wp2shell: more than a month later. Confirm 6.8.6, 6.9.5, 7.0.2. Patched is not clean.

Read the advisory

v5.167

minor

for the "Check if REST API is enabled". Thank you Dorel.

Fixed

  • for the "Check if REST API is enabled". Thank you Dorel.

v5.166

minor

10+ knowledgebase articles on https://wpsecurityninja.com/docs/

New

  • 10+ knowledgebase articles on https://wpsecurityninja.com/docs/

Improved

  • MainWP integration (Free)
  • integration with SN Vulnerability API server. todo - gzip først! *
  • integration with SN Vulnerability API server.
  • Pro MainWP integration (Pro)
  • 3rd party libraries.
  • MainWP integration (Free) - run remote tests.
  • "Remove unwanted files" fix to look for and delete even more files.
  • MainWP integration for MainWP users.
  • integration with SN Vulnerability API server - GZ compression.

Fixed

  • for "Username enumeration" test - Thank you Dorel.
  • for exporting - Thank you Dorel.

v5.165

minor

the events log pruning routines.

Improved

  • the events log pruning routines.

Notes

  • Code cleanup

v5.164

minor

Clicking "Details" button in the events log. Now you can see all details properly. Thank you Tom.

Fixed

  • Clicking "Details" button in the events log. Now you can see all details properly. Thank you Tom.

v5.163

minor

for 'undefined array' - related to the newly introduced feature where you can change the login er…

Fixed

  • for 'undefined array' - related to the newly introduced feature where you can change the login error message. Thank you Tom.
  • for emails sent out by vulnerability module even if you had no vulnerabilites.

v5.162

minor

for compatibility with "Stop Spammers Security | Block Spam Users, Comments, Forms" - Thank you @…

Fixed

  • for compatibility with "Stop Spammers Security | Block Spam Users, Comments, Forms" - Thank you @bobf000.

v5.161

minor

Change the message shown to users when they fail to log in. Default "Something went wrong"

New

  • Change the message shown to users when they fail to log in. Default "Something went wrong"

Fixed

  • Vulnerability folder creation bug on some installations. Result was that some users could not download vulnerabilities first time the function ran.

v5.160

minor

Users page: Show last time a user logged in. This can help identify inactive users. · Users page - Show last time a u…

New

  • Users page: Show last time a user logged in. This can help identify inactive users.
  • Users page - Show last time a user logged in. Help identify inactive users.
  • Users page - Show last time a user logged in. Help identify inactive users. Go to "Users" and check the added column "Last Login".
  • Added inline HelpScout beacon help for free users.

Improved

  • 3rd party libraries.

Fixed

  • Missing help beacon for some Premium users. Inline help just had 100+ articles added on how to use the plugin.
  • Missing help beacon for some Premium users. Also, we just added over 100+ articles added to the inline help.
  • Missing help beacon for some users. Also, we just added over 100+ articles to the inline help.
  • Some autofixes not working correctly.
  • Upgrade from free to premium error - Fatal error "Cannot redeclare"

Notes

  • No longer store vulnerabilites in database, saves to a local file instead. This will improve memory usage when scanning.
  • Improvement: No longer store vulnerabilites in database, saves to a local file instead. This will improve memory usage when scanning.
  • Improvement: No longer store vulnerabilites in database, saves to a local file instead. This lowers the memory usage when scanning.
  • WordPress 6.3 compatibility.
  • Improvement: The plugin longer stores vulnerabilites in database, saves to a local file instead. This lowers the memory usage when scanning.
  • WordPress 6.3.2 compatibility.
  • Improvement: The plugin longer stores vulnerabilites in database, saves to a local file instead. This lowers the memory usage.
  • Improvement: Added details in sidebar for firewall activities.
  • Major Update with many improvements *
  • Improvement: The events log now loads after pageload, and makes searching the log much easier and faster.
  • Major Update with many improvements
  • Improvement: Better email warnings with more details for any detected vulnerabilites.
  • Improvement: The plugin longer stores vulnerabilites in database, saves to a local file instead. This lowers the memory usage and overall speed.
  • Improvement: Trimming backup folder /sn-backups/ monthly to keep only latest 15 backups.

v5.159

minor

"Check if Application Passwords are enabled" gave warning eventhough function was disabled. Thank…

Fixed

  • "Check if Application Passwords are enabled" gave warning eventhough function was disabled. Thank you @tischtennis

v5.158

minor

More details for debugging API connection issues.

Improved

  • Freemius SDK to 2.5.7

Notes

  • More details for debugging API connection issues.
  • Visitor log visual updates.

v5.157.1

patch

Hotfix for referencing a wrong class name after moving to PHP namespaces in 5.157

Notes

  • Hotfix for referencing a wrong class name after moving to PHP namespaces in 5.157

v5.157

minor

Speed: Plugin options are no longer autoloaded. Older users might notice an improvement in websit…

Improved

  • PHP 8 compatibility.
  • PHP 8.2 compatibility.
  • visual layout problem in Events Logger.
  • visual layout in the visitor log

Fixed

  • When deleting an unwanted file via Core Scanner, the message reported an error even when file was successfully deleted.
  • Malware scan could fail due to unexpected output in JavaScript.

Notes

  • Speed: Plugin options are no longer autoloaded. Older users might notice an improvement in website speed - Thank you Parag.
  • General code improvements and removing old code.
  • General code improvements and cleaning.
  • Worked on PHP 8.2 compatibility - almost complete.

v5.156

minor

Checked WP 6.2 compatibility

Improved

  • Freemius SDK to 2.5.6

Notes

  • Checked WP 6.2 compatibility

v5.155

minor

Added details about blocked visitors on dashboard widget.

New

  • Added details about blocked visitors on dashboard widget.

Fixed

  • for notice that detected low memory incorrectly on systems with unlimited memory.
  • Notice that detected low memory incorrectly on systems with no limit memory setting (-1)
  • Warning notices regarding undefined array keys in the event logger. Thank you Jean-Claude :)

v5.154

minor

More details in email report, user IP and improved layout. Thank you Kevin for the suggestion. · You can now email ev…

New

  • More details in email report, user IP and improved layout. Thank you Kevin for the suggestion.
  • You can now email events log reports to more than one recipient. Thank you Kevin.

Improved

  • the "Application Passwords" test to include info on how to disable the feature. Thank you @lsbk :-)
  • the "Application Passwords" test to include info on how to disable the feature. Thank you @lsbk :-)

Fixed

  • PHP warning the first time the settings in the vulnerabilites module was updated.

v5.153

minor

A bug in the visitor log details when there is much info to display.

Improved

  • language files for translators, thank you :-)

Fixed

  • A bug in the visitor log details when there is much info to display.
  • The "Enable background plugin updates" notice was shown everywhere. Thank you Ian.
  • bug with unexpected results for tests to show up
  • Remove unused code for plugins not updated for a while. Thank you
  • The two Shellshock tests would fail on some servers.
  • A bug in the visitor log details when there is a lot of info to display.
  • The "Enable background plugin updates" notice was shown everywhere. Thank you Ian for pointing out.
  • Remove unused code for plugins not updated for a while. Thank you.
  • Scheduled Scanner tests with Core Scanner sometimes failed. Error found and fixed.
  • The two Shellshock tests would fail on some servers. Thank you Jeroen and Oliver.
  • bug with unexpected results for tests to show up.

Notes

  • Enable background plugin updates notice is now hidden forever when dismissed.
  • Change default time to store visitors to 7 days (much better for big sites with a lot of traffic)
  • Outdated testing now disabled per default.
  • Outdated plugins module completely removed for now.
  • "Outdated plugins" module completely removed for now to be reworked.

v5.152

minor

for not cleaning up old files when downloading vulnerable plugin list. Thank you @michaing :-)

Fixed

  • for not cleaning up old files when downloading vulnerable plugin list. Thank you @michaing :-)
  • for bug in events logger related to comments. Thank you Thomas :-)
  • for descriptions not showing properly for some vulnerabilites.
  • for not cleaning up old files when downloading vulnerable plugin list. Thank you @michaing.
  • for visitor log not working properly on some installations. Thank you Jean-Claude.
  • for bug in events logger related to comments. Thank you Thomas.

Notes

  • Language files updated.

Install the free plugin on WordPress.org, or go Pro for cloud firewall, malware scanning, and agency tools.

Larger screenshot

Enlarged image