PluginProbe ʕ •ᴥ•ʔ
Anti-Malware Security and Brute-Force Firewall / 4.21.89
Anti-Malware Security and Brute-Force Firewall v4.21.89
4.23.90 trunk 1.2.03.23 1.3.02.15 3.07.06 4.14.47 4.15.16 4.16.17 4.17.28 4.17.29 4.17.44 4.17.57 4.17.58 4.17.68 4.17.69 4.18.52 4.18.62 4.18.63 4.18.69 4.18.71 4.18.74 4.18.76 4.19.44 4.19.50 4.19.68 4.19.69 4.20.59 4.20.72 4.20.92 4.20.93 4.20.94 4.20.95 4.20.96 4.21.74 4.21.83 4.21.84 4.21.85 4.21.86 4.21.87 4.21.88 4.21.89 4.21.90 4.21.91 4.21.92 4.21.93 4.21.94 4.21.95 4.21.96 4.23.56 4.23.57 4.23.67 4.23.68 4.23.69 4.23.71 4.23.73 4.23.77 4.23.81 4.23.83 4.23.85 4.23.87 4.23.88 4.23.89
gotmls / readme.txt
gotmls Last commit date
images 3 years ago languages 3 years ago safe-load 3 years ago index.php 3 years ago readme.txt 3 years ago
readme.txt
540 lines
1 === Anti-Malware Security and Brute-Force Firewall ===
2 Plugin URI: https://gotmls.net/
3 Author: Eli Scheetz
4 Author URI: http://wordpress.ieonly.com/category/my-plugins/anti-malware/
5 Contributors: gotmls, scheeeli
6 Donate link: https://gotmls.net/donate/
7 Tags: security, firewall, anti-malware, scanner, automatic, repair, remove, malware, virus, threat, hacked, malicious, infection, timthumb, exploit, block, brute-force, wp-login, patch, antimalware, revslider, Revolution Slider
8 Version: 4.21.89
9 Stable tag: 4.21.89
10 Requires at least: 3.3
11 Tested up to: 6.1.1
12
13 This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.
14
15 == Description ==
16
17 **Features:**
18
19 * Download Definition Updates to protect against new threats.
20 * Run a Complete Scan to automatically remove known security threats, backdoor scripts, and database injections.
21 * Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins with known vulnerabilites.
22 * Upgrade vulnerable versions of timthumb scripts.
23
24 **Premium Features:**
25
26 * Patch your wp-login and XMLRPC to block Brute-Force and DDoS attacks.
27 * Check the integrity of your WordPress Core files.
28 * Automatically download new Definition Updates when running a Complete Scan.
29
30 Register this plugin at [GOTMLS.NET](http://gotmls.net/) and get access to new definitions of "Known Threats" and added features like Automatic Removal, plus patches for specific security vulnerabilities like old versions of timthumb. Updated definition files can be downloaded automatically within the admin once your Key is registered. Otherwise, this plugin just scans for "Potential Threats" and leaves it up to you to identify and remove the malicious ones.
31
32 NOTICE: This plugin make call to GOTMLS.NET to check for updates not unlike what WordPress does when checking your plugins and themes for new versions. Staying up-to-date is an essential part of any security plugin and this plugin can let you know when there are new plugin and definition update available. If you're allergic to "phone home" scripts then don't use this plugin (or WordPress at all for that matter).
33
34 **Special thanks to:**
35
36 * Clarus Dignus for design suggestions and graphic design work on the banner image.
37 * Jelena Kovacevic and Andrew Kurtis of webhostinghub.com for providing the Spanish translation.
38 * Marcelo Guernieri for the Brazilian Portuguese translation.
39 * Umut Can Alparslan for the Turkish translation.
40 * [Micha Cassola](https://profiles.wordpress.org/michacassola/) for the German translation.
41 * [Robi Erwin Setiawan](https://profiles.wordpress.org/situstarget/) for the Indonesian translation.
42
43 == Installation ==
44
45 1. Download and unzip the plugin into your WordPress plugins directory (usually `/wp-content/plugins/`).
46 1. Activate the plugin through the 'Plugins' menu in your WordPress Admin.
47 1. Register on gotmls.net and download the newest definition updates to scan for Known Threats.
48
49 == Frequently Asked Questions ==
50
51 = Why should I register? =
52
53 If you register on [GOTMLS.NET](http://gotmls.net/) you will have access to download definitions of New Threats and added features like automatic removal of "Known Threats" and patches for specific security issues like old versions of timthumb and brute-force attacks on wp-login.php. Otherwise, this plugin only scans for "Potential Threats" on your site, it would then be up to you to identify the good from the bad and remove them accordingly.
54
55 = How do I patch the Revolution Slider vulnerability? =
56
57 Easy, if you have installed and activated my this Anti-Malware plugin on your site then it will automatically block attempts to exploit the Revolution Slider vulnerability.
58
59 = How do I patch the wp-login vulnerability? =
60
61 The WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. This plugin can apply a patch that will block access to the WordPress Login page whenever this type of attack is detected. Just click the Install Patch button under Brute-force Protection on the Anti-Malware Setting page. For more information on this subject [read my blog](http://gotmls.net/tag/wp-login-php/).
62
63 = Why can't I automatically remove the "Potential Threats" in yellow? =
64
65 Many of these files may use eval and other powerful PHP function for perfectly legitimate reasons and removing that code from the files would likely cripple or even break your site so I have only enabled the Auto remove feature for "Know Threats".
66
67 = How do I know if any of the "Potential Threats" are dangerous? =
68
69 Click on the linked filename to examine it, then click each numbered link above the file content box to highlight the suspicious code. If you cannot tell whether or not the code is malicious just leave it alone or ask someone else to look at it for you. If you find that it is malicious please send me a copy of the file so that I can add it to my definition update as a "Know Threat", then it can be automatically removed.
70
71 = What if the scan gets stuck part way through? =
72
73 First just leave it for a while. If there are a lot of files on your server it could take quite a while and could sometimes appear to not be moving along at all even if it really is working. If it still seems stuck after a while then try running the scan again, be sure you try both the Complete Scan and the Quick scan.
74
75 = How did I get hacked in the first place? =
76
77 First, don't take the attack personally. Lots of hackers routinely run automated script that crawl the internet looking for easy targets. Your site probably got hacked because you are unknowingly an easy target. This might be because you are running an older version of WordPress or have installed a Plugin or Theme with a backdoor or known security vulnerability. However, the most common type of infection I see is cross-contamination. This can happen when your site is on a shared server with other exploitable sites that got infected. In most shared hosting environments it's possible for hackers to use an one infected site to infect other sites on the same server, sometimes even if the sites are on different accounts.
78
79 = What can I do to prevent it from happening again? =
80
81 There is no sure way to protect your site from every kind of hack attempt. That said, don't be an easy target. Some basic steps should include: hardening your password, keeping all your sites up-to-date, and run regular scans with Anti-Malware software like [GOTMLS.NET](http://gotmls.net/)
82
83 = Why does sucuri.net or the Google Safe Browsing Diagnostic page still say my site is infected after I have removed the malicious code? =
84
85 sucuri.net caches their scan results and will not refresh the scan until you click the small link near the bottom of the page that says "Force a Re-scan" to clear the cache. Google also caches your infected pages and usually takes some time before crawling your site again, but you can speed up that process by Requesting a Review in the Malware or Security section of [Google Webmaster Tools](https://www.google.com/webmasters/tools/). It is a good idea to have a Webmaster Tools account for your site anyway as it can provide lots of other helpful information about your site.
86
87 == Screenshots ==
88
89 1. The menu showing Anti-Malware options.
90 2. The Scan Setting page in the admin.
91 3. An example scan that found some threats.
92 4. The results window when "Automatic Repair" fixes threats.
93 5. The Quarantine showing threats that have been fix already.
94
95 == Changelog ==
96
97 = 4.21.89 =
98 * Added more late escapes and sanitizated all _SERVER variables.
99 * Checked code for compatibility with ClassicPress 1.5.0.
100
101 = 4.21.88 =
102 * Added late escapes to variables that were already escaped as requested by Code review team.
103 * Fixed a PHP warning about is_dir when it attempts check the existance of a directory that was scanned in the past but is now outside the allowable scan path.
104
105 = 4.21.87 =
106 * Code review and cleanup, added more sanitization.
107 * Fixed an error when attempting to unserialize an array.
108
109 = 4.21.86 =
110 * Improved the removal of database injections when values are serialized.
111 * Fixed a vulnerability in using unserialize with Class Objects.
112 * Fixed PHP warnings about undefined indexes.
113
114 = 4.21.85 =
115 * Prevented infinite looping on recursive sub-directories.
116 * Changed some default values.
117 * Checked code for compatibility with WordPress 6.1.1 and ClassicPress 1.4.4.
118
119 = 4.21.84 =
120 * Removed the no_error_reporting option used for debugging when server errors are breaking the site.
121 * Checked code for compatibility with WordPress 6.0.2 and ClassicPress 1.4.2.
122
123 = 4.21.83 =
124 * Fixed XSS vulnerability on debug URLs introduced in the last release, thanks Erwan Le Rousseau.
125 * Updated code with other various minor improvements bug fixed.
126 * Checked code for compatibility with WordPress 6.0.1 and ClassicPress 1.4.2.
127
128 = 4.21.74 =
129 * Updated code with various minor improvements to efficiency and compatibility.
130 * Checked code for compatibility with WordPress 6.0.
131
132 = 4.20.96 =
133 * Fixed XSS vulnerability by removing unsanitized QUERY_STRING.
134 * Cleaned up Quarantine code, removing legacy functions and adding more detailed info.
135 * Fixed undefined variable notice and checked code for compatibility with WordPress 5.9.2.
136
137 = 4.20.95 =
138 * Added more sanitization and validation to all user data entered for better security.
139 * checked code for compatibility with WordPress 5.9.
140
141 = 4.20.94 =
142 * Fixed an XSS vulnerability and checked code for compatibility with WordPress 5.8.3.
143
144 = 4.20.93 =
145 * Fixed undefined variable warning.
146 * Updated code for compatibility with PHP version 8.0.
147
148 = 4.20.92 =
149 * Added German translation thanks to Micha Cassola.
150 * Improved the Apache software version checker for better firewall compatibility.
151 * Fixed session compatibility that was conflicting with the REST API check in Site Health.
152 * Checked code for compatibility with WordPress 5.8.1 and ClassicPress 1.3.1.
153
154 = 4.20.72 =
155 * Updated registration form to be more compatible with newer iframe restrictions.
156 * Fixed session check on the Brute-Force patch to no longer need mod_rewrite.
157 * Removed older code from WordPress Repository.
158
159 = 4.20.59 =
160 * Various minor bug fixes.
161 * Added Core Files Definitions for ClassicPress.
162 * Tweaked code for better compatibility with WordPress 5.7.2 and ClassicPress 1.2.0.
163
164 = 4.19.69 =
165 * Fixed a JavaScript error caused by a new French translation.
166 * Checked code for compatibility with WordPress 5.4.1.
167
168 = 4.19.68 =
169 * Updated some external links.
170 * Tweaked code for better compatibility with PHP 7.4 and WordPress 5.4.
171
172 = 4.19.50 =
173 * Added even more error handling to the DB Scan for servers with the PHP memory_limit set too low.
174 * Modified the Directory Scan Depth to accept 0 as a value to indicate skipping the Directory Scan (use this to focus on the DB Scan).
175 * Added some Help tips to some of the options on the Settings page.
176
177 = 4.19.44 =
178 * Updated links to use HTTPS by default and fixed some old URLs.
179 * Various performance improvements.
180 * Added more error handling to the DB Scan.
181 * Fixed a few minor bugs causing PHP Notices.
182 * Fixed a path search to work on Windows servers.
183 * Tweaked code for compatibility with WP 5.3 (latest release).
184
185 = 4.18.76 =
186 * Cleaned up the Nonce Token creation and storage functions.
187 * Cleaned up View Quarantine page and fixed recovery link.
188 * Added debugging for login errors WP head and footer Hooks.
189
190 = 4.18.74 =
191 * Fixed a bug in the Nonce Token Errors that was created by changes in the last release.
192
193 = 4.18.71 =
194 * Added wp_options table to the db_scan.
195 * Fixed a few minor bugs in the db scan quarantine view.
196 * Changed some wording and other minor fomatting issues.
197 * Checked code for compatibility with WP 5.2.1 (latest release).
198
199 = 4.18.69 =
200 * Added a Warning message about the vulnerability in the yuzo-related-post plugin.
201 * Updated the Quarantine interface and added a re-scan / re-clean feature.
202 * Fixed a bug in the scan depth array that would produce PHP Notices in the error_log files under certain conditions.
203 * Changed some wording and other minor fomatting issues.
204 * Removed some outdated JavaScript that is no longer needed.
205 * Checked code for compatibility with WP 5.2 (latest release).
206
207 = 4.18.63 =
208 * Fixed a major bug in the Firewall updates that could cause a False Positive lockout.
209
210 = 4.18.62 =
211 * Fixed a bug in the Firewall that prevented some iPad devices from logging in.
212 * Fixed an encoding bug that prevented the Examine File window from dispaying some file formats.
213 * Restored the File Details window in the Examine File window.
214 * Updated code for compatibility with WP 5.1.1 (latest release).
215
216 = 4.18.52 =
217 * Added a whole new DB Scan category that looks for links and scripts injected directly into the database content and removes them.
218 * Updated Firewall landing page for HTTPS compatibility.
219 * Removed some old code that was no longer needed.
220 * Added a feature to clear cache files before running the Complete Scan, this will speed up the scan and prevent malware from being saved on your cached paged.
221 * Updated code for compatibility with WP 5.0.2 (latest release).
222
223 = 4.17.69 =
224 * Updated code for compatibility with WP 4.9.8 (latest release).
225 * Fixed PHP Notice for the unknown offset of SERVER_parts.
226 * Escaped single-quotes in translated strings for use within JavaScript.
227
228 = 4.17.68 =
229 * Updated code for compatibility with WP 4.9.7 (latest release).
230 * Removed wrong size dashicon from Settings link in plugin list.
231 * Removed the broken link to vote WORKS on wordpress.org.
232 * Reordered priorety on fixing Known Threats to be more efficient.
233
234 = 4.17.58 =
235 * Updated code for compatibility with WP 4.9.4 (latest release).
236 * Fixed dashicons sizing in css.
237 * Add ability to update registration email from within the plugin settings.
238 * Cleaned up expired nonce tokens left behind from an older version.
239
240 = 4.17.57 =
241 * Updated code for compatibility with WP 4.9.3 (latest release).
242 * Fixed registration form and alternate domain for definition updates to work on HTTPS.
243 * Fixed the wording on the Title check error message.
244
245 = 4.17.44 =
246 * Added Title check to make sure it does say you were hacked.
247 * Updated code for compatibility with WP 4.8.3 (latest release).
248 * Fixed Undefined variable error in Quarantine.
249 * Fixed XSS vulnerability in nonce error output.
250
251 = 4.17.29 =
252 * Changed the definition update URL to only use SSL when required.
253 * Updated PayPal form for better domestic IPN compatibility.
254
255 = 4.17.28 =
256 * Added the Turkish translation thanks to Umut Can Alparslan.
257 * Improved the auto update so that old definitions could be phased out and new threat types would be selected by default.
258 * Fixed the admin username change feature on multisite installs.
259 * Fixed the details window so that it scrolls to the highlighted code.
260 * Set defaults to disable the Potential Threat scan if other threats definitions are enabled.
261 * Encoded definitions array for DB storage.
262 * Fixed syntax error in the XMLRPC patch for newer versions of Apache.
263 * Added fall-back to manual updates if the Automatic update feature fails.
264 * Fixed PHP Notices about undefined variable added in last Version release.
265 * Improved Apache version detection.
266 * Changed Automatic update feature to automatically download all definitions and firewall updates.
267 * Added PHP and Apache version detections and changed the XMLRPC patch to work with Apache 2.4 directives.
268 * Removed the onbeforeunload function because Norton detected it as a False Positive.
269 * Removed code that was deprecated in PHP Version 7.
270 * Fixed PHP Notice about an array to string conversion with some rare global variable conditions.
271 * Added more firewall options.
272 * Moved Scan Log from the Quarantine page to the main Setings page.
273 * Fixed PHP Warning about an invalid argument in foreach and some other bugs too.
274 * Fixed "What to look for" Options so that changes are saved.
275 * Changed get_currentuserinfo to wp_get_current_user because the get_currentuserinfo function was deprecated in WP 4.5
276
277 = 4.16.17 =
278 * Removed Menu Item Placement Options because the add_object_page function was deprecated in WP 4.5.
279 * Added firewall options for better compatibility with WP Firewall 2.
280 * Fixed an XSS vulnerability in the debug output of the nonce token.
281 * Moved the Firewall Options to it's own page linked to from the admin menu.
282 * Moved the Quick Scan from the admin menu to the top of the Scan Settings page.
283 * Fixed PHP Warning about in_array function expecting parameter 2 to be an array, found by Georgey B.
284 * Made a few minor cosmetic changes and fixed a few other small bugs in the interface.
285 * Fixed the Nonce Token error caused by W3 Total Cache breaking the set_transient function in WordPress.
286 * Added the Brazilian Portuguese language files, thanks to Marcelo Guernieri for the translation.
287 * Fixed the admin menu and also some links that did not work on Windows server.
288 * Added Core Files to the Quick Scan list on the admin menu.
289 * Added a nonce token to prevent Cross-Site Request Forgery by admins who are logged-in from another site.
290 * Hardened against XSS vulnerability triggered by the file names being scanned (thanks to Mahadev Subedi).
291 * Improved brute-force patch compatibility with alternate wp-config.php location.
292 * Had to remove the encoding of the Default Definitions to meet the WordPress Plugin Guidelines.
293 * Improved the JavaScript in the new Brute-Force login patch so that it works with caching enabled on the login page.
294 * Improved the Brute-Force login patch with custom fields and JavaScript.
295 * Added a Save button to that Scan Settings page.
296 * Fixed a bug in the XMLRPC Patch "Unblock" feature.
297 * Added a link to purge the deleted Quarantine items from the database.
298 * Added firewall option to Block all XMLRPC calls.
299 * Fixed a few cosmetic bugs in the quarantine and firewall options.
300 * Fixed a bugs in the Quarantine that was memory_limit errors if there number of files in the was too high.
301 * Added the highlight malicious code feature back to the Quarantine file viewer.
302 * Added the ability to change the admin username if the current username is "admin".
303 * Improved the code in the Brute-Force Protection patch.
304 * Fixed a few bugs in the Core Files Check that was preventing it from fixing some unusual file modifications.
305 * Fixed a major bug that made multisite scan extremely slow and sometimes error out.
306 * Moved all ajax call out of the init function and into their own functions for better handling time.
307 * Moved the quarantine files into the database and deleted the old directory in uploads.
308 * Fixed some minor formatting issues in the HTML output on the settings page.
309 * Added a warning message if base64_decode has been disabled.
310 * Hardened against injected HTML content by encoding the tags with variables.
311 * Fixed debug option to exclude individual definitions.
312 * Hardened admin_init with current_user_can and realpath on the quarantine file deletion (thanks to J.D. Grimes).
313 * Fixed another XSS vulnerabilities in the admin (thanks to James H.)
314 * Hardened against XSS vulnerabilities in the admin (thanks to Tim Coen).
315 * Added feature to restore default settings for Exclude Extensions.
316 * Changed the encoding on the index.php file in the Quarantine to make it more human-readable.
317 * Fixed a few small bugs that were throwing PHP Notices in some configurations and added more info to some error messages.
318 * Extended execution_time during the Fix process to increase the number of files that could be fixed at a time.
319 * Added a Quarantine log to the database.
320 * Fixed a couple of minor bugs that would throw PHP notices.
321
322 = 4.15.16 =
323 * Created an automatic update feature that downloads any new definition updates before starting the scan.
324 * Added WordPress Core files to the new definitions update process and included a scan option to check the integrity of the Core files.
325 * Automatically whitelisted the unmodified WordPress Core files.
326 * Made more improvements to the Brute-Force protection patch and other minor cosmetic changes to the interface.
327 * Protected the HTML in my plugin from filter injections and fixed a few other minor bugs.
328 * Fixed a problem with deleting files from the Quarantine folder.
329 * Added a descriptive reason to the error displayed if the fix was unsuccessful.
330 * Added link to restore the default location of the Examine Results window.
331 * Improved the encoding of definition updates so that they would not be blocked by poorly written firewall rules.
332 * Suppressed the "Please make a donation" nag if the fix was unsuccessful, to avoid confusion over premium services.
333 * Removed debug alert from initial session check.
334 * Improved rewrite compatibility of session check for the Brute-Force Protection Installation.
335 * Improved session check for the option to Install Brute-Force Protection and added an error message on failure.
336 * Improved support for Multisite by only allowing Network Admins access to the Anti-Malware menu.
337 * Added link to view a simple scan history on the Quarantine page.
338 * Updated firewall to better protect agains new variations of the RevSlider Exploit.
339 * Improved check for session support before giving the option to Install Brute-Force patch.
340 * Added option to skip scanning the Quarantined files.
341 * Updated Brute-Force patch to fix the problem of being included more that once.
342 * Fixed a few minor bugs (better window positioning and css, cleaner results page, updated new help tab, etc.).
343 * Made sure that the plugin does not check my servers for updates unless you have registered (this opt-in requirement is part of the WordPress Repository Guidelines).
344 * Added exception for the social.png files to the skip files by extension list.
345 * Fixed removal of Known Threats from files in the Quarantine directory.
346 * Block SoakSoak and other malware from exploiting the Slider Revolution Vulnerability (THIS IS A WIDESPREAD THREAT RIGHT NOW).
347 * Enabled the Brute-Force protection option directly from the Settings page.
348 * Fixed window position to auto-adjust on small screens.
349
350 = 4.14.47 =
351 * Major upgrade to the protection for wp-login.php Brute-Force attempts.
352 * Fixes a bug in setting the permissions for read-only files so that they could still be cleaned.
353 * Fixes a minor bug with pass-by-reference which raises a fatal error in PHP v5.4.
354 * Enhanced the Examine File window with better styles and more info.
355 * Changed form submission of encrypted file lists to array values instead of keys.
356 * Fixes other minor bugs.
357 * Made the Examine File window sizable.
358 * Fixed a few small bugs and removed some old code.
359 * Added a link to my new twitter account.
360 * Re-purposed Quick Scan to just scan the most affected areas.
361 * Set the registration form to display by defaulted in the definition update section.
362 * Fixed a few small bugs in advanced features and directory depth determination.
363 * Fixed a session bug to display the last directory scanned.
364 * Fixed a few small cosmetic bugs for WP 3.8.
365 * Added Spanish translation, thanks to Jelena Kovacevic and Andrew Kurtis at webhostinghub.com.
366 * Updated string in the code and added a .pot file to be ready for translation into other languages.
367 * Added "Select All" checkbox to Quarantine and a new button to delete items from the Quarantine.
368 * Added a trace.php file for advanced session tracking.
369 * Fixed undefined index bug with menu_group item in settings array.
370 * Added support for multisite network admin menu and the ability to restrict admin access.
371 * Fixed a session bug in the progress bar related to the last release.
372 * Fixed a session bug that conflicted with jigoshop. (Thanks dragonflyfla)
373 * Fixed a few bug in the Whitelist definition feature.
374
375 = 3.07.06 =
376 * Added SSL support for definition updates and registration form.
377 * Upgraded the Whitelist feature so the it could not contain duplicates.
378 * Downgraded the WP-Login threat and changed it to an opt-in fix.
379 * Fixed a bug in the Add to Whitelist feature so the you do not need to update the definitions after whitelisting a file.
380 * Added ability to whitelist files.
381 * Fixed a major bug in yesterdays release broke the login page on some sites.
382 * Added a patch for the wp-login.php brute force attack that has been going around.
383 * Created a process to restore files from the Quarantine.
384 * Fixed a few other small bugs including path issues on Winblows server.
385
386 = 1.3.02.15 =
387 * Improved security on the Quarantine directory to fix the 500 error on some servers.
388 * Fixed count of Quarantined items.
389 * Added htaccess security to the Uploads directory.
390 * Linked the Quarantined items to the File Examiner.
391 * Added a scan category for Backdoor Scripts.
392 * Consolidated the Definition Types and added a Whitelist category.
393 * Completely redesigned the Definition Updates to handle incremental updates.
394 * Added "View Quarantine" to the menu.
395 * Enhanced Output Buffer to work with compression enabled (like ob_gzhandler).
396 * Moved the quarantine to the uploads directory to protect against blanket inclusion.
397 * Fixed Output Buffer issue for when ob_start has already been called.
398 * Enhanced the Automatic Fix process to handle bad directory permissions.
399 * Added more detailed error messages for different types of file errors.
400 * Improved overall error handling.
401 * Minor UI enhancements and a few bug fixes.
402 * Completely revamped the scan engine to handle large file systems with better error handling.
403 * Enhanced the results for the Automatic Fix process.
404 * Fixed a few other small bugs.
405 * Enhanced the iFrame for the File Viewer and Automatic Fix process.
406 * Improved error handling during the scan.
407 * Moved the File Viewer and Automatic Fix process into an iFrame to decrease scan time and memory usage.
408 * Enhanced the Automatic Fix process for better success with read-only files.
409 * Improved code cleanup process and general efficiency of the scan.
410 * Encoded definition update for better compatibility with some servers that have post limitation.
411 * Fixed XSS vulnerability.
412 * Changed registration to allow for multiple sites/keys to be registered under one user/email.
413 * Changed auto-update path to update threat level array for all new definition updates.
414 * Updated timthumb replacement patch to version 2.8.10 per WordPress.org plugins requirement.
415 * Fixed option to exclude directories so that the scan would not get stuck if omitted.
416 * Added support for winblows servers using BACKSLASH directory structures.
417 * Changed definition updates to write to the DB instead of a file.
418
419 = 1.2.03.23 =
420 * First versions available for WordPress (code removed, no longer compatible).
421
422 == Upgrade Notice ==
423
424 = 4.21.89 =
425 Added more late escapes and sanitizated all _SERVER variables and checked code for compatibility with ClassicPress 1.5.0.
426
427 = 4.21.88 =
428 Added late escapes to variables that were already escaped as requested by Code review team and fixed a PHP warning about is_dir.
429
430 = 4.21.87 =
431 Code review and cleanup, added more sanitization and fixed an error when attempting to unserialize an array.
432
433 = 4.21.86 =
434 Improved the removal of database injections when values are serialized, and fixed a vulnerability in using unserialize with Class Objects, as well as some other PHP warnings about undefined indexes.
435
436 = 4.21.85 =
437 Prevented infinite looping on recursive sub-directories and checked code for compatibility with WordPress 6.1.1 and ClassicPress 1.4.4.
438
439 = 4.21.84 =
440 Removed the no_error_reporting debug option and checked compatibility with WordPress 6.0.2 and ClassicPress 1.4.2.
441
442 = 4.21.83 =
443 Fixed XSS vulnerability, plus other minor improvements and compatibility with WordPress 6.0.1 and ClassicPress 1.4.2.
444
445 = 4.21.74 =
446 Updated code with various minor improvements to efficiency and compatibility with WordPress 6.0.
447
448 = 4.20.96 =
449 Fixed XSS vulnerability by removing unsanitized QUERY_STRING, cleaned up Quarantine code, and checked code for compatibility with WordPress 5.9.2.
450
451 = 4.20.95 =
452 Added more sanitization and validation to all user data entered for better security and checked code for compatibility with WordPress 5.9.
453
454 = 4.20.94 =
455 Fixed an XSS vulnerability and checked code for compatibility with WordPress 5.8.3.
456
457 = 4.20.93 =
458 Fixed undefined variable warning and updated code for compatibility with PHP version 8.0.
459
460 = 4.20.92 =
461 Added German translation, improved firewall compatibility with Apache, fixed session check in Site Health for REST API compatibility, and checked code compatibility with WordPress 5.8.1 and ClassicPress 1.3.1.
462
463 = 4.20.72 =
464 Updated registration form, fixed session check, and removed older code from WordPress Repository.
465
466 = 4.20.59 =
467 Various minor bug fixes, added Core Files Definitions for ClassicPress, and tweaked code for better compatibility with WordPress 5.7.2 and ClassicPress 1.2.0.
468
469 = 4.19.69 =
470 Fixed a JavaScript error caused by a new French translation and checked code for compatibility with WordPress 5.4.1.
471
472 = 4.19.68 =
473 Updated some external links and tweaked code for better compatibility with PHP 7.4 and WordPress 5.4.
474
475 = 4.19.50 =
476 Added even more error handling to the DB Scan for low memory_limit, modified the Directory Scan Depth to accept 0 as way to skip the Directory Scan, and added some Help tips to some of the options on the Settings page.
477
478 = 4.19.44 =
479 Updated links, added more error handling to the DB Scan, various performance improvements, fixed path to work on Windows servers and a few minor bugs causing PHP Notices, and weaked code for compatibility with WP 5.3 (latest release).
480
481 = 4.18.76 =
482 Cleaned up the Nonce Token code and Quarantine page, fixed recovery link, and added debugging for login errors plus WP head and footer Hooks.
483
484 = 4.18.74 =
485 Fixed a bug in the Nonce Token Errors that was created by changes in the last release.
486
487 = 4.18.71 =
488 Added wp_options table to the db_scan and fixed a few minor bugs in the quarantine view, and changed some wording and checked code for compatibility with WP 5.2.1 (latest release).
489
490 = 4.18.69 =
491 Added a Warning message about the vulnerability in the yuzo-related-post plugin, updated the Quarantine interface with a re-scan / re-clean feature, fixed a bug in the scan depth array that would produce PHP Notices, changed some wording and other minor fomatting issues, and checked code for compatibility with WP 5.2 (latest release).
492
493 = 4.18.63 =
494 Fixed a major bug in the Firewall updates that could cause a False Positive lockout.
495
496 = 4.18.62 =
497 Fixed a few minor bugs and updated code for compatibility with WP 5.1.1 (latest release).
498
499 = 4.18.52 =
500 Added a whole new DB Scan category, updated Firewall landing page, removed some old code that was no longer needed, clear cache files before running the Complete Scan,, and updated code for compatibility with WP 5.0.2 (latest release).
501
502 = 4.17.69 =
503 Updated code for compatibility with WP 4.9.8, fixed PHP Notice and escaped single-quotes in translated strings.
504
505 = 4.17.68 =
506 Updated code for compatibility with WP 4.9.7, removed dashicon from Settings link and the broken vote WORKS link, and reordered priorety on fixing Known Threats.
507
508 = 4.17.58 =
509 Updated code for compatibility with WP 4.9.4, fixed dashicons sizing in css, add ability to update registration email from within the plugin settings, and cleaned up expired nonce tokens left behind from an older version.
510
511 = 4.17.57 =
512 Updated code for compatibility with WP 4.9.3, fixed registration form and alternate domain for definition updates to work on HTTPS, and fixed the wording on the Title Check error message.
513
514 = 4.17.44 =
515 Added Title check to make sure it does say you were hacked, updated code for compatibility with WP 4.8.3 and fixed Undefined variable error in Quarantine and an XSS vulnerability in nonce error output.
516
517 = 4.17.29 =
518 Changed the definition update URL to only use SSL when required, and updated PayPal form for better domestic IPN compatibility.
519
520 = 4.17.28 =
521 Added the Turkish translation thanks to Umut Can Alparslan, improved the auto update feature, and fixed the admin username change feature on multisite installs (Plus many other improvement from v4.16.X: see Changelog for details).
522
523 = 4.16.17 =
524 Removed Menu Item Placement Options that were deprecated in WP 4.5, Added firewall options for better compatibility with WP Firewall 2, and fixed an XSS vulnerability in the debug output of the nonce token (Plus many other improvement from v4.15.X: see Changelog for details).
525
526 = 4.15.16 =
527 Created automatic definition updates that include WordPress Core files, more improvements to the Brute-Force protection patch (Plus many other improvement from v4.14.X: see Changelog for details).
528
529 = 4.14.47 =
530 Major upgrade to the protection for Brute-Force attempts, and a bug fix for resetting the permissions of read-only files (Plus many other improvement from v3.X: see Changelog for details).
531
532 = 3.07.06 =
533 Added SSL support for definition updates and upgraded the Whitelist feature (Plus many other improvement from v1.3.X: see Changelog for details).
534
535 = 1.3.02.15 =
536 Improved security on the Quarantine directory to fix the 500 error on some servers (Plus many other improvement from v1.2.X: see Changelog for details).
537
538 = 1.2.03.23 =
539 First versions available for WordPress (code removed, no longer compatible).
540