Kadence Security Pro
Fixes
- Fatal error when running on a site with an unprefixed version of Pimple or Psr/Container that was loaded before iThemes Security.
Tweaks
- iThemes Security now requires PHP 7.3 and WordPress 5.9 or later.
Features
- Introducing passkeys for Passwordless Login! Users can log into their site using biometrics like Face ID, Touch ID, or Windows Hello. Enable the new "Passkeys" module to add it as a Passwordless Login method.
Fixes
- Preliminary PHP 8.1 compatibility.
Tweaks
- Add Security Alert when running a PHP version older than 7.3.0. Future versions of iThemes Security will require PHP 7.3.0.
Fixes
- Don't attempt to Hide Backend when a Cron request is being processed.
- Prevent entering invalid date values when selecting a custom date range in the Security Dashboard.
Tweaks
- Require a Title when creating a new Dashboard.
Fixes
- Don't attempt to send a Site Scan notification for Clean scans preventing a fatal error after scheduled site scans.
- Initialize Theme in Dashboard Widget rectifying the "An error occurred while rendering this card" message.
- Use Site Registration Authentication when performing a Site Scan on Multisite Subsites rectifying the "Request is missing verification credentials" message.
Tweaks
- Schedule the Automatic Updater to run 5 minutes after a Site Scan finds Vulnerable Software.
Fixes
- Help styling on WordPress 5.9.
- Compatibility with plugins that expected a logged-in user during lockouts.
- Error when visiting the Notifications page after activating a module with notifications for the first time.
- Update deprecated withState usages to useState.
- Set a default value for the Notification User Roles control.
Tweaks
- iThemes Security now requires WordPress 5.8 or later.
Features
- Introduce a new Import Export feature that allows for greater customization and flexibility.
Fixes
- Scroll to top of window when navigating.
- Allow searching for Password Requirements.
- Login page would be blank when Passwordless Login was configured to use the "Username First" flow.
- Don't load WordPress and System Tweaks modules when the
ITSEC_DISABLE_MODULESconstant is enabled. - Prevent incidentally loading the Two-Factor module when it is unregistered.
- Conditionally display the NGINX File Path setting.
- Allow saving Notifications when "default recipients must contain at least 1 item" error is present.
Tweaks
- Reintroduce Feature Flags management UI.
- Reposition "Advanced" and "Tools" menu items to be more readable on lengthy screens.
Fixes
- Sites that did not support HTTPS, but had the SSL module active, but not configured, on upgrade would get redirected to the HTTPS version of the site.
- When the Change Admin User tool is run, update any User Groups referencing the old user id.
- Unregister the iThemes Security Two-Factor module when the Two-Factor Feature Plugin is enabled.
- Add missing and correct erroneous textdomains.
- WordPress footer would appear in the middle of the logs page.
Tweaks
- Move "Have I Been Pwned" integration to the Core plugin.
- Reduce filename length and complexity for built CSS and JS files.
Fixes
- Disable XML-RPC rules in server config files. Previously, XML-RPC was being disabled using the XML-RPC enabled filter.
- Fatal error on logs page when User Logging and Two-Factor are enabled and a user logs in using Two-Factor.
- Add missing constants to the debug page.
- Fatal error when sending the "Inactive Users" notification.
- Remove deleted recipients when saving notifications.
- Allow using reserved words as prefixes for the Hide Backend Login Slug.
- Enforce SSL would not redirect users from HTTP to HTTPS on the front-end of the website.
- Correct Site Scan statuses for scans with no issues.
Fixes
- Prevent Password Requirements being re-enabled if they were disabled before upgrading to iThemes Security 7.0, but had a group selected for them.
- Arguments to the implode function were reversed, causing a Fatal Error on PHP 8.
- Allow installing on WordPress 5.7.0, not just 5.7.1+.
- Ensure values passed to the TextareaListControl is an array.
- Don't run the dashboard migration if unneeded.
- Labels for Disable PHP Execution in Plugins and Themes were reversed.
- Activate the Geolocation module if Trusted Devices provided Geolocation API keys.
Tweaks
- iThemes Security now requires WordPress 5.7 and PHP 7.0 or later.
- The settings UI is now fully responsive and works great across mobile, tablet, and desktop devices.
- Improved keyboard and screen reader support.
- The User Security Profile Card now supports searching for specific users and filtering by User Role.
- The User Security Profile Card can now be used to Force password changes, force a user to lockout, and send a Two-Factor setup reminder.
- The Banned Users Card can add multiple bans at once.
- Add a new Global setting to control "Automatically Temporarily Authorize Hosts".
- When the Global setting "Hide Security Menu in Admin Bar" is enabled, notices will no longer be printed on non-iThemes Security pages. Instead, you can access the Message Center from the Settings or Dashbaord toolbars.
- The Security Dashboard has moved back to the Security menu and is now the default page.
- Your first security dashboard will be created automatically when you visit the dashboard for the first time. Create your own by clicking the dashboard's title, then select "Create New Dashboard".
- The Database Backups module is no longer available if you have BackupBuddy installed. If this behavior isn't desired, enable the "ITSEC_ENABLE_BACKUPS" constant.
- Activating the Magic Links module now enables the feature. The extraneous "Enable Lockout Bypass" setting has been removed.
- The Geolocation API configuration used by Trusted Devices has been moved into it's own dedicated "Geolocation" module.
- Modules are now based on a module.json configuration file. If you are registering custom iThemes Security module, you should update it to include a module.json file that adheres to the core/module-schema.json JSON Schema.
- Add a WP CLI command for running tools. See "wp help itsec tool" for more information.
- Split the Two-Factor and Dashboard module into a Core module and a Pro module. Settings for these modules are still stored in the base module.
- The Network Brute Force module had it's folder updated to "network-brute-force" from "ipcheck".
- New Object Oriented API for creating Password Requirements.
- New Settings and Modules REST API endpoints.
- New RPC REST API namespace. There is no backward compatibility promise for these API endpoints.
Features
- iThemes Security gets a redesigned interface focused on making it easier to configure and find what you're looking for. Read More: https://ithemes.com/?p=64448.
- Instantly search over everything in iThemes Security with a new instant search feature.
- Security Tools have been grouped into their own page. "Identify Server IPs" and "Security Check Pro" can be run manually without using Debug Mode.
- Relevant content from the Help Center, iThemes Blog, and iThemes YouTube channel is surfaced in a new Help area based on the current page. Click the "Help" button in the toolbar or the "Info" icon next to the page title to access it.
Deprecateds
- The following modules have been removed: 404 Detection, Away Mode, Change Content Directory, and Multisite Tweaks.
- The following WordPress and System Tweaks have been removed: Remove Windows Live Writer Header, EditURI Header, Comment Spam, Mitigate Attachment File Traversal Attack, Protect Against Tabnapping, Filter Long URL Strings, Filter Non-English Characters, Filter Request Methods, Remove File Writing Permissions.
- The "Backup Full Database" setting has been removed from the Backups module.
- The "Require SSL", "Front End SSL Mode", and "SSL for Dashboard" settings have been removed from the SSL module.
- The "Strengthen when Outdated" setting has been removed from the Version Management module.
Fixes
- Fix fatal errors when using PHP 8.
- Fix infinite loop when restricting who can use App Passwords on multisite installs.
- Ensure the ITSEC_Setup class does not exist before trying to load it. Display schema errors on multisite in the Network Admin.