WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

MainWP extension

Security Ninja for MainWP.

Changelog for the Security Ninja for MainWP Dashboard extension (not the child plugin on each site). Updated August 18, 2026.

Looking for the main plugin on each site? WP Security Ninja changelog

v2.3.0

Latest minor

Pro extension page is tabbed: Overview (fleet cards + top incidents), Events (global log), and Settings (fleet alerts…

New

  • Pro extension page is tabbed: Overview (fleet cards + top incidents), Events (global log), and Settings (fleet alerts + metrics history).
  • Optional Pro fleet email alerts (multi-recipient daily digest with rule toggles, fingerprint anti-spam, Send test email). Uses wp_mail on the MainWP dashboard.
  • Daily metrics history (90-day retention) feeds [securityninja.month.summary] progress.
  • Pro Reports token [securityninja.month.summary] for client-facing monthly security summaries.

Improved

  • Suggested next-step hints on fleet cards and per-site overview when counts are above zero.
  • Extension overview cards SSR (vulns, blocks, low score, malware, outdated child, stale sync).
  • Events table wraps long Action/Description text; fleet alerts UI clarifies global vs per-site scope and mail/SMTP requirements.
  • Bulk and per-site actions now use MainWP message banners and confirm dialogs instead of browser alert/confirm.
  • Fleet alert Settings shows the last mail attempt error when delivery fails (no retry queue).
  • Spanish (es_ES) translations for the agency pack UI, fleet alerts, metrics/reports copy, remediation hints, settings labels, and bulk IP actions.
  • Translations across locales.
  • German UI strings for the overview cards, sync notices, and IP management.
  • White Label bulk returns per-site results; bulk IP supports add/remove and lift ban/404.
  • Human settings labels, Sites column quickview, and scan status labels (Passed/Failed/Warning).

Fixed

  • German locale showed "Kaufen / Mieten" for the All Actions event filter.
  • Malware scan file list label "Linenumber" is now "Line number".
  • Free Settings tab shows a Pro upsell instead of a blank panel.

v2.2.2

patch

Pro Reports token [securityninja.month.summary] for client-facing monthly security summaries. · Pro extension page is…

New

  • Pro Reports token [securityninja.month.summary] for client-facing monthly security summaries.
  • Pro extension page is tabbed: Overview (fleet cards + top incidents), Events (global log), and Settings (fleet alerts + metrics history).
  • Optional Pro fleet email alerts (multi-recipient daily digest with rule toggles, fingerprint anti-spam, Send test email). Uses wp_mail on the MainWP dashboard.
  • Daily metrics history (90-day retention) feeds [securityninja.month.summary] progress.

Improved

  • Bulk and per-site actions now use MainWP message banners and confirm dialogs instead of browser alert/confirm.
  • Translations across locales. Last Run, Line number, and Events no longer use race, fabric, or conference wording.
  • German UI strings for the overview cards, sync notices, and IP management.
  • Extension overview cards SSR (vulns, blocks, low score, malware, outdated child, stale sync).
  • White Label bulk returns per-site results; bulk IP supports add/remove and lift ban/404.
  • Human settings labels, Sites column quickview, and scan status labels (Passed/Failed/Warning).
  • Suggested next-step hints on fleet cards and per-site overview when counts are above zero.
  • Events table wraps long Action/Description text; fleet alerts UI clarifies global vs per-site scope and mail/SMTP requirements.

Fixed

  • German locale showed "Kaufen / Mieten" for the All Actions event filter.
  • Malware scan file list label "Linenumber" is now "Line number".
  • Free Settings tab shows a Pro upsell instead of a blank panel.

v2.2.1

patch

Copying Malware Scanner whitelist settings now keeps filename, hash, and pattern entries instead…

Fixed

  • Copying Malware Scanner whitelist settings now keeps filename, hash, and pattern entries instead of flattening them into strings the child scanner ignores.
  • Saving the per-site Settings editor no longer strips malware whitelist hashes when the path list is unchanged.

v2.2.0

minor

Bulk "Copy settings" copies allowlisted settings from one synced Pro child to selected Pro sites, with a per-site pre…

New

  • Bulk "Copy settings" copies allowlisted settings from one synced Pro child to selected Pro sites, with a per-site preview before applying.
  • Lockout-prone settings such as blocked countries, login URL changes, and two-factor authentication stay excluded from bulk copies unless explicitly selected.
  • Bulk "Manage IPs" adds an IP or CIDR, with an optional note, to the whitelist or blacklist across selected Pro children running Security Ninja 5.285+.
  • Bulk "Update vulnerabilities" requests a separate one-off vulnerability database refresh on children running Security Ninja 5.297+, without waiting for their recurring job.
  • The per-site Settings editor supports blocked countries, Malware Scanner whitelist paths, and Core Scanner ignore paths on Security Ninja 5.297+ children.
  • The per-site Scan results tab includes a "Run scans" button using the same remote scan action as the Manage Sites bulk command.

Improved

  • Bulk operations show per-site success, skipped, and failure messages, then remind you to run MainWP Sync to refresh cached dashboard data.
  • Older children remain usable: settings arrays are omitted for Security Ninja 5.285 to 5.296, while unsupported sites are skipped with an upgrade message.
  • The IP form now follows MainWP form styling, gives notes a full-width field, and keeps actions clearly separated.
  • The Settings editor has a visible scroll panel and guidance so later modules are easier to find.
  • WordPress.org description now matches the shipped settings, IP management, overview, scan, and reporting-token features.

Fixed

  • Blocked countries selected through the MainWP dropdown are now included correctly when previewing and applying per-site changes.
  • Premium feature checks now use Freemius-safe standalone guards for reliable free and Pro builds.

v2.1.3

patch

Optional note when adding an IP or CIDR to a child site whitelist/blacklist from MainWP (requires a Security Ninja ve…

New

  • Optional note when adding an IP or CIDR to a child site whitelist/blacklist from MainWP (requires a Security Ninja version that supports IP notes on the child).

Improved

  • IP management table shows synced notes for whitelist/blacklist rules.

v2.1.2

patch

Marketing and UI copy aligned with actual scan behavior (Security Tests + Core Scanner on all sit…

Improved

  • Marketing and UI copy aligned with actual scan behavior (Security Tests + Core Scanner on all sites; Malware Scanner only when the child has Security Ninja Pro).
  • Updated translation template (POT).
  • Readme Note clarifies what free vs Pro child sites sync to MainWP.

Fixed

  • Pro Reports tokens no longer attempt a broken remote get_test_results call; empty-state messages shown when sync cache is missing.
  • MainWP install-check metadata updated (version, URLs, author).
  • White-label default URL typo (wpecurityninja.com to wpsecurityninja.com).
  • Stray duplicate

    in All Events Pro upsell markup.

Notes

  • Unused bulk malware-scan JavaScript handler (malware runs via "Run all security scans" on Pro child sites).
  • Unreachable white-label bulk-action JavaScript.

v2.1.1

patch

Search filter on the editable settings list to find options quickly. · Per-site Settings tab: edit allowlisted Securi…

New

  • Search filter on the editable settings list to find options quickly.
  • Per-site Settings tab: edit allowlisted Security Ninja options from MainWP, preview only changed keys, then apply to the child site after confirmation (requires Security Ninja 5.285+ on the child site).

Improved

  • Per-site Settings tab shows a single editable settings panel (removed duplicate read-only dump).
  • Remote settings updates send changed keys only; synced cache refreshes after a successful apply.
  • MainWP 6.1 default light and dark theme support for the sidebar menu icon and extension page header logo (theme-aware colors; white logo variant in dark mode).
  • Sidebar menu icon spacing and sizing aligned with native MainWP labeled-icon items for both active and inactive states.

Fixed

  • Webhook URL and other allowlisted fields render even when missing from synced child data (e.g. empty webhook URL never saved on the child).
  • Sidebar menu no longer shows duplicate icons in light or dark theme.
  • Extension page header logo link markup (valid link to wpsecurityninja.com).

Notes

  • "Update database tables" bulk action and per-site Settings button (child plugin still creates tables on upgrade/activation).

v2.1.0

minor

Phase 1 MainWP dashboard: per-site at-a-glance (test score, vulnerabilities, firewall, last sync); read-only synced s…

New

  • Phase 1 MainWP dashboard: per-site at-a-glance (test score, vulnerabilities, firewall, last sync); read-only synced settings; IP management table with remote add/remove and lift ban actions (requires Security Ninja 5.285+ on the child site).
  • Global overview summary cards (firewall off, sites with vulnerabilities, recent blocks) and top incidents table (7 days) on the All Events page. The firewall-off card lists affected site names with links to each site tab.
  • AI Security Advisor executive summary on the per-site tab when synced from Pro child sites.
  • Event Details column and modal for raw_data on events synced from Security Ninja 5.285+.

Improved

  • AJAX handlers validate MainWP site edit permissions; overview cache clears on site sync.
  • Per-site Security Ninja tab reorganized into Overview, Scan results, IP management, and Settings tabs. Scan cards moved to Scan results; settings and IP management separated. Sites table quickview opens Scan results directly.

v2.0.18

patch

"Run all security scans" runs Security Tests and Core Scanner on all child sites, and also runs t…

Improved

  • "Run all security scans" runs Security Tests and Core Scanner on all child sites, and also runs the Malware Scanner when the child site has Security Ninja Pro, regardless of the Scheduler setting. Sync the site again after running to see updated results in the dashboard.
  • Per-site Security Ninja tab redesigned with clear section cards (Vulnerabilities, Security Tests, Core Scanner, Malware Scanner), short summaries, last-run times, and optional "View details" collapse for a cleaner, responsive layout.
  • Malware Scanner details (file list) on the per-site tab are now shown only for Pro users; free users see last run and summary with an upgrade notice.
  • Output escaping and sanitization throughout (human_time_diff, version strings, and dynamic content) for consistency with WordPress coding standards.

v2.0.17

patch

"Update database tables" (force create tables) available from the individual site Security Ninja tab and from Manage…

New

  • Pro "Update database tables" (force create tables) available from the individual site Security Ninja tab and from Manage Sites bulk actions (Pro). Requires Security Ninja 5.271 or newer on the child site (this function was introduced in Security Ninja 5.271).

Fixed

  • Resolved fatal error when logging in with 2FA (e.g. SiteGround Security): "Call to a member function is_migration() on bool" in Freemius SDK on admin_init.

v2.0.16

patch

MainWP Time Tracker Extension conflict resolved. Scripts and styles now load only on Security Nin…

Improved

  • Reduced script footprint on the MainWP dashboard for better compatibility with other extensions.
  • Code quality and hardening throughout the extension.
  • Input validation and output handling for greater stability.
  • Events log prune task stability.
  • Updated third-party libraries.
  • Updated translation file.

Fixed

  • MainWP Time Tracker Extension conflict resolved. Scripts and styles now load only on Security Ninja-related pages (Extensions, Manage Sites, site tab).
  • DataTable initialization wrapped in existence check to prevent JavaScript errors on pages where the events table is not present.
  • Renamed white-label modal IDs from mainwp-popup to secnin-mainwp-whitelabel-popup to avoid ID conflicts with other MainWP extensions.
  • Corrected "Matched pattern" label in malware scan results.

Install Security Ninja on each child site, then add the MainWP extension on your Dashboard.

Larger screenshot

Enlarged image