Kadence Security Pro
Features
- Security Check now attempts to automatically determine the location of the remote IP in the $_SERVER variable in order to protect against IP spoofing.
- Security Check now attempts to automatically determine if the site supports https connections. If support is found, it asks the user if they wish to redirect http requests to https.
Tweaks
- Changed Two Factor login confirmation code emails to avoid spam filters.
Tweaks
- Periodically retry malware scans when there is a temporary error with the scanning service before alerting users of the issue.
- Improved compatibility for Recaptcha on the front-end on slower to load websites.
Removeds
- Removed the “Replace jQuery With a Safe Version” feature as its use (protecting against a specific jQuery bug: https://bugs.jquery.com/ticket/9521) is many years old and is no longer a concern.
Fixes
- Fixed way to work around Hide Backend on some hosts.
- Bumped version number of some scripts to ensure that they refresh properly.
Features
- Added support for email notifications when automatic updates are installed.
Tweaks
- Multisite Support for Settings Exports
- Added warnings to the Version Management settings page if the system or site configuration could prevent automatic updates from working as expected.
- Added support for validating the Recaptcha hostname by using the ‘itsec_recaptcha_validate_host’ filter.
- Refresh module settings after an import has been completed.
- Notify the user of invalid file paths for Log Files, Backups and NGINX Conf file during an import.
- Replaced file locking with database locking. This method of locking is compatible with all systems as it does not require the ability to write files. It also allows for locking to work on sites that have multiple front-end servers with a shared database. Since file locking is no longer used, the Global Settings > Disable File Locking setting was removed.
- Add “Copy to Clipboard” functionality for server and wp-config rules.
Fixes
- Prevent 404s when following links in email notifications on a site with Hide Backend enabled.
- Ensure uninstall process is not run when another version of iThemes Security is still active.
- Fixed method of working around Hide Backend.
- Warnings are no longer generated when saving a user profile with a role of “No role for this site” selected.