Vardalion Security 2.3.0
- Added local WordPress comment anti-spam protection.
- Added untrusted post anti-spam inspection with Pending Review handling.
- Added anti-spam settings and configurable thresholds.
- Added administrator-only Anti-Spam Diagnostics with controlled checks and no content creation.
- Fixed anti-spam URL detection for www-prefixed and bare domains, and included the comment author URL in analysis.
- Added a regression diagnostic for the real-world seven-www-link spam pattern.
- Fixed the default comment scoring so five or more detected links independently reaches the default spam threshold.
- Anti-spam detections now dispatch the existing Vardalion security-alert action so enabled email alerts can report them.
- Added a branded HTTP 403 Vardalion block screen for high-confidence comment spam, with an option to retain the WordPress spam-queue workflow.
- Added conservative single-link intelligence for shortened/punycode destinations and 30-day local destination-domain reputation learned only from high-confidence spam.
- Added legitimate and suspicious single-link diagnostics.
- Rebuilt every enforcement screen with a unified high-impact Vardalion visual system and category-specific threat accents.
- Integrated the anti-spam 403 response into the shared block-page renderer and added a Comment Spam Block admin preview.
- Fixed anti-spam security-log events so the Points column records the actual spam classification score instead of zero.
- Audited threat-score block logging: automatic IP block events already retain the resulting threat score; policy/manual range events remain zero because no threat score triggers them.
- Fixed the admin block-page preview validator to allow the new Comment Spam Block preview.
- Resolved WordPress.org Plugin Check warnings in anonymous anti-spam form handling, diagnostics, and settings-view variable prefixing.
- Fixed Vardalion email sender display name to use the WordPress Site Title.

Vardalion Security 2.2.12
--------------------------
* Fixed remaining controller/view variable mismatches found during the release audit.
* Restored recent events and today's event count on the main dashboard.
* Restored subnet data on IP Intelligence.
* Restored today's event count in the WordPress dashboard widget.
* Retains the Security Log, Blocked IPs, SQL and block-page fixes from 2.2.8-2.2.11.

Vardalion Security 2.2.11
--------------------------
* Fixed malformed block-response HTML that caused unstyled/oversized block pages.
* Restored a valid viewport declaration and WordPress-enqueued external stylesheet output.
* Retains the Security Log and Blocked IPs fixes from 2.2.8-2.2.10.

Vardalion Security 2.2.10
--------------------------
* Fixed Blocked IPs rows not rendering because the controller populated `$blocks` while the view expected `$wpaegis_blocks`.
* Retains the Security Log fixes from 2.2.8 and 2.2.9.

Vardalion Security 2.2.9
-------------------------
* Fixed Security Log rows not rendering because the controller populated `$events` while the view expected `$wpaegis_events`.
* Retains the 2.2.8 SQL query correction.

Vardalion Security 2.2.8
-------------------------
* Fixed Security Log pagination showing matching event totals while the event table was empty.
* Avoids re-preparing already-prepared filter SQL when applying pagination.

2.2.7
- Replaced the final dynamic cursor comparison expression with fixed prepared SQL branches.
- Resolves the remaining Plugin Check PreparedSQL errors.

2.2.6
- Corrected event-log prepared-query placeholder handling.
- Prepared filter values while constructing validated WHERE fragments.
- Replaced dynamic sort interpolation with fixed ASC/DESC query branches.
- Corrected pagination and export prepare() replacement arguments.

2.2.5
- Refactored event-log database calls to pass prepared SQL directly to WordPress database methods.
- Removed intermediate SQL variables flagged by Plugin Check.
- Preserved validated filters and uncached real-time audit-log behaviour.

2.2.4
- Converted the final dynamic security-table identifiers to WordPress `%i` placeholders.
- Documented intentional uncached audit-log reads.
- Completed the final full Plugin Check warning-remediation pass.

2.2.3
- Reworked dynamic table queries to use WordPress identifier placeholders.
- Documented intentional uncached direct database access for security enforcement and audit logging.
- Documented explicit uninstall schema cleanup for plugin-owned tables.
- Further reduced full Plugin Check warnings.

2.2.2
- Hardened WordPress Plugin Check compliance.
- Added translator context for formatted email-alert strings.
- Improved request sanitization and documented intentional read-only GET processing.
- Improved database identifier preparation and documented controlled security-table queries.
- Removed the explicit close of the streamed CSV output handle.
- Prefixed template variables reported by WordPress Coding Standards.

2.2.1
- Renamed the public WordPress.org identity to Vardalion Security.
- Updated public branding and logo assets.
- Moved the standalone block-response CSS to an enqueued stylesheet.
- Removed the obsolete load_plugin_textdomain() call for WordPress.org distribution.
- Preserved all established wpaegis_* internal compatibility identifiers.

2.2.1-dev.2
- Fixed the Vardalion Security WordPress admin submenu after the branding refresh.
- Restored the internal parent menu slug `wp-aegis` for Blocked IPs, IP Intelligence, Blocked Networks, Security Log, Block Page Preview and Settings.
- No security data, licensing, Pro API or database identifiers changed.

Vardalion Security changelog

2.2.0
- Introduced the permanently free Vardalion Security Core architecture.
- Removed licence, trial and third-party executable updater implementation from Core.
- Added the extension service registry for separately distributed companion plugins.
- Preserved existing security database schema and shared Core settings for upgrade compatibility.
- Retained firewall, brute-force protection, threat scoring, automatic IP blocking, repeat-offender escalation, logging, IP intelligence, manual network blocking and Emergency Mode.
- Corrected maintenance diagnostics to check Core-owned schedules only.
- Removed stale licensing/updater-development UI references.
- Reworked readme.txt for WordPress.org submission requirements and external-service disclosure.
- Added a Core-to-Pro comparison screen and dashboard callout that are hidden automatically when Pro is active.
- Added a prominent Upgrade to Pro button to the main dashboard hero when Pro is not installed.
- Ensured standard third-party/WordPress admin notices remain readable on Vardalion Security admin screens.
- Fixed the Vardalion Security Pro comparison page layout so it no longer inherits compact dashboard flex styling.
- Removed the false maintenance warning for the obsolete wpaegis_reputation_sweep cron schedule.
- Added suggested Vardalion Security data-processing text to the WordPress Privacy Policy Guide.
