== Changelog ==
= 1.8.5 - 2026-10-08 =
* Added translation support for admin screens, setup steps, emails, and notifications.
* Added German and Brazilian Portuguese translations.
* Improved output escaping for scanner error messages and email notifications.

= 1.8.4 - 2026-10-04 =
* Improved file integrity checks for known WordPress core, plugin, and theme files while keeping local hash caching for files without component details.
* Fixed deep scans flagging valid WordPress images as unknown files, and updated integrity cards to show the affected file path.
* Fixed IP detection sometimes running the same check more than once.
* Made scheduled scans more reliable when a scan is already running or the service is temporarily busy.
* Cloudflare Sync now only shows warnings when something needs your attention.

= 1.8.3 - 2026-09-30 =
* Fixed valid WordPress core files being mislabeled when their paths contain plugin or theme folders, and clarified unexpected core-file findings.
* Preserved ignored scanner findings across upgrades and rescans with versioned, locally owned finding identities and compatibility migration.
* Changed finding evidence now creates a new active issue instead of inheriting an unrelated ignore decision.
* Hardened scanner schema provisioning, multisite migration execution, and transactional ignore/unignore persistence.
* Scanner modules now return to a safe state when all of their findings are ignored, using full-result counts rather than the visible page.
* Added privacy-friendly blacklist checks for external domains found in posts, pages, and WordPress settings.
* Improved SiteFort admin styling to prevent layout and control issues caused by third-party plugins that apply aggressive global CSS resets, including Tailwind rules marked !important.

= 1.8.2 - 2026-09-25 =
* Added privacy-friendly blacklist checks for external domains found in posts, pages, and WordPress settings.
* Improved SiteFort admin styling to prevent layout and control issues caused by third-party plugins that apply aggressive global CSS resets, including Tailwind rules marked !important.

= 1.8.1 - 2026-09-02 =
** XML-RPC sign-in failures now count toward the normal login limits, appear clearly in the logs.
* Tightened safe-network range updates with stronger signature, freshness, and replay checks.
* Added automatic retries when a range update or firewall configuration refresh fails.

= 1.8.0 - 2026-08-31 =
* Improved Console delivery with a durable outbound queue and safe migration of legacy scheduled events.
* Replaced the permanent scanner watchdog with scan-scoped recovery, scheduler fallback, and bounded maintenance.
* Improved constrained-hosting recovery, queue safeguards, and firewall response handling.
* Reduced false alarms when deep scans inspect valid images or harmless placeholder files.
* Improved large-file scanning with hash analysis up to 20 MB, an 8 MB secure upload limit, and clearer results when either step is skipped.

= 1.7.13 - 2026-08-21 =
* Improved CAPTCHA management with clearer provider status, form coverage controls, and console credential sync.
* Refined 2FA setup and account management, including email-verified recovery code renewal and clearer policy states.

= 1.7.12 - 2026-08-21 =
* Added CAPTCHA support for WooCommerce My Account login, registration, and supported checkout account-creation flows.
* Added CAPTCHA integration for custom frontend login and registration forms.
* Added 2FA setup and management to WooCommerce My Account → Account security.
* Added 2FA management support for membership, LMS, client portal, and custom frontend account pages.
* Improved custom login URL compatibility across login, registration, and password reset flows.

= 1.7.11 - 2026-08-14 =
* Fixed WordPress and the early firewall resolving different visitor IPs behind CDNs, proxies, and load balancers.
* Explicit administrator IP-source choices are now honored exactly, with warnings instead of silently selecting another source.
* Conflicting forwarding headers now pause local blocking until the visitor IP source is verified.
* Improved automatic detection across rotating or unlisted CDN edges while retaining strict validation for provider and trusted-proxy decisions.
* IP verification now runs on any activated license, repeats daily, and covers all subsites on a domain.

= 1.7.10 - 2026-08-07 =
* Choosing a proxy header now takes effect on its own. It previously needed a matching trusted proxy range, and was ignored without one.
* Behind a CDN, the firewall no longer treats the CDN's address as the visitor. It pauses and asks which address is the real one.
* The address traffic reaches the site through can no longer be added to the blocklist.
* The 7-day dashboard chart was leaving out firewall blocks.

= 1.7.9 - 2026-08-05 =
* Visitor IPs are now detected automatically behind a local proxy, load balancer, or Cloudflare, instead of leaving the firewall paused.
* When detection still needs a decision, the Advanced tab shows the problem and a one-click fix.
* A paused firewall is easier to spot, with a warning icon and an amber toggle.
* An expired login session now explains what happened and how to recover, instead of showing a raw "Cookie check failed" error.

= 1.7.8 - 2026-08-04 =
* Fixed accounts getting stuck on the forced password-change screen, with the new password silently discarded.
* Fixed password reset emails containing a broken link.
* Fixed a fatal error on hosts without the mbstring and iconv PHP extensions.
* Fixed sign-in, two-factor and firewall checks reading an empty request on some hosting setups.

= 1.7.7 - 2026-07-28 =
* A Console request to connect now waits for site-admin approval instead of connecting automatically, with a dismissible admin notice and an approve or dismiss card in Settings > Integrations.
* Scanner settings (schedule, scan intensity, exclusions, and quarantine retention) can now be configured remotely from Console, without an admin needing to open WordPress.

= 1.7.6 - 2026-07-27 =
* Redesigned the Scheduled Scans settings: one on/off toggle, simpler frequency choices (Every 12 hours, Daily, Weekly), and each option now tells you exactly when it runs. Daily scans run at 2:00 AM site time.
* Notice banners for a suspended or revoked license can now be dismissed, and stay dismissed until the plan changes again.
* Polished the Scanner page's notice banners for clearer, more consistent styling.

= 1.7.5 - 2026-07-20 =
* Scanner-pattern 404 requests now count toward the Detect & Block Scanners ban threshold, so probing bots get banned instead of only rate limited.
* Sustained scanner-like 404 volume escalates to an automatic IP ban even below the per-minute limit.
* 404 handling now yields to redirects and 410 responses set by SEO plugins; scanner probes still count toward bans either way.
* Search crawler verification now runs only when a block or ban is imminent instead of on every crawler request.
* The Balanced and Maximum bot profiles now block requests that send no user agent.
* The Maximum bot profile now blocks visitors caught impersonating Google or Bing crawlers (proven by DNS verification, never on a failed lookup).
* Known SEO and service crawlers no longer accumulate scanner-ban points from stale-link 404s.
* The AI-training opt-out now lists all recognized AI training crawlers in robots.txt instead of only Google-Extended and Applebot-Extended.
* Tightened hacking-tool signatures so generic words inside legitimate app names can no longer trigger a false block.

= 1.7.4 =
* Console commands now execute and confirm in under a second instead of waiting for a background cron cycle.
* Cloudflare now connects with a single API Token: a pre-scoped token creation link, one Save & Verify step, and clearer errors for tokens with missing permissions. Global API Key auth is removed.
* MaxMind GeoIP credentials are now verified with MaxMind before saving, so a mistyped Account ID or License Key is rejected immediately instead of stored.
* The country database now refreshes weekly as intended and shows its last update time.

= 1.7.3 =
* Fixed the Vulnerabilities scan step showing as complete when vulnerabilities were found.
* Scans now recover and finish on their own if a background security check is interrupted, instead of appearing stuck.
* Improved scan speed and reduced database load, most noticeable on sites with many files.

= 1.7.2 =
* Login URL protection now recognizes browsers that previously signed in to wp-admin and sends them to the login page instead of the block page after their session expires.
* Login lockout emails now include a secure one-click unlock link that works even while you are locked out yourself.
* Redesigned the Security Overview dashboard around a single health banner with a clear next action.

= 1.7.1 =
* Moved verified search crawler and Cloudflare safe-network ranges to the SiteFort Intel feed with signed updates, bundled fallback data, and migration from the old crawler-range cache.
* Improved verified crawler handling so Google, Bing, and Cloudflare ranges never fall back to an empty set, while custom safe ranges can still be cleared from the feed.
* Added standby signing keys for safe-network feeds and scanner hash-cache proofs.
* Removed the unused firewall WHOIS/RDAP lookup endpoint so the plugin no longer makes direct RIPE or ARIN IP ownership lookups.

= 1.7.0 =
* Fixed scans appearing stuck on "Initializing" while checks were completing in the background; scan progress now shows as soon as the first check runs.
* SiteFort now detects when the host cannot run background scan processing, shows a notice explaining the reduced-speed mode and how to fix it with a server cron job, and stops sending wake-up requests that cannot succeed.
* Scans in reduced-speed mode now run several checks per status refresh instead of one, so they finish much sooner on affected hosts.
* Background worker dispatch failures are now logged with the failure reason instead of failing silently.
* Added the sitefort_scanner_worker_ack_timeout filter for slow hosts that need a longer worker dispatch timeout.

= 1.6.9 =
* Fixed Server-Level WAF updates on hosts with incompatible SiteFort data directory permissions.
* Improved Server-Level WAF errors and file-permission diagnostics for the SiteFort data directory.

= 1.6.8 =
* Updated search crawler IP verification to Google's new published range location and bundled the complete Google and Bing range lists, so genuine crawlers are recognized from the moment of installation.
* Fixed database table creation on hosts with a MyISAM default engine or legacy index size limits; installation now completes on all supported MySQL and MariaDB configurations.
* SiteFort tables now use the InnoDB engine where the server provides it, and existing installations are converted automatically.
* The Tools diagnostic now reports schema migration status, the last migration failure, and table engine details instead of a plain table count.

= 1.6.7 =
* Scan notices such as background task errors and skipped items no longer count as security findings or trigger scan alerts.
* Files too large to scan now appear as a low-severity finding with an option to delete the file.

= 1.6.6 =
* Added a configurable notification for custom login URL changes, delivered to your chosen email and webhook recipients.
* "Block AI training crawlers" now also adds Google-Extended and Applebot-Extended opt-out rules to robots.txt, covering Google and Apple AI training that cannot be blocked by user agent.
* SiteFort now registers your site over HTTPS when it is served over TLS, even if WordPress reports an http Site Address (for example behind a proxy or CDN).

= 1.6.5 =
* Improved search-engine crawler verification: Google and Bing crawlers are now also confirmed against their official published IP ranges, refreshed automatically, so genuine crawlers are recognized reliably even when a host's reverse DNS is slow or unavailable.
* Scan preflight now runs once per scan instead of repeating mid-scan, preventing needless scan-cache resets that slowed large first-time scans.

= 1.6.4 =
* Fixed ghost administrator detection being skipped during automated background scans, so hidden admin accounts are now caught on scheduled and remote scans, not just manual ones.

= 1.6.3 =
* Fixed quick scans dropping unknown and modified plugin or core file findings that a deep scan had detected; these integrity findings now persist across both scan types.
* Improved ghost administrator detection to catch admin accounts hidden from the WordPress Users list, and made suspicious admin username findings clearer.

= 1.6.2 =
* Scanner now shows clear maintenance notices and improved messaging when cloud deep-analysis limits are reached.
* Firewall traffic log now records the real user agent for pre-WordPress blocks instead of a placeholder.
* Improved CSV export formatting for audit and firewall logs, made firewall log processing more resilient to unusual entries, and refined content scanning and header checks for better reliability.
* Added an option to block AI training crawlers (GPTBot, ClaudeBot, and similar) while keeping AI assistants and AI search crawlers allowed.
* Search-engine crawlers (Google, Bing) are now confirmed by reverse DNS; requests that falsely claim to be them are blocked on the Balanced and Maximum policies, while genuine crawlers and transient DNS hiccups are always allowed through.

= 1.6.1 =
* Performance: greatly reduced the number of database queries on every page load by reading all settings in a single cached query, autoloading small status flags, and loading background and cloud work only where it is actually needed.
* Fixed a fatal error that could occur when the dashboard loaded its site health and reporting statistics.
* Hardened encryption of stored secrets with authenticated encryption bound to each storage slot, and made credential recovery safer so a temporary decryption error can no longer clear a valid connection.
* Tightened the file permissions of the plugin's encryption key.

= 1.6.0 =
* Sensitive-data scanner now reports exposed archives and backups only in the site root and wp-content, not inside uploads/plugins/themes.
* Exposed-file findings are scored by severity and confirmed more accurately to reduce false positives.
* Strong-password enforcement can now target specific user roles (defaults to Administrators); removed the rarely-used password-reuse and role-promotion options.
* Two-factor enforcement now defaults to Administrators, and the role pickers list the site's actual roles, including custom ones.
* REST API restriction now allows anonymous reads of public content for better theme and headless compatibility, while still blocking user enumeration.
* Bundled PHP libraries are now namespace-isolated to avoid conflicts with other plugins that ship the same dependencies.

= 1.5.3 =
* Fixed a fatal error when the hidden login 404 block rendered themes like Avada/WooCommerce.

= 1.5.2 =
* Improved scanner compatibility with refreshed WordPress.org file baselines.
* Improved activation validation for invalid email addresses and license keys.

= 1.5.1 =
* Added an admin compatibility notice for security plugins that may overlap with SiteFort server hardening.

= 1.5.0 =
* Improved scanner worker wakeup reliability on hosts that interrupt one-second loopback requests.
* Improved scanner cloud queue utilization and final scan log hydration on managed hosting.
* Added a secure tool to rename the default admin username with locking, transactions, multisite handling, and audit logging.

= 1.4.0 =
* Improved scanner cloud upload reliability with streamed S3 batch uploads and safer fallback handling.
* Prevented SiteFort runtime data files from delaying scan completion while preserving malicious hash detections.

= 1.3.0 =
* Improved cloud wakeup handling so completed cloud scan jobs can securely resume site polling without requiring the admin console.

= 1.2.0 =
* Fixed scan finding notification actions to open the scanner page instead of the dashboard.
* Added concise contextual copy to SiteFort notification emails before scan, firewall, vulnerability, digest, and fallback event details.
* Improved scanner findings empty states and vulnerability remediation card updates during active scans.

= 1.1.0 =
* Improved scanner worker recovery and server-load interruption messaging.
* Optimized setup wizard two-factor loading with a consolidated overview request.
* Hardened command queue and login lockout cleanup to prevent stale database growth.

= 1.0.2 =
* Bundled shared timestamp parsing into the admin shared asset to avoid a separate time chunk.

= 1.0.1 =
* Hardened automated scan scheduling with scanner-owned cron intervals, boot-time reconciliation, site-time run alignment, and stale schedule cleanup.
* Fixed audit log, dashboard, and firewall timestamps to use UTC event time consistently.
* Fixed dashboard and report daily totals to respect the WordPress site timezone instead of the server or database timezone.
* Added site-time display and CSV export fields for audit events while keeping UTC as the canonical timestamp.
* Updated file logs to write ISO-8601 UTC timestamps and retain legacy UTC log parsing.

= 1.0.0 =
* Initial release
