Kadence Security Pro
Tweaks
- Allow for customizing access to the Application Passwords feature.
- Added comment to prevent Tide from marking the plugin as not compatible with PHP 5.3.
- Differentiate between "Enforced Two-Factor" and "Configured Two-Factor" in User Security Check.
Fixes
- Improve clearing of previous File Change file hashes.
- Internal links to a filtered logs page.
- Prevent duplicate "user-logged-in" log items when logging-in with Two Factor.
- Prevent multiple session tokens from being created when logging-in with Two Factor.
- Prevent missing provider information when logging a successful Two Factor authentication.
- Fixed incorrect detail text for Local Brute Force Protection on the Grade Report.
Features
- Add Two-Factor On-Board flow.
Tweaks
- Support disabling enforced Two-Factor the first time a user logs-in.
- Introduced Login Interstitial framework to consolidate code between Password Requirements & Two Factor.
Fixes
- Resolve warnings when upgrading file change settings.
- Allow read-only Application Passwords to make HEAD requests.
Tweaks
- Move Online Files hashes to a separate storage setting to improve performance on sites with large number of plugins or themes.
- Add description for File Change recovery related logs.
- Don't report removed files if the removal is caused by a new file extension being excluded.
Fixes
- Improved detection of REST API requests on sites without a home dir.
- Improve File Change recovery system on high-traffic websites.
- Fix warnings on debug file change log items.
Fixes
- Fixed a fatal error condition that could occur on the Grade Report page when specific combinations of manual roles for Two-Factor Protection > User Type Protection were selected.
Features
- Added Grade Report, a tool to identify security weaknesses on the site with options to fix the detected issues.
Fixes
- Ensure all users with the
manage_optionscapability are available when selecting contacts in the Notification Center.
Tweaks
- Added minimal API for adding additional entries to the Security admin menu.
Fixes
- Warning when uninstalling a plugin while File Change module is active.
Tweaks
- Shrink storage size of file scans.
- Make recovering file scan log smaller.
Fixes
- Prevent WP admin dashboard JavaScript from crashing when the File Change module is not loaded.
Tweaks
- Track raw memory used by the file change scanner as well.
- Page Load Scheduler: Unschedule single events before running them. This mirrors the behavior of the WP Cron scheduler.
Tweaks
- File Change Scan uses a new batching mechanism to prevent crashing on hosts but still generating only one report per-day.
- Updated list of File Change excluded file types to include more media extensions.
- File Scan "chunk" option is removed.
- Specifying a manual file scan list has been removed.
- Security Digest now includes all lockouts that have occurred since the last email.
Fixes
- Don't prompt for security check when visiting the settings page after running the security check WP CLI command.
Features
- Add WP CLI commands for running the Security Check Scan, managing Modules and enrolling in Network Brute Force.
Fixes
- When using the Cron scheduling system, malware scans that had failed and been scheduled to retry would fail to reschedule the original scan event upon success.
- Added ability to show object data for classes that are not loaded to the Logs page.
- Fixed logging system references to "fatal-error" that should be "fatal".
- Prevent PHP warning when completing database backups that are not emailed to any recipients.
- Prevent PHP warning about converting an array to a string when adding notification data.
Fixes
- Fixed situation that could cause lockout notifications being sent for whitelisted IPs.
- Fixed issue where saving Global Settings would be blocked by an unwritable "Path to Log Files" path when the "Log Type" is set to "Database Only".
- Fixed issue that prevented log database entries from purging and log file entries from rotating on a schedule.