PluginProbe
Passster – Password Protect Pages and Content / 4.3.16
Passster – Password Protect Pages and Content v4.3.16
4.3.16 4.3.15 4.3.14 4.3.12 4.3.13 4.3.11 4.3.10 4.3.9 4.3.8 4.3.7 4.3.6 4.3.5 trunk 3.5.4 3.5.5.2 3.5.5.8 3.5.5.9 4.0 4.1.4 4.2.10 4.2.11 4.2.12 4.2.13 4.2.14 4.2.15 All 48 releases
← All changes | readme.txt +439 -91 3.5.44.3.16 View file →
@@ -1,141 +1,484 @@
1 -=== Passster - Password Protection ===
2 -Contributors: patrickposner
3 -Tags: password protection, content protection, content restriction, captcha, membership, cookie restriction, members area, password protect
4 -Requires at least: 4.6
5 -Tested up to: 5.8
6 -Requires PHP: 7.0
7 -Stable tag: 3.5.4
1 +=== Passster - Password Protect Pages and Content ===
2 +Contributors: wpchill, silkalns
3 +Tags: password protect, password, restrict content, sitewide, password protection
4 +Requires at least: 6.5
5 +Tested up to: 7.1
6 +Requires PHP: 7.2
7 +License: GPLv2 or later
8 +License URI: https://www.gnu.org/licenses/gpl-2.0.html
9 +Stable tag: 4.3.16
8 10
9 -Passster is the best and simplest solution to password-protect your content.
11 +== Description ==
12 +## Password Protect Pages, Posts & Content in WordPress
10 13
11 -== Description ==
14 +Passster is an all-in-one plugin to password protect pages, content, or your entire site in seconds—quick, secure, and easy to use.
15 +Passster offers three protection modes to cover every use case you may think of when it comes to password protecting your WordPress website.
12 16
13 -Protect your entire website, only single pages or posts or just areas of content within it.
14 -Passster brings a lot of flexibility in creating password-protected areas on your website.
17 +https://www.youtube.com/watch?v=kjYklVLVFD8&list=PLM2tOjfhVrZdo_H26CV2I-UfdqpDWxo3D&index=4
15 18
16 -**Area protection**
19 +### Passster Pro – Even more protection features when making a purchase
17 20
18 -Create protected areas that can be added with a simple shortcode.
19 -The shortcode will be fully generated for you based on your configuration of your area.
21 +**Multiple Passwords & Password Lists**
22 +- Assign multiple passwords for different users.
23 +- Create and manage large password lists for easy control.
20 24
21 -**Page protection**
25 +**Quick & Bulk Edit for Password Protection**
26 +- Use WordPress **Quick Edit** and **Bulk Edit** to protect multiple pages instantly.
22 27
23 -Protect entire pages with the same settings you already know from the area protection, but without even using a shortcode.
24 -It blocks the entire page while keeping your layout intact instead of showing an ugly protection layout.
28 +**Unlock Content by User Role or Email**
29 +- Automatically grant access to specific users or email addresses.
25 30
26 -**Global Protection**
31 +**Password Expiration & Usage Limits**
32 +- Set passwords to expire after a number of uses, first use, or by a time limit (hours, days, weeks).
33 +- Track which passwords were used and when they will expire.
27 34
28 -On each page, you can select to activate the global protection. Each visitor without the required password will be redirected to the page
29 -as long as they are not authenticated. The Cookie option from Passster->Options is required for this.
35 +**Generate Unlock Links**
36 +- Create encrypted unlock links so users can access content without entering a password.
37 +- Automatically shorten links with **Bit.ly** for easy sharing.
30 38
31 -**Pagebuilder**
39 +**WooCommerce Protection & Sales**
40 +- Protect WooCommerce pages, products, and checkout with a password.
41 +- Sell access to protected content—generate and email passwords automatically after purchase.
32 42
33 -All three protection modes supporting all well-known page builders.
34 -Currently successfully tested are:
43 +**Detailed Password Usage Statistics**
44 +- Track when and how often passwords are used.
45 +- View first usage date, IP (optional), and browser details.
35 46
36 -* WPBakery Pagebuilder
37 -* Elementor / Elementor Pro
38 -* Beaver Builder
39 -* Divi Builder
40 -* Oxygen Builder
41 -* Gutenberg
47 +## Quick Comparison (Free vs. Pro)
42 48
43 -To avoid any layout shifts or rendering problems, it's highly recommended to activate the "Reload after successful validation" option in Passster->Options->Compatibility Mode.
49 +### Free Version:
50 +✔ Protect sections of pages using shortcodes or blocks.
51 +✔ Secure entire pages and posts.
52 +✔ Automatically protect child pages with a single click.
53 +✔ Lock down your entire site with a password.
54 +✔ Unlock protected content without refreshing the page.
55 +✔ Customize the design, labels, and descriptions of the password form.
56 +✔ Use cookies to grant access across multiple protected areas.
44 57
58 +### Pro Version:
59 +✔ Everything in the free version, plus:
60 +✔ Protect content with **multiple passwords** or password lists.
61 +✔ Quickly set up password protection via Quick Edit or Bulk Edit.
62 +✔ Protect content using **Google reCAPTCHA or hCAPTCHA**.
63 +✔ Unlock protected content by **user role or email**.
64 +✔ Set passwords to **expire** based on usage limits or time intervals.
65 +✔ Generate encrypted **unlock links** for seamless access.
66 +✔ Track and prevent **concurrent password sharing**.
67 +✔ Secure **WooCommerce products and store pages**.
68 +✔ Sell access to protected content via **WooCommerce integration**.
69 +✔ Detailed statistics on password usage and lists.
45 70
46 -= Features =
71 +Get it now on [passster.com/](https://passster.com/)
47 72
48 -**Free**
73 +### Documentation
49 74
50 -* restrict areas and add them via shortcode
51 -* restrict pages
52 -* restrict your entire website
53 -* use a single password or a captcha for protection
54 -* AJAX for unlocking with caching and without a reload
55 -* change the global styles and texts in the WordPress Customizer
56 -* Use cookies to save encrypted passwords for longer access
75 +Learn more about this plugin [in our official documentation](https://passster.com/kb/)
57 76
58 -**Pro**
77 +== Support ==
78 +* Free users: [Ask in our forum](https://wordpress.org/support/plugin/content-protector/)
79 +* Pro users: [Get priority help](https://passster.com/contact-us/?utm_source=wordpress.org&utm_medium=web&utm_campaign=description&utm_term=contact+us)
59 80
60 -Additionally to all free features, the pro version includes:
81 +== Frequently Asked Questions ==
61 82
62 -* use multiple passwords
63 -* use large passwords lists with password expiration by usage and date
64 -* use Google ReCaptcha (v2 and v3) for protection
65 -* expire passwords from a list after one-time usage, after several usages, or by time (hours, days, weeks, months)
66 -* modify headline, description, placeholder, buttons per shortcode
67 -* modify headline, description, placeholder, buttons per page
68 -* auto-unlock content per user and user role
69 -* unlock content with encrypted links and use Bitly to shorten the entire URL (optional)
83 += Can I use Passster in multiple languages =
84 +All primary texts and information can be modified from the admin area of Passster.
85 +The plugin is fully translatable in your language. There are only en_EN and de_DE at the moment, but you can easily add your preferred language as a .po/.mo.
86 +It’s also fully compatible with WPML and Polylang.
70 87
71 -Paired with exceptional support directly from the developer, timely updates and feature integrations, and extensive documentation you can't go wrong with Passster Pro.
72 -Get it now on [patrickposner.dev](https://patrickposner.dev/plugins/passster/)
88 += Where do I report security bugs found in this plugin? =
73 89
74 -**Documentation**
90 +Please report security bugs found in the source code of the Passster plugin through the [Patchstack Vulnerability Disclosure Program](https://patchstack.com/database/vdp/9e5fb73f-e810-474a-a64f-c86081aa9b46). The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin."
75 91
76 -I regularly optimize the documentation and release extensive tutorials on how to use Passster in a multitude of use-cases.
92 +== Screenshots ==
93 +1. Passster Password Form
94 +2. Passster Settings Area General
95 +3. Passster Settings Area Design
96 +4. Passster Protected Areas
97 +5. Passster Protected Areas in page edit
98 +6. Passster Password Lists - Pro only
99 +7. Passster Statistics - Pro only
77 100
78 -Learn more on [patrickposner.dev/docs](https://patrickposner.dev/docs/)
101 +== Installation ==
79 102
80 -== Support ==
103 +Passster is simple to install:
81 104
82 -The free support is exclusively limited to the wordpress.org support forum.
105 +1. Download the .zip'
106 +2. Unzip
107 +3. Upload the directory to your '/wp-content/plugins' directory
108 +4. Go to the plugin management page and enable the Passster Plugin
109 +5. Browse to Settings > Passster
110 +6. Customise your settings and your good to go!
83 111
84 -Any kind of email priority support, customization, and integration help need a valid premium license.
112 +== Changelog ==
113 += 4.3.16 - 18.09.2026 =
114 +* Added: Post Type Level Protection: password-protect an entire post type at once.
115 +* Fixed: Unlock link redirects on archive pages.
85 116
86 -=== CODING STANDARDS MADE IN GERMANY ===
117 += 4.3.15 - 10.09.2026 =
118 +* Fixed: Compatibility issue with some page builders.
87 119
88 -The plugin is coded with **modern PHP** and **WordPress standards** in mind. It’s fully OOP coded. It’s highly extendable for developers through several actions and filter hooks.
120 += 4.3.14 - 03.09.2026 =
121 +* Fixed: Security update.
122 +* Fixed: Minor admin UI improvements.
89 123
90 -Passster keeps your website performance in mind. Every script is **loaded conditionally** and all input and output data is secured.
124 += 4.3.13 - 02.09.2026 =
125 +* Fixed: Security update.
91 126
127 += 4.3.12 - 01.09.2026 =
128 +* Fixed: Security update.
92 129
93 -=== MULTI-LANGUAGE ===
130 += 4.3.11 - 25.08.2026 =
131 +* Fixed: Some Design settings were not being applied to the password form.
94 132
95 -All major texts and information can be modified from the admin area of Passster.
133 += 4.3.10 - 21.08.2026 =
134 +* Fixed: Various password validation and unlock reliability improvements.
96 135
97 -The plugin is **fully translatable** in your language. At the moment there are only en_EN and de_DE, but you can easily add your preferred language as a .po/.mo.
136 += 4.3.9 - 13.08.2026 =
137 +* Fixed: Security issue (thanks to WPScan).
138 +* Fixed: Block editor freezing when selecting a block built with page builders like Spectra.
139 +* Changed: Hid noisy Freemius notices (opt-in reminder, premium activation, plan upgrade messages).
140 +* Changed: Updated Freemius SDK to 2.13.4.
98 141
99 -It’s also fully compatible with WPML and Polylang.
142 += 4.3.8 - 03.08.2026 =
143 +* Fixed: Security issue.
144 +* Fixed: Block editor freezing on pages built with Elementor.
145 +* Changed: Improved Protected Content block toolbar performance on pages with many blocks.
100 146
101 -== Screenshots ==
102 -1. Passster Password Form
103 -2. Passster Areas
104 -3. Passster Settings
105 -3. Passster Customizer Options
147 += 4.3.7 - 27.07.2026 =
148 +* Fixed: Security issue (thanks to Pierre Rudloff).
106 149
107 -== Installation ==
150 += 4.3.6 - 23.07.2026 =
151 +* Added: "Show Password" label is now customizable from the General settings tab.
152 +* Fixed: Per-page form text being used even when "Overwrite Defaults" is disabled.
153 +* Fixed: Instruction text showing as garbled characters when using the Protected Area block.
154 +* Fixed: Security issues (thanks to Revanth Hari Narayana Matte).
108 155
109 -Passster is simple to install:
156 += 4.3.5 - 02.06.2026 =
157 +* Fixed: hCaptcha cookie not being recognized on subsequent page loads.
158 +* Fixed: Unlock links with special characters in instructions could cause encoding errors.
159 +* Fixed: Pass parameter being lost during global protection redirect.
110 160
111 -1. Download the .zip'
112 -1. Unzip
113 -1. Upload the directory to your '/wp-content/plugins' directory
114 -1. Go to the plugin management page and enable the Passster Plugin
115 -1. Browse to Settings > Passster
116 -1. Customise your settings and your good to go!
161 += 4.3.4 - 08.05.2026 =
162 +* Fixed: Replaced non-functional license activation button on free version with installation guide for Passster PRO.
163 +* Fixed: Category lock not showing password form on regular post category archive pages.
117 164
118 -== Changelog ==
165 += 4.3.3 - 03.04.2026 =
166 +* Changed: Enhance PS_Rest_Handler to allow public access to additional Passster endpoints for guest users.
119 167
168 += 4.3.2 - 30.03.2026 =
169 +* Fixed: Category lock for WooCommerce products and categories.
170 +* Changed: Page refresh on unlock is now on by default. Inline unlock can be enabled via Advanced → Unlock Behaviour.
171 +
172 += 4.3.1 - 20.03.2026 =
173 +* Fixed: Password label should not be visible, it's there for accessibility reasons.
174 +* Fixed: Password label is now translatable.
175 +* Fixed: Missing loading animation.
176 +
177 += 4.3.0 - 20.03.2026 =
178 +* Changed: Refactor settings display and added statistics page.
179 +* Added: Category lock.
180 +* Added: Passter Protected Area Gutenberg wrapper block.
181 +
182 += 4.2.29 - 12.02.2026 =
183 +* Fixed: Password validation and unlock link generation failing when the password contains the % character.
184 +
185 += 4.2.28 - 02.02.2026 =
186 +* Fixed: Nonce validation failing for logged-in users when fetched via REST endpoint.
187 +
188 += 4.2.27 - 27.01.2026 =
189 +* Fixed: Prevent nonce from being cached.
190 +* Fixed: Page protect children option.
191 +
192 += 4.2.26 - 16.01.2026 =
193 +* Fixed: Security update
194 +
195 += 4.2.25 - 14.01.2026 =
196 +* Fixed: Passster protected events do not show up in The Events Callendar REST requests.
197 +* Changed: Prevent nonce from being cached.
198 +* Fixed: Security update
199 +
200 += 4.2.24 - 12.01.2026 =
201 +* Fixed: Vulnerability in passster shortcode.
202 +* Fixed: Fix allowing hashed in unlocking page url.
203 +
204 += 4.2.23 - 08.01.2026 =
205 +* Fixed: Bug preventing password validation.
206 +
207 += 4.2.22 - 05.01.2026 =
208 +* Fixed: Vulnerability in passster shortcode.
209 +
210 += 4.2.21 - 18.12.2025 =
211 +* Fixed: Vulnerability in passster shortcode.
212 +
213 += 4.2.20 - 22.10.2025 =
214 +* Fixed: Security update
215 +
216 += 4.2.19 - 02.10.2025 =
217 +* Fixed: Vulnerability in passster shortcode.
218 +
219 += 4.2.18 - 15.09.2025 =
220 +* Added: null alt attribute to ps-loader image for better accessibility compliance.
221 +* Changed: Made password form input IDs unique per protected area to prevent duplicate IDs when using multiple forms on the same page.
222 +
223 += 4.2.17 - 22.07.2025 =
224 +* Fixed: Users with allowed roles can now access other pages when global restriction is active and the password page is excluded for them.
225 +
226 += 4.2.16 - 09.07.2025 =
227 +* Changed: Allow HTML & shortcodes in instructions.
228 +
229 += 4.2.15 - 17.03.2025 =
230 +* Added: Support for Turnstile captcha.
231 +
232 += 4.2.14 - 25.02.2025 =
233 +* Fixed: Unlock link was not working properly.
234 +
235 += 4.2.13 - 03.02.2025 =
236 +* Fixed: Global protection page was not being protected even if "Activate Protection" was on.
237 +
238 += 4.2.12 - 20.12.2024 =
239 +* Changed: Security update - Updated Freemius SDK
240 +
241 += 4.2.10 - 11.12.2024 =
242 +* Changed: Updated upsells information
243 +
244 += 4.2.9 - 10.12.2024 =
245 +* Added: Settings upsells
246 +
247 += 4.2.8 - 06.12.2024 =
248 +* Changed: Readme update
249 +
250 += 4.2.7 =
251 +
252 +* WP 6.7 compatibility
253 +* dependency updates
254 +* PHP 8.3 compatibility
255 +* make headline removable via design settings
256 +* default tag for headlines is now <span> for SEO purposes
257 +* fixed expiration with cookie usage (pro-only)
258 +
259 += 4.2.6.6 =
260 +
261 +* WP 6.6 compatiblity
262 +* latest dependencies for the block editor
263 +* fixed missing default value breaking design settings
264 +* latest Freemius SDK upgrade
265 +
266 += 4.2.6.5 =
267 +
268 +* improved expiration for passwords with unlock links
269 +* fixed escaping for redirect parameter
270 +* several security improvements
271 +* updated to 6.5 compatibility
272 +
273 += 4.2.6.4 =
274 +
275 +* exclude pagebuilders from rest restriction (frontend editing)
276 +
277 += 4.2.6.3 =
278 +
279 +* fixed components for WP 6.4.3 release (margin/radius)
280 +* restrict Rest API access with global protection
281 +
282 += 4.2.6.2 =
283 +
284 +* added exception for sanitized array setting (exclude pages)
285 +
286 += 4.2.6.1 =
287 +
288 +* added hook to combine generated password with order
289 +* improved sanitization on importer
290 +* added russian + ukrainian translation
291 +* SDK upgrade
292 +
293 += 4.2.6 =
294 +
295 +* WordPress 6.4 compatibility
296 +
297 += 4.2.5 =
298 +
299 +* WooCommerce email trigger after status complete
300 +* added filter for generated password
301 +* protected page optional for WooCommerce integration
302 +* improved admin UI contrasts
303 +* restructured design settings
304 +
305 += 4.2.4 =
306 +
307 +* WP 6.3 compatibility
308 +
309 += 4.2.3 =
310 +
311 +* some Freemius integration improvements
312 +
313 += 4.2.2 =
314 +
315 +* improved logout button markup
316 +* added action after validating password list hash
317 +* Freemius SDK update to 2.5.10
318 +
319 += 4.2.1 =
320 +
321 +* improved admin UI with permanent sidebar
322 +* improved value handling for margin/padding to avoid PHP notices
323 +* added filter to validate payment before sending e-mail (pro-only)
324 +
325 += 4.2 =
326 +
327 +* selling and generating passwords with WooCommerce (pro-only)
328 +* assign and manage multiple passwords lists (pro-only)
329 +* hotfix editing areas with Oxygen Builder
330 +* helper methods to automatically generate and add passwords to lists
331 +* statistics for password usage + custom database table
332 +* expiration statistics for passsword lists
333 +* fixed area shortcode inspector controls
334 +* GPDR friendly tracking implementation
335 +
336 += 4.1.4 =
337 +
338 +* reverted hcaptcha integration
339 +* updated admin links to new URL structure
340 +* fixed expiration settings with new encryption
341 +* fixed PHP notice if reCaptcha doesn't return a response
342 +
343 += 4.1.3.1 =
344 +
345 +* v4 API integration for Bit.ly
346 +
347 += 4.1.3 =
348 +
349 +* fixed conditional for unlock links
350 +* support for additional URL parameters in cache friendly URLs
351 +* prevent multiple renders in quick edit
352 +* hcaptcha with checkbox
353 +* removed default margin from CSS
354 +* copy shortcode with fallback for Block Editor
355 +* removed deprecated compatibility method
356 +
357 += 4.1.2 =
358 +
359 +* fallback solution to get post id in classic editor
360 +* fixed saving meta data in classic editor
361 +* compatibility with disable gutenberg plugin
362 +
363 += 4.1.1 =
364 +
365 +* fixed regex pattern in deprecated shortcode
366 +* removed regex pattern for captcha as the feature no longer exists
367 +
368 += 4.1 =
369 +
370 +* protect child pages
371 +* quick edit and bulk edit pages/posts for protection (pro-only)
372 +* hCaptcha protection (pro-only)
373 +* preventing PHP notices with concurrent usage and recaptcha
374 +* better dynamics for admin column + less intrusive styling
375 +
376 += 4.0.1 =
377 +
378 +* fixed reCAPTCHA selection not saving in admin
379 +* improved fallback margin/padding for protection block
380 +* improved description of the unlock mode to make it easier to understand
381 +
382 += 4.0 =
383 +
384 +* entirely new admin UI rewritten with React
385 +* custom block to select areas
386 +* ability to generate passwords
387 +* improved global protection UI
388 +* ability to exlude pages from global protection
389 +* on-the-fly unlock link generation
390 +
391 += 3.5.5.7 =
392 +
393 +* modified Freemius prefix to prevent compatibility errors with Post SMTP plugin
394 +
395 += 3.5.5.6 =
396 +
397 +* fixed Elementor integration with areas.
398 +
399 += 3.5.5.5.2 =
400 +
401 +* improved fallback solution to convert base64 to hmac
402 +* changed validation priority: cookies - links - post data for quicker validation
403 +
404 += 3.5.5.5.1 =
405 +
406 +* integrated converter to automatically convert old link encryption to new hashed encryption
407 +* fixed missing hash_nonce value in wp_localize_scripts
408 +
409 += 3.5.5.5 =
410 +
411 +* dynamic version number for cache busting after update
412 +* new encryption for encrypted links
413 +* cleared up upgrade/activation code
414 +* includes + load_textdomain in plugins_loaded
415 +* fixed task priority with global protection and redirect
416 +* fixed ReCaptcha v2 validation and content return statement
417 +* better default settings
418 +
419 +
420 += 3.5.5.4 =
421 +
422 +* improved hmac validation with cookies
423 +* fixed reload in combination with global page protection
424 +* introduced a unique secret key per installation
425 +* reverted Rest API implementation and used Ajax instead
426 +
427 += 3.5.5.3.1 =
428 +
429 +* fix for captcha/recaptcha validation with hew hmac encryption
430 +
431 += 3.5.5.3 =
432 +
433 +* fixed escaping area id in shortcode
434 +* implemented concurrent logins feature
435 +* encryption for cookies with unique secret key (hmac)
436 +* dedicated ajax class to handle validation
437 +* Rest API implementation for password encryption
438 +* general code cleanup (better performance + improved doc blocks)
439 +* consistent singletone pattern for all classes
440 +* better check for areas and full page protection (improved security)
441 +* latest freemius SDK
442 +* improved cookie-js implementation with sameSite attributes
443 +* fixed logo font rendering
444 +
445 += 3.5.5.2 =
446 +
447 +* filter to disable base64 encryption for cookies and links
448 +* Freemius SDK update
449 +* jQuery migrate fix for captcha
450 +* improved escaping of shortcode attributes (area and password lists)
451 +
452 += 3.5.5.1 =
453 +
454 +* better permission check settings page
455 +* better permission check metaboxes
456 +* improved german translation
457 +* added redirect parameter and settings
458 +* updated cookie js for better compatibility
459 +* added support for WooCommerce products and shop pages
460 +* filter to allow spaces in passwords
461 +* fixed version number
462 +
120 463 = 3.5.4 =
121 464
122 -- fixed notice for checking areas
123 -- updated dependencies
124 -- fixed security issue in is_valid()
125 -- fixed validation with reload option
465 +* fixed notice for checking areas
466 +* updated dependencies
467 +* fixed security issue in is_valid()
468 +* fixed validation with reload option
126 469
127 470 = 3.5.3 =
128 471
129 -- security patch
130 -- better error handling with fade and clear input
131 -- better area restriction
132 -- better performance for password checkups
133 -- removed rych hash dependency
134 -- improved WooCommerce product restriction
135 -- Gutenberg Support for areas
136 -- fixed notice for bitly check
137 -- fixed notice for recaptcha validation
472 +* security patch
473 +* better error handling with fade and clear input
474 +* better area restriction
475 +* better performance for password checkups
476 +* removed rych hash dependency
477 +* improved WooCommerce product restriction
478 +* Gutenberg Support for areas
479 +* fixed notice for bitly check
480 +* fixed notice for recaptcha validation
138 481
139 482 = 3.5.2 =
140 483
141 484 * fix for shortcode validation capabilities
@@ -584,4 +927,9 @@
584 927 Added required images for JQuery UI theme and fixed some i18n strings.
585 928
586 929 = 1.0 =
587 930 Initial release.
931 +
932 +== Upgrade Notice ==
933 +
934 += 4.2.13 =
935 +This resolved an issue with the "Activate Protection" option set for the Global protection page.