PluginProbe
Loginizer / 2.1.1
Loginizer v2.1.1
2.1.1 2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 1.3.3 All 75 releases
← All changes | init.php +152 -166 1.9.8 → 2.1.1 View file →
@@ -4,9 +4,9 @@
4 4 echo 'You are not allowed to access this page directly.';
5 5 exit;
6 6 }
7 7
8 -define('LOGINIZER_VERSION', '1.9.8');
8 +define('LOGINIZER_VERSION', '2.1.1');
9 9 define('LOGINIZER_DIR', dirname(LOGINIZER_FILE));
10 10 define('LOGINIZER_URL', plugins_url('', LOGINIZER_FILE));
11 11 define('LOGINIZER_PRO_URL', 'https://loginizer.com/features#compare');
12 12 define('LOGINIZER_PRICING_URL', 'https://loginizer.com/pricing');
@@ -187,8 +187,29 @@
187 187 $wpdb->query("ALTER TABLE ".$wpdb->prefix."loginizer_logs ADD `url` VARCHAR(255) NOT NULL DEFAULT '' AFTER `ip`;");
188 188
189 189 }
190 190
191 + // Setting alignment to left in social login ?
192 + if($version < 201){
193 + $social_settings = get_option('loginizer_social_settings', []);
194 +
195 + if(!empty($social_settings)){
196 + if(!empty($social_settings['login']) && (!empty($social_settings['login']['login_form']) || !empty($social_settings['login']['registration_form']))){
197 + $social_settings['login']['button_alignment'] = 'left';
198 + }
199 +
200 + if(!empty($social_settings['woocommerce']) && (!empty($social_settings['woocommmerce']['login_form']) || !empty($social_settings['woocommerce']['registration_form']))){
201 + $social_settings['woocommerce']['button_alignment'] = 'left';
202 + }
203 +
204 + if(!empty($social_settings['comment']) && !empty($social_settings['comment']['enable_buttons'])){
205 + $social_settings['comment']['button_alignment'] = 'left';
206 + }
207 +
208 + update_option('loginizer_social_settings', $social_settings);
209 + }
210 + }
211 +
191 212 // Save the new Version
192 213 update_option('loginizer_version', LOGINIZER_VERSION);
193 214
194 215 // TODO:: REMOVE THIS AFTER MARCH 2025
@@ -204,9 +225,9 @@
204 225 }
205 226
206 227 }
207 228
208 -// Add the action to load the plugin
229 +// Add the action to load the plugin
209 230 add_action('plugins_loaded', 'loginizer_load_plugin');
210 231
211 232 // The function that will be called when the plugin is loaded
212 233 function loginizer_load_plugin(){
@@ -214,8 +235,18 @@
214 235 global $loginizer;
215 236
216 237 // Check if the installed version is outdated
217 238 loginizer_update_check();
239 +
240 + // There was an issue were for some users update was stuck, and free was able to get updated through auto updater option
241 + // removing these filters fixes that issue, and our Pro update blocker was improved in 2.1.1
242 + // This check can be removed 1 year from 28.09.2026
243 + if(defined('LOGINIZER_PRO_VERSION') && version_compare(LOGINIZER_PRO_VERSION, '2.1.1', '<')){
244 + foreach(['site_transient_update_plugins', 'pre_site_transient_update_plugins'] as $hook){
245 + remove_filter($hook, 'loginizer_pro_disable_manual_update_for_plugin'); // Older Pro used the default priority
246 + remove_filter($hook, 'loginizer_pro_disable_manual_update_for_plugin', 99);
247 + }
248 + }
218 249
219 250 // Set the array
220 251 if(empty($loginizer)){
221 252 $loginizer = array();
@@ -268,8 +299,14 @@
268 299 }
269 300
270 301 // When was the database cleared last time
271 302 $loginizer['last_reset'] = get_option('loginizer_last_reset');
303 +
304 + if(!isset($loginizer['ultimate-member-active'])){
305 + $um_is_active = in_array('ultimate-member/ultimate-member.php', apply_filters('active_plugins', get_option('active_plugins', [])));
306 +
307 + $loginizer['ultimate-member-active'] = !empty($um_is_active) ? true : false;
308 + }
272 309
273 310 //print_r($loginizer);
274 311
275 312 // Clear retries
@@ -305,17 +342,22 @@
305 342 // Is called before displaying the error message so that we dont show that the username is wrong or the password
306 343 // Update Error message
307 344 add_action('wp_login_errors', 'loginizer_error_handler', 10001, 2);
308 345 add_action('woocommerce_login_failed', 'loginizer_woocommerce_error_handler', 10001);
309 - add_action('wp_login', 'loginizer_login_success', 10, 2);
346 + add_action('wp_login', 'loginizer_login_success', 11, 2);
347 + add_action('rsssl_two_factor_user_authenticated', 'loginizer_rsssl_2fa_success');
348 +
349 + if(!empty($loginizer['ultimate-member-active'])){
350 + add_action('wp_login_failed', 'loginizer_ultimatemember_error_handler', 10001);
351 + }
310 352
311 - if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings']) && !loginizer_is_blacklisted()){
353 + if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings'])){
312 354 add_filter('wp_login_errors', 'loginizer_social_login_error_handler', 10000, 2);
313 355 }
314 356 }
315 357
316 358 // Social Login Form Actions
317 - if(!empty($loginizer['social_settings']) && !loginizer_is_blacklisted()){
359 + if(!empty($loginizer['social_settings'])){
318 360 if(!empty($loginizer['social_settings']['login']['login_form'])){
319 361 add_action('login_form', 'loginizer_social_btn_login');
320 362 }
321 363 }
@@ -326,63 +368,16 @@
326 368
327 369 if(is_admin()){
328 370 include_once LOGINIZER_DIR . '/main/admin.php';
329 371 }
330 -
372 +
331 373 // ----------------
332 374 // PRO INIT END
333 375 // ----------------
334 376
335 - // Is the premium features there ?
336 - if(!defined('LOGINIZER_PREMIUM')){
337 -
338 - if(current_user_can('activate_plugins')){
339 - // The promo time
340 - $loginizer['promo_time'] = get_option('loginizer_promo_time');
341 - if(empty($loginizer['promo_time'])){
342 - $loginizer['promo_time'] = time();
343 - update_option('loginizer_promo_time', $loginizer['promo_time']);
344 - }
345 -
346 - // Are we to show the loginizer promo
347 - if(!empty($loginizer['promo_time']) && $loginizer['promo_time'] > 0 && $loginizer['promo_time'] < (time() - (30*24*3600))){
348 -
349 - add_action('admin_notices', 'loginizer_promo');
350 -
351 - }
352 -
353 - if(!empty($loginizer['csrf_promo']) && $loginizer['csrf_promo'] > 0 && $loginizer['csrf_promo'] < (time() - 86400)){
354 -
355 - add_action('admin_notices', 'loginizer_csrf_promo');
356 -
357 - }
358 -
359 - // Are we to disable the promo
360 - if(isset($_GET['loginizer_promo']) && (int)$_GET['loginizer_promo'] == 0){
361 - update_option('loginizer_promo_time', (0 - time()) );
362 - die('DONE');
363 - }
364 -
365 - $loginizer['backuply_promo'] = get_option('loginizer_backuply_promo_time');
366 -
367 - if(empty($loginizer['backuply_promo'])){
368 - $loginizer['backuply_promo'] = abs($loginizer['promo_time']);
369 - update_option('loginizer_backuply_promo_time', $loginizer['backuply_promo']);
370 - }
371 -
372 - // Setting CSRF Promo time
373 - $loginizer['csrf_promo'] = get_option('loginizer_csrf_promo_time');
374 -
375 - if(empty($loginizer['csrf_promo'])){
376 - $loginizer['csrf_promo'] = abs($loginizer['promo_time']);
377 - update_option('loginizer_csrf_promo_time', $loginizer['csrf_promo']);
378 - }
379 - }
380 - }
381 -
382 377 // Secuity checks for social login.
383 - if(!empty($_GET['lz_social_provider']) && loginizer_can_login()){
384 - include_once LOGINIZER_DIR . '/main/social-login.php';
378 + if(!empty($_GET['lz_social_provider']) && loginizer_can_login() && empty($_GET['lz_api'])){
379 + add_action('init', 'loginizer_social_login_load');
385 380 return;
386 381 }
387 382 }
388 383
@@ -491,8 +486,11 @@
491 486 }
492 487
493 488 $lz_error['ip_blocked'] = $loginizer['msg']['lockout_err'].' '.$_time;
494 489
490 + if(!empty($loginizer['ultimate-member-active']) && class_exists('UM')){
491 + \UM()->form()->add_error('blocked_msg', $lz_error['ip_blocked']);
492 + }
495 493 return false;
496 494 }
497 495 }
498 496
@@ -507,26 +505,31 @@
507 505
508 506 if(empty($blacklist)){
509 507 return false;
510 508 }
511 -
509 +
510 + $current_ip_inet = inet_ptoi($loginizer['current_ip']);
511 +
512 512 foreach($blacklist as $k => $v){
513 -
513 +
514 + $start_inet = inet_ptoi($v['start']);
515 + $end_inet = inet_ptoi($v['end']);
516 +
514 517 // Is the IP in the blacklist ?
515 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip']) && inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
518 + if($start_inet <= $current_ip_inet && $current_ip_inet <= $end_inet){
516 519 $result = 1;
517 520 break;
518 521 }
519 -
522 +
520 523 // Is it in a wider range ?
521 - if(inet_ptoi($v['start']) >= 0 && inet_ptoi($v['end']) < 0){
524 + if($start_inet >= 0 && $end_inet < 0){
522 525
523 526 // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
524 527 // if the current IP is <= than the start of the range, it is within the range
525 528 // OR
526 529 // if the current IP is <= than the end of the range, it is within the range
527 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip'])
528 - || inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
530 + if($start_inet <= $current_ip_inet
531 + || $current_ip_inet <= $end_inet){
529 532 $result = 1;
530 533 break;
531 534 }
532 535
@@ -532,9 +535,9 @@
532 535
533 536 }
534 537
535 538 }
536 -
539 +
537 540 // You are blacklisted
538 541 if(!empty($result)){
539 542 $lz_error['ip_blacklisted'] = $loginizer['msg']['ip_blacklisted'];
540 543 return true;
@@ -543,52 +546,8 @@
543 546 return false;
544 547
545 548 }
546 549
547 -function loginizer_is_whitelisted(){
548 -
549 - global $wpdb, $loginizer, $lz_error;
550 -
551 - $whitelist = $loginizer['whitelist'];
552 -
553 - if(empty($whitelist)){
554 - return false;
555 - }
556 -
557 - foreach($whitelist as $k => $v){
558 -
559 - // Is the IP in the blacklist ?
560 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip']) && inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
561 - $result = 1;
562 - break;
563 - }
564 -
565 - // Is it in a wider range ?
566 - if(inet_ptoi($v['start']) >= 0 && inet_ptoi($v['end']) < 0){
567 -
568 - // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
569 - // if the current IP is <= than the start of the range, it is within the range
570 - // OR
571 - // if the current IP is <= than the end of the range, it is within the range
572 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip'])
573 - || inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
574 - $result = 1;
575 - break;
576 - }
577 -
578 - }
579 -
580 - }
581 -
582 - // You are whitelisted
583 - if(!empty($result)){
584 - return true;
585 - }
586 -
587 - return false;
588 -
589 -}
590 -
591 550 // When the login fails, then this is called
592 551 // We need to update the database
593 552 function loginizer_login_failed($username, $is_2fa = ''){
594 553
@@ -607,53 +566,78 @@
607 566
608 567 if(empty($lz_cannot_login) && empty($loginizer['ip_is_whitelisted']) && empty($loginizer['no_loginizer_logs'])){
609 568
610 569 // The params which comes when social login returns an error, have some characters, which WordPress could not save.
611 - $server_uri = $_SERVER['REQUEST_URI'];
612 - if(!empty($_SERVER['REQUEST_URI']) && strpos($_SERVER['REQUEST_URI'], 'lz_social_provider') !== FALSE){
613 - $request_uri = explode('=', $_SERVER['REQUEST_URI']);
570 + // REQUEST_URI / HTTP_HOST are not always set (WP-CLI, some CGI and XML-RPC setups)
571 + $server_uri = isset($_SERVER['REQUEST_URI']) ? $_SERVER['REQUEST_URI'] : '';
572 + $http_host = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '';
573 +
574 + if(!empty($server_uri) && strpos($server_uri, 'lz_social_provider') !== FALSE){
575 + $request_uri = explode('=', $server_uri);
614 576 $server_uri = $request_uri[0];
615 577 }
616 578
617 - $url = @addslashes((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$_SERVER['HTTP_HOST'].$server_uri);
618 - $url = esc_url($url);
579 + // No addslashes() here, $wpdb->prepare() below does the escaping
580 + $url = esc_url((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$http_host.$server_uri);
619 581
582 + // Must never be 0, we divide by it below
583 + $max_retries = (int) $loginizer['max_retries'] < 1 ? 1 : (int) $loginizer['max_retries'];
584 +
585 + // This way is atomic now, the earlier one were causing race condition.
586 + // NOTE : In the UPDATE part `count` is already the new value, as MySQL / MariaDB
587 + // evaluate the assignments from left to right, so lockout must NOT add 1 again
588 + $upsert = $wpdb->prepare(
589 + "INSERT INTO `".$wpdb->prefix."loginizer_logs`
590 + (username, time, count, ip, lockout, url)
591 + VALUES
592 + (%s, %d, 1, %s, FLOOR(1 / %d), %s)
593 + ON DUPLICATE KEY UPDATE
594 + username = VALUES(username),
595 + time = VALUES(time),
596 + count = count + 1,
597 + lockout = FLOOR(count / %d),
598 + url = VALUES(url)",
599 + $username,
600 + time(),
601 + $loginizer['current_ip'],
602 + $max_retries,
603 + $url,
604 + $max_retries
605 + );
606 + $wpdb->query($upsert);
607 +
608 + // Re-read the persisted row so email/retries-left reflect the actual count
620 609 $sel_query = $wpdb->prepare("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = %s", $loginizer['current_ip']);
621 610 $result = lz_selectquery($sel_query);
622 -
623 - if(!empty($result)){
624 - $lockout = floor((($result['count']+1) / $loginizer['max_retries']));
625 -
626 - $update_data = array('username' => $username,
627 - 'time' => time(),
628 - 'count' => $result['count']+1,
629 - 'lockout' => $lockout,
630 - 'url' => $url);
631 -
632 - $where_data = array('ip' => $loginizer['current_ip']);
633 -
634 - $format = array('%s','%d','%d','%d','%s');
635 - $where_format = array('%s');
636 -
637 - $wpdb->update($wpdb->prefix.'loginizer_logs', $update_data, $where_data, $format, $where_format);
638 -
639 - // Do we need to email admin ?
640 - if(!empty($loginizer['notify_email']) && $lockout >= $loginizer['notify_email']){
641 -
642 - $lockout_time = $loginizer['lockout_time'];
643 -
644 - if($lockout >= $loginizer['max_lockouts']){
645 - // extended lockout is in hours so we have to convert to minute
646 - $lockout_time = $loginizer['lockouts_extend'];
647 - }
648 -
649 - $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
650 - $mail = array();
651 - $mail['to'] = $loginizer['notify_email_address'];
652 - $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
653 - $mail['message'] = 'Hi,
654 611
655 -'.($result['count']+1).' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
612 + if(empty($result)){
613 + $result = array('count' => 0);
614 + }
615 +
616 + $count = (int) $result['count'];
617 + $lockout = !empty($result['lockout']) ? (int) $result['lockout'] : 0;
618 +
619 + // The lockout goes up only on every max_retries'th failure, which is the
620 + // attempt that actually locks the IP out. On the failures in between there
621 + // is nothing new to report, so we must not email on each one of them
622 + $is_new_lockout = !empty($count) && ($count % $max_retries) == 0;
623 +
624 + // Do we need to email admin ?
625 + if(!empty($loginizer['notify_email']) && !empty($is_new_lockout) && $lockout >= $loginizer['notify_email']){
626 +
627 + $lockout_time = $loginizer['lockout_time'];
628 +
629 + if($lockout >= $loginizer['max_lockouts']){
630 + $lockout_time = $loginizer['lockouts_extend'];
631 + }
632 +
633 + $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
634 + $mail = array();
635 + $mail['to'] = $loginizer['notify_email_address'];
636 + $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
637 + $mail['message'] = 'Hi,
638 +
639 +'.(int) $result['count'].' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
656 640 '.home_url().'
657 641
658 642 Last '.$fail_type.' Attempt : '.date('d/M/Y H:i:s P', time()).'
659 643 Last User Attempt : '.$username.'
@@ -661,35 +645,22 @@
661 645
662 646 Regards,
663 647 Loginizer';
664 648
665 - @wp_mail($mail['to'], $mail['subject'], $mail['message']);
666 - }
667 - }else{
668 - $result = array();
669 - $result['count'] = 0;
670 -
671 - $insert_data = array('username' => $username,
672 - 'time' => time(),
673 - 'count' => 1,
674 - 'ip' => $loginizer['current_ip'],
675 - 'lockout' => 0,
676 - 'url' => $url);
677 -
678 - $format = array('%s','%d','%d','%s','%d','%s');
679 -
680 - $wpdb->insert($wpdb->prefix.'loginizer_logs', $insert_data, $format);
649 + @wp_mail($mail['to'], $mail['subject'], $mail['message']);
681 650 }
682 -
683 - // We need to add one as this is a failed attempt as well
684 - $result['count'] = $result['count'] + 1;
651 +
685 652 loginizer_update_attempt_stats(0);
686 - $loginizer['retries_left'] = ($loginizer['max_retries'] - ($result['count'] % $loginizer['max_retries']));
687 - $loginizer['retries_left'] = $loginizer['retries_left'] == $loginizer['max_retries'] ? 0 : $loginizer['retries_left'];
653 + $loginizer['retries_left'] = $max_retries - ($count % $max_retries);
654 + $loginizer['retries_left'] = $loginizer['retries_left'] == $max_retries ? 0 : $loginizer['retries_left'];
688 655
689 656 }
690 657 }
691 658
659 +function loginizer_rsssl_2fa_success($user){
660 + loginizer_login_success('', $user);
661 +}
662 +
692 663 function loginizer_login_success($user_login, $user) {
693 664 global $wp_version, $loginizer;
694 665
695 666 loginizer_update_attempt_stats(1);
@@ -843,11 +814,22 @@
843 814 wc_add_notice( loginizer_retries_left(), 'error' );
844 815 }
845 816 }
846 817
818 +function loginizer_ultimatemember_error_handler(){
819 +
820 + if(class_exists('UM')){
821 + \UM()->form()->add_error('remaining_tries', loginizer_retries_left());
822 + }
823 +}
824 +
847 825 // Handles social login URL
848 826 function loginizer_social_login_error_handler($errors = '', $redirect_to = ''){
849 827 global $loginizer;
828 +
829 + if(loginizer_is_blacklisted()){
830 + return $errors;
831 + }
850 832
851 833 loginizer_get_social_error();
852 834
853 835 if(empty($loginizer['social_errors'])){
@@ -944,8 +926,12 @@
944 926 $loginizer['2fa_msg'][$lk] = $loginizer['2fa_d_msg'][$lk];
945 927 }
946 928 }
947 929
930 +}
931 +
932 +function loginizer_social_login_load(){
933 + include_once LOGINIZER_DIR . '/main/social-login.php';
948 934 }
949 935
950 936 // Checks if softaculous is installed on the server.
951 937 function loginizer_check_softaculous(){