Product limitations, upgrades, and support evidence
Know what the module can and cannot prove, how to plan upgrades, and what evidence to collect before requesting support.
Not rated yet
DNN Defender provides defense in depth, not a guarantee that compromise is impossible. Request
controls cannot inspect traffic that never reaches the DNN application, repair vulnerable DNN
core code, sanitize files already stored before protection, or recover a database without an
external backup. Native-code malware, encrypted/password-protected archives, custom protocols,
direct filesystem access, and upstream volumetric attacks require additional controls.
The API Security Scanner analyzes supported managed controller, ASHX, and ASMX patterns that it can
map from installed assemblies and configuration. Dynamically generated routes, native components,
external services, encrypted or unavailable code, reflection patterns outside the supported IL
model, and business authorization implemented beyond the reachable analysis boundary still
require manual review and bounded testing. A clean scan is not proof that every possible custom
route or module workflow is safe.
Upgrade policy
- Prefer the DNN vendor-fixed version for published core vulnerabilities.
- Use DNN Defender strict/prevention controls to reduce exposure when compatibility, time, or
change risk delays the upgrade.
- Enter FIM Maintenance Mode for the deployment, test the site, review differences, then refresh
the baseline only after approval.
- Retain DNN Defender after upgrade because misconfiguration, vulnerable extensions, credentials,
unsafe uploads, and future advisories remain relevant.
Support evidence checklist
Provide DNN and DNN Defender versions, edition/license state, UTC time range, relevant sanitized
paths/routes, control modes, exported Scan/Audit/WAF/FIM rows, scheduler status, and the exact error
message. Remove credentials, connection strings, personal information, and sensitive payloads
before sharing evidence.
For scanner concerns, include the final decision and every engine verdict rather than only the
overall score. For WAF concerns, include whether the action was Observed or Blocked and the
correlation context. For FIM concerns, include baseline time, change type, protected-file count,
and recovery-copy availability.
Was this page helpful?