The latest updates to WP Security Ninja for WordPress, currently v5.293. Updated July 28, 2026.
v5.293
Latest
minor
File Viewer - Safely preview common images (PNG, JPG, JPEG, GIF, WebP, ICO) from Core and Malware Scanner results. SV…
New
✓
File Viewer - Safely preview common images (PNG, JPG, JPEG, GIF, WebP, ICO) from Core and Malware Scanner results. SVG is not supported. Images are verified before display and shown only in the admin viewer (they are not executed).
Improved
✓
File Viewer - Very large text/log files show a truncated preview instead of failing when over the size limit.
✓
Core Scanner - The View File button only appears when the file can actually be opened in the viewer.
✓
Security Tests - The unused-themes check no longer treats keeping an extra default WordPress (Twenty*) theme as required. Any inactive theme can be flagged for removal, matching the auto-fixer behavior. Thank you for the feedback.
Fixed
✓
File Viewer - Extensionless and rotated log files such as error_log and error_log.1 open more reliably, including case-insensitive name matching.
✓
Fixes - Disable Username Enumeration no longer blocks URLs with parameters like book_author= (e.g. store search). It now matches only the WordPress author= parameter, and skips the block for logged-in users.
v5.292
minor
Prettier interface for confirmations and overlays across free and Pro — replaces browser confirm/alert on Tools, scan…
New
✓
Prettier interface for confirmations and overlays across free and Pro — replaces browser confirm/alert on Tools, scanners, Firewall, Events, AI Advisor, 2FA, and more. Escape closes, backdrop cancels, Enter confirms.
✓
Optional notes/labels on manual IP whitelist and blacklist entries (IP Management), including CIDR ranges. Notes are limited to 150 characters and stored separately so existing installs and list matching stay compatible.
Improved
✓
Translations - Full POT refresh and locale sync.
✓
Translations - 2FA email and login strings covered in language packs (Spanish included).
✓
Pro
White Label (Pro) - HTML emails use your plugin icon (when set) in branding.
✓
Pro
2FA (Pro) - Custom intro and enter-code texts from Login Protection now appear on the 2FA login screen.
✓
Pro
2FA (Pro) - Email verification codes now use the same shared email template as other Security Ninja emails.
✓
Settings import/export and MainWP sync include IP notes when present.
✓
Update Freemius SDK.
✓
readme.txt - Shortened short description, description, and changelog to meet WordPress.org length limits.
Fixed
✓
Pro
2FA (Pro) - Login "Back to site" link uses the correct text domain so it can be translated.
✓
Pro
2FA (Pro) - Email "Time:" label is properly registered for translation.
✓
AI Security Advisor - Omit temperature from WordPress AI connector requests so providers that reject sampling parameters (e.g. newer Claude models) work reliably. Thank you Tyson.
✓
Pro
Cloud Firewall (Pro) - Avoid PHP warning when REMOTE_ADDR is missing during cron blocklist sync. Thank you Tom.
✓
AI Security Advisor - Omit temperature from WordPress AI connector requests so providers that reject sampling parameters (e.g. newer Claude models) work reliably.
v5.291
minor
Overview tab - AI Security Advisor card, next best actions, what changed since your last AI review, and quick action…
New
✓
Overview tab - AI Security Advisor card, next best actions, what changed since your last AI review, and quick action links to key modules.
✓
Security Advisor - Suggested next steps and "what changed since last report" panels use scan snapshots without an extra AI call.
✓
Pro
Cloud Firewall (Pro) - MonSpark uptime monitoring IPs are included in the built-in automatic whitelist (always on; no checkbox required). Thank you Heath.
✓
Pro
Malware Scanner (Pro) - Flags suspicious plugin and theme folder structure when wordpress.org checksums are unavailable (review recommended, separate from malware signatures).
Improved
✓
Pro
2FA (Pro) - Login verification updates apply immediately after plugin updates.
✓
Pro
2FA (Pro) - Administrator is pre-selected under Required Roles when 2FA is not yet enabled; clearer grace period help for required roles.
✓
AI Security Advisor - Model selection follows WordPress AI Client settings.
✓
Pro
Cloud Firewall (Pro) - Added more WP Compress service IPs to the built-in automatic whitelist (always on; no checkbox required).
✓
Core Scanner - Detects unexpected files in the WordPress root and hidden dotfiles in wp-admin and wp-includes.
✓
Pro
Malware Scanner (Pro) - Clearer integrity messaging; structural findings included in issue counts, whitelist, scheduled reports, and AI advisor context.
✓
Core Scanner - OS metadata files (e.g. .DS_Store) are excluded from scan results.
✓
Core Scanner - Severity levels (critical, warning, notice) with guidance for phpinfo and dev-tool files; table-based results UI.
✓
Core Scanner - Live scan results without page reload; summary stats; Overview Core Integrity widget.
✓
Pro
White Label (Pro) - Security Advisor and Overview use your white label plugin name in the UI and AI reports. Thank you Davina.
✓
Pro
Visitor Log (Pro) - Cleaner Refresh button on the visitor log page.
✓
Core Scanner - Summary strip with scan context, status banner, and last-scan metadata; delete or restore individual rows without a full rescan.
✓
Pro
Malware Scanner (Pro) - Issue counter on the Malware tab when suspicious files are found.
✓
Pro
Malware Scanner (Pro) - Summary strip with last-scan context, status banner, and Whitelist all; streamlined results header.
✓
Pro
Malware Scanner (Pro) - Findings use the same table layout as Core Scanner (file, severity, guidance, actions) with location group headers.
✓
Core Scanner and Malware Scanner - Cleaner findings list layout.
✓
Pro
2FA (Pro) - Login verification script uses file-based cache busting so browser updates apply immediately after plugin updates.
✓
Pro
2FA (Pro) - Administrator is pre-selected under Required Roles when 2FA is not yet enabled; grace period help text now correctly refers to required roles only.
✓
AI Security Advisor - Uses the WordPress AI Client model selection only (removed provider-specific fallback preferences).
✓
Pro
White Label (Pro) - Security Advisor uses your white label plugin name in the UI and AI reports. Thank you Davina.
Fixed
✓
AI Security Advisor - Database upgrade on update adds the snapshot column to existing AI report tables so comparisons work on upgraded sites.
✓
Pro
2FA (Pro) - Email code verification works when you press Verify or Enter.
✓
AI Security Advisor - Your selected AI connector applies when you generate a report.
✓
Setup wizard - Opens automatically on first install only.
✓
Cloud Firewall - Filter Suspicious Queries no longer false-positives on s2Member loader URLs.
✓
Pro
2FA (Pro) - Email code verification no longer fails with "Error processing request" when pressing Verify or Enter (JavaScript scope fix).
✓
AI Security Advisor - Selected AI connector applies when generating a report without saving settings first.
✓
Setup wizard - First installs redirect to the wizard only once; existing sites updating the plugin are not redirected.
Notes
✓
2026-07-
v5.290
minor
2FA (Pro) - Optional mode: enable 2FA without requiring any role; leave all required roles unchecked for opt-in only…
New
✓
Pro
2FA (Pro) - Optional mode: enable 2FA without requiring any role; leave all required roles unchecked for opt-in only (with an admin notice when saved).
✓
Pro
2FA (Pro) - Users can enable 2FA from their profile (authenticator app or email, when allowed) even if their role is not required.
✓
Pro
2FA (Pro) - Admins can allow authenticator app and/or email; users choose their method at login when both are enabled (preference is remembered).
Improved
✓
Pro
2FA (Pro) - Required roles can be fully unchecked and stay saved (previously Administrator was forced back on).
✓
Pro
2FA (Pro) - Grace period "Skip for now" applies only to role-required users who have not voluntarily enrolled.
✓
Pro
2FA (Pro) - Grace period can be set to 0 days to enforce setup immediately.
✓
Wizard - CSS on installation.
✓
CSS on wizard installation.
✓
Pro
2FA (Pro) - Grace period can be set to 0 days to enforce setup immediately (matches the settings description).
✓
Pro
2FA (Pro) - Grace period can be set to 0 days to enforce setup immediately
Notes
✓
2026-06-30 *
v5.289
minor
Tools (Pro) - "Clear visitor log" button to delete all firewall visitor log entries manually. · Setup wizard availabl…
New
✓
Pro
Tools (Pro) - "Clear visitor log" button to delete all firewall visitor log entries manually.
✓
Setup wizard available for all; first install opens the wizard automatically.
✓
Malware Scanner — Whitelist all button for currently flagged files (with confirmation).
✓
Setup wizard available for free and Pro; first install opens the wizard automatically.
Improved
✓
Cloud Firewall – The firewall master switch now consistently controls all firewall enforcement (404 Guard, WooCommerce protection, country rules, and cloud IP blocking). Login Protection (brute-force limits, rename login, 2FA, and related messages) continues to operate independently when the firewall is turned off.
✓
Wizard - single Pro overview on Welcome for free users; removed per-step upgrade buttons.
✓
Wizard - Events Logger and Vulnerability Scanner activation steps.
✓
Wizard - Login protection as dedicated Pro step.
✓
Wizard - Pro badges on footer nav for Login, Fixes, and WooCommerce (hidden for licensed Pro users).
✓
Wizard - skip wizard from intro; rerun warning only shown after wizard has been completed once.
✓
Wizard - Dead code cleanup.
✓
Renamed review-notice dismiss nonce for clarity (wf_sn_dismiss_review).
✓
Tools page - unique form IDs and dedicated nonce fields/actions per form (Update Database, Reset 2FA, Legacy cleanup, Import, Secret URL reset).
✓
Cloud Firewall - suspicious-query filtering now resolves visitor hostnames only when needed for blocked-hostname rules, with per-IP caching. Thank you Paul.
✓
Cloud Firewall - Bundled data lists (ManageWP/UptimeRobot/Uptimia service IPs and the country list) are now stored as JSON data files so security scanners no longer flag them as false positives. Thank you Daryl.
✓
Security Tests - When a test cannot reach your site (e.g. a connection timeout), it now reports a "Warning / could not verify" result instead of a hard failure, so temporary network hiccups no longer look like new security problems.
✓
Tools page — unique form IDs and dedicated nonce fields/actions per form (Update Database, Reset 2FA, Legacy cleanup, Import, Secret URL reset).
✓
Wizard — free users get basic firewall setup; Pro steps for Fixes, WooCommerce, and cloud firewall; tasteful upgrade prompts on Pro-only steps.
✓
Wizard — skip wizard from intro; rerun warning only shown after wizard has been completed once.
✓
Wizard — free users get basic firewall setup; Pro steps for Fixes, WooCommerce, and cloud firewall.
✓
Wizard — single Pro overview on Welcome for free users; removed per-step upgrade buttons.
✓
Wizard — Events Logger and Vulnerability Scanner activation steps.
✓
Wizard — Login protection as dedicated Pro step (brute-force blocking moved off firewall step).
✓
Wizard — Pro badges on footer nav for Login, Fixes, and WooCommerce (hidden for licensed Pro users).
✓
Wizard — activation steps list default settings; Events step lists full logging scope.
✓
Wizard — done step links to security tests, vulnerability scan, core scanner, and Events Logger.
✓
Wizard — prominent rerun warning; Skip to Dashboard marks wizard complete; hide Get started menu after completion.
✓
Pro
Wizard — restart wizard from sidebar (all users) and Tools page (Pro); Events Activate applies full baseline options.
✓
Wizard — removed legacy filesystem prompt; progress nav accessibility; dead code cleanup.
✓
Cloud Firewall — suspicious-query filtering now resolves visitor hostnames only when needed for blocked-hostname rules, with per-IP caching. Thank you Paul.
Fixed
✓
Pro
Cloud Firewall (Pro) - Visitor log retention ("Keep visitor logs for") is now enforced by a daily scheduled cleanup task.
✓
Cloud Firewall - Manual whitelist entries for localhost (127.0.0.1 / ::1) now reliably exempt requests from cloud reputation blocks; server cron and WP-CLI traffic is no longer blocked during early firewall checks. Non-public IPs are excluded from cloud blacklist matching.
✓
Pro
Cloud Firewall (Pro) - Country blocking now blocks the full site when "Only block these countries from login functionality" is OFF, regardless of the "Prevent Banned IPs from Accessing the Site" setting. Previously, country bans could behave like login-only blocks when that IP setting was OFF.
✓
Apply Fix - after a fix completes, the test row refreshes automatically (spinner stops, status icon and score update, clear success message).
✓
Pro
Scheduled Scanner (Pro) - Scheduled scans now self-heal. If the scheduled event goes missing (for example after a long scan times out or a cron/optimization plugin clears it), it is recreated automatically instead of requiring you to re-save settings.
✓
Pro
Scheduled Scanner (Pro) - Email reports now show the correct status changes. Status labels (Good / Warning / Failed) and the "improvement" vs "security concern" wording are no longer reversed.
✓
Pro
2FA (Pro) - After verifying 2FA, the post-login redirect now mirrors WordPress core's capability handling. Users on roles that cannot access wp-admin are sent to an appropriate page instead of the dashboard (which could bounce them to the front page and appear logged out). Thank you Jason.
✓
Apply Fix — after a fix completes, the test row refreshes automatically (spinner stops, status icon and score update, clear success message).
✓
Cloud Firewall — Manual whitelist entries for localhost (127.0.0.1 / ::1) now reliably exempt requests from cloud reputation blocks; server cron and WP-CLI traffic is no longer blocked during early firewall checks. Non-public IPs are excluded from cloud blacklist matching.
✓
Pro
Cloud Firewall (Pro) — Country blocking now blocks the full site when "Only block these countries from login functionality" is OFF, regardless of the "Prevent Banned IPs from Accessing the Site" setting. Previously, country bans could behave like login-only blocks when that IP setting was OFF.
Notes
✓
REMOVED: WP Pointer "thank you for installing" tour and dashboard welcome banner (replaced by wizard).
✓
REMOVED: Unused MainWP remote actions (run_malware_scan, update_vulnerabilities, force_create_tables); malware runs via run_all_tests, tables created on activation/upgrade.
v5.288
minor
Tools - "Reset 2FA" no longer fails with "The link you followed has expired."; a success notice i…
Fixed
✓
Tools - "Reset 2FA" no longer fails with "The link you followed has expired."; a success notice is shown after reset; confirmation dialog added before resetting all users. Thank you Jason.
✓
Tools — "Reset 2FA" no longer fails with "The link you followed has expired."; a success notice is shown after reset; confirmation dialog added before resetting all users. Thank you Jason.
Notes
✓
2026-06-
v5.287
minor
Change Login URL (Pro) - Works when Cloud Firewall is disabled; only "Change login URL" and the s…
Improved
✓
Pro
Change Login URL (Pro) - Admin Preview shows the same URL the plugin uses (?slug on Plain permalinks, /slug/ otherwise).
✓
Pro
Change Login URL (Pro) — Admin Preview shows the same URL the plugin uses (?slug on Plain permalinks, /slug/ otherwise).
Fixed
✓
Pro
Change Login URL (Pro) - Works when Cloud Firewall is disabled; only "Change login URL" and the slug need to be enabled under Login Protection.
✓
Pro
Change Login URL (Pro) - /your-slug/ login URLs work even when permalinks are Plain (fixes 404 when the Preview link used a path-style URL).
✓
Pro
Change Login URL (Pro) - Reliable path matching for subdirectory installs; fallback serves login if WordPress resolved the request as a 404.
✓
Pro
Change Login URL (Pro) - wp-admin blocking applies to /wp-admin with or without a trailing slash.
✓
Pro
Change Login URL (Pro) — Works when Cloud Firewall is disabled; only “Change login URL” and the slug need to be enabled under Login Protection.
✓
Pro
Change Login URL (Pro) — /your-slug/ login URLs work even when permalinks are Plain (fixes 404 when the Preview link used a path-style URL).
✓
Pro
Change Login URL (Pro) — Reliable path matching for subdirectory installs; fallback serves login if WordPress resolved the request as a 404.
✓
Pro
Change Login URL (Pro) — wp-admin blocking applies to /wp-admin with or without a trailing slash.
✓
Pro
Change Login URL (Pro) - Works when Cloud Firewall is disabled; only “Change login URL” and the slug need to be enabled under Login Protection.
v5.286
minor
MainWP integration - child sites accept allowlisted Security Ninja settings updates from the Security Ninja for MainW…
New
✓
MainWP integration - child sites accept allowlisted Security Ninja settings updates from the Security Ninja for MainWP extension (update_settings remote action; changed keys only).
✓
MainWP integration — child sites accept allowlisted Security Ninja settings updates from the Security Ninja for MainWP extension (update_settings remote action; changed keys only).
Improved
✓
MainWP settings updates are logged in Events with a list of changed setting keys (no values stored), so you can see what was changed from the dashboard.
✓
AI Security Advisor - works more reliably with WordPress 7 AI connectors (including DeepSeek and OpenAI). The plugin picks the right request format for each service instead of failing when structured JSON is not supported.
✓
AI Security Advisor - Reports are faster and cheaper. Only tests that need attention are included, with short summaries.
✓
AI Security Advisor - report output is cleaned up and checked before it is saved.
✓
AI Security Advisor - full reports can be longer (higher token limit).
✓
AI Security Advisor - when something goes wrong, the page shows a more helpful error message, and the failure is logged in Events so you can see what happened.
✓
AI Security Advisor - successful and failed AI requests in Events now record which connector and model were used (prompt chip id only when relevant).
✓
AI Security Advisor — failed audit requests now show a specific error message in the UI instead of a generic "Request failed", and failures are recorded in Events with the error detail for troubleshooting.
✓
AI Security Advisor — works more reliably with WordPress 7 AI connectors (including DeepSeek and OpenAI). The plugin picks the right request format for each service instead of failing when structured JSON is not supported.
✓
AI Security Advisor — Reports are faster and cheaper. Only tests that need attention are included, with short summaries.
✓
AI Security Advisor — report output is cleaned up and checked before it is saved.
✓
AI Security Advisor — full reports can be longer (higher token limit).
✓
AI Security Advisor — when something goes wrong, the page shows a more helpful error message, and the failure is logged in Events so you can see what happened.
✓
AI Security Advisor — successful and failed AI requests in Events now record which connector and model were used (prompt chip id only when relevant).
v5.285
minor
MainWP integration (Phase 1) - sync now includes IP management entries (up to 200), AI Security Advisor executive sum…
New
✓
MainWP integration (Phase 1) - sync now includes IP management entries (up to 200), AI Security Advisor executive summary, and optional event raw_data for the top 50 events. Remote IP actions (whitelist/blacklist add/remove, lift local ban, lift 404 guard ban) via the Security Ninja for MainWP extension 2.1.0+.
✓
MainWP integration (Phase 1) — sync now includes IP management entries (up to 200), AI Security Advisor executive summary, and optional event raw_data for the top 50 events. Remote IP actions (whitelist/blacklist add/remove, lift local ban, lift 404 guard ban) via the Security Ninja for MainWP extension 2.1.0+.
Improved
✓
AI Security Advisor - when an AI connector request fails, the page now shows the provider's actual error message instead of a generic "temporarily unavailable" notice, so quota, billing, and configuration issues are easier to diagnose.
✓
AI Security Advisor — when an AI connector request fails, the page now shows the provider's actual error message (sanitized) instead of a generic "temporarily unavailable" notice, so quota, billing, and configuration issues are easier to diagnose.
✓
AI Security Advisor — when an AI connector request fails, the page now shows the provider's actual error message instead of a generic "temporarily unavailable" notice, so quota, billing, and configuration issues are easier to diagnose.
Fixed
✓
Upgrading from the free plugin to Pro no longer causes a site error when both versions are present during install or activation. Pro skips loading Composer again if the free copy already loaded it, then Freemius deactivates free on activation.
Notes
✓
2026-
v5.284
minor
WordPress 7 Abilities (optional, on by default): expose read-only security data to other WordPress AI clients-Securit…
New
✓
WordPress 7 Abilities (optional, on by default): expose read-only security data to other WordPress AI clients-Security Test summary (passed/warning/failed), 7-day attack activity vs the previous week, and the latest saved AI Security Advisor report. Control exposure under Security Advisor → Settings; turning this off does not affect generating reports or follow-ups on the Security Advisor page.
✓
Added a dismissable "Re-evaluate with AI" reminder after tests, scans, and firewall setting changes (stays hidden after dismiss until a new security event occurs).
✓
WordPress 7 Abilities (optional, on by default): expose read-only security data to other WordPress AI clients—Security Test summary (passed/warning/failed), 7-day attack activity vs the previous week, and the latest saved AI Security Advisor report. Control exposure under Security Advisor → Settings; turning this off does not affect generating reports or follow-ups on the Security Advisor page.
Improved
✓
Pro
Rename Login (Pro) - Recognized temporary-login plugin links (Temporary Login Without Password, One Time Login, Magic Login, Login Links) are no longer blocked when accessing wp-admin before authentication completes. Extend via the securityninja_rename_login_allow_autologin filter.
✓
AI Security Advisor now uses WordPress 7 structured AI responses for more reliable report output.
✓
AI Security Advisor reports now include richer context from Security Tests, Vulnerability Scanner, Core Scanner, and recent security events.
✓
Pro sites now include Malware Scanner findings in AI report context when available.
✓
Pro
Rename Login (Pro) — Recognized temporary-login plugin links (Temporary Login Without Password, One Time Login, Magic Login, Login Links) are no longer blocked when accessing wp-admin before authentication completes. Extend via the securityninja_rename_login_allow_autologin filter.
Fixed
✓
Pro
Change Login URL (Pro) - Checkout and other frontend flows that use WordPress admin-post.php (for example FluentCart account creation during checkout) no longer show "Access Denied" for visitors. Legitimate public handlers registered with admin_post_nopriv_* are allowed; direct access to the rest of wp-admin stays blocked.
✓
Pro
Change Login URL (Pro) — Checkout and other frontend flows that use WordPress admin-post.php (for example FluentCart account creation during checkout) no longer show “Access Denied” for visitors. Legitimate public handlers registered with admin_post_nopriv_* are allowed; direct access to the rest of wp-admin stays blocked.
✓
Pro
Change Login URL (Pro) - Checkout and other frontend flows that use WordPress admin-post.php (for example FluentCart account creation during checkout) no longer show “Access Denied” for visitors. Legitimate public handlers registered with admin_post_nopriv_* are allowed; direct access to the rest of wp-admin stays blocked.
v5.283
minor
Cloud Firewall (Pro) - Satellite ASN softening now works consistently across country blocking (in…
Improved
✓
Pro
Cloud Firewall (Pro) - IP Management shows your blacklist, whitelist, and temporary blocks in one searchable table, so you can see everything in one place.
✓
Pro
Cloud Firewall (Pro) - Add, edit, and remove IP rules directly from the table; add several at once with one IP or range per line.
✓
Pro
Cloud Firewall (Pro) - Copy your full blacklisted or whitelisted lists, or clear temporary blocks, from easy buttons below the table.
✓
Pro
Cloud Firewall (Pro) — IP Management shows your blacklist, whitelist, and temporary blocks in one searchable table, so you can see everything in one place.
✓
Add, edit, and remove IP rules directly from the table; add several at once with one IP or range per line.
✓
Copy your full blacklisted or whitelisted lists, or clear temporary blocks, from easy buttons below the table.
Fixed
✓
Pro
Cloud Firewall (Pro) - Satellite ASN softening now works consistently across country blocking (including Starlink).
✓
2FA setup during frontend login now shows the manual entry secret key again, matching the backend user profile setup flow.
✓
Pro
Cloud Firewall (Pro) — Satellite ASN softening now works consistently across country blocking (including Starlink).
Notes
✓
2026-xx-xx
v5.282
minor
Tools (Pro) - Cleanup button securely removes legacy options or data. Thank you Davina for the idea. · Cloud Firewall…
New
✓
Pro
Tools (Pro) - Cleanup button securely removes legacy options or data. Thank you Davina for the idea.
✓
Pro
Cloud Firewall (Pro) - Option to soften country blocking for satellite ISPs like Starlink. Easily enable or adjust under Firewall → Settings for smoother access while keeping strong protection.
✓
Pro
Cloud Firewall (Pro) — Option to soften country blocking for satellite ISPs like Starlink. Easily enable or adjust under Firewall → Settings for smoother access while keeping strong protection.
Improved
✓
Cloud Firewall - IP whitelist entries written as ranges (CIDR, one per line on IP Management) now apply the same way everywhere: visitor checks, secret recovery links, and automatic whitelist logic no longer treat ranges like plain single IPs only in some code paths.
✓
Pro
Cloud Firewall (Pro) - If a country or cloud block is skipped because the visitor is using a satellite ISP (satellite ASN softening), you'll now see this clearly in the Events log.
✓
Cloud Firewall — IP whitelist entries written as ranges (CIDR, one per line on IP Management) now apply the same way everywhere: visitor checks, secret recovery links, and automatic whitelist logic no longer treat ranges like plain single IPs only in some code paths.
✓
Pro
Cloud Firewall (Pro) — If a country or cloud block is skipped because the visitor is using a satellite ISP (satellite ASN softening), you'll now see this clearly in the Events log.
Fixed
✓
Pro
Two-factor authentication (Pro) - When 2FA is enabled but required roles were missing or invalid, login could skip the 2FA step. Security Ninja now falls back to requiring Administrator so the code prompt always appears for protected accounts.
✓
Saving 2FA status would fail if firewall not enabled. Thank you Vassos.
✓
Pro
Cloud Firewall (Pro) - Clearing all countries in country blocking and saving now actually turns country blocking off. Previously, choosing "none" could leave old selections in place because empty lists were not saved correctly.
✓
Pro
Cloud Firewall (Pro) — Clearing all countries in country blocking and saving now actually turns country blocking off. Previously, choosing “none” could leave old selections in place because empty lists were not saved correctly.
✓
Pro
Two-factor authentication (Pro) — When 2FA is enabled but required roles were missing or invalid, login could skip the 2FA step. Security Ninja now falls back to requiring Administrator so the code prompt always appears for protected accounts.
✓
Pro
Cloud Firewall (Pro) - Clearing all countries in country blocking and saving now actually turns country blocking off. Previously, choosing “none” could leave old selections in place because empty lists were not saved correctly.
Notes
✓
2026-04-
✓
Added a new Tools-page Cleanup button. Securely removes any legacy options or data. Thank you Davina for the idea.
v5.281
minor
2FA - Post-verification redirects now match WordPress core validation for relative and absolute r…
Improved
✓
Security Tests - the "outdated plugins" check no longer saves full WordPress.org plugin metadata to the database. Thank you Davina.
✓
AI Security Advisor - improved PII handling.
✓
Malware Scanner - respects the same ignore paths as the scanner library during filesystem traversal (e.g. wp-admin/ and wp-includes/), so WordPress core files are no longer signature-scanned when already excluded-use Core Scanner for core integrity.
✓
Malware Scanner - WordPress core JS bundles under wp-includes/js/dist/ and wp-admin/js/ are excluded from malware pattern matching by default (fewer false positives on minified/vendor scripts). Plugins, themes, and uploads are still scanned.
✓
Security Tests — the "outdated plugins" check no longer saves full WordPress.org plugin metadata to the database. Thank you Davina.
✓
AI Security Advisor — improved PII handling.
✓
Malware Scanner — respects the same ignore paths as the scanner library during filesystem traversal (e.g. wp-admin/ and wp-includes/), so WordPress core files are no longer signature-scanned when already excluded—use Core Scanner for core integrity.
✓
Malware Scanner — WordPress core JS bundles under wp-includes/js/dist/ and wp-admin/js/ are excluded from malware pattern matching by default (fewer false positives on minified/vendor scripts). Plugins, themes, and uploads are still scanned.
Fixed
✓
2FA - Post-verification redirects now match WordPress core validation for relative and absolute redirect_to URLs ( Rename Login compatible ). AJAX responses always include a safe redir_to / redirect_url with admin_url() fallback so editors and other roles are not sent to the front page unexpectedly. Thank you Davina.
✓
Malware Scanner - "Revert Whitelist" now correctly persists file removal, so reverted files no longer reappear after page reload. Thank you Vassos.
✓
Malware Scanner — "Revert Whitelist" now correctly persists file removal, so reverted files no longer reappear after page reload. Thank you Vassos.
✓
2FA — Post-verification redirects now match WordPress core validation for relative and absolute redirect_to URLs ( Rename Login compatible ). AJAX responses always include a safe redir_to / redirect_url with admin_url() fallback so editors and other roles are not sent to the front page unexpectedly. Thank you Davina.
v5.280
minor
Display bug on Events -> Settings subtab. Thank you Aldin for spotting it.
Fixed
✓
Display bug on Events -> Settings subtab. Thank you Aldin for spotting it.
Notes
✓
Fix for display bug on Events -> Settings subtab. Thank you Aldin for spotting it.
v5.279
minor
AI Security Advisor - interface and functionality; big improvements.
Improved
✓
AI Security Advisor - interface and functionality; big improvements.
✓
Security Tests - long help text is no longer embedded on every plugin admin screen, so the dashboard stays lighter in memory and loads faster.
✓
Updated translation files.
✓
Security Tests — long help text is no longer embedded on every plugin admin screen, so the dashboard stays lighter in memory and loads faster.
Fixed
✓
Cloud Firewall - Failed login warning emails no longer cause a fatal error ("Class Wf_Sn_Security_Utils not found") when wp_login_failed ran before the init hook (e.g. another plugin handling login during plugins_loaded).
✓
Cloud Firewall — Failed login warning emails no longer cause a fatal error ("Class Wf_Sn_Security_Utils not found") when wp_login_failed ran before the init hook (e.g. another plugin handling login during plugins_loaded).
Notes
✓
Improved - AI Security Advisor interface and functionality - Big improvements.
✓
Updated translation files
v5.278
minor
2026-04-
Improved
✓
Security Tests — long help text is no longer embedded on every plugin admin screen, so the dashboard stays lighter in memory and loads faster; explanations load when you open a test’s details (same guidance as before).
✓
Security Tests — long help text is no longer embedded on every plugin admin screen, so the dashboard stays lighter in memory and loads faster.
Notes
✓
2026-04-
v5.277
minor
2026-04-
Improved
✓
Cloud Firewall crawler validation now supports verified AI crawlers (OpenAI and Perplexity) using user-agent plus cached published IP ranges. Anthropic are not auto-whitelisted.
Fixed
✓
Firewall redirect - Blocked visitor redirect now supports external URLs as configured. We now use validated wp_redirect() for this setting (http/https only), preventing fallback to wp-admin when an external domain is set.
Notes
✓
2026-04-
v5.276
minor
Event Logger – reliability: Event Logger now records settings changes, post updates, plugin activ…
Improved
✓
Maintenance release - minor improvements and stability.
Fixed
✓
Security Fixes — Saving the Fixes screen now applies wp-config changes only when toggles are ON: disable file editor, disable WP_DEBUG, and secure session cookies. Previously, always-present form keys made the “on” paths run even when options were OFF, which could append duplicate define() lines and trigger PHP notices (thanks Masahiro Kasahara for the report). update_define also skips appending a constant that is already defined (e.g. set from an included file).
✓
Security Fixes - Saving the Fixes screen now applies wp-config changes only when toggles are ON: disable file editor, disable WP_DEBUG, and secure session cookies. Previously, always-present form keys made the “on” paths run even when options were OFF, which could append duplicate define() lines and trigger PHP notices (thanks Masahiro Kasahara for the report). update_define also skips appending a constant that is already defined (e.g. set from an included file).
✓
Setup wizard - Fixed errors in the wizard and made a few small improvements.
Notes
✓
Event Logger – reliability: Event Logger now records settings changes, post updates, plugin activation/deactivation, and user events correctly when the module is enabled. Previously, events could be missing due to licensing checks blocking the write path; logging no longer depends on that for storing events.
✓
Event Logger – less noise: A single click to update an already-published post now creates one log entry instead of three. Saving a settings page (e.g. General) creates one entry instead of duplicate entries.
✓
Event Logger – clearer actions: Settings saves are logged with the action "options_saved" and show which settings page was updated (e.g. General, Reading). Internal WordPress hook names like "whitelist_options" are no longer shown in the log.
✓
Event Logger – security: Passwords and account activation keys are never stored in the log or shown in event details. User registration and profile update events only store non-sensitive data.
✓
Setup wizard – Fixed errors in the wizard and made a few small improvements.
✓
Maintenance release - Minor improvements and stability.
v5.275
minor
Event Logger – Now also logs activated_plugin, deactivated_plugin, add_user_role, and remove_user_role for a fuller a…
New
✓
Event Logger – Now also logs activated_plugin, deactivated_plugin, add_user_role, and remove_user_role for a fuller audit trail.
✓
AI Security Advisor - Get a plain-English security summary and top improvements from your security tests. Uses WordPress 7 AI Connectors (OpenAI, Google, Anthropic); no domains, URLs, or personal data are sent.
✓
AI Security Advisor - Overview tab shows when your site was last reviewed and a one-line teaser from the latest report, or invites you to run your first review or set up a connector.
✓
AI Security Advisor - Dashboard widget shows advisor status at a glance (last reviewed, ready for first review, or set up) with a quick link to the Security Advisor page.
Improved
✓
Event Logger - less noise: A single click to update an already-published post now creates one log entry instead of three. Saving a settings page (e.g. General) creates one entry instead of duplicate entries.
✓
Event Logger - clearer actions: Settings saves are logged with the action "options_saved" and show which settings page was updated (e.g. General, Reading). Internal WordPress hook names like "whitelist_options" are no longer shown in the log.
✓
Event Logger - security: Passwords and account activation keys are never stored in the log or shown in event details. User registration and profile update events only store non-sensitive data.
Fixed
✓
Event Logger – Plugin and theme installs are now logged (previously only updates were recorded). Activate and deactivate events are always logged with a fallback label when plugin name cannot be read.
✓
Event Logger - reliability: Event Logger now records settings changes, post updates, plugin activation/deactivation, and user events correctly when the module is enabled. Previously, events could be missing due to licensing checks blocking the write path; logging no longer depends on that for storing events.
✓
Event Logger - Login events are recorded only when a valid user is present, so your log stays accurate when other plugins or tools fire login-related hooks.
Notes
✓
Event Logger – reliability: Event Logger now records settings changes, post updates, plugin activation/deactivation, and user events correctly when the module is enabled. Previously, events could be missing due to licensing checks blocking the write path; logging no longer depends on that for storing events.
✓
Event Logger – less noise: A single click to update an already-published post now creates one log entry instead of three. Saving a settings page (e.g. General) creates one entry instead of duplicate entries.
✓
Event Logger – clearer actions: Settings saves are logged with the action "options_saved" and show which settings page was updated (e.g. General, Reading). Internal WordPress hook names like "whitelist_options" are no longer shown in the log.
✓
Event Logger – security: Passwords and account activation keys are never stored in the log or shown in event details. User registration and profile update events only store non-sensitive data.
✓
AI Security Advisor – Get a plain-English security summary and top improvements from your security tests. Uses WordPress 7 AI Connectors (OpenAI, Google, Anthropic); no domains, URLs, or personal data are sent.
✓
AI Security Advisor – Overview tab shows when your site was last reviewed and a one-line teaser from the latest report, or invites you to run your first review or set up a connector.
✓
AI Security Advisor – Dashboard widget shows advisor status at a glance (last reviewed, ready for first review, or set up) with a quick link to the Security Advisor page.
✓
Event Logger – Login events are recorded only when a valid user is present, so your log stays accurate when other plugins or tools fire login-related hooks.
v5.274
minor
Including email template properly.
Improved
✓
2FA - Redirect logic improvements.
Fixed
✓
2FA - Email template now included properly.
Notes
✓
Including email template properly.
✓
Improvements for 2FA redirect logic.
v5.273
minor
Malware Scanner – "Reset results" link under the scan button lets you clear previous scan results when a scan has bee…
New
✓
Malware Scanner – "Reset results" link under the scan button lets you clear previous scan results when a scan has been run before and you want to refresh.
✓
Malware Scanner – You can now exclude specific paths or folders from malware scans. Use "Exclude paths from scan" on the Malware Scanner tab: enter one path pattern per line (e.g. */plugins/plugin-name/*). Paths listed there are skipped by the scanner and never reported as malware. Ideal for excluding trusted plugins (e.g. Leadpages, AccessAlly, UpdraftPlus) that trigger false positives.
✓
Malware Scanner – Path patterns are stored in the same whitelist as per-file whitelisted items; both are included in Import/Export (Tools page) under malware scanner settings.
✓
Malware Scanner – Developers can add or modify excluded paths in code using the securityninja_malware_exclude_paths filter. Documentation: https://wpsecurityninja.com/docs/malware-scanner/how-to-exclude-paths/
Improved
✓
Malware Scanner – The "Scan your website" button is now disabled while a scan is running, so you can't accidentally start a second scan. It becomes clickable again as soon as the scan finishes or if something goes wrong.
✓
Malware Scanner – Scan progress and results now appear directly under the scan button instead of further down the page, so you can follow what's happening without scrolling.
✓
Scheduler – Added a short reminder that Malware Scanner is included only when you choose "Enable scheduled scans for all", so it's clear how to get Malware in your scheduled runs.
✓
Pro
Scheduler – Scheduled scans (Security Tests, Core Scanner, Malware Scanner) now use the bundled Action Scheduler (Pro). "Run now" queues the scan in the background so it no longer times out on slow or remote requests; recurring scans run via Action Scheduler for reliable unattended execution. The Pro plugin bundles Action Scheduler; no separate install required. The library is included only in the premium build (free version does not load or reference it).
✓
Malware Scanner is now faster and more reliable; scans use less memory and you get clearer progress feedback. You can also include the Malware Scanner in the Scheduler (Security Ninja → Scheduler): choose "Enable scheduled scans for all" to run security tests, Core Scanner, and Malware Scanner on a schedule and get a single email report so you stay alerted to changes or suspicious files.
Fixed
✓
Scheduler – Malware Scanner now runs correctly when you have "Enable scheduled scans for all" selected. If your scan log was created before Malware support was added, the plugin will update it automatically the next time a scheduled scan runs, so the Malware column in the scan log will show results instead of "Not run".
✓
Country blocking – Visitors whose country cannot be determined (e.g. some IPv6 addresses) are no longer blocked, this could happen on some servers.
✓
Security tests – Prevent "Undefined array key" and "sprintf(): Passing null to parameter #1" PHP warnings/deprecations when building test result messages. Tests that do not define msg_ok, msg_bad, or msg_warning now use a safe default format string so scheduled runs and step-by-step runs no longer log errors (fixes issues in both free and premium when test definitions omit these keys).
✓
Hotfix – Removed unencrypted malware signature files from the plugin package (vendor/scr34m/.../definitions/ and base64_patterns/). The scanner uses only encrypted .dat files stored elsewhere. The bundled .txt files were never used at runtime but triggered false-positive virus alerts on some hosts. They are now stripped so they are never included in the plugin itself.
✓
Removed unencrypted malware signature files from the plugin package (vendor/scr34m/.../definitions/ and base64_patterns/). The scanner uses only encrypted .dat files stored elsewhere. The bundled .txt files were never used at runtime but triggered false-positive virus alerts on some hosts. They are now stripped so they are never included in the plugin itself.
Notes
✓
2026-03-
v5.272
minor
Malware Scanner – "Reset results" link under the scan button lets you clear previous scan results when a scan has bee…
New
✓
Malware Scanner – "Reset results" link under the scan button lets you clear previous scan results when a scan has been run before and you want to refresh.
✓
Malware Scanner – You can now exclude specific paths or folders from malware scans. Use "Exclude paths from scan" on the Malware Scanner tab: enter one path pattern per line (e.g. */plugins/plugin-name/*). Paths listed there are skipped by the scanner and never reported as malware. Ideal for excluding trusted plugins (e.g. Leadpages, AccessAlly, UpdraftPlus) that trigger false positives.
✓
Malware Scanner – Path patterns are stored in the same whitelist as per-file whitelisted items; both are included in Import/Export (Tools page) under malware scanner settings.
✓
Malware Scanner – Developers can add or modify excluded paths in code using the securityninja_malware_exclude_paths filter. Documentation: https://wpsecurityninja.com/docs/malware-scanner/how-to-exclude-paths/
Improved
✓
Malware Scanner is now faster and more reliable; scans use less memory and you get clearer progress feedback. You can also include the Malware Scanner in the Scheduler (Security Ninja → Scheduler): choose "Enable scheduled scans for all" to run security tests, Core Scanner, and Malware Scanner on a schedule and get a single email report so you stay alerted to changes or suspicious files.
✓
Malware Scanner – The "Scan your website" button is now disabled while a scan is running, so you can't accidentally start a second scan. It becomes clickable again as soon as the scan finishes or if something goes wrong.
✓
Malware Scanner – Scan progress and results now appear directly under the scan button instead of further down the page, so you can follow what's happening without scrolling.
✓
Scheduler – Added a short reminder that Malware Scanner is included only when you choose "Enable scheduled scans for all", so it's clear how to get Malware in your scheduled runs.
✓
Pro
Scheduler – Scheduled scans (Security Tests, Core Scanner, Malware Scanner) now use the bundled Action Scheduler (Pro). "Run now" queues the scan in the background so it no longer times out on slow or remote requests; recurring scans run via Action Scheduler for reliable unattended execution. The Pro plugin bundles Action Scheduler; no separate install required. The library is included only in the premium build (free version does not load or reference it).
✓
Malware Scanner - Now faster and more reliable; scans use less memory and you get clearer progress feedback. You can also include the Malware Scanner in the Scheduler (Security Ninja → Scheduler): choose "Enable scheduled scans for all" to run security tests, Core Scanner, and Malware Scanner on a schedule and get a single email report so you stay alerted to changes or suspicious files.
Fixed
✓
Country blocking – Visitors whose country cannot be determined (e.g. some IPv6 addresses) are no longer blocked, this could happen on some servers.
✓
Scheduler – Malware Scanner now runs correctly when you have "Enable scheduled scans for all" selected. If your scan log was created before Malware support was added, the plugin will update it automatically the next time a scheduled scan runs, so the Malware column in the scan log will show results instead of "Not run".
✓
Security tests – Prevent "Undefined array key" and "sprintf(): Passing null to parameter #1" PHP warnings/deprecations when building test result messages. Tests that do not define msg_ok, msg_bad, or msg_warning now use a safe default format string so scheduled runs and step-by-step runs no longer log errors (fixes issues in both free and premium when test definitions omit these keys).
✓
404 Guard – First 404 from an IP is no longer logged; logging starts from the 2nd 404 onward to reduce log noise. Approaching-threshold, final-warning, and block events are unchanged.
✓
Visitor Log – Country flag is now shown next to the IP when country is known, matching Event Log behavior. A geolocation fallback is used for older entries where country was not stored.
Fixed
✓
2FA login redirect – After completing 2FA, users (including admins) are now redirected to the dashboard or requested URL instead of the front page. Redirect logic now matches WordPress core: uses wp_validate_redirect() and the login_redirect filter; skip-2FA path now captures redirect_to from POST as well as GET.
✓
404 Guard – IPs whose monitoring window has expired are no longer shown in "Being Monitored". Expired count transients are excluded from the list and deleted to avoid DB bloat, so stale entries (e.g. "expires in -45130 seconds") no longer appear.
✓
404 Guard – IPs whose monitoring window has expired are no longer shown in "Being Monitored". Expired count transients are excluded from the list and deleted to avoid DB bloat, so stale entries no longer appear.
✓
2FA login redirect – After completing 2FA, users (including admins) are now redirected to the dashboard or requested URL instead of the front page. Redirect logic now matches WordPress core: uses wp_validate_redirect() and the login_redirect filter.
✓
Resolved fatal error when Security Ninja and AR for WooCommerce (or other plugins using chillerlan/php-settings-container) were active together; our copy is now loaded early and aliased in admin to prevent duplicate class declaration.
Notes
✓
2026-02-
v5.270
minor
Core Scanner – You can now open a printable report when the scan finds issues. Use "Print / Download report" to open…
New
✓
Core Scanner – You can now open a printable report when the scan finds issues. Use "Print / Download report" to open the report in a new window and print or save as PDF for your records or support.
Improved
✓
Core Scanner – The report button is always visible; when no issues are detected it shows a short notice so you know the option is available after the next scan with findings.
✓
Core Scanner – Original WordPress core files are cached for one day when restoring or comparing, so repeat operations are faster and put less load on external servers.
✓
Core Scanner – "View differences" now opens in the same unified File Viewer layout as "View File", with consistent styling, file metadata, and shared security validation instead of a separate standalone page.
Fixed
✓
Secure cookies fix now writes ini_set lines before any closing PHP tag in wp-config.php, preventing "headers already sent" and cookie/login issues. Thanks to Olga for the detailed report that made this fix possible.
✓
Firewall enable modal – "Send email" (activate and send unblock link) now works. The unblock-email AJAX action was not registered and the handler expected the email in GET; the action is now registered and all unblock-email requests use POST only.
✓
Fixed PHP 8.1 deprecation notice "Implicit conversion from float to int loses precision" in Cloud Firewall IPv6 CIDR matching. Thanks to Lesford for the report.
Notes
✓
2026-02-
✓
TECH: All internal script and style references now use non-minified JS and CSS only; minified copies have been removed to simplify the codebase.
v5.269
minor
Added compatibility with temporary login plugins ("Temporary Login Without Password", "One Time Login", "Magic Login"…
New
✓
Added compatibility with temporary login plugins ("Temporary Login Without Password", "One Time Login", "Magic Login", "Login Links"). Temporary login links are now automatically whitelisted from suspicious query detection when the corresponding plugin is active. Detection is logged for audit purposes. Other plugins can extend this compatibility using the securityninja_temporary_login_params and securityninja_is_temporary_login_link filters - more info on website.
Fixed
✓
Fixed fatal error "Object of class WP_Error could not be converted to string" in Overview tab when displaying event details containing WP_Error objects. The code now properly checks for WP_Error objects before passing them to esc_html() and displays the error message instead.
✓
Fixed fatal error preventing WooCommerce logins via public forms when SN_Geolocation class was not loaded. Code now checks for class existence before use.
Notes
✓
2026-02-
v5.268
minor
Firewall now allows logged-in administrators to access WordPress backend (wp-admin, admin-ajax.ph…
Improved
✓
UI label for suspicious query filtering has been updated from "Block Suspicious Page Requests" to "Filter Suspicious Queries" to match support documentation and make it easier for users to find the setting when following support instructions.
Fixed
✓
Firewall now allows logged-in administrators to access WordPress backend (wp-admin, admin-ajax.php) even when their IP address is banned. This prevents administrators from being locked out when their IP was banned by a false positive from the suspicious query filter, 404 Guard, brute-force protection, or other firewall features. This fixes the "Updating failed. The response is not a valid JSON response" error when saving pages in the block editor (Gutenberg) when the admin's IP was previously banned.
✓
2FA login redirects now work correctly for users logging in via public forms (such as Paid Member Subscriptions, WooCommerce, and other third-party login forms).
v5.267
minor
2026-02-xx
Improved
✓
Litespeed servers - Added documentation and in-app notices for all security headers (CSP, X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security, Referrer-Policy, Permissions-Policy). LiteSpeed users can add headers directly to .htaccess using the examples in each test description. Thank you Tom for the feedback.
✓
Core Scanner - Interface loads faster with tabs lazy-loading content in different tabs.
✓
Firewall – When "Block IP Network" is enabled, known social and link-preview crawlers (e.g. Facebook, LinkedIn, Twitter) are no longer blocked by default. Link previews when you share your site on social networks now work without having to whitelist IPs.
Fixed
✓
Events Logger, Overview, and Visitor Log – Country flags now correctly show the event/visitor IP's country instead of the logged-in admin's IP when the site is behind Cloudflare or similar proxies.
Notes
✓
2026-02-xx
v5.266
minor
2026-02-xx
Improved
✓
Login Protection – Prune job for banned IPs now runs hourly.
✓
404 Guard - Logging details for blocked requests.
✓
Updated language file for translations.
Fixed
✓
Login Protection – Banned IPs expired entries are removed immediately instead of waiting for the prune job.
✓
Cloud Firewall IP Management – "Locally Banned IPs" list now shows only currently banned IPs (expired bans are excluded).
✓
Cloud Firewall – Test IP and "Clear list of banned IPs" functionality fixed.
Notes
✓
2026-02-xx
✓
Improvement: Logging details for 404 Guard.
✓
Updated language file for translations.
v5.265
minor
2026-02-
Improved
✓
Vulnerability list updating faster and consume less memory.
✓
Tested up to WP 6.9.1.
Fixed
✓
Issues with 2FA for some user.
Notes
✓
2026-02-
✓
Tested up to WP 6.9.1
v5.264
minor
Fixed wpdb::prepare() error during plugin uninstallation when dropping database tables.
Improved
✓
Vulnerability module now recreates and re-downloads its data files when they are missing, so you no longer need to reinstall the plugin to fix a "JSONL file not readable" error.
Fixed
✓
Fixed wpdb::prepare() error during plugin uninstallation when dropping database tables.
✓
Fixed potential error during plugin uninstallation when dropping database tables.
✓
Vulnerability scanner no longer blocks wp-admin after deactivating and reactivating the plugin. If the vulnerability data files are missing or unreadable (e.g. after reactivation or server changes), the plugin now recovers automatically: it shows the vulnerability count as zero until the data is restored in the background, and the dashboard continues to load normally.
✓
Login Protection - "Failed login warnings" toggle now correctly saves when disabled (was reverting to enabled because unchecked checkbox is omitted from form POST).
✓
Email 2FA now works correctly for all user roles.
✓
Hardened vulnerability JSONL file handling: guard fclose() on stream and catch all errors when counting records, so missing or unreadable files never cause a fatal in wp-admin.
✓
2FA – Disabling 2FA in settings now persists correctly; toggle uses a hidden input so unchecked state is saved.
v5.263
minor
2026-01-
Improved
✓
Vulnerability scanner now reads vulnerability feeds in a streaming, memory-efficient way to reduce peak memory usage.
✓
Vulnerability scanner - Improved bandwidth usage getting vulnerabilities for all users.
✓
Vulnerability scanner - Now reads vulnerability feeds in a streaming, memory-efficient way to reduce peak memory usage.
Notes
✓
2026-01-
✓
Fix for PHP notice regarding user country detection in firewall for free users.
✓
Improved bandwidth usage getting vulnerabilities for all users.
Install the free plugin on WordPress.org, or go Pro for cloud firewall, malware scanning, and agency tools.
We use optional analytics and ad measurement cookies with your consent. Self-hosted Umami covers traffic and aggregate site usage without cookies and does not need this choice.