Kadence Security Pro
Features
- Introduces a scheduling framework for handling events. Cron is now used by default, and will switch to using an alternate scheduling system if it detects an error. To disable this detection set ITSEC_DISABLE_CRON_TEST in your wp-config.php file.
Deprecateds
- The ITSEC_FILE_CHECK_CRON and ITSEC_BACKUP_CRON constants have been deprecated. Use ITSEC_USE_CRON instead.
Fixes
- Fix occasional duplicate backups and file scans.
Tweaks
- Preserve notification settings when the responsible module is deactivated.
Fixes
- Process 404 lockouts on the ‘wp’ hook to prevent a headers have already been sent warning message.
- Ensure Hide Backend emails are properly sent when activating Hide Backend before saving the Notification Center for the first time.
- Prevent warning from being issued on new installs by allowing previous settings to be preserved if they exist.
- Better handle WP_Error objects in mail errors that occurred before updating to first patch release.
- A non static method was being called statically.
Fixes
- Don’t display file change admin notifications if the Notify Admin setting is not enabled.
Fixes
- Fixed source of the following warning: “mysql_real_escape_string() expects parameter 1 to be string, object given”.
Tweaks
- Updated queries and prepare statements to account for changes to the esc_sql() function in WordPress 4.8.3.
Fixes
- Fixed the File Change module being incorrectly enabled when upgrading.
Fixes
- Only enable the Lockout email notification is the Daily Digest was previously disabled.
- Fix JavaScript error when loading the Notification Center on some systems.
- Don’t store WP Error objects for mail errors preventing a fatal error for rare PHPMailer errors.
- Prevent error on upgrade warning the subject line was empty.
- Ensure file change notification is properly enabled/disabled on upgrade.
- Fallback to correct default subject lines.
- Don’t enable all administrators as the recipients for emails where all custom email addresses did not have corresponding users.
Tweaks
- Properly enable lockout and file change notifications, uncheck all administrators as recipients when necessary.
Features
- Introduces the Notification Center, a centralized place to manage and customize email notifications sent by iThemes Security.
Fixes
- Corrected some Javascript and CSS links not generating correctly on Windows servers.
- Properly restrict Application Password’s to read only REST API rqeuests when overriding the HTTP method used.
- Ensure scheduled malware scan cron hook is setup when the module is activated.
Tweaks
- Simplify script enqueuing for Two Factor.
Fixes
- Fixed SQL query bug that resulted in the “Minutes to Remember Bad Login (check period)” setting being ignored.
- Fixed bug that prevents wp-admin/install.php blocking from working properly on nginx servers.
- Don’t attempt to do an SSL redirect when WP CLI is running.
Features
- Introduces Magic Links module. Users can now request a magic login link when logging in during a brute force attack on their username.
- Added a new setting in WordPress Tweaks: “Login with Email Address or Username”.
Tweaks
- Host email images from the plugin instead of relying on iThemes servers to help email clients marking messages as spam or blocking images.
- Added Magic Links, a new Pro-only feature, to be activated by Security Check.
- Rearranged modules to be listed alphabetically.
Fixes
- Improved Recaptcha compatibility with WooCommerce.
- Error when searching for modules preventing modules from appearing.
- Use the wp_options table when acquiring locks in Multisite.
- Prevent duplicate daily digest emails on sites with high load.
Fixes
- Fixed logical error that prevented backups from executing.
- Fixed issue that could cause database locks to flood the database.