Solid Security
Features
- iThemes Security is now Solid Security! Learn More: https://go.solidwp.com/security-welcome-to-solidwp
- The Firewall screen brings together the Firewall functionality Solid Security provides into one easy to use screen. More Firewall features are coming soon!
- The Vulnerabilities screen identifies what vulnerable software you have on your site and guides you through next steps.
- Identify risks in your site's security with the the expanded Site Scan functionality.
- The User Security screen keeps you appraised of the security practices your site's users are following. Easily apply actions to multiple users in one-click like resetting passwords or logging out active sessions.
- The dashboard and settings screens have been redesigned to make it easier to find what you're looking for.
- The Security Summary dashboard card gives you a snapshot of the most important security issues affecting your site.
- Add support for loading Solid Security via an MU-Plugin for improved performance when blocking attackers.
Tweaks
- Solid Security now requires WordPress 6.2 or later.
- Remove the IP Tracker Online link from the logs page.
Fixes
- PHP 8.2 compatibility.
- Resolved PHP warnings when unexpected data is encountered during software updates.
Tweaks
- iThemes Security is becoming Solid Security soon. Learn More: https://go.solidwp.com/security-free-notice-ithemes-becoming-solidwp
Fixes
- Don't require "Write to Files" to be enabled to use the "Rotate Encryption Key" tool.
Tweaks
- Enforce encryption for Two-Factor secrets.
- Add Stellar and Solid banners.
Fixes
- Fallback to the homepage when Enforce SSL encounters a non-safelisted redirect destination.
- IP Detection on sites behind Load Balancers that appended their IP address to X-Forwarded-For and did not provide a Real IP header.
Fixes
- Update Password Strength library to the latest version. This fixes discrepancies between the realtime password strength estimation and the enforced password strength.
Security
- Prevent open redirects attacks against the Enforce SSL module. This attack requires spoofing the Host header which requires additional conditions to exploit. Thanks to nlpro for reporting the issue. Read More: https://ithemes.com/?p=84309
Tweaks
- Add "All" tab to the Features page.
- Don't show "Ban" buttons in Security Dashboard if the user won't be able to create a ban.
Fixes
- Prevent Headers Already Sent warning when a lockout occurs during a WP Cron request on some server setups.
- Manually load Sodium Polyfill for servers that have an older version of libsodium installed.
- Error when saving the File Change settings when the "notify_admin" setting was set.
- Prevent a redirect loop when logging in on sites that take more than 5 seconds to load the Dashboard.
Fixes
- File Logs not rotating.
- PHP warning when loading Icon Fonts in certain configurations.
- Don't attempt to Hide Backend when a Cron request is being processed.
- Prevent entering invalid date values when selecting a custom date range in the Security Dashboard.
- Preliminary PHP 8.1 compatibility.
- File Change "notify_admin" settings validation error.
Tweaks
- iThemes Security now requires PHP 7.3 and WordPress 5.9 or later.
- Add "Ban Lockout" button to the Active Lockouts card.
- Thanks to Calvin Alkan for reporting the security issues fixed in this release.
Security
- Add support for encrypting Two-Factor Mobile App secrets. Enable via Tools -> Set Encryption Key.
- Deprecate Automatic Proxy Detection. Instead, manually configure Proxy Detection or use Security Check. Fix IP spoofing attacks.
Tweaks
- Require a Title when creating a new Dashboard.
Fixes
- Don't attempt to send a Site Scan notification for Clean scans preventing a fatal error after scheduled site scans.
Fixes
- Error when visiting the Notifications page after activating a module with notifications for the first time.
- Update deprecated withState usages to useState.
Features
- Include the full iThemes Security Site Scanner in iThemes Security Free. Scheduled scans are disabled by default.
Fixes
- Scroll to top of window when navigating.
- Allow searching for Password Requirements.
- Don't load WordPress and System Tweaks modules when the
ITSEC_DISABLE_MODULESconstant is enabled. - Prevent incidentally loading the Two-Factor module when it is unregistered.
- Conditionally display the NGINX File Path setting.
- Allow saving Notifications when "default recipients must contain at least 1 item" error is present.
- Help styling on WordPress 5.9.
- Compatibility with plugins that expected a logged-in user during lockouts.
Tweaks
- iThemes Security now requires WordPress 5.8 or later.
- Add new "Go Pro" page that includes an overview of features in iThemes Security Pro.