=== Polanger Admin Suite – Secure, Control & Customize WordPress Admin ===
Contributors: polangersoft
Tags: menu manager, customize, 2fa, firewall, login security
Requires at least: 5.7
Tested up to: 7.0
Stable tag: 1.5.9
Requires PHP: 7.0
License: GPLv3 or later
License URI: https://www.gnu.org/licenses/gpl-3.0.html

All-in-one WordPress admin control and security. Manage menus, access, dashboard, login protection, firewall, activity logs, and more.

== Description ==

**Polanger Admin Suite** is a modular, all-in-one WordPress admin control and security plugin built to help you customize, protect, and manage your website from one place.

Instead of installing separate plugins for admin customization, access control, login protection, firewall security, dashboard management, and activity tracking, Polanger brings these tools together in one clean, modular interface.

Whether you're a developer, agency, or site owner, Polanger helps you build a cleaner admin experience, stronger access controls, and a safer WordPress installation.

* [Live Demo](https://polanger.com/polanger-admin-suite/wp-admin)

= Features =

* Modular admin suite: enable only the tools you need and keep wp-admin lightweight.
* Menu Manager with hiding, renaming, reordering, custom icons, custom menu items, URL blocking, and Shield protection indicators.
* Admin Bar, Login Page, Dashboard Center, Activity Log, and admin notice controls from one interface.
* Login hardening with custom login URL, reCAPTCHA, Two-Factor Authentication, recovery keys, trusted devices, and brute-force protection.
* Frontend Content Visibility for role-based access control on posts, pages, and supported custom post types.
* Design System with theme presets, PG Aurora, smart contrast correction, scoped styling, typography, and live preview controls.
* Comment Security Layer and Firewall addons for comment abuse, malicious requests, bot probes, authentication abuse, REST/XML-RPC protection, country blocking, WordPress integrity monitoring, file protection, and safe core recovery.
* WooCommerce Security for store login, registration, lost password, reCAPTCHA, 2FA, and customer authentication rate limiting.
* Polanger Shield for admin page blocking, element hiding, contextual notes, Demo Lock, Global Demo Mode, and safer client/admin demo workflows.
* Maintenance Center for coming soon, maintenance, deployment, preview access, branded public messages, countdowns, and role-based bypass rules.

= Why Polanger Admin Suite? =

* **All-in-One Admin & Security Control** - Replace multiple admin, access, and security tools with one modular solution
* **Clean & Organized Dashboard** - Remove clutter and simplify your workflow
* **Layered WordPress Security** - Protect authentication, suspicious requests, critical files, WordPress integrity, and geographic access
* **Modern UI** - Fast, intuitive, and easy to use
* **Built for Agencies & Teams** - Perfect for multi-user environments

= Core Features =

== Admin Menu Manager ==
* Hide any admin menu or submenu item
* Role-based visibility control
* Rename menu items and submenus
* Change icons with 200+ Dashicons
* Drag & drop menu reordering
* Block direct URL access to hidden pages
* Visual indicators for hidden and modified items
* Custom admin menu builder (create your own menus)

== Admin Bar Customization ==
* Replace or remove WordPress logo
* Hide unwanted admin bar items
* Add custom links with icons
* Manage frontend and backend admin bar
* Auto-detect plugin and theme items

== Login Security & Customization ==
* Custom login URL (hide wp-login.php)
* Google reCAPTCHA v2 & v3 support
* Custom login page design (logo, colors, background)
* Brute-force protection with configurable login attempt limits and lockouts
* Hardened login flows with safer redirects and protected authentication routes

== Email Two-Factor Authentication (2FA) ==
* Email-based verification codes
* Role-based enforcement
* Recovery keys for backup access
* Configurable expiration times
* Super admin protection

== Authenticator App (TOTP) ==
* Google Authenticator and Microsoft Authenticator support
* Time-based One-Time Password (TOTP) verification
* Multi-user architecture with per-user enrollment
* Mandatory enrollment flow for users in required roles
* Profile page 2FA management (Users → Profile)
* Admin visibility: enrollment status only, no secret access
* Safe secret rotation with pending secret system
* Old authenticator remains active until new setup is verified
* Secure secret storage with AES-256-CBC encryption
* Manual secret entry with provisioning URI support
* One-time recovery keys (10 keys per user, auto-regenerated on rotation)
* Email fallback option when authenticator is unavailable
* Brute-force protection with configurable lockout
* Replay attack prevention with time-slice tracking
* Seamless integration with core 2FA settings (roles, lockout, expiry)

== Activity Log ==
* Track logins, plugin changes, content updates, and more
* Filter by user, action, and date
* Export logs (CSV)
* Email alerts for critical actions
* Privacy-conscious logging with controlled activity data collection

== Dashboard Control ==
* Hide default WordPress widgets
* Hide third-party plugin widgets
* Control admin notices
* Create custom dashboard widgets
* Per-user dashboard visibility

== Multisite Control ==
* Network-wide default settings for multisite installations
* Site-level override controls for supported modules
* Lock system for Menu Manager, Admin Bar, Login Security, Activity Log, and Dashboard Center
* Network-aware addon activation support
* Developer-friendly effective settings filter architecture

== Access Control ==
* Restrict plugin access to specific users
* Read-only mode support
* Prevent unauthorized access
* Super admin safety protection

== Design System ==
* Token-based admin theming system for consistent and scalable customization
* Customize colors across admin UI (sidebar, admin bar, background, text, surfaces)
* Sidebar background, text color, and menu item styling
* Admin bar background, text color, submenu background, and submenu text color
* Built-in presets (e.g. Dark, Minimal, Default) with one-click application
* Automatic CSS generation with cache-friendly performance
* Enhanced Smart Contrast uses WCAG-aware ratios, gradient sampling, dynamic admin-surface monitoring, icon correction, and late theme guards while preserving colors that are already readable
* Typography controls including font family and basic shape settings
* Scoped styling to avoid conflicts with WordPress core and plugins
* Extensible architecture for future themes, layouts, and design packs

== Frontend Content Visibility ==
* Per-content frontend access control for posts, pages, and supported custom post types
* Visibility modes for public, logged-in users only, selected roles only, or hidden-from-selected-roles workflows
* Multiple denied behaviors including login redirect, 404, access denied message, and custom redirect
* Theme-friendly replacement mode or dedicated access denied page for stricter template control
* Optional hiding from archives, search results, public REST responses, and WordPress XML sitemaps
* Rich-text access denied messages with TinyMCE, HTML, and shortcode support

== reCAPTCHA Protection ==
* Centralized Google reCAPTCHA key management (v2 and v3)
* All reCAPTCHA configuration consolidated in one dedicated addon
* Login form protection
* Registration form protection
* Lost password form protection
* Comment form protection (works with Comment Security addon)
* Configurable v3 score threshold
* Badge position customization for v3
* Automatic script loading only when needed

== Firewall ==

* WordPress-aware Firewall with request protection, file integrity monitoring, malware behavior detection, and safe recovery tools
* Monitor Only, Safe Protection, and Strict modes for observation, everyday protection, or more aggressive protection during attacks
* Blocks common bot probes, exposed-file scans, traversal attempts, suspicious request patterns, unsafe methods, and other high-risk traffic
* Native WordPress login, registration, and lost-password rate limiting with identity and IP-based protection
* REST API and XML-RPC hardening with compatibility-aware controls for anonymous requests, user enumeration, multicall abuse, and pingbacks
* Request scoring combines multiple suspicious signals before making monitoring or blocking decisions
* IP allowlist and denylist rules with IPv4/IPv6 CIDR support, trusted proxy handling, and temporary cooldowns for repeated abusive traffic
* Country Access Control blocks visitors from selected countries using a compact local DB-IP Country Lite database without sending visitor IP addresses to a remote geolocation API
* Country data is prepared only when countries are selected, checked periodically for updates, and removed when the country policy is cleared
* Security response headers, WordPress Application Password controls, and username enumeration protection
* Official WordPress core integrity verification detects modified, missing, and unauthorized core files using exact-version and locale checksums
* Supported WordPress.org plugins are verified against official package manifests, while premium and custom plugins/themes use safer executable-file change monitoring instead of being treated as malware
* Incremental executable monitoring detects unexpected PHP and other executable changes across `wp-content` while recognizing normal WordPress core, plugin, theme, and translation updates
* Upload protection detects executable/PHP-bearing media files and can prevent PHP execution inside uploads on supported Apache environments
* High-confidence malware behavior detection looks for combined indicators such as encoded execution chains, request-driven command execution, suspicious includes, and similar dangerous behaviors
* Strict Extended Server Hardening can protect supported Apache/LiteSpeed sites against sensitive-file exposure, development metadata leaks, backup/log access, directory browsing, and unsafe server-level requests before WordPress/PHP handles them
* Strict server rules use isolated, transactional `.htaccess` management with verification, health checks, automatic rollback, and safe cleanup without modifying WordPress or third-party markers
* Safe WordPress Core Repair can restore verified modified or missing official core files and quarantine unauthorized core files without automatically deleting ambiguous custom code
* No-reload **Scan Now** performs a detailed integrity scan with live progress, chunked asynchronous processing, safe locking, and WP-Cron continuation if the browser tab closes
* Low-impact scheduled integrity scans and automatic post-update verification help detect later file changes without requiring constant full scans
* Integrity findings are separated into **Critical**, **Review**, and **Notice** levels so package differences and custom code are not automatically presented as malware
* Compact integrity reports group findings by component, provide a quick preview, and offer a filtered paginated viewer for larger reports
* Recent Firewall Events use bounded storage to record meaningful security decisions without becoming a heavy full-traffic logger
* Built-in Firewall Diagnostics safely test request protection, rate limits, REST/XML-RPC behavior, IP/CIDR rules, security headers, country access, integrity checks, upload protection, scan scheduling, and Strict server hardening without sending malicious traffic
* Protection presets configure sensible defaults automatically while still respecting administrator-customized settings


== WooCommerce Security ==
* Adds WooCommerce-specific reCAPTCHA locations for customer login, registration, and lost password forms
* Extends the existing Polanger 2FA flow into WooCommerce customer login while preserving My Account and checkout return paths
* Adds customer authentication rate limiting for login failures, account registrations, and lost password requests
* Includes Light, Balanced, and Strict protection profiles so store owners can choose safe limits without tuning every number manually
* Requires WooCommerce and uses dependency-aware loading so the addon does not run in incomplete store environments
* Reuses Polanger's existing reCAPTCHA and 2FA systems instead of creating a disconnected WooCommerce security stack

== Polanger Shield ==
* Blocks selected wp-admin pages for selected users with optional direct URL blocking
* Hides selected admin interface areas from the real screen using the floating Shield tool
* Adds contextual notes to admin elements so teams can document workflows directly inside wp-admin
* Demo Lock keeps selected admin screens visible while preventing save, publish, AJAX, REST, and destructive changes for demo users
* Global Demo Mode turns wp-admin into a controlled read-only demo environment for eligible administrator accounts
* Safe Mode gives authorized managers a temporary recovery path when reviewing or troubleshooting Shield rules
* Menu Manager integration shows when a menu or submenu item is already protected by Shield, helping avoid duplicate restrictions
* The Shield dashboard provides status/type filters, 25-rule pagination, localized dates and states, bulk actions, and a mobile-safe scroll region so every saved rule remains manageable

= Addon Architecture =

Polanger Admin Suite includes a modular addon system designed for scalability and clarity.

== Core Addons ==
* Admin Bar
* Dashboard Center
* Admin Activity Log
* Custom Admin Menu Builder
* Multisite Control
* Design System
* Comment Security Layer
* Authenticator (TOTP)
* reCAPTCHA
* Firewall
* Maintenance Center
* WooCommerce Security - WooCommerce customer login, registration, lost password, reCAPTCHA, 2FA, and rate limiting integration
* Polanger Shield - admin page blocking, element hiding, contextual notes, Demo Lock, Global Demo Mode, and Menu Manager protection indicators

== 3rd Party Addons ==
* Reserved for future ecosystem integrations
* Addons are managed from the built-in **Addons** tab
* Core addons and external addons are separated for easier management

= Built for Real-World Use =

Polanger is designed for:

* Agencies managing client websites
* Developers who need full admin control
* Teams working with multiple user roles
* Site owners who want a cleaner dashboard

= Lightweight & Secure =

* Built with WordPress coding standards
* Nonce verification for all actions
* Capability checks for all operations
* Sanitized inputs and secure database queries
* Optimized for performance


= Available Languages =

Polanger Admin Suite currently includes translations for:

* English (default)
* Turkish (tr_TR)
* Arabic (ar)
* Russian (ru_RU)
* Chinese - Simplified (zh_CN)
* Spanish (es_ES)
* German (de_DE)

More information:

* [Live Demo](https://polanger.com/polanger-admin-suite/wp-admin)
* [Documentation](https://polanger.com/documentation/polanger-admin-suite/docs/)
* [Developer](https://polanger.com/documentation/polanger-admin-suite/developer/)

== Installation ==

1. Upload the plugin to `/wp-content/plugins/`
2. Activate it from the Plugins menu
3. Access via **Settings -> Polanger Admin**

== Frequently Asked Questions ==

= Does this replace multiple plugins? =
Yes. Polanger combines menu management, login security, dashboard control, and activity logging in one plugin.

= Can I control user access? =
Yes. You can restrict menu visibility and plugin access per user or role.

= Is it safe to use on client sites? =
Absolutely. Polanger is built with security and multi-user environments in mind.

= Will it slow down my site? =
No. The plugin is optimized to remain lightweight and efficient.

== Screenshots ==

1. Admin Suite dashboard overview
2. Menu manager with drag & drop
3. Login customization panel
4. Activity log interface
5. Dashboard widget controls

== Changelog ==

= 1.5.9 =

* New: Scan Now runs a complete no-reload integrity scan with live percentage, stage, and processed-file counters; work is split into locked AJAX batches and can continue safely through WP-Cron if the page closes
* New: Country Access Control blocks selected countries through a compact local DB-IP database, displays removable live country chips, supports a customizable localized 403 page, and refreshes active data approximately every 15 days
* New: Strict Extended Server Hardening adds bounded Apache/LiteSpeed protection before PHP with transactional .htaccess writes, live health verification, rollback, diagnostics, and automatic cleanup when Strict protection leaves service
* Improved: Firewall integrity now combines exact-version WordPress core checksums, supported WordPress.org plugin verification, executable drift monitoring, high-confidence malware behavior signals, daily low-cost scans, post-update verification, and explicit verified core repair
* Improved: Integrity findings now use a compact summary, grouped components, ten-row preview, filtered AJAX-paginated modal, critical administrator alerts, and replacement of the previous report after each completed scan instead of accumulating scan history
* Improved: Firewall now includes complete Turkish, German, Spanish, Russian, Simplified Chinese, and Arabic coverage for current Firewall screens, diagnostics, findings, country names, and blocked-visitor defaults
* Improved: Firewall cards, actions, progress details, country controls, selected-country chips, and findings modal now adapt more cleanly to narrow tablet and mobile screens
* Improved: Design System Smart Contrast now evaluates WCAG contrast across solid, transparent, and gradient surfaces, protects readable existing colors, corrects icons and dynamic plugin UI, and monitors supported editor frames
* Fixed: Shield now intercepts visual selector clicks before target controls can execute, builds subdirectory-safe Test URLs, keeps Shield-only managers on the dedicated settings tab, avoids disabled Global Demo user queries, and reports missing rule actions accurately
* Improved: Shield adds filtered 25-row rule pagination, mobile-safe tables and floating tools, accessible modal focus handling, cache-safe asset versions, precise Demo control decoration, and complete current translations in all six bundled languages

= 1.5.8 =

* Improved: Country Access Control now lets administrators review and remove selected countries as live chips, customize the localized blocked-visitor page title and message, and preserve the secure HTTP 403 layout with unobtrusive DB-IP attribution
* Improved: Firewall now ships complete Turkish, German, Spanish, Russian, Simplified Chinese, and Arabic translations, including diagnostics, integrity results, Country Access Control, and localized country names
* New: Optional local Country Access Control downloads DB-IP Country Lite only after explicit country selection, enforces selected countries in every enabled Firewall mode, and checks for monthly data updates approximately every 15 days
* New: Strict Extended Server Hardening adds bounded Apache/LiteSpeed protection before PHP, transactional root .htaccess writes, post-write health verification, rollback, diagnostics, and automatic cleanup whenever Strict protection leaves service
* New: Firewall adds exact-version WordPress core integrity, official plugin SHA-256 checks, update-aware executable monitoring, uploads execution protection, malware behavior signals, scheduled scans, and explicit verified core repair with quarantine
* Fixed: Firewall rate windows no longer slide indefinitely, Monitor Only keeps threshold state, REST rate limiting is visible and migrated to its intended preset, trusted proxy chains resolve safely, and sensitive event query values are redacted
* Fixed: WooCommerce Security settings tab registration now loads reliably when WooCommerce becomes available later in the WordPress plugin bootstrap order
* Fixed: Design System PG Aurora active tab and nested navigation contrast now keeps selected settings tabs, addon subtabs, and gradient surfaces readable
* Improved: Polanger Shield admin page restrictions now block targeted users more consistently and surface Shield-controlled menu protections inside Menu Manager
* Improved: Firewall request scoring has been refined for more accurate suspicious request detection while preserving safer preset behavior

= 1.5.7 =

* New: Design System now includes the PG Aurora admin theme preset with a modern light dashboard style, gradient menu states, improved sidebar icon handling, refined submenu hierarchy, and polished classic WordPress admin screen compatibility
* Improved: Firewall request protection was refined with safer preset behavior, compatibility-aware REST handling, and clearer optional tuning boundaries for production sites
* Improved: Strict REST protection now preserves WooCommerce Store API compatibility automatically when WooCommerce is active, preventing cart, checkout, and account flows from being blocked by anonymous REST write hardening
* Improved: Menu Manager mobile layout now uses responsive card-based rows with cleaner visibility controls, submenu expansion, custom name fields, and cache-safe admin UI stylesheet loading
* Fixed: Design System preset application now updates saved theme tokens reliably, reflects changes immediately on the settings page, and includes an inline fallback so generated admin theme CSS cannot silently fail on stricter live hosting setups

= 1.5.6 =

* New: Firewall addon adds Monitor Only, Balanced, and Strict WordPress-aware request protection for common bot probes, native auth rate limits, XML-RPC hardening, REST pressure, anonymous user enumeration, IP rules, temporary cooldowns, and lightweight event logging while respecting custom administrator overrides
* Improved: Firewall defaults, Monitor Only behavior, REST compatibility, CIDR validation, proxy IP detection, and event logging safety were refined to reduce false positives and lockout risk
* Fixed: Plugin update notifications remain visible on the Plugins screen when admin notice hiding is enabled
* Improved: The Shield dashboard displays the Global Demo Mode summary only while demo protection is active
* New: Menu Manager identifies menu and submenu items already protected by active Shield page rules and shows affected users and direct URL protection details without duplicating restrictions
* Fixed: Shield user ID handling now safely normalizes administrator records returned as objects, preventing PHP warnings in protected admin and menu integration checks
* Improved: Maintenance Center preview and content editing were refined with admin-safe preview rendering, stronger preview button contrast, and richer text color controls in visual editors

= 1.5.5 =

* Improved: Admin Suite interface refined with cleaner layouts, smoother navigation, and more consistent settings screens
* Improved: Better compatibility across login security, frontend visibility, dashboard controls, and modular addon workflows
* Improved: Module loading optimized to keep the WordPress admin experience faster and lighter when only selected features are enabled
* Improved: Responsive behavior polished across key Admin Suite screens for a more comfortable tablet and mobile admin experience
* Fixed: Minor visual and settings synchronization issues reported in selected admin screens

= 1.5.4 =

* Improved: Frontend Content Visibility editing was streamlined with a clearer access-rule workflow, making role-based hiding easier to understand on posts, pages, and supported custom post types while preserving compatibility with older saved rules
* Improved: Frontend Content Visibility now serves a dedicated Polanger protected 404 screen when denied behavior is set to 404, avoiding broken or inconsistent theme-level 404 layouts
* Improved: Login Security redirect handling and protected-route interception were hardened for unauthorized access attempts to custom login and admin entry points
* Improved: The built-in protected 404 experience was refined with cleaner messaging, a simplified layout, and WordPress 6.4+ compatibility hardening for deprecated emoji style output

= 1.5.3 =

* New: Frontend Content Visibility core module for posts, pages, and supported custom post types with role-based audience control, denied behavior routing, and discovery hiding for archives, REST API, and XML sitemaps
* Improved: Admin design system and user interface components enhanced for a better user experience.
* Improved: Mobile and responsive layouts optimized across various plugin screens.
* Improved: Enhanced security measures and hardening implemented for the Two-Factor Authentication (2FA) module.
* Improved: Translation catalogs and compiled language packs were refreshed for the current release across bundled locales

= 1.5.2 =

* Improved: Menu Manager now captures late-registered and dynamically reordered top-level admin menus more reliably, fixing cases where some third-party plugin menus did not appear in the manager list
* Improved: Menu Manager list ordering now better mirrors the effective live WordPress sidebar order for plugins that reposition themselves through custom menu filters
* Improved: Design System was expanded into a richer WCAG-aware admin theming engine with semantic color tokens, advanced typography controls, and a live preview playground
* Improved: Design System presets were redesigned into curated professional themes, with stronger compatibility across admin menus, admin bar states, metaboxes, tables, widgets, and classic editor screens
* Improved: Design System Midnight compatibility was hardened for third-party admin UI, including low-contrast text recovery and dark dropdown/menu readability fixes that only activate for the Midnight preset
* Improved: Mobile admin usability refinements across settings layouts and action controls for better spacing, responsiveness, and alignment on smaller screens

= 1.5.1 =

* Fixed: Resolved an issue where reCAPTCHA could fail to appear on the custom login page under certain configurations
* Improved: Better integration and compatibility between Authenticator App (TOTP) and reCAPTCHA verification flows
* Improved: Comment Guard reCAPTCHA integration is now more stable and reliable across comment submission scenarios
* Fixed: Resolved login page logo cropping issues on responsive and custom layout configurations
* Improved: On mobile devices, the login page language selector is now displayed inside a compact drawer for a cleaner layout
* New: Added option to completely disable the language switcher on the login page

= 1.5.0 =

* New: Authenticator App (TOTP) addon – Google/Microsoft Authenticator support with multi-user architecture, mandatory enrollment flow for required roles, profile page 2FA management, safe secret rotation (pending secret system prevents lockouts), AES-256-CBC encryption, recovery keys with auto-regeneration on rotation, trusted device memory, email fallback, and brute-force protection
* New: reCAPTCHA addon – centralized Google reCAPTCHA v2/v3 key management; all reCAPTCHA configuration consolidated from multiple locations into one dedicated addon for login, registration, lost password, and comment forms
* Improved: Design System – added Sidebar Background, Sidebar Text Color, Admin Bar Background, Admin Bar Text Color, Admin Bar Submenu Background, and Admin Bar Submenu Text Color customization options
* Improved: Design System color compatibility – enhanced contrast handling and readability corrections across admin UI components
* Improved: Menu Manager – resolved conflict issues with certain third-party plugins and themes
* Improved: Mobile responsiveness – comprehensive layout and interaction improvements across all admin screens for better tablet and smartphone usability
* Improved: 2FA settings form – resolved nested form submission issue for reliable Save Settings functionality

= 1.4.3 =

* New: Comment Security Layer addon – multi-layer comment protection with honeypot trap, HMAC-signed timing tokens, per-IP flood control (per-minute and per-hour windows), keyword and URL blocklists, behavior scoring engine with configurable thresholds, and silent action modes (spam queue, trash, or silent drop)

* Improved: Login page design – refined mobile layout with corrected form card proportions, improved spacing around inputs and buttons on small screens, and more consistent hover and focus state rendering across breakpoints

* Improved: Login page background rendering – smoother gradient transitions and better full-coverage rendering for background images on narrow viewports; improved visual layering between background and form card

* Improved: Admin panel mobile responsiveness – layout and spacing adjustments across Settings, Addons, and Activity Log screens; better usability on tablet and mobile viewports with more appropriate touch target sizing

* Improved: Sub-tab settings saves – partial save operations now only process and re-validate the submitted field group instead of the full settings object, reducing redundant sanitization passes on every tab change

* Improved: Addon list layout – card grid now wraps and spaces more cleanly on narrow viewports; improved readability of addon status indicators on mobile

= 1.4.2 =

* New: Multisite Control addon – manage network-wide defaults, lock policies, and site-level overrides from a single system
* New: Design System addon – token-based admin theming with presets, generated CSS, and extensible architecture

* New: Network-aware settings engine with effective settings merging across supported modules
* New: Network lock support for core modules (Menu Manager, Admin Bar, Login Security, Activity Log, Dashboard Center)
* New: Site-level override indicators and network-managed notices for clearer control visibility

* New: Developer hook `polanger_admin_theme_assets` for extending admin UI styling without modifying core files

* Improved: 2FA system stability and security
  - Enhanced verification flow with stronger session and user validation
  - Secure resend flow with nonce protection and stricter token handling
  - Improved trusted device and IP resolution (proxy-aware validation)
  - Login flow now respects "Remember Me" preference
  - Safer email handling with runtime checks and fallback protection
  - Automatic reset of invalid email verification states
  - Prevents enabling 2FA when email delivery is not properly configured

* Improved: Design System readability and contrast handling
  - Automatic contrast correction for dark/light surfaces
  - Improved text visibility across admin UI components (postbox, notices, tables, forms)
  - More consistent styling across WordPress admin elements

* Improved: Addon system architecture
  - Better addon activation flow with optional network-wide activation
  - Expanded developer documentation with hooks, filters, and theming examples
  - Improved extensibility for future addon-based features

* Improved: General stability, security, and internal optimizations

= 1.4.1 =
* Improved: Activity Log export flow (CSV/JSON) output handling on Settings page for more consistent downloads
* Improved: Settings export callback visibility and `admin_init` lifecycle compatibility
* Improved: Activity Log query hardening with validated table-name usage and allowlisted `ORDER BY` handling
* Improved: 2FA verification comparison updated with timing-safe hash validation (`hash_equals`)
* Improved: Activity Log IP resolution now prefers `REMOTE_ADDR` and supports trusted-proxy based forwarded-header parsing
* Improved: Settings input validation for `allowed_users` with strict array-type guards before normalization

= 1.4.0 =
* Major update: Polanger expanded into a full Admin Suite with optional addons managed from one interface
* New: Full Admin Suite experience (menu, login, security, dashboard, activity log)
* New: Custom Admin Menu Builder
* New: Role-based access control improvements
* Improved: UI/UX across all modules
* Improved: Performance and stability
* Improved: Security layers and validation
* Fixed: Minor bugs and edge cases

= 1.3.1 =
* Fixed: Prevented foreach warning when settings are missing
* Improved: Stability improvements for fresh installs

== Upgrade Notice ==

= 1.5.9 =
Adds full no-reload integrity scanning, local country blocking, Strict server hardening, enhanced Smart Contrast, complete Firewall localization, and improved mobile layouts.

= 1.5.8 =
Improves WooCommerce Security settings tab loading, PG Aurora active tab contrast, Shield/Menu Manager protection consistency, and Firewall request scoring behavior.

= 1.5.7 =
Firewall protection has safer REST compatibility behavior, including automatic WooCommerce Store API preservation in Strict mode.

= 1.5.6 =
Firewall protection modes now provide broader request hardening while plugin update notifications remain visible on the Plugins screen.

= 1.5.2 =
Maintenance release focused on Menu Manager compatibility, Design System polish, and mobile admin usability. Includes improved detection and ordering for third-party menus, more reliable Design System preset/readability behavior, and responsive UI refinements.

= 1.5.1 =
Bug fixes and improvements: Fixed reCAPTCHA display on custom login pages, improved Authenticator and reCAPTCHA integration, enhanced Comment Guard reCAPTCHA stability, fixed login page logo cropping on responsive layouts, mobile language selector now in compact drawer, and new option to disable language switcher.

= 1.5.0 =
Major security update with two new addons: Authenticator App (TOTP) featuring multi-user architecture, mandatory enrollment flow, profile page management, and safe secret rotation; reCAPTCHA addon for centralized bot protection. Design System expanded with sidebar and admin bar color controls. Improved mobile responsiveness and menu manager stability.

= 1.4.3 =
Introduces the Comment Security Layer addon with honeypot, timing tokens, flood control, scoring, and silent mode. Includes login page design refinements, improved mobile responsiveness across admin screens, and internal settings processing optimizations.

= 1.4.2 =
Adds Multisite Control plus expanded 2FA security and verification flow improvements for safer multisite-ready authentication handling.

= 1.4.1 =
Maintenance release with developer-focused security and reliability improvements across Activity Log, 2FA, and Settings validation flows.

= 1.4.0 =
Major update! Polanger is now a complete Admin Suite with modular optional addons managed from one central interface.
