Kadence Security Pro
Tweaks
- Update Patchstack details for existing vulnerabilities.
Features
- Restrict Admin Access module under Features > Login Security to configure authorized country access to your dashboard.
- Security Headers module under Advanced to enforce essential HTTP security headers.
Tweaks
- Ensure generated Nginx config rules are valid for customized directory structures.
Tweaks
- The Solid Security Basic and Solid Security Pro plugins can no longer be active at the same time.
- Config files now show “Solid Security” instead of “iThemes Security”.
- Improved Database Backups dashboard widget when the feature is disabled.
- Clarify the 2FA onboarding email confirmation message.
- Improve Passwordless Login styling.
- All Gutenberg blocks use API version 3.
- Show the plugin changelog in the plugin information pop-up.
- The lib/updater library has been updated to 1.9.3.
Security
- Update the “tmp” npm package.
- Don’t include package.json in zip.
Fixes
- Vulnerable Software dashboard card didn’t render properly.
- Firewall rules that depend on HTTP headers didn’t work correctly in all cases.
- PHP Warning: Undefined array key 1 core/admin-pages/logs-list-table.php.
- Logs will appear in the correct order regardless of database version.
- PHP Warning: Array offset on value of type null core/modules/security-check-pro/class-itsec-security-check-pro.php.
Tweaks
- Send notification about new vulnerabilities found during manual scan.
- Site Scan page: show mitigated vulnerabilities, ensure all unresolved vulnerabilities are visible.
Fixes
- Notification settings could not be updated.
Fixes
- Admin should be able to edit 2FA options for other users.
Tweaks
- Clarify Site Scan description to reflect the new scheduling frequency.
- Increase minimum PHP requirement to 7.4 and update the admin notice accordingly.
Fixes
- The padding on the WP Admin Dashboard page was incorrect.
- PHP notice about early translations loading on the settings screen.
- Treat Central IPs as trusted to ensure Central isn’t blocked by Trusted Devices restrictions.
Features
- Learn more: https://solidwp.com/?p=110379
- Patchstack Priority tells you how quickly you should address a vulnerability so you can focus on the most critical issues.
- The Security Digest email includes a complete list of vulnerabilities affecting your site.
Tweaks
- The Site Scan email now only includes newly found vulnerabilities to prevent notification fatigue.
- Site Scans now run hourly to detect new vulnerabilities.
- Make frontend JS code compatible with React 18.
Tweaks
- The lib/updater library has been updated to 1.9.1
Tweaks
- Development and staging sites no longer take up a separate license. Learn more: https://solidwp.com/blog/seamless-solidwp-licensing-across-all-your-environments/
- Reduce number of steps in the onboarding sequence.
Fixes
- Notification Center settings could not be properly saved.