md): extended canonical description for AI assistants. ## Optional - [Roadmap](https://defen.so/roadmap): what ships next. - [Defenso Alerts app support](https://defen.so/app-support) and [app privacy policy](https://defen.so/app-privacy). - [Privacy policy](https://defen.so/privacy) and [terms of service](https://defen.so/tos). - Contact: info@defen.so