Plugin Name: WP Defender
Author: WPMU DEV
Tested up to: 7.1.1

Change Log:

= 6.3.0 ( 2026-09-22 ) =

- Enhancement: Update malware signatures
- Enhancement: Make Scan settings uneditable while scanning is in progress
- Enhancement: Upgrade node packages
- Enhancement: Display country name tooltip on country flag hover in Firewall Logs
- Enhancement: Reduce the plugin archive size by removing legacy code in some files
- Enhancement: Translation improvements
- Enhancement: Display scan details of issue with a suspicious code with automatic scrolling
- Enhancement: Update support and product roadmap links
- Enhancement: DOM improvements when Pwned/Strong passwords are enabled
- Enhancement: Style improvements on Issues page
- Enhancement: Scan progress bar improvements
- Enhancement: Placeholder copy for Files, folders and file types field
- Enhancement: Show count of lockouts in the notice within Malicious Bot detector
- Enhancement: Improve config applying message
- Fix: Unlock Pro features on free plan for sites hosted by WPMU DEV
- Fix: Passing null to parameter #1 on class-malicious-bot.php
- Fix: Audit logs are causing an error when updating menu items
- Fix: Defender blocking entire America if Armenia is blocked in geoblocking
- Fix: Messaging missing for the config file imports
- Fix: Defender > Strong passwords option breaks the WP Application Password
- Fix: Dropdown scroll issue in smaller screens
- Fix: Overlapping modals on Dashboard page
- Fix: Minor code improvements

= 6.2.4 ( 2026-09-01 ) =

- Fix: Username does not appear in some Audit Log events
- Fix: Audit module stores un-interpolated {{user_login}} in some logs
- Fix: Minor improvements in vulnerability detection

= 6.2.3 ( 2026-08-31 ) =

- Enhancement: Improved Audit Log UI across Dashboard and Audit Log pages
- Enhancement: Added a "Save your API keys to load" preview state for Bot Protection CAPTCHA settings
- Enhancement: Updated the event type label in the detailed Audit Log view from 'Content' to 'Context'
- Fix: Resolved an issue where audit log events from multi-event requests were not synchronizing to the Hub
- Fix: Fixed a UI layout issue when editing Nginx configuration under Hardening > Prevent Information Disclosure
- Fix: Addressed a deprecation notice for Webauthn::verify_response()
- Fix: Fixed a visual bug where the "Learn how we detect your IP" link overlapped the background border at 1280px screen widths
- Fix: Minor code improvements

= 6.2.2 ( 2026-08-24 ) =

- Fix: Streamlined schema method by removing bootstrap trait

= 6.2.1 ( 2026-08-20 ) =

- Fix: 2FA > Web Authentication method binds credential verification to the target user (props: Tai)

= 6.2.0 ( 2026-08-18 ) =

- New: Audit Log for Free Hub and WP.org users
- Enhancement: Compatibility with WordPress 7.1
- Enhancement: Replace PHP-DI third-party package with custom lightweight DI Container
- Enhancement: Display the Audit Log Storage retention setting
- Enhancement: Handle UI state when all scan types are disabled on the Settings page
- Enhancement: Update WPMU DEV domain in Audit service codebase
- Enhancement: Validate secret-key API response before writing to wp-config.php
- Enhancement: Improve toast message when attempting to disable the last enabled Malware Scan type
- Enhancement: Remove dash-notice submodule
- Enhancement: Ensure all scan status messages are displayed during scan progress
- Enhancement: Improving user communication while the site is connecting to the Hub
- Fix: Clicking on 'View Logs' link does not filter Firewall Logs after the redirect
- Fix: Security improvements on Hub-Connector (props: Jakub Herman)
- Fix: Prevent adding duplicate recipient email addresses in Reports and Alerts
- Fix: Changing the default report template should not affect existing recipient(s) preferences
- Fix: Fix responsive layout issues on Dashboard, Two-Factor Auth and Other Settings plugin pages
- Fix: Reverting to Defender 5 causes JavaScript errors on the Notifications page
- Fix: Recipients don't receive email for all types of 'Firewall Alert' when a firewall lockout is enabled and triggered for XSS, Fake Bot, or 'Non-installed plugin lockout'
- Fix: Logs are displayed without timezone on Audit and Firewall log pages
- Fix: Improve Malware Alert and Report flow for 'always_send' and 'error_send' params
- Fix: Email notifications title issue with apostrophes
- Fix: The scheduled time notice does not show after the Free upgrade
- Fix: Defender Welcome Modal is displayed in wrong version
- Fix: 3 strings were not imported for translation due to emoji
- Fix: Unable to access the Custom Rules page
- Fix: Force Authentication is not restricted to roles enabled under User Roles
- Fix: Settings page layout breaks at 1280px with horizontal scrollbar
- Fix: Incorrect 'Enable Bot Protection' modal on disabled reCAPTCHA toggles
- Fix: Pagination remains visible after ignoring all files and only disappears after clicking a page
- Fix: Defender Audit Logs creates incorrect and duplicate entries when updating General Settings
- Fix: Minor code improvements

= 6.1.0 ( 2026-07-22 ) =

- Enhancement: Improved compatibility of Central IP list status with Unlimited Hosting environments
- Enhancement: Extended Whitelabel support to cover Global Firewall branding
- Enhancement: User Agent lockout features reflected in the overall lockout count alongside 404 and Login lockouts
- Enhancement: Added tooltip for the "Security actions required" badge and confirmation notice after applying configuration presets
- Enhancement: Improved recipient name validation in Reports & Alerts and smarter alert scheduling for months with fewer than 31 days
- Enhancement: Users remain on the current page after connecting to the Hub
- Enhancement: Updated CVSS score handling for outdated plugin issues
- Enhancement: Updated Defender icon, configuration branding, dropdown design, and Hub Connector submodule
- Fix: Resolved multiple v5 to v6 upgrade issues where notification, 2FA, and Usage Tracking settings were incorrectly reset or disabled
- Fix: Fixed errors triggered by third-party plugin conflicts and Notification model properties
- Fix: Fixed WP-CLI command handling, including duplicate scan lines and missing subcommands
- Fix: Resolved AntiBot and Bot Protection state issues, including Unlock Me button and feature activation modal
- Fix: Fixed Firewall Logs status filter, IPv6 Blocklist lookup, and custom IP block/allow list sync
- Fix: Fixed UI issues including pagination, file details panel truncation, and config dialog behavior
- Fix: Minor code improvements, PHP warning fixes, and performance refinements

= 6.0.1 ( 2026-07-08 ) =

- Fix: Resolved a fatal error caused by legacy null date values


1115077-1790072345-au