Kadence Security Pro
Fixes
- Error if all Kadence products are managed by Nexcess licensing.
Fixes
- Race condition in file write could empty wp-config.php/.htaccess files.
Tweaks
- Updated branding from SolidWP to Kadence.
- Updated branding references from StellarWP to Nexcess.
Fixes
- Prevent email retry loops by ensuring the scheduled notification properties are saved.
Tweaks
- Update Patchstack details for existing vulnerabilities.
Features
- Restrict Admin Access module under Features > Login Security to configure authorized country access to your dashboard.
- Security Headers module under Advanced to enforce essential HTTP security headers.
Tweaks
- Ensure generated Nginx config rules are valid for customized directory structures.
Tweaks
- The Solid Security Basic and Solid Security Pro plugins can no longer be active at the same time.
- Config files now show "Solid Security" instead of "iThemes Security".
- Improved Database Backups dashboard widget when the feature is disabled.
- Clarify the 2FA onboarding email confirmation message.
- Improve Passwordless Login styling.
- All Gutenberg blocks use API version 3.
- Show the plugin changelog in the plugin information pop-up.
- The lib/updater library has been updated to 1.9.3.
Security
- Update the "tmp" npm package.
- Don't include package.json in zip.
Fixes
- Vulnerable Software dashboard card didn't render properly.
- Firewall rules that depend on HTTP headers didn't work correctly in all cases.
- PHP Warning: Undefined array key 1 core/admin-pages/logs-list-table.php.
- Logs will appear in the correct order regardless of database version.
- PHP Warning: Array offset on value of type null core/modules/security-check-pro/class-itsec-security-check-pro.php.
Tweaks
- Send notification about new vulnerabilities found during manual scan.
- Site Scan page: show mitigated vulnerabilities, ensure all unresolved vulnerabilities are visible.
Fixes
- Notification settings could not be updated.
Fixes
- Admin should be able to edit 2FA options for other users.
