=== CodeCanvas Guard Release History ===

= 1.3.2 =

* Replaced standalone browser `<style>` output with WordPress-enqueued stylesheet assets.
* Moved login honeypot and Turnstile presentation rules into an enqueued login stylesheet.
* Tightened nonce ordering for settings and session actions so request data is inspected only after intent verification.
* Added explicit capability checks to self-service 2FA management actions.
* Rotated protected-login route-test tokens after successful verification so each test URL is single-use.
* Corrected the bundled QR generator source URL and WordPress.org contributor metadata.

= 1.3.1 =

* Remediated the WordPress.org Plugin Check report for database preparation, filesystem mutations, input validation, uninstall scope, and unique runtime naming.
* Added documented, narrow exceptions for service-backed Turnstile loading, public login/recovery verification tokens, one-time namespace migration queries, and privacy operations on Guard's custom audit table.
* Preserved profile, protected-login, pending verification, activation, confirmation, 2FA, recovery, scanner, and repair state during the compliance update.

= 1.2.3 =

* Preserved selected protection profiles across settings saves.
* Prevented profiles and protected-login state from overwriting each other.
* Added verified database readback and rollback for settings transactions.

= 1.2.2 =

* Preserved proposed login addresses and route verification across reloads and return visits.
* Prevented unrelated login-settings saves from restarting the protected-login wizard.

= 1.2.1 =

* Added verified protected-login activation persistence and immediate route registration.
* Preserved verified proposals when activation failed.

= 1.2.0 =

* Added severity-based advanced findings, update detection, known-vulnerability matching, suspicious-PHP patterns, executable-upload detection, sensitive-file comparison, review/approval states, filters, exports, and scheduled result-change emails.

= 1.1.4 =

* Added the Safe Repair and Quarantine Centre, protected recovery points, official-source core/plugin repair, post-repair verification, quarantine restore, permission rollback, repair evidence, and update awareness.

= 1.1.3 =

* Added priority-aware monitoring, exact coverage reporting, per-component allowances, and selectable 20,000/40,000/60,000-file capacity.

= 1.1.2 =

* Added the recovery-first protected-login wizard, recovery-link countdown/download, email previews and diagnostics, and responsive settings improvements.

= 1.1.1 =

* Added responsive HTML and plain-text security email templates.

= 1.1.0 =

* Added file-change monitoring, scheduled scans, local QR enrollment, session management, optional Turnstile, and verified hidden-login activation.

= 1.0.0 =

* Initial release.
