Kadence Security Pro
Fixes
- Bump lib/updater
Tweaks
- Disable the WordPress 5.5 Auto-Update UI when iThemes Security Version Management is being used to manage auto-updates.
- Make the Site Scanner Report a configurable admin notice.
- Add a security message if a user needs to update their license information.
- Check if a licensed user is defined when checking license status.
- Use an opaque token for site scan verification to reduce invalid secret errors.
Fixes
- Error when trying to run Security Check on new installations.
Tweaks
- Add support for updating a plugin/theme directly from the Site Scanner vulnerability details page.
- Update site scanner notification language to be less alarming.
- Change insensitive language to be more inclusive.
Features
- The new, improved WordPress Security Site Scan powered by iThemes performs automatic checks for known website vulnerabilities and, if a patch is available, iThemes Security Pro can now automatically apply the fix for you.
Tweaks
- Added support for muting specific vulnerability notifications. After performing a new site scan, click the link for details about a vulnerability. Then click the “mute” button to stop being notified about that particular issue.
- Remove quick bans. Persist banned hosts to .htaccess or nginx.conf on an hourly schedule.
- Cap banned hosts persisted to .htaccess or nginx.conf to the most recent 100. This number can be adjusted with the “itsec_ban_users_max_hosts_for_server_config” filter. Older banned hosts will be locked out after WordPress loads.
Fixes
- File Change Security Message would not appear for new installs.
Tweaks
- Ensure randomly generated passwords are considered strong by the Strong Passwords library.
- Suggest a 32 character password when forcing a password change.
Fixes
- PHP warning when a user’s email address is updated outside of the user edit admin page.
- Fix login interstitials on WP Engine when using a front-end login form.
- PHP warning when checking opaque tokens.
- PHP warning after succesfully connecting a site to iThemes Sync via the login connection flow.
Tweaks
- Deprecated Dashboard Widget has been removed.
Fixes
- PHP warning when evaluating password requirements.
Tweaks
- Check tables exist after completing a DB upgrade.
Fixes
- Users with weak passwords would not be forced to change their password if the strong password requirement had been enabled after their password strength was checked.
Tweaks
- Add LifterLMS support to the reCAPTCHA module.
Fixes
- Don’t block registration page when “wp-signup.php” is the Hide Backend register slug.
Fixes
- Update security dashboard and admin notices styling to be compatible with WordPress 5.4.
- Periodically clear expired opaque tokens.
- Exclude “Process Update” and “Process Stop” logs when other process logs are hidden.
- Exclude process logs from the Malware Scan card.
Tweaks
- Use dashicons instead of font-awesome, and native font stack instead of Open Sans on the Grade Report.
Fixes
- Due to a Google reCAPTCHA API change, trying to use v3 or Invisible reCAPTCHA may have always resulted in the “You must submit the reCAPTCHA to proceed. Please try again.” error. You may have to empty your server cache or browser cache to receive the fix.
Tweaks
- Further improve logs performance.