Kadence Security Pro
Features
- Refreshed UI for manging per-user security settings like Passwordless Login, Passkeys, Two-Factor and Privilege Escalation. The previous Two-Factor UI can be enabled using the SOLID_SECURITY_LEGACY_2FA_UI constant.
- A new block "Solid Security User Security Settings" let's you display this UI on the front-end of your website. The [solid_security_user_profile_settings] shortcode can be used if you're not yet using the Block Editor.
Tweaks
- Solid Security now requires WordPress 6.3 or later.
- Display a snackbar notice when sending a 2FA reminder from the Site Scan page.
- Include a link directly to the Patchstack database in the Site Scanner alert email.
- Remove iThemes Security is now Solid Security banners from the admin.
Fixes
- An error occurred when trying to create a new Firewall rule as a draft.
- Trying to enable Network Brute Force from the Security messages center linked to the wrong place.
- During onboarding, a double scrollbar was displayed on some screen sizes.
Features
- Add support for creating custom firewall rules.
Tweaks
- Add support for configuring firewall settings from the Firewall page.
Fixes
- The firewall page would appear empty when geolocation could not retrieve a country code.
Security
- Harden SolidWP Updater against XSS attacks. Thanks to Robin Wood (digi.ninja) for disclosing this issue.
Security
- Don't disclose the login URL when using Hide Backend on a site with comments enabled and comment registration required. Thanks to Naveen Muthusamy for disclosing this issue.
Tweaks
- Check for the promote_user capability when using Privilege Escalation in addition to edit_user.
- Remove the iThemes Security is now Solid Security banner from admin-facing email notifications.
- The lib/updater library has been updated to 1.8.1
- Add a
wp ithemes-licensing set-licensed-urlWP-CLI command.
Fixes
- Prevent the User Security page from crashing when "Show Avatars" is disabled in the WordPress discussion settings.
- Fix some filters on the User Security page not working as expected.
- Fix spacing on the Two-Factor form when backup methods are enabled.
- Fix fatal error when there is an error retrieving Patchstack license information.
- Styling issues on WordPress 6.4.
Tweaks
- Add pagination to the Firewall logs table.
- Various UI improvements.
Fixes
- On sites with no logo, a broken image appeared in some emails.
- In some email clients, the Solid Security logo would stretch too wide.
Fixes
- Ensure new database tables are created.
Tweaks
- iThemes Security is now Solid Security! Learn More: https://go.solidwp.com/changelog-what-is-patchstack
- Solid Security now requires WordPress 6.2 or later.
- The dashboard and settings screens have been redesigned to make it easier to find what you're looking for.
- The Security Summary dashboard card gives you a snapshot of the most important security issues affecting your site.
- Add support for loading Solid Security via an MU-Plugin for improved performance when blocking attackers.
- Remove the IP Tracker Online link from the logs page.
Features
- Virtual Patching powered by Patchstack protects your site from vulnerable software even when you can't update to a fixed version.
- The Firewall screen brings together the Firewall functionality Solid Security provides into one easy to use screen. More Firewall features are coming soon!
- The Vulnerabilities screen identifies what vulnerable software you have on your site and guides you through next steps.
- Identify risks in your site's security with the the expanded Site Scan functionality.
- The User Security screen keeps you appraised of the security practices your site's users are following. Easily apply actions to multiple users in one-click like resetting passwords or logging out active sessions.
Fixes
- PHP 8.2 compatibility.
- Resolved PHP warnings when unexpected data is encountered during software updates.
Tweaks
- iThemes Security is becoming Solid Security soon. Learn More: https://go.solidwp.com/security-wpadmin-ithemes-becoming-solidwp
Fixes
- Username First login compatibility with WordPress 6.3.
Fixes
- Passwordless Login compatibility with WordPress 6.3.
Tweaks
- Add support for mandating User Verification when using passkeys.
Fixes
- Don't require "Write to Files" to be enabled to use the "Rotate Encryption Key" tool.