DadsFam Login Security — changelog for older versions
(Newer versions are listed in readme.txt and on the plugin's What's new tab.)

= 1.6.0 =
* New: the whole admin screen has been rebuilt in the DadsFam house style — one calm, tabbed screen (Dashboard · Activity · Settings) that leads with what is true right now and what to do about it, in plain English. Protection status at a glance, a “finish locking things down” checklist that disappears once you're done, big tap-tiles, and an “if something goes wrong” panel with the fix written right there.
* New: “Never lock me out” — one click puts your own address on the allow list, from the dashboard or the checklist.
* New: instant lockout for bot usernames. Anyone trying “admin”, “root”, “test” and friends when no such account exists is a bot; they're locked out on the first try instead of the fifth. Real accounts with those names are never affected. The list is editable.
* New: protection levels. Pick Relaxed, Balanced (recommended) or Strict instead of juggling five numbers — the numbers are still there for people who want them.
* New: Cloudflare and proxy support. Behind Cloudflare, every visitor used to look like the same address, so one bot could lock out your whole site. Choose “Cloudflare” or “Another proxy” under Settings → Where visitors' addresses come from; forwarded headers are only ever trusted when the request genuinely came from the proxy, so nobody can fake their address. The dashboard warns you if it spots Cloudflare and the setting is still on “plain hosting”.
* New: a recovery valve for the free plugin. Add `define( 'DFLS_DISABLE_LOCKOUTS', true );` to wp-config.php and every lockout is switched off until you remove it. The dashboard shows a red warning while it is in place.
* New: “Let everyone back in” clears every active lockout at once; “Block for good” on any row moves an address to the deny list.
* New: the activity log shows “Chrome on Windows” instead of a 200-character user agent, filters with pills, and lets you block an attacker straight from the row.
* Improved: locked-out addresses hammering a real account no longer cost a password-hash check per attempt — the lockout is now applied before the (deliberately slow) password comparison.
* Improved: dashboard statistics come from one query instead of five, and are memoised per request.
* Improved: the live dashboard pauses when the tab is hidden and refreshes the moment you come back.
* Changed: minimum WordPress version is now 6.0. Tested up to 7.0.

= 1.5.5 =
* Fixed: the honeypot bot trap could block genuine sign-ins when a password manager (1Password, LastPass, Bitwarden, browser autofill) filled the hidden field on the visitor's behalf. The trap now ignores values that simply mirror what the visitor legitimately typed, so real people get in and bots still get caught.
* Improved: the honeypot field now carries the ignore hints password managers actually respect, so most of them skip it entirely.

= 1.5.4 =
* New: a clear warning on the plugin’s admin pages when a known conflicting login/2FA plugin (e.g. Loginizer) is active at the same time — running two can break sign-in.
* Improved: translation-ready — the plugin now loads its text domain from a /languages folder.

= 1.5.3 =
* Performance: added a composite database index (status + time) so the dashboard statistics and charts stay fast even with very large activity logs. The index is added automatically on update.

= 1.5.2 =
* Improved: the Activity Log now labels email-link (magic-link) sign-ins from the Pro add-on.
* Hardened: the new-sign-in email alert is wrapped so it can never interfere with logging in.

= 1.5.1 =
* Improved: the Activity Log now labels passkey events (passkey added, removed, sign-in) written by the Pro add-on.

= 1.5.0 =
* New: optional new-sign-in email alert — the account owner is emailed when their account is signed into from an IP not seen before (opt-in under Settings → Notifications; the first login is remembered silently).
* New: export the activity log to CSV from the Activity Log page.
* New: filter the Activity Log by two-factor / security audit events (2FA on/off, device trusted/removed, codes reset).

= 1.4.1 =
* Improved: the Activity Log now shows two-factor audit events (2FA on/off, device trusted/removed, backup codes reset) with their own clear labels.
* Improved: the live dashboard ticker stays focused on genuine login attempts.

= 1.4.0 =
* New: live attack arcs — glowing comet trails streak across the threat sphere from each attacker to a marker representing your site.
* New: ambient pulse rings radiate from the security-score gauge, tinted to your current status.
* New: a soft cursor-follow spotlight glides across each panel for a premium, fluid feel.
* New: unblocking an IP now plays a satisfying “zap” as the row clears.
* Accessibility: all new effects switch off with “reduce motion”.

= 1.3.0 =
* New: rotating 3D wireframe “threat sphere” that plots live attack activity.
* New: hacker-style “decode” animation — stat numbers and the security score scramble, then lock in, on load.
* New: a glowing scan line sweeps across the failed-logins chart.
* New: subtle animated aurora glow behind the whole dashboard (light & dark).
* Accessibility: all of the above switch off automatically with “reduce motion”.

= 1.2.0 =
* New: live “security console” dashboard — an animated Protection Score gauge that reacts to real-time conditions.
* New: live activity ticker and a sweeping attack radar that plots your top attacking IPs.
* New: animated constellation backdrop, 3D-tilt stat cards, and glowing animated panel borders.
* New: one-click Dark Mode (remembered between visits) and an optional alert sound when a new lockout happens.
* Accessibility: every effect is disabled automatically when “reduce motion” is on; sound is off by default.

= 1.1.0 =
* New: live, self-refreshing security dashboard — stats update automatically every 12 seconds with no page reload.
* New: animated 14-day failed-login chart with hover tooltips and smooth transitions.
* New: animated count-up stat cards, and at-a-glance summary cards on the Activity Log page.
* Improved: premium glass UI across the dashboard, log and settings pages.
* Accessibility: all animations honour the “reduce motion” system setting.

= 1.0.0 =
* Initial release: brute-force lockouts, IP allow/deny lists, activity log, dashboard, email alerts, honeypot, generic errors, and hardening (user-enumeration, XML-RPC, pingback).
