=== Security Ninja – WordPress Security & Firewall ===
Contributors: lkoudal, cleverplugins, freemius
Donate link: https://wpsecurityninja.com/
Tags: security, firewall, waf, vulnerability, malware
License: GPLv3
License URI: https://www.gnu.org/licenses/gpl-3.0.html
Requires at least: 4.7
Tested up to: 7.0.2
Stable tag: 5.294
Requires PHP: 7.4

WordPress security plugin: free 8G firewall/WAF, 50+ tests, vulnerability/core scanning, events logging, AI reports.

== Description ==

Security Ninja is a lightweight **WordPress security plugin** that helps protect your site from common attacks and security mistakes - without turning your dashboard into a cockpit.

[youtube https://www.youtube.com/watch?v=5zzzQTPmbS0]

**Web Application Firewall (WAF)** (based on the 8G ruleset) to block common malicious requests, plus 50+ security checks, a full vulnerability scanner, and a core integrity scanner to spot risky settings and unexpected file changes.

Upgrade to Pro for Cloud Firewall, malware scanning/cleanup, login brute-force protection and 2FA, export/webhooks, and scheduled scans.

This plugin can be downloaded for free without any paid subscription from <a href="https://wordpress.org/plugins/security-ninja/">the official WordPress repository</a>.



**Included for free**
- **Basic Firewall (8G-based)** – Blocks common malicious requests and bot noise before it becomes a problem.
- **50+ Security Tests** – Fast audit of common WordPress security misconfigurations.
- **Vulnerability Scanner** – Highlights known issues in plugins/themes so you can patch faster.
- **Core Scanner** – Detect modified or unexpected files in WordPress core folders.
- **Basic Events Logger** – Logs **firewall events** and **login attempts (successful/failed)**.
- **AI Security Advisor (WordPress 7)** – AI-generated audit summaries and guided follow-ups from your scans, using WordPress AI Connectors (you choose the LLM provider). Optional WordPress Abilities let other AI tools on your site read test summaries, attack activity, and your latest saved report.

**Pro adds**
- **Cloud Firewall & advanced WAF** – Block 600+ million known bad IPs, country blocking, IP management, and stronger firewall controls (free includes the 8G-based firewall).
- **Advanced Malware Scanner** – Detect and clean malicious code and suspicious files.
- **Login protection & 2FA** – Limit failed logins, rename the login URL, and add two-factor authentication.
- **One-click Fixes** – Harden WordPress from the Fixes page (XML-RPC, file editor, headers, and more).
- **Full Events Logger** – Export logs, scheduled email reports, webhooks (e.g. Slack/Discord), and deeper alerting.
- **Scheduled scans & reporting** – Automated security scans and reports.


**Key Features**

Security Ninja is a lightweight **WordPress firewall plugin** and security toolkit designed to help you find misconfigurations, block common attacks, and stay ahead of known vulnerabilities - without slowing your site down.

**Comprehensive WordPress Security Testing**

Security Ninja performs 50+ advanced security tests to identify issues before attackers exploit them. This includes:

- **Login and password checks** – Audits weak passwords and related settings (Pro adds failed-login limits, rename login, and 2FA).
- **File integrity monitoring** – Detects unauthorized changes to WordPress core files, themes, and plugins.
- **Database security checks** – Identifies weak database permissions and potential SQL injection threats.
- **User role audits** – Ensures no unauthorized administrator accounts exist.
- **Security misconfiguration scans** – Identifies and fixes weak settings that could compromise security.

**Enhanced Vulnerability Scanner**

Proactively alerts you to known vulnerabilities in plugins and themes so you can patch before they are exploited.

**Core Scanner – WordPress Installation Integrity**

Ensures your WordPress installation remains untampered and free of unauthorized files.

- **Full core file integrity check** – Scans every file in core WordPress folders for modifications.
- **Unknown file detection** – Flags extra or unexpected files in core directories.
- **Built-in file viewer** – Review flagged files in the dashboard.
- **Restore or delete** – Restore altered core files with one click, or remove suspicious unknowns.


**Advanced Malware Scanner – Detect & Remove Malware Instantly (PRO)**

Security Ninja includes a high-performance malware scanner that automatically checks your WordPress core, plugins and themes for:

- **Malicious scripts and backdoors** – Identifies hidden malware and harmful injections.
- **Trojan and virus detection** – Scans for suspicious PHP and JavaScript entries.
- **One-click malware removal** – Instantly quarantine and delete infected files.

**WordPress Firewall & Real-Time Threat Protection**

Security Ninja includes a **basic firewall for free** (8G-based) to block common malicious requests. Upgrade to Pro for more advanced WAF controls.

- **Basic protection (Free)** – 8G rules block many common exploit patterns and abusive requests.
- **Advanced protection (Pro)** – Cloud Firewall, country blocking, IP lists, and additional intelligence/automation.
- **Login brute-force protection (Pro)** – Limit failed logins and harden the login flow (not included in the free firewall).

**Automatic service whitelisting (Pro)**

Cloud Firewall (Pro) whitelists known third-party service IPs so remote maintenance, optimization, and monitoring tools are less likely to be blocked. No manual IP entry is required for these built-in lists.

- **WP Compress** – image optimization and compression service
- **MonSpark** – uptime and website monitoring
- **Modular DS** – remote site management
- **WPMU DEV** – hosting and management platform
- **Divi Dash** – Elegant Themes site management
- **Fastpixel** – optimization service
- **Broken Link Checker** – link checking service
- **GetTerms** – cookie consent scanner (getterms.io)

**Optional one-click whitelists** (Firewall → IP Management; enable per service):
- **ManageWP** – enabled by default on new installs
- **WP Rocket** – caching and optimization
- **UptimeRobot** – uptime monitoring
- **Uptimia** – uptime monitoring

You can still add your own IPs and CIDR ranges manually on the IP Management screen.

**Login Security & Two-Factor Authentication (2FA) (PRO)**

Your WordPress login page is a primary target for hackers. Security Ninja enhances login security with:

- **Two-Factor Authentication (2FA)** – Requires additional verification for safer logins.
- **Brute-force attack protection** – Limits failed login attempts to block unauthorized access.
- **Rename login** - Getting a lot of requests to your login form? Hide it for spammers.

**One-Click Security Fixes & WordPress Hardening (PRO)**

Manually fixing security issues is time-consuming. Security Ninja provides one-click hardening to:

- **Disable XML-RPC** – Blocks common DDoS attacks and brute-force exploits.
- **Restrict file editing** – Prevents unauthorized theme and plugin modifications.
- **Hide PHP error messages** – Stops hackers from exploiting sensitive error details.

And many more fixes to harden your WordPress security!

**Events Logger / Activity Tracking**

Security Ninja includes a **basic events logger for free** so you can see what’s happening on your site.

- **Free:** firewall events and login attempts (successful/failed) in the dashboard.
- **Pro:** export security logs, scheduled email reports, webhooks (e.g. Slack/Discord), and deeper alerting.

**Automated Security Scans & Reports (PRO)**

Security Ninja performs scheduled security scans and sends reports directly to your inbox.

- Set up daily, weekly, or monthly security scans.
- Receive email alerts about vulnerabilities and malware infections.
- Analyze detailed reports to keep your website secure.

**Block Spam & Malicious Bots Instantly (PRO)**

Hackers and spammers use bots to exploit WordPress websites. Security Ninja prevents:

- **Fake registrations and spam comments** – Stops bots from even getting to your site.
- **Malicious bot attacks** – Blocks scripts attempting to hack your site.
- **Unwanted traffic** – Reduces server load by preventing unnecessary bot access.

**AI Security Advisor - from scan results to clear next steps (WordPress 7)**

Understanding a security scan shouldn’t feel like homework. **AI Security Advisor** uses your connected LLM (via **WordPress 7 AI Connectors**) to turn Security Ninja findings into a readable audit: executive summary, prioritized improvements, and suggested follow-up prompts-not an open-ended chatbot.

Reports draw on Security Tests, the Vulnerability Scanner, Core Scanner, recent firewall/login events, and on Pro sites Malware Scanner results when available. Saved reports stay on your site until you remove them.

**What you need**  
AI Security Advisor is included in the free plugin but requires **WordPress 7**. You connect the AI/LLM provider yourself under **Settings → Connectors** in WordPress; Security Ninja does not host or supply API keys.

**WordPress Abilities (optional)**  
On WordPress 7, Security Ninja can register read-only **Abilities** so other AI tools on the same site can fetch a test summary, 7-day attack activity, or your latest saved audit-useful if you use multiple AI integrations. Report generation and follow-ups on the Security Advisor page work independently of this.

**Privacy, in everyday language**  
Only non-identifying security context (test results, scan status, event counts-not personal data) is sent to your chosen AI provider to build a report.

If you are not on WordPress 7 yet, you will see a notice on the AI Security Advisor screen; the rest of Security Ninja continues to work as usual.

---

**Join thousands of satisfied users who trust Security Ninja to keep their websites safe. Start protecting your online presence today.**

===Extensions===
**MainWP** - Manage Security Ninja across many sites from one MainWP Dashboard. Security Ninja on each child site includes MainWP integration built in (no extra plugin on child sites).

* **Free addon** - <a href="https://wordpress.org/plugins/security-ninja-for-mainwp/" target="_blank">Security Ninja for MainWP</a> (WordPress.org): view test results and vulnerabilities per site, trigger remote security scans, and sync fresh results. Works with child sites on free or Pro Security Ninja; data shown matches what each site’s installed version provides.
* **Premium addon** - Adds a combined events log across all connected sites, search/filter for security events, and remote white-label control on Pro child sites. Requires Security Ninja Pro on child sites for log and white-label features. Available from your <a href="https://wpsecurityninja.com/account/" target="_blank">WP Security Ninja account</a>; see <a href="https://wpsecurityninja.com/mainwp/" target="_blank">MainWP integration</a> for details.

https://wordpress.org/plugins/security-ninja-for-mainwp/


> **Security Ninja Pro** adds Cloud Firewall (600+ million known bad IPs), country blocking, advanced WAF controls, Malware Scanner, login protection (failed-login limits, rename login, 2FA), One-click Fixes, full Events Logger (export, webhooks, scheduled reports), and scheduled scans. The free plugin already includes the 8G firewall, 50+ security tests, Vulnerability Scanner, Core Scanner, basic Events Logger, and AI Security Advisor on WordPress 7.

An all-in-one security solution for any site. With premium support and continuous updates Security Ninja **Pro** is a perfect tool to keep your site safe. <a href="https://wpsecurityninja.com/?utm_source=wordpressorg&utm_medium=content&utm_campaign=readme&utm_content=see-what-pro-offers">See what the PRO version offers</a>

Automatically block **600+ million bad IPs** with one click! <a href="https://wpsecurityninja.com/?utm_source=wordpressorg&utm_medium=content&utm_campaign=readme&utm_content=cloud-firewall">Security Ninja Pro Firewall</a> will help you stay one step ahead of bad guys by using the collective know-how of millions of attacked sites, and ban bad guys before they even open your site.

> Read more about Pro features on the <a href="https://wpsecurityninja.com/?utm_source=wordpressorg&utm_medium=content&utm_campaign=readme&utm_content=readmoreaboutpro">Security Ninja website</a>

**What others say about the plugin**

* <a href="https://wpmayor.com/security-ninja-review-wordpress-security-plugin/">WP Mayor: "Easy-to-Use WordPress Security Plugin"</a>
* <a href="https://wplift.com/security-ninja-review">WPLift</a>
* <a href="https://www.wpexplorer.com/wordpress-security-can-security-ninja-keep-your-site-safe/">WPExplorer</a>
* <a href="https://wploop.com/security-ninja-review/">WP Loop</a>
* <a href="https://www.bitcatcha.com/blog/security-ninja-plugin-review/">Bitcatcha.com</a>
* <a href="https://www.webhostingsecretrevealed.net/blog/wordpress-blog/10-actionable-wordpress-security-tips/">WebHostingSecretRevealed</a>
* <a href="https://www.ravisinghblog.in/wp-security-ninja-review/">Ravi Singh</a>
* <a href="https://tutorials7.com/security-ninja-review.html">Tutorials 7</a>
* <a href="https://www.onlinedecoded.com/security-ninja-review/">onlinedecoded.com</a>

**Tests**
* The tests include:
  * brute-force attack on user accounts to test password strength
  * numerous installation parameters tests
  * file permissions
  * version hiding
  * 0-day exploits tests
  * debug and auto-update modes tests
  * database configuration tests
  * Apache and PHP related tests
  * WP options tests
  * security headers and related server response checks

* The full suite covers 50+ checks across WordPress core/plugins/themes, user accounts and passwords, file permissions, debug modes, database configuration, PHP settings, security headers, and more. Open Security Ninja in your dashboard for the complete list with explanations and fix guidance.

**License info**

* <a href="https://github.com/carhartl/jquery-cookie">jQuery Cookie Plugin, Copyright 2013 Klaus Hartl</a>

* The vulnerability scanner uses data from the <a href="https://nvd.nist.gov/">National Vulnerability Database - NVD</a>

* This product includes IP2Location LITE data available from <a href="https://lite.ip2location.com">https://lite.ip2location.com</a>.

* This plugin uses the <a href="https://github.com/collizo4sky/persist-admin-notices-dismissal">Persist Admin notice Dismissals</a> by Collins Agbonghama @collizo4sky

* Firewall rules are based on 8G Firewall by Jeff Starr - https://perishablepress.com/8g-blacklist/

= How can I report security bugs? =

You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. [Report a security vulnerability.](https://patchstack.com/database/vdp/security-ninja)


== Installation ==

= Installing from WordPress =

1. Open WordPress admin, go to Plugins, click Add New
2. Enter "Security Ninja" in search and hit Enter
3. Plugin will show up as the first on the list, click "Install Now"
4. Activate & go to Tools - Security Ninja to make your site more secure

= Installing Manually =

1. Download the plugin.
2. Unzip it and upload to _wp-content/plugin/_
3. Open WordPress admin - Plugins and click "Activate" next to the plugin
4. Activate & go to Security Ninja to make your site more secure

== Frequently Asked Questions ==

= Does the free version include a WordPress firewall (WAF)? =
Yes. Security Ninja includes a **basic Web Application Firewall (WAF) for free**, based on the 8G ruleset. It blocks common malicious requests and reduces bot noise.

= Does Security Ninja protect against brute force attacks and login attempts? =
**Pro** includes login brute-force protection (failed-login limits), rename login, and 2FA. The **free** version records login attempts (successful/failed) in the Events Logger and runs security tests that check password strength-it does not block repeated failed logins on its own.

= Does Security Ninja include a WordPress vulnerability scanner? =
Yes. The **Vulnerability Scanner is fully available in the free version** and helps you identify known vulnerabilities in plugins/themes so you can patch quickly.

= Who is this plugin for? =
Site owners, agencies, and developers who want a lightweight WordPress security plugin to harden sites and catch problems early.

= Will this plugin slow down my site? =
In normal operation, no. Some scans can temporarily use more resources while they run.

= What changes will Security Ninja make to my site? =
Security Ninja runs checks and shows recommendations. Some Pro features can add active protection layers (firewall/WAF controls, login protection), which you can configure.

= What if I encounter issues with the plugin? =
While we strive for universal compatibility, if you face any issues, our support team is ready to assist. Visit our [support forum](https://wordpress.org/support/plugin/security-ninja) to open a new thread, and we'll help you as soon as possible.


== Screenshots ==

1. Firewall & Events overview (blocked requests + quick stats).
2. Firewall Events log (see what was blocked and why).
3. Vulnerability Scanner (find vulnerable plugins/themes and patch fast).
4. Security Tests (one-click audit with clear pass/fail results).
5. Core Scanner (detect modified/unknown core files).

== Changelog ==

= 5.294 =
* 2026-08-02
* FIX: Vulnerability Scanner - Local vulnerability database files are stored compressed so host malware scanners no longer false-positive on known-issue descriptions (e.g. wp-config). Thank you Lee.
* FIX: Compatibility - Imposter-prefixed vendor autoload no longer claims unprefixed chillerlan namespaces, fixing a fatal when LatePoint (and similar plugins) generate booking QR codes. Thank you Daniel.
* FIX: Core Scanner - Scheduled (cron) scans no longer fail with "Insufficient permissions". Manual scans were fine; background runs now complete as expected. Thank you Mirco.
* IMPROVED: Cloud Firewall - Faster visitor checks with less DNS and disk work on each page load.
* IMPROVED: Vulnerability Scanner - Lighter scheduled vulnerability list updates with lower memory use.
* FIX: AI Security Advisor - Prevent a critical error on Overview when WordPress AI Client connector checks fail (e.g. TypeError from getModelMetadataMap). Admin stays usable; thank you Tyson.
* FIX: AI Security Advisor - WordPress Abilities register on plugin load so REST and other AI tools can discover them reliably.
* FIX: AI Security Advisor - Abilities load their data when invoked outside the Advisor screen (no fatal on REST/MCP calls).
* IMPROVED: AI Security Advisor - WordPress Abilities exposure is on by default for new installs (can be turned off in AI settings).
* FIX: Vulnerability Scanner - Admin menu badge and other admin hot paths no longer load the full vulnerability database on every wp-admin request (could time out / 502 on slower hosts). Counts are served from cache; scans run in the background via WP-Cron. Thank you Christopher.
* FIX: Vulnerability Scanner - Opening Security Ninja no longer sync-downloads the vulnerability database when files are missing; updates are scheduled in the background. Pending scans no longer show a false "no vulnerabilities" message.
* IMPROVED: Vulnerability Scanner - Plugin/theme and vulnerability-database updates keep the last known results until the background rescan finishes (no empty badge gap).
* IMPROVED: Cloud Firewall - Logged-in admins skip expensive ban checks in wp-admin and admin-ajax; local banned-IP list is cached per request.
* IMPROVED: sn-global.js loads only on Security Ninja admin pages; AI Security Advisor class files load on demand instead of every request.
* IMPROVED: Cloud Firewall (Pro) - Added GetTerms cookie scanner IP (45.55.125.144) to the built-in automatic whitelist (always on; no checkbox required). Thank you Jamie.
* FIX: Cloud Firewall (Pro) - "Only block these countries from login functionality" now works when "Prevent Banned IPs from Accessing the Site" is ON. Previously, country login-only could still full-site block via the visitor check path. Thank you Jamie.

= 5.293 =
* 2026-07-22
* NEW: File Viewer - Safely preview common images (PNG, JPG, JPEG, GIF, WebP, ICO) from Core and Malware Scanner results. SVG is not supported. Images are verified before display and shown only in the admin viewer (they are not executed).
* FIX: File Viewer - Extensionless and rotated log files such as error_log and error_log.1 open more reliably, including case-insensitive name matching.
* IMPROVED: File Viewer - Very large text/log files show a truncated preview instead of failing when over the size limit.
* IMPROVED: Core Scanner - The View File button only appears when the file can actually be opened in the viewer.
* IMPROVED: Security Tests - The unused-themes check no longer treats keeping an extra default WordPress (Twenty*) theme as required. Any inactive theme can be flagged for removal, matching the auto-fixer behavior. Thank you for the feedback.
* FIX: Fixes - Disable Username Enumeration no longer blocks URLs with parameters like book_author= (e.g. store search). It now matches only the WordPress author= parameter, and skips the block for logged-in users.

= 5.292 =
* 2026-07-15
* IMPROVED: Translations - Full POT refresh and locale sync.
* IMPROVED: Translations - 2FA email and login strings covered in language packs (Spanish included).
* IMPROVED: White Label (Pro) - HTML emails use your plugin icon (when set) in branding.
* FIX: 2FA (Pro) - Login "Back to site" link uses the correct text domain so it can be translated.
* IMPROVED: 2FA (Pro) - Custom intro and enter-code texts from Login Protection now appear on the 2FA login screen.
* IMPROVED: 2FA (Pro) - Email verification codes now use the same shared email template as other Security Ninja emails.
* FIX: 2FA (Pro) - Email "Time:" label is properly registered for translation.
* NEW: Prettier interface for confirmations and overlays across free and Pro — replaces browser confirm/alert on Tools, scanners, Firewall, Events, AI Advisor, 2FA, and more. Escape closes, backdrop cancels, Enter confirms.
* NEW: Optional notes/labels on manual IP whitelist and blacklist entries (IP Management), including CIDR ranges. Notes are limited to 150 characters and stored separately so existing installs and list matching stay compatible.
* IMPROVED: Settings import/export and MainWP sync include IP notes when present.
* FIX: AI Security Advisor - Omit temperature from WordPress AI connector requests so providers that reject sampling parameters (e.g. newer Claude models) work reliably. Thank you Tyson.
* IMPROVED: Update Freemius SDK.
* IMPROVED: readme.txt - Shortened short description, description, and changelog to meet WordPress.org length limits.
* FIX: Cloud Firewall (Pro) - Avoid PHP warning when REMOTE_ADDR is missing during cron blocklist sync. Thank you Tom.

= 5.291 =
* 2026-07-06
* NEW: Overview tab - AI Security Advisor card, next best actions, what changed since your last AI review, and quick action links to key modules.
* NEW: Security Advisor - Suggested next steps and "what changed since last report" panels use scan snapshots without an extra AI call.
* FIX: AI Security Advisor - Database upgrade on update adds the snapshot column to existing AI report tables so comparisons work on upgraded sites.
* FIX: 2FA (Pro) - Email code verification works when you press Verify or Enter.
* IMPROVED: 2FA (Pro) - Login verification updates apply immediately after plugin updates.
* IMPROVED: 2FA (Pro) - Administrator is pre-selected under Required Roles when 2FA is not yet enabled; clearer grace period help for required roles.
* FIX: AI Security Advisor - Your selected AI connector applies when you generate a report.
* IMPROVED: AI Security Advisor - Model selection follows WordPress AI Client settings.
* FIX: Setup wizard - Opens automatically on first install only.
* IMPROVED: Cloud Firewall (Pro) - Added more WP Compress service IPs to the built-in automatic whitelist (always on; no checkbox required).
* FIX: Cloud Firewall - Filter Suspicious Queries no longer false-positives on s2Member loader URLs. 
* NEW: Cloud Firewall (Pro) - MonSpark uptime monitoring IPs are included in the built-in automatic whitelist (always on; no checkbox required). Thank you Heath.
* IMPROVED: Core Scanner - Detects unexpected files in the WordPress root and hidden dotfiles in wp-admin and wp-includes.
* NEW: Malware Scanner (Pro) - Flags suspicious plugin and theme folder structure when wordpress.org checksums are unavailable (review recommended, separate from malware signatures).
* IMPROVED: Malware Scanner (Pro) - Clearer integrity messaging; structural findings included in issue counts, whitelist, scheduled reports, and AI advisor context.
* IMPROVED: Core Scanner - OS metadata files (e.g. .DS_Store) are excluded from scan results.
* IMPROVED: Core Scanner - Severity levels (critical, warning, notice) with guidance for phpinfo and dev-tool files; table-based results UI.
* IMPROVED: Core Scanner - Live scan results without page reload; summary stats; Overview Core Integrity widget.
* IMPROVED: White Label (Pro) - Security Advisor and Overview use your white label plugin name in the UI and AI reports. Thank you Davina.
* IMPROVED: Visitor Log (Pro) - Cleaner Refresh button on the visitor log page.
* IMPROVED: Core Scanner - Summary strip with scan context, status banner, and last-scan metadata; delete or restore individual rows without a full rescan.
* IMPROVED: Core Scanner - Findings action buttons match Malware Scanner styling (View File, Diff, Restore, Delete).
* IMPROVED: Malware Scanner (Pro) - Issue counter on the Malware tab when suspicious files are found.
* IMPROVED: Malware Scanner (Pro) - Summary strip with last-scan context, status banner, and Whitelist all; streamlined results header.
* IMPROVED: Malware Scanner (Pro) - Findings use the same table layout as Core Scanner (file, severity, guidance, actions) with location group headers.
* IMPROVED: Core Scanner and Malware Scanner - Cleaner findings list layout.

= 5.290 =
* 2026-06-30
* NEW: 2FA (Pro) - Optional mode: enable 2FA without requiring any role; leave all required roles unchecked for opt-in only (with an admin notice when saved).
* NEW: 2FA (Pro) - Users can enable 2FA from their profile (authenticator app or email, when allowed) even if their role is not required.
* NEW: 2FA (Pro) - Admins can allow authenticator app and/or email; users choose their method at login when both are enabled (preference is remembered).
* IMPROVED: 2FA (Pro) - Required roles can be fully unchecked and stay saved (previously Administrator was forced back on).
* IMPROVED: 2FA (Pro) - Grace period "Skip for now" applies only to role-required users who have not voluntarily enrolled.
* IMPROVED: 2FA (Pro) - Grace period can be set to 0 days to enforce setup immediately.
* IMPROVED: Wizard - CSS on installation.

= 5.289 =
* 2026-06-18
* FIX: Cloud Firewall (Pro) - Visitor log retention ("Keep visitor logs for") is now enforced by a daily scheduled cleanup task.
* NEW: Tools (Pro) - "Clear visitor log" button to delete all firewall visitor log entries manually.
* NEW: Setup wizard available for all; first install opens the wizard automatically.
* IMPROVED: Cloud Firewall – The firewall master switch now consistently controls all firewall enforcement (404 Guard, WooCommerce protection, country rules, and cloud IP blocking). Login Protection (brute-force limits, rename login, 2FA, and related messages) continues to operate independently when the firewall is turned off.
* FIX: Cloud Firewall - Manual whitelist entries for localhost (127.0.0.1 / ::1) now reliably exempt requests from cloud reputation blocks; server cron and WP-CLI traffic is no longer blocked during early firewall checks. Non-public IPs are excluded from cloud blacklist matching.
* FIX: Cloud Firewall (Pro) - Country blocking now blocks the full site when "Only block these countries from login functionality" is OFF, regardless of the "Prevent Banned IPs from Accessing the Site" setting. Previously, country bans could behave like login-only blocks when that IP setting was OFF.
* IMPROVED: Wizard - single Pro overview on Welcome for free users; removed per-step upgrade buttons.
* IMPROVED: Wizard - Events Logger and Vulnerability Scanner activation steps.
* IMPROVED: Wizard - Login protection as dedicated Pro step.
* IMPROVED: Wizard - Pro badges on footer nav for Login, Fixes, and WooCommerce (hidden for licensed Pro users).
* IMPROVED: Wizard - skip wizard from intro; rerun warning only shown after wizard has been completed once.
* IMPROVED: Wizard - Dead code cleanup.
* REMOVED: WP Pointer "thank you for installing" tour and dashboard welcome banner (replaced by wizard).
* IMPROVED: Renamed review-notice dismiss nonce for clarity (`wf_sn_dismiss_review`).
* NEW: Security Tests Quick Filter - **Fixable** shows tests with one-click auto-fix available.
* NEW: Malware Scanner - **Whitelist all** button for currently flagged files (with confirmation).
* FIX: Apply Fix - after a fix completes, the test row refreshes automatically (spinner stops, status icon and score update, clear success message).
* IMPROVED: Tools page - unique form IDs and dedicated nonce fields/actions per form (Update Database, Reset 2FA, Legacy cleanup, Import, Secret URL reset).
* IMPROVED: Cloud Firewall - suspicious-query filtering now resolves visitor hostnames only when needed for blocked-hostname rules, with per-IP caching. Thank you Paul.
* IMPROVED: Cloud Firewall - Bundled data lists (ManageWP/UptimeRobot/Uptimia service IPs and the country list) are now stored as JSON data files so security scanners no longer flag them as false positives. Thank you Daryl.
* REMOVED: Unused MainWP remote actions (run_malware_scan, update_vulnerabilities, force_create_tables); malware runs via run_all_tests, tables created on activation/upgrade.
* FIX: Scheduled Scanner (Pro) - Scheduled scans now self-heal. If the scheduled event goes missing (for example after a long scan times out or a cron/optimization plugin clears it), it is recreated automatically instead of requiring you to re-save settings.
* FIX: Scheduled Scanner (Pro) - Email reports now show the correct status changes. Status labels (Good / Warning / Failed) and the "improvement" vs "security concern" wording are no longer reversed.
* IMPROVED: Security Tests - When a test cannot reach your site (e.g. a connection timeout), it now reports a "Warning / could not verify" result instead of a hard failure, so temporary network hiccups no longer look like new security problems.
* FIX: 2FA (Pro) - After verifying 2FA, the post-login redirect now mirrors WordPress core's capability handling. Users on roles that cannot access wp-admin are sent to an appropriate page instead of the dashboard (which could bounce them to the front page and appear logged out). Thank you Jason.
* IMPROVED: Updated bundled dependencies - Freemius WordPress SDK (2.13.1 → 2.13.2), phpseclib (2.0.54 → 2.0.55), and PHP Malware Scanner (1.0.30 → 1.0.31).

= 5.288 =
* 2026-06-09
* FIX: Tools - "Reset 2FA" no longer fails with "The link you followed has expired."; a success notice is shown after reset; confirmation dialog added before resetting all users. Thank you Jason.


= 5.287 =
* 2026-06-02
* FIX: Change Login URL (Pro) - Works when Cloud Firewall is disabled; only "Change login URL" and the slug need to be enabled under Login Protection.
* FIX: Change Login URL (Pro) - `/your-slug/` login URLs work even when permalinks are Plain (fixes 404 when the Preview link used a path-style URL).
* FIX: Change Login URL (Pro) - Reliable path matching for subdirectory installs; fallback serves login if WordPress resolved the request as a 404.
* FIX: Change Login URL (Pro) - wp-admin blocking applies to `/wp-admin` with or without a trailing slash.
* IMPROVED: Change Login URL (Pro) - Admin Preview shows the same URL the plugin uses (`?slug` on Plain permalinks, `/slug/` otherwise).

= 5.286 =
* 2026-06-01
* NEW: MainWP integration - child sites accept allowlisted Security Ninja settings updates from the Security Ninja for MainWP extension (`update_settings` remote action; changed keys only).
* IMPROVED: MainWP settings updates are logged in Events with a list of changed setting keys (no values stored), so you can see what was changed from the dashboard.
* IMPROVED: AI Security Advisor - works more reliably with WordPress 7 AI connectors (including DeepSeek and OpenAI). The plugin picks the right request format for each service instead of failing when structured JSON is not supported.
* IMPROVED: AI Security Advisor - Reports are faster and cheaper. Only tests that need attention are included, with short summaries.
* IMPROVED: AI Security Advisor - report output is cleaned up and checked before it is saved.
* IMPROVED: AI Security Advisor - full reports can be longer (higher token limit).
* IMPROVED: AI Security Advisor - when something goes wrong, the page shows a more helpful error message, and the failure is logged in Events so you can see what happened.
* IMPROVED: AI Security Advisor - successful and failed AI requests in Events now record which connector and model were used (prompt chip id only when relevant).

= 5.285 =
* 2026-05-26
* FIX: Upgrading from the free plugin to Pro no longer causes a site error when both versions are present during install or activation. Pro skips loading Composer again if the free copy already loaded it, then Freemius deactivates free on activation.
* IMPROVED: AI Security Advisor - when an AI connector request fails, the page now shows the provider's actual error message instead of a generic "temporarily unavailable" notice, so quota, billing, and configuration issues are easier to diagnose.
* NEW: MainWP integration (Phase 1) - sync now includes IP management entries (up to 200), AI Security Advisor executive summary, and optional event raw_data for the top 50 events. Remote IP actions (whitelist/blacklist add/remove, lift local ban, lift 404 guard ban) via the Security Ninja for MainWP extension 2.1.0+.

= 5.284 =
* 2026-05-23
* FIX: Change Login URL (Pro) - Checkout and other frontend flows that use WordPress `admin-post.php` (for example FluentCart account creation during checkout) no longer show "Access Denied" for visitors. Legitimate public handlers registered with `admin_post_nopriv_*` are allowed; direct access to the rest of wp-admin stays blocked.
* IMPROVED: Rename Login (Pro) - Recognized temporary-login plugin links (Temporary Login Without Password, One Time Login, Magic Login, Login Links) are no longer blocked when accessing wp-admin before authentication completes. Extend via the `securityninja_rename_login_allow_autologin` filter.
* IMPROVED: AI Security Advisor now uses WordPress 7 structured AI responses for more reliable report output.
* IMPROVED: AI Security Advisor reports now include richer context from Security Tests, Vulnerability Scanner, Core Scanner, and recent security events.
* IMPROVED: Pro sites now include Malware Scanner findings in AI report context when available.
* NEW: WordPress 7 Abilities (optional, on by default): expose read-only security data to other WordPress AI clients-Security Test summary (passed/warning/failed), 7-day attack activity vs the previous week, and the latest saved AI Security Advisor report. Control exposure under Security Advisor → Settings; turning this off does not affect generating reports or follow-ups on the Security Advisor page.
* NEW: Added a dismissable "Re-evaluate with AI" reminder after tests, scans, and firewall setting changes (stays hidden after dismiss until a new security event occurs).

= 5.283 =
* 2026-05-18
* FIX: Cloud Firewall (Pro) - Satellite ASN softening now works consistently across country blocking (including Starlink).
* FIX: 2FA setup during frontend login now shows the manual entry secret key again, matching the backend user profile setup flow.
* IMPROVED: Cloud Firewall (Pro) - IP Management shows your blacklist, whitelist, and temporary blocks in one searchable table, so you can see everything in one place.
* IMPROVED: Cloud Firewall (Pro) - Add, edit, and remove IP rules directly from the table; add several at once with one IP or range per line.
* IMPROVED: Cloud Firewall (Pro) - Copy your full blacklisted or whitelisted lists, or clear temporary blocks, from easy buttons below the table.

= 5.282 =
* 2026-05-05
* FIX: Two-factor authentication (Pro) - When 2FA is enabled but required roles were missing or invalid, login could skip the 2FA step. Security Ninja now falls back to requiring **Administrator** so the code prompt always appears for protected accounts.
* FIX: Saving 2FA status would fail if firewall not enabled. Thank you Vassos.
* NEW: Tools (Pro) - Cleanup button securely removes legacy options or data. Thank you Davina for the idea.
* FIX: Cloud Firewall (Pro) - Clearing **all** countries in country blocking and saving now actually turns country blocking off. Previously, choosing "none" could leave old selections in place because empty lists were not saved correctly.
* IMPROVED: Cloud Firewall - IP whitelist entries written as **ranges** (CIDR, one per line on IP Management) now apply the same way everywhere: visitor checks, secret recovery links, and automatic whitelist logic no longer treat ranges like plain single IPs only in some code paths.
* NEW: Cloud Firewall (Pro) - Option to soften country blocking for satellite ISPs like Starlink. Easily enable or adjust under Firewall → Settings for smoother access while keeping strong protection.
* IMPROVED: Cloud Firewall (Pro) - If a country or cloud block is skipped because the visitor is using a satellite ISP (satellite ASN softening), you'll now see this clearly in the Events log.


= 5.281 =
* 2026-04-22
* FIX: 2FA - Post-verification redirects now match WordPress core validation for relative and absolute `redirect_to` URLs ( Rename Login compatible ). AJAX responses always include a safe `redir_to` / `redirect_url` with `admin_url()` fallback so editors and other roles are not sent to the front page unexpectedly. Thank you Davina.
* IMPROVED: Security Tests - the "outdated plugins" check no longer saves full WordPress.org plugin metadata to the database. Thank you Davina.
* IMPROVED: AI Security Advisor - improved PII handling.
* FIX: Malware Scanner - "Revert Whitelist" now correctly persists file removal, so reverted files no longer reappear after page reload. Thank you Vassos.
* IMPROVED: Malware Scanner - respects the same ignore paths as the scanner library during filesystem traversal (e.g. `wp-admin/` and `wp-includes/`), so WordPress core files are no longer signature-scanned when already excluded-use Core Scanner for core integrity.
* IMPROVED: Malware Scanner - WordPress core JS bundles under `wp-includes/js/dist/` and `wp-admin/js/` are excluded from malware pattern matching by default (fewer false positives on minified/vendor scripts). Plugins, themes, and uploads are still scanned.

= 5.280 =
* 2026-04-17
* FIX: Display bug on Events -> Settings subtab. Thank you Aldin for spotting it.

= 5.279 =
* 2026-04-15
* IMPROVED: AI Security Advisor - interface and functionality; big improvements.
* FIX: Cloud Firewall - Failed login warning emails no longer cause a fatal error ("Class Wf_Sn_Security_Utils not found") when `wp_login_failed` ran before the `init` hook (e.g. another plugin handling login during `plugins_loaded`).
* IMPROVED: Security Tests - long help text is no longer embedded on every plugin admin screen, so the dashboard stays lighter in memory and loads faster.
* IMPROVED: Updated translation files.

...

Entire changelog can be seen here: <a href="https://wpsecurityninja.com/changelog/" target="_blank">https://wpsecurityninja.com/changelog/</a>
