PluginProbe
Loginizer / 2.1.2
Loginizer v2.1.2
2.1.2 2.1.1 2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 All 76 releases
← All changes | main/admin.php +204 -66 1.9.8 → 2.1.2 View file →
@@ -3,15 +3,82 @@
3 3 if(!defined('ABSPATH')){
4 4 die('Hacking Attempt!');
5 5 }
6 6
7 -// HOOKS
8 -add_action('admin_menu', 'loginizer_admin_menu');
9 -add_action('admin_notices', 'loginizer_social_login_url_alert');
10 -add_action('admin_footer', 'loginizer_social_interim_js');
11 -add_action('admin_init', 'loginizer_admin_actions');
12 -//add_filter("plugin_action_links_plugin_loginizer", 'loginizer_plugin_action_links');
7 +function loginizer_admin_hooks(){
8 + add_action('admin_menu', 'loginizer_admin_menu');
9 + add_action('admin_notices', 'loginizer_social_login_url_alert');
10 + add_action('admin_footer', 'loginizer_social_interim_js');
11 + add_action('admin_init', 'loginizer_admin_actions');
12 + // add_filter("plugin_action_links_plugin_loginizer", 'loginizer_plugin_action_links');
13 +
14 + loginizer_admin_promo_hooks();
15 +}
13 16
17 +function loginizer_admin_promo_hooks(){
18 + global $loginizer;
19 +
20 + if(!current_user_can('activate_plugins') || defined('SITEPAD')){
21 + return;
22 + }
23 +
24 + // Is the premium features there ?
25 + if(!defined('LOGINIZER_PREMIUM')){
26 + // The promo time
27 + $loginizer['promo_time'] = get_option('loginizer_promo_time');
28 + if(empty($loginizer['promo_time'])){
29 + $loginizer['promo_time'] = time();
30 + update_option('loginizer_promo_time', $loginizer['promo_time']);
31 + }
32 +
33 + // Are we to show the loginizer promo
34 + if(!empty($loginizer['promo_time']) && $loginizer['promo_time'] > 0 && $loginizer['promo_time'] < (time() - (30*24*3600))){
35 + add_action('admin_notices', 'loginizer_promo');
36 + }
37 +
38 + if(!empty($loginizer['csrf_promo']) && $loginizer['csrf_promo'] > 0 && $loginizer['csrf_promo'] < (time() - 86400)){
39 + add_action('admin_notices', 'loginizer_csrf_promo');
40 + }
41 +
42 + // Are we to disable the promo
43 + if(isset($_GET['loginizer_promo']) && (int)$_GET['loginizer_promo'] == 0){
44 + update_option('loginizer_promo_time', (0 - time()) );
45 + die('DONE');
46 + }
47 +
48 + $loginizer['backuply_promo'] = get_option('loginizer_backuply_promo_time');
49 + if(empty($loginizer['backuply_promo'])){
50 + $loginizer['backuply_promo'] = abs($loginizer['promo_time']);
51 + update_option('loginizer_backuply_promo_time', $loginizer['backuply_promo']);
52 + }
53 +
54 + // Setting CSRF Promo time
55 + $loginizer['csrf_promo'] = get_option('loginizer_csrf_promo_time');
56 +
57 + if(empty($loginizer['csrf_promo'])){
58 + $loginizer['csrf_promo'] = abs($loginizer['promo_time']);
59 + update_option('loginizer_csrf_promo_time', $loginizer['csrf_promo']);
60 + }
61 + }
62 +
63 + // === Plugin Update Notice === //
64 + $plugin_update_notice = get_option('softaculous_plugin_update_notice', []);
65 + $available_update_list = get_site_transient('update_plugins');
66 +
67 + if(
68 + !empty($available_update_list) &&
69 + is_object($available_update_list) &&
70 + !empty($available_update_list->response) &&
71 + !empty($available_update_list->response['loginizer/loginizer.php']) &&
72 + (empty($plugin_update_notice) || empty($plugin_update_notice['loginizer/loginizer.php']) || (!empty($plugin_update_notice['loginizer/loginizer.php']) &&
73 + version_compare($plugin_update_notice['loginizer/loginizer.php'], $available_update_list->response['loginizer/loginizer.php']->new_version, '<')))
74 + ){
75 + add_action('admin_notices', 'loginizer_plugin_update_notice');
76 + add_filter('softaculous_plugin_update_notice', 'loginizer_update_notice_filter');
77 + }
78 + // === Plugin Update Notice === //
79 +}
80 +
14 81 function loginizer_admin_actions(){
15 82 global $loginizer;
16 83
17 84 if(defined('LOGINIZER_PREMIUM') && !defined('SITEPAD') && current_user_can('activate_plugins') && isset($_GET['page']) && strpos($_GET['page'], 'loginizer') !== FALSE){
@@ -392,9 +459,9 @@
392 459 }
393 460 </script>
394 461
395 462 <hr />
396 - <a href="http://loginizer.com" target="_blank">Loginizer</a> '.__('v'.LOGINIZER_VERSION.'. You can report any bugs ','loginizer').'<a href="http://wordpress.org/support/plugin/loginizer" target="_blank">'.__('here','loginizer').'</a>.';
463 + <a href="http://loginizer.com" target="_blank">Loginizer</a> v'.LOGINIZER_VERSION.'. '.__('You can report any bugs ','loginizer').'<a href="http://wordpress.org/support/plugin/loginizer" target="_blank">'.__('here','loginizer').'</a>.';
397 464
398 465 }
399 466
400 467 echo '
@@ -481,11 +548,24 @@
481 548 // Rename Login
482 549 add_submenu_page('loginizer', __('Security Settings', 'loginizer'), __('Rename Login', 'loginizer'), 'activate_plugins', 'loginizer', 'loginizer_security_settings');
483 550
484 551 }
485 -
552 +
486 553 // Brute Force
487 554 add_submenu_page('loginizer', __('Brute Force Settings', 'loginizer'), __('Brute Force', 'loginizer'), 'activate_plugins', 'loginizer_brute_force', 'loginizer_brute_force_settings');
555 +
556 + if(defined('LOGINIZER_PREMIUM')){
557 + // WAF Security Firewall
558 + $new_badge = '<span style="display: inline-block; font-size:10px; margin-left: 3px; padding: 0px 5px; color: #fff; background-color: #d63638; border-radius: 5px;">'.__('New', 'loginizer').'</span>';
559 + $tag_new = time() < strtotime('2026-03-01') ? $new_badge : '';
560 +
561 + add_submenu_page('loginizer', __('Country Block', 'loginizer'), __('Country Block', 'loginizer').' '.$tag_new, 'activate_plugins', 'loginizer_firewall', 'loginizer_firewall_settings');
562 +
563 + // Login Page Branding, the check keeps an older Pro from fataling on a newer Free
564 + if(defined('LOGINIZER_PRO_DIR') && file_exists(LOGINIZER_PRO_DIR . 'main/settings/loginbranding.php')){
565 + add_submenu_page('loginizer', __('Login Page Branding', 'loginizer'), __('Login Branding', 'loginizer').(time() < strtotime('2026-11-06') ? ' '.$new_badge : ''), 'activate_plugins', 'loginizer_login_branding', 'loginizer_login_branding_settings');
566 + }
567 + }
488 568
489 569 // PasswordLess
490 570 add_submenu_page('loginizer', __($loginizer['prefix'].'PasswordLess Settings', 'loginizer'), __('PasswordLess', 'loginizer'), 'activate_plugins', 'loginizer_passwordless', 'loginizer_passwordless_settings');
491 571
@@ -497,21 +577,21 @@
497 577
498 578 }
499 579
500 580 // reCaptcha
501 - add_submenu_page('loginizer', __($loginizer['prefix'].'reCAPTCHA Settings', 'loginizer'), __('reCAPTCHA', 'loginizer'), 'activate_plugins', 'loginizer_recaptcha', 'loginizer_recaptcha_settings');
581 + add_submenu_page('loginizer', $loginizer['prefix'].__('reCAPTCHA Settings', 'loginizer'), __('reCAPTCHA', 'loginizer'), 'activate_plugins', 'loginizer_recaptcha', 'loginizer_recaptcha_settings');
502 582
503 583 // Temporary Login
504 - add_submenu_page('loginizer', __($loginizer['prefix'].'SSO', 'loginizer'), __('Single Sign On', 'loginizer'). ((time() < strtotime('30 November 2023')) ? ' <span style="color:yellow;">Update</span>' : ''), 'activate_plugins', 'loginizer_sso', 'loginizer_sso_settings');
584 + add_submenu_page('loginizer', $loginizer['prefix'].__('SSO', 'loginizer'), __('Single Sign On', 'loginizer'). ((time() < strtotime('30 November 2023')) ? ' <span style="color:yellow;">Update</span>' : ''), 'activate_plugins', 'loginizer_sso', 'loginizer_sso_settings');
505 585
506 586 // Social Login
507 - $hook_name = add_submenu_page('loginizer', __($loginizer['prefix'].'social_login', 'loginizer'), __('Social Login', 'loginizer') . ((time() < strtotime('30 July 2024')) ? ' <span style="color:red;">New</span>' : ''), 'activate_plugins', 'loginizer_social_login', 'loginizer_social_login_settings');
587 + $hook_name = add_submenu_page('loginizer', $loginizer['prefix']. __('Social Login', 'loginizer'), __('Social Login', 'loginizer') . (defined('LOGINIZER_PREMIUM') && (time() < strtotime('30 June 2025')) ? ' <span style="color:yellow;font-size:12px;">Updated</span>' : ''), 'activate_plugins', 'loginizer_social_login', 'loginizer_social_login_settings');
508 588
509 589 // Security Settings
510 590 if(!defined('SITEPAD')){
511 591
512 592 // Security Settings
513 - add_submenu_page('loginizer', __($loginizer['prefix'].'Security Settings', 'loginizer'), __('Security Settings', 'loginizer'), 'activate_plugins', 'loginizer_security', 'loginizer_security_settings');
593 + add_submenu_page('loginizer', $loginizer['prefix'].__('Security Settings', 'loginizer'), __('Security Settings', 'loginizer'), 'activate_plugins', 'loginizer_security', 'loginizer_security_settings');
514 594
515 595 // File Checksums
516 596 add_submenu_page('loginizer', __('Loginizer File Checksums', 'loginizer'), __('File Checksums', 'loginizer'), 'activate_plugins', 'loginizer_checksums', 'loginizer_checksums_settings');
517 597
@@ -541,68 +621,60 @@
541 621 function loginizer_promo(){
542 622
543 623 echo '
544 624 <style>
545 -.lz_button {
546 -background-color: #4CAF50; /* Green */
547 -border: none;
548 -color: white;
549 -padding: 8px 16px;
550 -text-align: center;
551 -text-decoration: none;
552 -display: inline-block;
553 -font-size: 16px;
554 -margin: 4px 2px;
555 --webkit-transition-duration: 0.4s; /* Safari */
556 -transition-duration: 0.4s;
557 -cursor: pointer;
558 -}
559 -
560 -.lz_button:focus{
561 -border: none;
562 -color: white;
563 -}
564 -
565 -.lz_button1 {
566 -color: white;
625 +.wp-core-ui .lz_button1 {
567 626 background-color: #4CAF50;
568 -border:3px solid #4CAF50;
627 +border-color: transparent;
628 +border-radius: 2px;
629 +color: #fff;
569 630 }
570 631
571 -.lz_button1:hover {
572 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
573 -color: white;
574 -border:3px solid #4CAF50;
632 +.wp-core-ui .lz_button1:hover {
633 +background-color:#3b963f;
634 +border-color: transparent;
635 +border-radius: 2px;
636 +color: #fff;
575 637 }
576 638
577 -.lz_button2 {
578 -color: white;
639 +.wp-core-ui .lz_button2 {
579 640 background-color: #0085ba;
641 +border-color: transparent;
642 +border-radius: 2px;
643 +color: #fff;
580 644 }
581 645
582 -.lz_button2:hover {
583 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
584 -color: white;
646 +.wp-core-ui .lz_button2:hover {
647 +background-color: #0175a3;
648 +border-color: transparent;
649 +border-radius: 2px;
650 +color: #fff;
585 651 }
586 652
587 -.lz_button3 {
588 -color: white;
653 +.wp-core-ui .lz_button3 {
589 654 background-color: #365899;
655 +border-color: transparent;
656 +border-radius: 2px;
657 +color: #fff;
590 658 }
591 659
592 -.lz_button3:hover {
593 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
594 -color: white;
660 +.wp-core-ui .lz_button3:hover {
661 +border-color: transparent;
662 +background-color: #274785;
663 +color:#fff;
595 664 }
596 665
597 -.lz_button4 {
598 -color: white;
599 -background-color: rgb(66, 184, 221);
666 +.wp-core-ui .lz_button4 {
667 +background-color: #14171A;
668 +border-color: transparent;
669 +border-radius: 2px;
670 +color: #fff;
600 671 }
601 672
602 -.lz_button4:hover {
603 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
604 -color: white;
673 +.wp-core-ui .lz_button4:hover {
674 +background-color: #24292E;
675 +color: #fff;
676 +border-color: transparent;
605 677 }
606 678
607 679 .loginizer_promo-close{
608 680 float:right;
@@ -639,12 +711,12 @@
639 711 </a>
640 712 <img src="'.LOGINIZER_URL.'/assets/images/loginizer-200.png" style="float:left; margin:10px 20px 10px 10px" width="100" />
641 713 <p style="font-size:16px">We are glad you like Loginizer and have been using it since the past few days. It is time to take the next step </p>
642 714 <p>
643 - <a class="lz_button lz_button1" target="_blank" href="https://loginizer.com/features">Upgrade to Pro</a>
644 - <a class="lz_button lz_button2" target="_blank" href="https://wordpress.org/support/view/plugin-reviews/loginizer">Rate it 5★\'s</a>
645 - <a class="lz_button lz_button3" target="_blank" href="https://www.facebook.com/Loginizer-815504798591884/">Like Us on Facebook</a>
646 - <a class="lz_button lz_button4" target="_blank" href="https://twitter.com/home?status='.rawurlencode('I use @loginizer to secure my #WordPress site - https://loginizer.com').'">Tweet about Loginizer</a>
715 + <a class="button lz_button1" target="_blank" href="https://loginizer.com/features">'.esc_html__('Upgrade to Pro', 'loginizer').'</a>
716 + <a class="button lz_button2" target="_blank" href="https://wordpress.org/support/view/plugin-reviews/loginizer">Rate it 5★\'s</a>
717 + <a class="button lz_button3" target="_blank" href="https://www.facebook.com/Loginizer-815504798591884/">'.esc_html__('Like Us on Facebook', 'loginizer').'</a>
718 + <a class="button lz_button4" target="_blank" href="https://x.com/intent/tweet?text='.rawurlencode('I use @loginizer to secure my #WordPress site - https://loginizer.com').'">'.esc_html__('Post on X about Loginizer', 'loginizer').'</a>
647 719 </p>
648 720 </div>';
649 721
650 722 }
@@ -681,9 +753,8 @@
681 753 }
682 754
683 755 function loginizer_dashboard(){
684 756 include_once LOGINIZER_DIR . '/main/settings/dashboard.php';
685 -
686 757 loginizer_page_dashboard();
687 758 }
688 759
689 760 function loginizer_sso_settings(){
@@ -697,8 +768,17 @@
697 768
698 769 loginizer_social_login();
699 770 }
700 771
772 +function loginizer_firewall_settings(){
773 + include_once LOGINIZER_PRO_DIR . 'main/settings/waf.php';
774 + loginizer_pro_firewall();
775 +}
776 +
777 +function loginizer_login_branding_settings(){
778 + \LoginizerPro\Settings\LoginBranding::page();
779 +}
780 +
701 781 // Hides the interim login poup after successful login.
702 782 function loginizer_social_interim_js(){
703 783
704 784 if(isset($_GET['interim_login']) && $_GET['interim_login'] === 'lz' && is_user_logged_in()){
@@ -716,10 +796,11 @@
716 796 // We want to show this error to user which has sufficient privilage
717 797 if(!current_user_can('activate_plugins')){
718 798 return;
719 799 }
720 -
721 - if(get_option('loginizer_social_login_url', '') === wp_login_url()){
800 +
801 + $set_login_url = get_option('loginizer_social_login_url', '');
802 + if(empty($set_login_url) || $set_login_url === wp_login_url()){
722 803 return;
723 804 }
724 805
725 806 $provider_settings = get_option('loginizer_provider_settings', []);
@@ -730,14 +811,23 @@
730 811 return;
731 812 }
732 813
733 814 $has_enabled = false;
815 + $has_non_login_auth = false;
734 816 foreach($provider_settings as $provider){
735 - if($provider['enabled']){
817 + if(empty($provider['loginizer_social_key']) && !empty($provider['enabled'])){
818 + $has_non_login_auth = true;
819 + }
820 +
821 + if(!empty($provider['enabled'])){
736 822 $has_enabled = true;
737 - break;
738 823 }
739 824 }
825 +
826 + // We will only show this error if the user is using key based config
827 + if(empty($has_non_login_auth)){
828 + return;
829 + }
740 830
741 831 // If we have no Provider enabled then just show the warning on the social login page.
742 832 if(empty($has_enabled) && (empty($_GET['page']) || $_GET['page'] !== 'loginizer_social_login')){
743 833 return;
@@ -743,9 +833,9 @@
743 833 return;
744 834 }
745 835
746 836 echo '<div class="notice notice-error">
747 - <h4>'.esc_html__('Your changed login slug!', 'loginizer').'</h4>
837 + <h4>'.esc_html__('You changed login slug!', 'loginizer').'</h4>
748 838 <p>'.esc_html__('You changed the login slug and have some social login apps enabled. These social login apps use the login URL as the redirect URI. This means that since the login URL has changed, the social login will now break.', 'loginizer').'</p>
749 839
750 840 <h4>'.esc_html__('How to fix:', 'loginizer').'</h4>
751 841 <p>'.esc_html__('When you created secret keys for the social apps, you also provided a Redirect URI. To fix this issue, you need to update that Redirect URI.', 'loginizer').'<br/>
@@ -871,5 +961,53 @@
871 961 var admin_url = "'.admin_url().'"+"admin-ajax.php";
872 962 jQuery.post(admin_url, data, function(response){
873 963 });
874 964 });');
875 -}
965 +}
966 +
967 +function loginizer_update_notice_filter($plugins = []){
968 + $plugins['loginizer/loginizer.php'] = 'Loginizer';
969 +
970 + return $plugins;
971 +}
972 +
973 +function loginizer_plugin_update_notice(){
974 + if(defined('SOFTACULOUS_PLUGIN_UPDATE_NOTICE')){
975 + return;
976 + }
977 +
978 + $to_update_plugins = apply_filters('softaculous_plugin_update_notice', []);
979 +
980 + if(empty($to_update_plugins)){
981 + return;
982 + }
983 +
984 + /* translators: %1$s is replaced with a "string" of name of plugins, and %2$s is replaced with "string" which can be "is" or "are" based on the count of the plugin */
985 + $msg = sprintf(__('New versions of %1$s %2$s available. Updating ensures better performance, security, and access to the latest features.', 'loginizer'), '<b>'.esc_html(implode(', ', $to_update_plugins)).'</b>', (count($to_update_plugins) > 1 ? 'are' : 'is')) . ' <a class="button button-primary" href='.esc_url(admin_url('plugins.php?plugin_status=upgrade')).'>Update Now</a>';
986 +
987 + define('SOFTACULOUS_PLUGIN_UPDATE_NOTICE', true); // To make sure other plugins don't return a Notice
988 + echo '<div class="notice notice-info is-dismissible" id="loginizer-plugin-update-notice">
989 + <p>'.$msg. '</p>
990 + </div>';
991 +
992 + wp_register_script('loginizer-update-notice', '', ['jquery'], '', true);
993 + wp_enqueue_script('loginizer-update-notice');
994 + wp_add_inline_script('loginizer-update-notice', 'jQuery("#loginizer-plugin-update-notice").on("click", function(e){
995 + let target = jQuery(e.target);
996 +
997 + if(!target.hasClass("notice-dismiss")){
998 + return;
999 + }
1000 +
1001 + var data;
1002 +
1003 + // Hide it
1004 + jQuery("#loginizer-plugin-update-notice").hide();
1005 +
1006 + // Save this preference
1007 + jQuery.post("'.admin_url('admin-ajax.php?action=loginizer_close_update_notice').'&security='.wp_create_nonce('loginizer_promo_nonce').'", data, function(response) {
1008 + //alert(response);
1009 + });
1010 + });');
1011 +}
1012 +
1013 +loginizer_admin_hooks();