PluginProbe
Passster – Password Protect Pages and Content / 4.3.17
Passster – Password Protect Pages and Content v4.3.17
4.3.17 4.3.16 4.3.15 4.3.14 4.3.12 4.3.13 4.3.11 4.3.10 4.3.9 4.3.8 4.3.7 4.3.6 4.3.5 trunk 3.5.4 3.5.5.2 3.5.5.8 3.5.5.9 4.0 4.1.4 4.2.10 4.2.11 4.2.12 4.2.13 4.2.14 All 49 releases
← All changes | readme.txt +412 -78 3.5.5.2 → 4.3.17 View file →
@@ -1,123 +1,452 @@
1 -=== Passster - Password Protection ===
2 -Contributors: patrickposner
3 -Tags: password protection, content protection, content restriction, captcha, membership, cookie restriction, members area, password protect
4 -Requires at least: 4.6
5 -Tested up to: 6.0
6 -Requires PHP: 7.0
7 -Stable tag: 3.5.5.2
1 +=== Passster - Password Protect Pages and Content ===
2 +Contributors: wpchill, silkalns
3 +Tags: password protect, password, restrict content, sitewide, password protection
4 +Requires at least: 6.5
5 +Tested up to: 7.1
6 +Requires PHP: 7.2
7 +License: GPLv2 or later
8 +License URI: https://www.gnu.org/licenses/gpl-2.0.html
9 +Stable tag: 4.3.17
8 10
9 -Passster is the best and simplest solution to password-protect your content.
11 +== Description ==
12 +## Password Protect Pages, Posts & Content in WordPress
10 13
11 -== Description ==
14 +Passster is an all-in-one plugin to password protect pages, content, or your entire site in seconds—quick, secure, and easy to use.
15 +Passster offers three protection modes to cover every use case you may think of when it comes to password protecting your WordPress website.
12 16
13 -Protect your entire website, only single pages or posts or just areas of content within it.
14 -Passster brings a lot of flexibility in creating password-protected areas on your website.
17 +https://www.youtube.com/watch?v=kjYklVLVFD8&list=PLM2tOjfhVrZdo_H26CV2I-UfdqpDWxo3D&index=4
15 18
16 -**Area protection**
19 +### Passster Pro – Even more protection features when making a purchase
17 20
18 -Create protected areas that can be added with a simple shortcode.
19 -The shortcode will be fully generated for you based on your configuration of your area.
21 +**Multiple Passwords & Password Lists**
22 +- Assign multiple passwords for different users.
23 +- Create and manage large password lists for easy control.
20 24
21 -**Page protection**
25 +**Quick & Bulk Edit for Password Protection**
26 +- Use WordPress **Quick Edit** and **Bulk Edit** to protect multiple pages instantly.
22 27
23 -Protect entire pages with the same settings you already know from the area protection, but without even using a shortcode.
24 -It blocks the entire page while keeping your layout intact instead of showing an ugly protection layout.
28 +**Unlock Content by User Role or Email**
29 +- Automatically grant access to specific users or email addresses.
25 30
26 -**Global Protection**
31 +**Password Expiration & Usage Limits**
32 +- Set passwords to expire after a number of uses, first use, or by a time limit (hours, days, weeks).
33 +- Track which passwords were used and when they will expire.
27 34
28 -On each page, you can select to activate the global protection. Each visitor without the required password will be redirected to the page
29 -as long as they are not authenticated. The Cookie option from Passster->Options is required for this.
35 +**Generate Unlock Links**
36 +- Create encrypted unlock links so users can access content without entering a password.
37 +- Automatically shorten links with **Bit.ly** for easy sharing.
30 38
31 -**Pagebuilder**
39 +**WooCommerce Protection & Sales**
40 +- Protect WooCommerce pages, products, and checkout with a password.
41 +- Sell access to protected content—generate and email passwords automatically after purchase.
32 42
33 -All three protection modes supporting all well-known page builders.
34 -Currently successfully tested are:
43 +**Detailed Password Usage Statistics**
44 +- Track when and how often passwords are used.
45 +- View first usage date, IP (optional), and browser details.
35 46
36 -* WPBakery Pagebuilder
37 -* Elementor / Elementor Pro
38 -* Beaver Builder
39 -* Divi Builder
40 -* Oxygen Builder
41 -* Gutenberg
47 +## Quick Comparison (Free vs. Pro)
42 48
43 -To avoid any layout shifts or rendering problems, it's highly recommended to activate the "Reload after successful validation" option in Passster->Options->Compatibility Mode.
49 +### Free Version:
50 +✔ Protect sections of pages using shortcodes or blocks.
51 +✔ Secure entire pages and posts.
52 +✔ Automatically protect child pages with a single click.
53 +✔ Lock down your entire site with a password.
54 +✔ Unlock protected content without refreshing the page.
55 +✔ Customize the design, labels, and descriptions of the password form.
56 +✔ Use cookies to grant access across multiple protected areas.
44 57
58 +### Pro Version:
59 +✔ Everything in the free version, plus:
60 +✔ Protect content with **multiple passwords** or password lists.
61 +✔ Quickly set up password protection via Quick Edit or Bulk Edit.
62 +✔ Protect content using **Google reCAPTCHA or hCAPTCHA**.
63 +✔ Unlock protected content by **user role or email**.
64 +✔ Set passwords to **expire** based on usage limits or time intervals.
65 +✔ Generate encrypted **unlock links** for seamless access.
66 +✔ Track and prevent **concurrent password sharing**.
67 +✔ Secure **WooCommerce products and store pages**.
68 +✔ Sell access to protected content via **WooCommerce integration**.
69 +✔ Detailed statistics on password usage and lists.
45 70
46 -= Features =
71 +Get it now on [passster.com/](https://passster.com/)
47 72
48 -**Free**
73 +### Documentation
49 74
50 -* restrict areas and add them via shortcode
51 -* restrict pages
52 -* restrict your entire website
53 -* use a single password or a captcha for protection
54 -* AJAX for unlocking with caching and without a reload
55 -* change the global styles and texts in the WordPress Customizer
56 -* Use cookies to save encrypted passwords for longer access
75 +Learn more about this plugin [in our official documentation](https://passster.com/kb/)
57 76
58 -**Pro**
77 +== Support ==
78 +* Free users: [Ask in our forum](https://wordpress.org/support/plugin/content-protector/)
79 +* Pro users: [Get priority help](https://passster.com/contact-us/?utm_source=wordpress.org&utm_medium=web&utm_campaign=description&utm_term=contact+us)
59 80
60 -Additionally to all free features, the pro version includes:
81 +== Frequently Asked Questions ==
61 82
62 -* use multiple passwords
63 -* use large passwords lists with password expiration by usage and date
64 -* use Google ReCaptcha (v2 and v3) for protection
65 -* expire passwords from a list after one-time usage, after several usages, or by time (hours, days, weeks, months)
66 -* modify headline, description, placeholder, buttons per shortcode
67 -* modify headline, description, placeholder, buttons per page
68 -* auto-unlock content per user and user role
69 -* unlock content with encrypted links and use Bitly to shorten the entire URL (optional)
83 += Can I use Passster in multiple languages =
84 +All primary texts and information can be modified from the admin area of Passster.
85 +The plugin is fully translatable in your language. There are only en_EN and de_DE at the moment, but you can easily add your preferred language as a .po/.mo.
86 +It’s also fully compatible with WPML and Polylang.
70 87
71 -Paired with exceptional support directly from the developer, timely updates and feature integrations, and extensive documentation you can't go wrong with Passster Pro.
72 -Get it now on [patrickposner.dev](https://patrickposner.dev/plugins/passster/)
88 += Where do I report security bugs found in this plugin? =
73 89
74 -**Documentation**
90 +Please report security bugs found in the source code of the Passster plugin through the [Patchstack Vulnerability Disclosure Program](https://patchstack.com/database/vdp/9e5fb73f-e810-474a-a64f-c86081aa9b46). The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin."
75 91
76 -I regularly optimize the documentation and release extensive tutorials on how to use Passster in a multitude of use-cases.
92 +== Screenshots ==
93 +1. Passster Password Form
94 +2. Passster Settings Area General
95 +3. Passster Settings Area Design
96 +4. Passster Protected Areas
97 +5. Passster Protected Areas in page edit
98 +6. Passster Password Lists - Pro only
99 +7. Passster Statistics - Pro only
77 100
78 -Learn more on [patrickposner.dev/docs](https://patrickposner.dev/docs/)
101 +== Installation ==
79 102
80 -== Support ==
103 +Passster is simple to install:
81 104
82 -The free support is exclusively limited to the wordpress.org support forum.
105 +1. Download the .zip'
106 +2. Unzip
107 +3. Upload the directory to your '/wp-content/plugins' directory
108 +4. Go to the plugin management page and enable the Passster Plugin
109 +5. Browse to Settings > Passster
110 +6. Customise your settings and your good to go!
83 111
84 -Any kind of email priority support, customization, and integration help need a valid premium license.
112 +== Changelog ==
113 += 4.3.17 - 02.10.2026 =
114 +* Fixed: Blocks from plugins like Kadence Blocks not displaying inside Protected Areas after unlock.
115 +* Fixed: Error when using multiple password lists without any list selected.
85 116
86 -=== CODING STANDARDS MADE IN GERMANY ===
117 += 4.3.16 - 18.09.2026 =
118 +* Added: Post Type Level Protection: password-protect an entire post type at once.
119 +* Fixed: Unlock link redirects on archive pages.
87 120
88 -The plugin is coded with **modern PHP** and **WordPress standards** in mind. It’s fully OOP coded. It’s highly extendable for developers through several actions and filter hooks.
121 += 4.3.15 - 10.09.2026 =
122 +* Fixed: Compatibility issue with some page builders.
89 123
90 -Passster keeps your website performance in mind. Every script is **loaded conditionally** and all input and output data is secured.
124 += 4.3.14 - 03.09.2026 =
125 +* Fixed: Security update.
126 +* Fixed: Minor admin UI improvements.
91 127
128 += 4.3.13 - 02.09.2026 =
129 +* Fixed: Security update.
92 130
93 -=== MULTI-LANGUAGE ===
131 += 4.3.12 - 01.09.2026 =
132 +* Fixed: Security update.
94 133
95 -All major texts and information can be modified from the admin area of Passster.
134 += 4.3.11 - 25.08.2026 =
135 +* Fixed: Some Design settings were not being applied to the password form.
96 136
97 -The plugin is **fully translatable** in your language. At the moment there are only en_EN and de_DE, but you can easily add your preferred language as a .po/.mo.
137 += 4.3.10 - 21.08.2026 =
138 +* Fixed: Various password validation and unlock reliability improvements.
98 139
99 -It’s also fully compatible with WPML and Polylang.
140 += 4.3.9 - 13.08.2026 =
141 +* Fixed: Security issue (thanks to WPScan).
142 +* Fixed: Block editor freezing when selecting a block built with page builders like Spectra.
143 +* Changed: Hid noisy Freemius notices (opt-in reminder, premium activation, plan upgrade messages).
144 +* Changed: Updated Freemius SDK to 2.13.4.
100 145
101 -== Screenshots ==
102 -1. Passster Password Form
103 -2. Passster Areas
104 -3. Passster Settings
105 -3. Passster Customizer Options
146 += 4.3.8 - 03.08.2026 =
147 +* Fixed: Security issue.
148 +* Fixed: Block editor freezing on pages built with Elementor.
149 +* Changed: Improved Protected Content block toolbar performance on pages with many blocks.
106 150
107 -== Installation ==
151 += 4.3.7 - 27.07.2026 =
152 +* Fixed: Security issue (thanks to Pierre Rudloff).
108 153
109 -Passster is simple to install:
154 += 4.3.6 - 23.07.2026 =
155 +* Added: "Show Password" label is now customizable from the General settings tab.
156 +* Fixed: Per-page form text being used even when "Overwrite Defaults" is disabled.
157 +* Fixed: Instruction text showing as garbled characters when using the Protected Area block.
158 +* Fixed: Security issues (thanks to Revanth Hari Narayana Matte).
110 159
111 -1. Download the .zip'
112 -1. Unzip
113 -1. Upload the directory to your '/wp-content/plugins' directory
114 -1. Go to the plugin management page and enable the Passster Plugin
115 -1. Browse to Settings > Passster
116 -1. Customise your settings and your good to go!
160 += 4.3.5 - 02.06.2026 =
161 +* Fixed: hCaptcha cookie not being recognized on subsequent page loads.
162 +* Fixed: Unlock links with special characters in instructions could cause encoding errors.
163 +* Fixed: Pass parameter being lost during global protection redirect.
117 164
118 -== Changelog ==
165 += 4.3.4 - 08.05.2026 =
166 +* Fixed: Replaced non-functional license activation button on free version with installation guide for Passster PRO.
167 +* Fixed: Category lock not showing password form on regular post category archive pages.
119 168
169 += 4.3.3 - 03.04.2026 =
170 +* Changed: Enhance PS_Rest_Handler to allow public access to additional Passster endpoints for guest users.
171 +
172 += 4.3.2 - 30.03.2026 =
173 +* Fixed: Category lock for WooCommerce products and categories.
174 +* Changed: Page refresh on unlock is now on by default. Inline unlock can be enabled via Advanced → Unlock Behaviour.
175 +
176 += 4.3.1 - 20.03.2026 =
177 +* Fixed: Password label should not be visible, it's there for accessibility reasons.
178 +* Fixed: Password label is now translatable.
179 +* Fixed: Missing loading animation.
180 +
181 += 4.3.0 - 20.03.2026 =
182 +* Changed: Refactor settings display and added statistics page.
183 +* Added: Category lock.
184 +* Added: Passter Protected Area Gutenberg wrapper block.
185 +
186 += 4.2.29 - 12.02.2026 =
187 +* Fixed: Password validation and unlock link generation failing when the password contains the % character.
188 +
189 += 4.2.28 - 02.02.2026 =
190 +* Fixed: Nonce validation failing for logged-in users when fetched via REST endpoint.
191 +
192 += 4.2.27 - 27.01.2026 =
193 +* Fixed: Prevent nonce from being cached.
194 +* Fixed: Page protect children option.
195 +
196 += 4.2.26 - 16.01.2026 =
197 +* Fixed: Security update
198 +
199 += 4.2.25 - 14.01.2026 =
200 +* Fixed: Passster protected events do not show up in The Events Callendar REST requests.
201 +* Changed: Prevent nonce from being cached.
202 +* Fixed: Security update
203 +
204 += 4.2.24 - 12.01.2026 =
205 +* Fixed: Vulnerability in passster shortcode.
206 +* Fixed: Fix allowing hashed in unlocking page url.
207 +
208 += 4.2.23 - 08.01.2026 =
209 +* Fixed: Bug preventing password validation.
210 +
211 += 4.2.22 - 05.01.2026 =
212 +* Fixed: Vulnerability in passster shortcode.
213 +
214 += 4.2.21 - 18.12.2025 =
215 +* Fixed: Vulnerability in passster shortcode.
216 +
217 += 4.2.20 - 22.10.2025 =
218 +* Fixed: Security update
219 +
220 += 4.2.19 - 02.10.2025 =
221 +* Fixed: Vulnerability in passster shortcode.
222 +
223 += 4.2.18 - 15.09.2025 =
224 +* Added: null alt attribute to ps-loader image for better accessibility compliance.
225 +* Changed: Made password form input IDs unique per protected area to prevent duplicate IDs when using multiple forms on the same page.
226 +
227 += 4.2.17 - 22.07.2025 =
228 +* Fixed: Users with allowed roles can now access other pages when global restriction is active and the password page is excluded for them.
229 +
230 += 4.2.16 - 09.07.2025 =
231 +* Changed: Allow HTML & shortcodes in instructions.
232 +
233 += 4.2.15 - 17.03.2025 =
234 +* Added: Support for Turnstile captcha.
235 +
236 += 4.2.14 - 25.02.2025 =
237 +* Fixed: Unlock link was not working properly.
238 +
239 += 4.2.13 - 03.02.2025 =
240 +* Fixed: Global protection page was not being protected even if "Activate Protection" was on.
241 +
242 += 4.2.12 - 20.12.2024 =
243 +* Changed: Security update - Updated Freemius SDK
244 +
245 += 4.2.10 - 11.12.2024 =
246 +* Changed: Updated upsells information
247 +
248 += 4.2.9 - 10.12.2024 =
249 +* Added: Settings upsells
250 +
251 += 4.2.8 - 06.12.2024 =
252 +* Changed: Readme update
253 +
254 += 4.2.7 =
255 +
256 +* WP 6.7 compatibility
257 +* dependency updates
258 +* PHP 8.3 compatibility
259 +* make headline removable via design settings
260 +* default tag for headlines is now <span> for SEO purposes
261 +* fixed expiration with cookie usage (pro-only)
262 +
263 += 4.2.6.6 =
264 +
265 +* WP 6.6 compatiblity
266 +* latest dependencies for the block editor
267 +* fixed missing default value breaking design settings
268 +* latest Freemius SDK upgrade
269 +
270 += 4.2.6.5 =
271 +
272 +* improved expiration for passwords with unlock links
273 +* fixed escaping for redirect parameter
274 +* several security improvements
275 +* updated to 6.5 compatibility
276 +
277 += 4.2.6.4 =
278 +
279 +* exclude pagebuilders from rest restriction (frontend editing)
280 +
281 += 4.2.6.3 =
282 +
283 +* fixed components for WP 6.4.3 release (margin/radius)
284 +* restrict Rest API access with global protection
285 +
286 += 4.2.6.2 =
287 +
288 +* added exception for sanitized array setting (exclude pages)
289 +
290 += 4.2.6.1 =
291 +
292 +* added hook to combine generated password with order
293 +* improved sanitization on importer
294 +* added russian + ukrainian translation
295 +* SDK upgrade
296 +
297 += 4.2.6 =
298 +
299 +* WordPress 6.4 compatibility
300 +
301 += 4.2.5 =
302 +
303 +* WooCommerce email trigger after status complete
304 +* added filter for generated password
305 +* protected page optional for WooCommerce integration
306 +* improved admin UI contrasts
307 +* restructured design settings
308 +
309 += 4.2.4 =
310 +
311 +* WP 6.3 compatibility
312 +
313 += 4.2.3 =
314 +
315 +* some Freemius integration improvements
316 +
317 += 4.2.2 =
318 +
319 +* improved logout button markup
320 +* added action after validating password list hash
321 +* Freemius SDK update to 2.5.10
322 +
323 += 4.2.1 =
324 +
325 +* improved admin UI with permanent sidebar
326 +* improved value handling for margin/padding to avoid PHP notices
327 +* added filter to validate payment before sending e-mail (pro-only)
328 +
329 += 4.2 =
330 +
331 +* selling and generating passwords with WooCommerce (pro-only)
332 +* assign and manage multiple passwords lists (pro-only)
333 +* hotfix editing areas with Oxygen Builder
334 +* helper methods to automatically generate and add passwords to lists
335 +* statistics for password usage + custom database table
336 +* expiration statistics for passsword lists
337 +* fixed area shortcode inspector controls
338 +* GPDR friendly tracking implementation
339 +
340 += 4.1.4 =
341 +
342 +* reverted hcaptcha integration
343 +* updated admin links to new URL structure
344 +* fixed expiration settings with new encryption
345 +* fixed PHP notice if reCaptcha doesn't return a response
346 +
347 += 4.1.3.1 =
348 +
349 +* v4 API integration for Bit.ly
350 +
351 += 4.1.3 =
352 +
353 +* fixed conditional for unlock links
354 +* support for additional URL parameters in cache friendly URLs
355 +* prevent multiple renders in quick edit
356 +* hcaptcha with checkbox
357 +* removed default margin from CSS
358 +* copy shortcode with fallback for Block Editor
359 +* removed deprecated compatibility method
360 +
361 += 4.1.2 =
362 +
363 +* fallback solution to get post id in classic editor
364 +* fixed saving meta data in classic editor
365 +* compatibility with disable gutenberg plugin
366 +
367 += 4.1.1 =
368 +
369 +* fixed regex pattern in deprecated shortcode
370 +* removed regex pattern for captcha as the feature no longer exists
371 +
372 += 4.1 =
373 +
374 +* protect child pages
375 +* quick edit and bulk edit pages/posts for protection (pro-only)
376 +* hCaptcha protection (pro-only)
377 +* preventing PHP notices with concurrent usage and recaptcha
378 +* better dynamics for admin column + less intrusive styling
379 +
380 += 4.0.1 =
381 +
382 +* fixed reCAPTCHA selection not saving in admin
383 +* improved fallback margin/padding for protection block
384 +* improved description of the unlock mode to make it easier to understand
385 +
386 += 4.0 =
387 +
388 +* entirely new admin UI rewritten with React
389 +* custom block to select areas
390 +* ability to generate passwords
391 +* improved global protection UI
392 +* ability to exlude pages from global protection
393 +* on-the-fly unlock link generation
394 +
395 += 3.5.5.7 =
396 +
397 +* modified Freemius prefix to prevent compatibility errors with Post SMTP plugin
398 +
399 += 3.5.5.6 =
400 +
401 +* fixed Elementor integration with areas.
402 +
403 += 3.5.5.5.2 =
404 +
405 +* improved fallback solution to convert base64 to hmac
406 +* changed validation priority: cookies - links - post data for quicker validation
407 +
408 += 3.5.5.5.1 =
409 +
410 +* integrated converter to automatically convert old link encryption to new hashed encryption
411 +* fixed missing hash_nonce value in wp_localize_scripts
412 +
413 += 3.5.5.5 =
414 +
415 +* dynamic version number for cache busting after update
416 +* new encryption for encrypted links
417 +* cleared up upgrade/activation code
418 +* includes + load_textdomain in plugins_loaded
419 +* fixed task priority with global protection and redirect
420 +* fixed ReCaptcha v2 validation and content return statement
421 +* better default settings
422 +
423 +
424 += 3.5.5.4 =
425 +
426 +* improved hmac validation with cookies
427 +* fixed reload in combination with global page protection
428 +* introduced a unique secret key per installation
429 +* reverted Rest API implementation and used Ajax instead
430 +
431 += 3.5.5.3.1 =
432 +
433 +* fix for captcha/recaptcha validation with hew hmac encryption
434 +
435 += 3.5.5.3 =
436 +
437 +* fixed escaping area id in shortcode
438 +* implemented concurrent logins feature
439 +* encryption for cookies with unique secret key (hmac)
440 +* dedicated ajax class to handle validation
441 +* Rest API implementation for password encryption
442 +* general code cleanup (better performance + improved doc blocks)
443 +* consistent singletone pattern for all classes
444 +* better check for areas and full page protection (improved security)
445 +* latest freemius SDK
446 +* improved cookie-js implementation with sameSite attributes
447 +* fixed logo font rendering
448 +
120 449 = 3.5.5.2 =
121 450
122 451 * filter to disable base64 encryption for cookies and links
123 452 * Freemius SDK update
@@ -602,4 +931,9 @@
602 931 Added required images for JQuery UI theme and fixed some i18n strings.
603 932
604 933 = 1.0 =
605 934 Initial release.
935 +
936 +== Upgrade Notice ==
937 +
938 += 4.2.13 =
939 +This resolved an issue with the "Activate Protection" option set for the Global protection page.