Kadence Security Pro
Security
- Fixed display of unescaped data on logs page.
Tweaks
- The logging system now differentiates between WP-CLI commands, WP-Cron scheduled events, and normal page requests.
Fixes
- Fixed the File Change scanner in that it previously could fail to exclude selected directories on some systems.
Tweaks
- Cleaned up styling in settings to make some settings stand out better.
- Use plugin build for cache busting assets.
- Extract scheduling loop system to iThemes Security Core for future development.
Fixes
- Fixed issue preventing the Two-Factor override from iThemes Sync from working as expected.
- Cannot use object of type WP_Error as array in Malware Scanner.
- Reordered loading of logging class to allow for logging earlier.
Fixes
- Fixed issue that could cause login attempts to bypass recaptcha protection.
Fixes
- Fixed “undefined offset” error when displaying specific migrated old log entries.
Fixes
- Fixed schema issue with new logs table.
Tweaks
- Updated logging system to keep track of more information and have more options to filter and sort log entries.
- Improved efficiency of File Change Detection scanning.
- Added malware scan support for scanning all sites in a Multisite Network.
Fixes
- Fixed issue that could register loading the logging page as a failed login attempt on some sites.
Features
- Online Files Comparison now supports WordPress.org plugins.
Tweaks
- Add support for changing position of the Invisible Recaptcha badge.
- Display user lockouts in Lockout Sidebar.
- Use the current site URL instead of the network URL when sending Two Factor Email codes.
Fixes
- Fixed issue that could prevent Sync from loading Malware Scan results if a scan previously failed.
- Fixed method that could be used to discover hidden login slug on some sites.
- Hide Backend notifications not being properly sent when first enabled.
- Load translations on the plugins_loaded hook.
- Log logins with User Logging when logging in with Two Factor.
- Prevent login page being hidden when following the “Confirm Email Address” notification URL.
- Update to the REST API “Restricted Access” feature to protect against methods to work around the restricted access.
Tweaks
- Add ‘site_title’ as an available tag for the Two Factor email.
Fixes
- Fix scheduling retries for Malware Scans on sites that don’t fully support WordPress’s cron system.
- Reactivating Away Mode now replaces the active file if you had previously removed it.
- Ensure lockouts take effect immediately, even on systems where changes to server configuration files do not take effect immediately.
- Warning on new installations when activating certain Version Management features.
Fixes
- Make Cron scheduler available in more circumstances.
- Events with the Twice Daily schedule would not be carried over when switching scheduler strategies.
- Backup schedules respect the interval chosen.
- Prevent multiple cron tests from being scheduled at once.
- Cron test being stuck in a loop preventing a site from switching back to the cron scheduler.
- Prevent warnings when a single and recurring event were scheduled at the same time.
Tweaks
- Sort scheduled events in WP CLI command.
Fixes
- Fixed issue where scheduled events could repeat on sites that do not properly support WordPress’s cron system.