iThemes Security


De beste WordPress beveiliging plugin om WordPress te beschermen

On average, 30,000 websites are hacked every day. Every 39 seconds, a new cyberattack happens somewhere on the web.

The good news is that most security disasters can be prevented. Using iThemes Security, you can identify and stop attacks on your website. Saving yourself the time and cost of repairing a hacked website.

Beveilig je site in minuten

The iThemes Security setup and onboarding experience is designed to allow anyone to secure their WordPress website in under 10 minutes, without needing a degree in cybersecurity.

Knowing that you have enabled all the right security settings for your website will leave you feeling like your site has never been more secure.

Security Site Templates to Fit Your Type of Site

An eCommerce site requires a different level of security than your average blog. iTheme Security Site Templates make it quick and easy to apply the right security settings for your website.

Choose from six different site templates to apply the type of security your site needs:
1. Ecommerce – websites that sell products or services
2. Network – websites that connect people or communities
3. Non-Profit – websites that promote your cause and collect donations
4. Blog – websites that share your thoughts or start a conversation
5. Portfolio – websites that showcase your craft
6. Brochure – simple websites that promote your business

Real-Time Website Security Dashboard

Every day, lots of activity is happening on your website that you can’t see. Many of these activities can be related to your site’s security, so monitoring these events is vital to keeping your site secure.

The iThemes Security Pro plugin provides a real-time WordPress security dashboard that monitors security-related events on your site around the clock. The iThemes Security Dashboard is a dynamic dashboard with all your WordPress website’s security activity stats in one place, including brute force attacks, banned users, active lockouts, site scan results, and user security stats (Pro).

WordPress login beveiliging

Beveilig je WordPress login met verschillende lagen van beveiliging

  • Two-Factor Authentication (2FA) – Make your WordPress login nearly impenetrable to attack by requiring users to enter a security code along with a password to login. The iThemes Security plugin allows you to add two-factor authentication to your WordPress login with several authentication methods, including mobile apps like Authy and Google Authenticator, email, and backup codes.
  • Password Requirements – Create and enforce a password policy for your users in less than a minute.
  • reCAPTCHA (Pro) – Stop bad bots from engaging in abusive activities on your website, such as attempting to break into your website using compromised passwords, posting spam, or even scraping your content.
  • Passwordless Logins (Pro) – WordPress security made easy. Secure your user accounts with 2fa & strong passwords while allowing real users login with a click of a mouse.
  • Trusted Devices (Pro) – Identify the devices you and other users use to block session hijacking attacks and limit Administrator privileges to Trusted Devices.

The Right Amount of Security for Every User Level

Different types of user levels require different levels of security. During the iThemes Security setup process, you can identify your website’s key user groups. Once the different types of users are identified, you can apply the level of security that is just right for each user group.

Hier zijn een aantal voorbeelden van hoe gebruikersgroepen nuttig zijn voor het beveiligen van je site:

  • For Clients – Let’s say you are configuring iThemes Security on a client’s website. You will decide whether or not they are required to use two-factor authentication and if they should have access to the iThemes Security settings.
  • For Customers – If you have an eCommerce website, you will decide whether or not you want to protect customer accounts with a password policy.

Machtiging verhoging (Pro) voegt ook een veilige manier toe om tijdelijke toegang op beheerdersniveau tot je site te verlenen.

Block Bad Bots & Ban User Agents with Lockouts

  • Ban Users – Permanently block repeat offenders from accessing your site.
    Local Brute Force Protection – Automatically identify and stop the most common method of attack on WordPress sites.
  • Network Brute Force Protection – The network is the iThemes Security community and is over a million websites strong. If someone tries to break into websites in the iThemes Security community, iThemes Security will block them across the network.
  • Magic Links (Pro) – Security shouldn’t get in your way. Magic Links allow you to log in to your WordPress site while your username is locked out by the iThemes Security Local Brute Force Protection feature.

Monitor Your Site’s Security Health

  • File Change Detection – iThemes Security logs changes made to your website that can help detect malicious activity on your website.
  • Site Scanner – Enable twice-daily checks for known vulnerabilities of WordPress core file, plugins and themes. Using the Google Safe Browsing API, the Site Scan also checks your Google’s blocklist status and will alert you if Google has found any malware on your website.
  • Site Scanner (Pro) – Unlock Version Management to automatically apply a patch to vulnerable software detected by the Site Scan when one is available.
  • User Logging (Pro) – Keep a record of user activity in your WordPress security logs, including login/logout, user registration, adding/removing plugins, switching themes, changes to posts and pages, and more.
  • Version Management (Pro) – The Version Management feature in iThemes Security Pro allows you to auto-update WordPress, plugins, and themes. Beyond that, Version Management also has options to harden your website when you are running outdated software and scan for old websites.

Sitebeveiliging hulpmiddelen

  • Enforce SSL – Force all connections to the website to be made over SSL/TLS.
  • Database Backups – Create backups of your WordPress database. (Not a complete backup.)
  • Geolocation (Pro) – Improve Trusted Devices by connecting to an external location or mapping API.

Geavanceerde beveiligingsgereedschappen

  • Identify Server IPs – Prevent issues caused by inadvertently locking out your server IPs.
  • Change User ID 1 – Change the user ID for the first WordPress user.
  • Change Database Prefix -Change the database prefix that WordPress uses.
  • Check File Permission – See the file and directory permissions of key areas of your site.
  • Server Config Rules – View or flush the server security rules generated by iThemes Security.
  • wp-config.php Rules – View or flush the wp-config.php security rules generated by iThemes Security.
  • Change WordPress Salts – Secure your site after a successful attack by changing the WordPress salts used to secure cookies and security tokens.
  • Hide Login URL – The Hide Backend setting can change the login URL of your site.

Heb je hulp nodig?

Gratis ondersteuning is mogelijk beschikbaar met de hulp van de community in support forums(Let op: dit is community-ondersteuning geboden iThemes niet bijhoudt in support. Forums ).

Ons Hulp centrum zal je helpen een iThemes Security expert te worden.

Get added peace of mind with professional support from our expert team and pro features to take your site’s security to the next level with iThemes Security Pro.

Herstel van een gehackte site

iThemes Security makes regular backups of your WordPress database, allowing you to get back online quickly in the event of a hack or security breach. Use iThemes Security to create and email database backups on a customizable schedule.

Voor volledige site backups en de mogelijkheid om WordPress te herstellen of verplaatsen naar een nieuwe host of domein, bekijkBackupBuddy.


Laat het ons weten als je wil bijdragen aan een vertaling.

iThemes Sync integratie

Meer dan één WordPress site beheren ? Release blokkades opheffen en je thema’s , plugins en WordPress core up-to date houden vanaf één dashboard met iThemes Sync Pro.Begin met je gratis trial van Themes Sync Pro.


Uitgebracht onder de voorwaarden van de GNU General Public License.


  • Security Site Templates to Fit Your Type of Site
  • Real-Time Security Dashboard
  • WordPress login beveiliging
  • Block Bad Bots & Ban User Agents with Lockouts
  • Monitor Your Site's Security Health
  • Sitebeveiliging hulpmiddelen
  • Geavanceerde beveiligingsgereedschappen


Waarom heeft iThemes Security de nieuwste WordPress-versie nodig? Kan ik een iets oudere versie niet gebruiken?

  • Een van de beste beveiligingsmethoden voor een eigenaar van een WordPress- site is het up-to-date houden van software. Daarom testen we deze plug- in alleen op de nieuwste stabiele versie van WordPress en garanderen alleen dat deze in de nieuwste versie werkt.

Will this plugin completely stop all attacks on my site?

  • No. iThemes Security is designed to help improve the security of your WordPress installation from many common attack methods, but it cannot prevent every possible attack. Nothing replaces diligence and good practice. This plugin makes it a little easier for you to apply both.

Is deze plug-in alleen voor nieuwe WordPress-installaties of kan ik deze ook op bestaande sites gebruiken ?

  • Veel van de wijzigingen die door deze plugin worden aangebracht, zijn complex en kunnen bestaande sites doorbreken . Hoewel iThemes Security op een nieuwe of bestaande site kan worden geïnstalleerd , raden we je ten zeerste aan eenvolledige backupvan je bestaande site voordat je functies in deze plugin toepast .

Werkt deze plugin op alle servers en hosts?

  • iThemes Security vereist dat Apache of LiteSpeed ​​en mod_rewrite of NGINX werken.

Welke veranderingen brengt deze plugin aan die mijn site kapot kunnen maken?

  • iThemes Security makes significant changes to your database and other site files which can be problematic for existing WordPress sites. Again, we strongly recommended making a complete backup of your site before using this plugin. While problems are rare, most support requests involve the failure to make a proper backup before installation. DISCLAIMER: Under no circumstances do we release this plugin with any warranty, implied or otherwise. We cannot be held responsible for any damage that might arise from the use of this plugin.
  • IThemes beveiligingsvergrendelingen repareren
  • Wat is er gewijzigd door iThemes Security


7 september 2023
I’ve been using iThemes for a while . It's super user friendly and when I do need support, it’s been quick and professional.
25 juli 2023
When paired with Cloudflare for added security, this plugin is nice and lightweight. It's secure enough when you already have other security measures on your website and good hosting. I do wish they had an option to disable reporting vulnerable software every time a plugin was one miner version behind on updates, especially since I have an auto update plugin on my website. Other than that, if you have good and secure hosting, and are using a cloudflare dns, this is a good and lightweight plugin. (note: I'm also using nginx instead of apache).
17 juli 2023 4 reacties
I installed the plugin, and set up to receive newsletters related to the plugin.First day, 256 emails. I said ok, they sent me some to catch up.second day 324Third day, in the first 12 hours, 183… And I'm only talking about the newsletters, on top of that, you have to add the emails that the plugin sends from the web to warn of problems.So, if you decide to install the program, be prepared to receive around 500 emails per day… enjoy it… not meif I try to cancel the newsletter? I sure did. but, they keep coming and coming and coming.If I tried to contact support? I sure did. and they told me that I could deactivate it from the control panel (which I had already done and explained in the email I sent them) and that the records did not appear as a paid user…
17 juni 2023
I've tried a few, but even the free version of iThemes plugin already did more than the others which I can't name. Excellent and thank you.
Lees alle 3.918 beoordelingen

Bijdragers & ontwikkelaars

“iThemes Security” is open source software. De volgende personen hebben bijgedragen aan deze plugin.


“iThemes Security” is vertaald in 19 talen. Dank voor de vertalers voor hun bijdragen.

Vertaal “iThemes Security” naar jouw taal.

Interesse in ontwikkeling?

Bekijk de code, haal de SVN repository op, of abonneer je op het ontwikkellog via RSS.



  • News: iThemes Security is becoming Solid Security soon. Learn More:


  • Important: Enforce encryption for Two-Factor secrets.
  • Tweak: Add Stellar and Solid banners.
  • Bug Fix: Don’t require “Write to Files” to be enabled to use the “Rotate Encryption Key” tool.


  • Bug Fix: Fallback to the homepage when Enforce SSL encounters a non-safelisted redirect destination.
  • Bug Fix: IP Detection on sites behind Load Balancers that appended their IP address to X-Forwarded-For and did not provide a Real IP header.


  • Security Hardening: Prevent open redirects attacks against the Enforce SSL module. This attack requires spoofing the Host header which requires additional conditions to exploit. Thanks to nlpro for reporting the issue. Read More:
  • Bug Fix: Update Password Strength library to the latest version. This fixes discrepancies between the realtime password strength estimation and the enforced password strength.


  • Tweak: Add “All” tab to the Features page.
  • Tweak: Don’t show “Ban” buttons in Security Dashboard if the user won’t be able to create a ban.
  • Bug Fix: Prevent Headers Already Sent warning when a lockout occurs during a WP Cron request on some server setups.
  • Bug Fix: Manually load Sodium Polyfill for servers that have an older version of libsodium installed.
  • Bug Fix: Error when saving the File Change settings when the “notify_admin” setting was set.
  • Bug Fix: Prevent a redirect loop when logging in on sites that take more than 5 seconds to load the Dashboard.


  • Important: iThemes Security now requires PHP 7.3 and WordPress 5.9 or later.
  • Security: Add support for encrypting Two-Factor Mobile App secrets. Enable via Tools -> Set Encryption Key.
  • Security: Deprecate Automatic Proxy Detection. Instead, manually configure Proxy Detection or use Security Check. Fix IP spoofing attacks.
  • Enhancement: Add “Ban Lockout” button to the Active Lockouts card.
  • Bug Fix: File Logs not rotating.
  • Bug Fix: PHP warning when loading Icon Fonts in certain configurations.
  • Bug Fix: Don’t attempt to Hide Backend when a Cron request is being processed.
  • Bug Fix: Prevent entering invalid date values when selecting a custom date range in the Security Dashboard.
  • Bug Fix: Preliminary PHP 8.1 compatibility.
  • Bug Fix: File Change “notify_admin” settings validation error.
  • Thanks to Calvin Alkan for reporting the security issues fixed in this release.


  • Tweak: Require a Title when creating a new Dashboard.
  • Bug Fix: Don’t attempt to send a Site Scan notification for Clean scans preventing a fatal error after scheduled site scans.


  • Bug Fix: Error when visiting the Notifications page after activating a module with notifications for the first time.
  • Bug Fix: Update deprecated withState usages to useState.


  • Important: iThemes Security now requires WordPress 5.8 or later.
  • New Feature: Include the full iThemes Security Site Scanner in iThemes Security Free. Scheduled scans are disabled by default.
  • Tweak: Add new “Go Pro” page that includes an overview of features in iThemes Security Pro.
  • Bug Fix: Scroll to top of window when navigating.
  • Bug Fix: Allow searching for Password Requirements.
  • Bug Fix: Don’t load WordPress and System Tweaks modules when the ITSEC_DISABLE_MODULES constant is enabled.
  • Bug Fix: Prevent incidentally loading the Two-Factor module when it is unregistered.
  • Bug Fix: Conditionally display the NGINX File Path setting.
  • Bug Fix: Allow saving Notifications when “default recipients must contain at least 1 item” error is present.
  • Bug Fix: Help styling on WordPress 5.9.
  • Bug Fix: Compatibility with plugins that expected a logged-in user during lockouts.


  • Enhancement: Reintroduce Feature Flags management UI.
  • Tweak: Reposition “Advanced” and “Tools” menu items to be more readable on lengthy screens.
  • Bug Fix: When the Change Admin User tool is run, update any User Groups referencing the old user id.
  • Bug Fix: WordPress footer would appear in the middle of the logs page.
  • Bug Fix: Add missing translation strings file.


  • Bug Fix: Sites that did not support HTTPS, but had the SSL module active, but not configured, on upgrade would get redirected to the HTTPS version of the site.
  • Bug Fix: Unregister the iThemes Security Two-Factor module when the Two-Factor Feature Plugin is enabled.
  • Bug Fix: Allow activation on WordPress 5.7.0.
  • Bug Fix: Add missing textdomains.


  • Important: iThemes Security now requires WordPress 5.7 and PHP 7.0 or later.
  • New: iThemes Security gets a redesigned interface focused on making it easier to configure and find what you’re looking for. Read More:
  • New: Instantly search over everything in iThemes Security with a new instant search feature.
  • New: Security Tools have been grouped into their own page. “Identify Server IPs” and “Security Check Pro” can be run manually without using Debug Mode.
  • New: Relevant content from the Help Center, iThemes Blog, and iThemes YouTube channel is surfaced in a new Help area based on the current page. Click the “Help” button in the toolbar or the “Info” icon next to the page title to access it.
  • New: The settings UI is now fully responsive and works great across mobile, tablet, and desktop devices.
  • New: Two-Factor is now part of the core iThemes Security plugin.
  • Enhancement: Improved keyboard and screen reader support.
  • Enhancement: The Banned Users Card can add multiple bans at once.
  • Tweak: Add a new Global setting to control “Automatically Temporarily Authorize Hosts”.
  • Tweak: When the Global setting “Hide Security Menu in Admin Bar” is enabled, notices will no longer be printed on non-iThemes Security pages. Instead, you can access the Message Center from the Settings or Dashbaord toolbars.
  • Tweak: The Database Backups module is no longer available if you have BackupBuddy installed. If this behavior isn’t desired, enable the “ITSEC_ENABLE_BACKUPS” constant.
  • Tweak: The Geolocation API configuration used by Trusted Devices has been moved into it’s own dedicated “Geolocation” module.
  • Tweak: Move “Have I Been Pwned” integration to the Core plugin.
  • Tweak: Reduce filename length and complexity for built CSS and JS files.
  • Removed: The following modules have been removed: 404 Detection, Away Mode, Change Content Directory, and Multisite Tweaks.
  • Removed: The following WordPress and System Tweaks have been removed: Remove Windows Live Writer Header, EditURI Header, Comment Spam, Mitigate Attachment File Traversal Attack, Protect Against Tabnapping, Filter Long URL Strings, Filter Non-English Characters, Filter Request Methods, Remove File Writing Permissions.
  • Removed: The “Backup Full Database” setting has been removed from the Backups module.
  • Removed: The “Require SSL”, “Front End SSL Mode”, and “SSL for Dashboard” settings have been removed from the SSL module.
  • Bug Fix: Fix fatal errors when using PHP 8.
  • Bug Fix: Fix infinite loop when restricting who can use App Passwords on multisite installs.
  • Bug Fix: Ensure the ITSEC_Setup class does not exist before trying to load it. Display schema errors on multisite in the Network Admin.
  • Bug Fix: Labels for Disable PHP Execution in Plugins and Themes were reversed.
  • Bug Fix: Add missing constants to the debug page.
  • Bug Fix: Remove deleted recipients when saving notifications.
  • Bug Fix: Correct Site Scan statuses for scans with no issues.
  • Dev Note: Modules are now based on a module.json configuration file. If you are registering custom iThemes Security module, you should update it to include a module.json file that adheres to the core/module-schema.json JSON Schema.
  • Dev Note: The Network Brute Force module had it’s folder updated to “network-brute-force” from “ipcheck”.
  • Dev Note: New Object Oriented API for creating Password Requirements.
  • Dev Note: New Settings and Modules REST API endpoints.
  • Dev Note: New RPC REST API namespace. There is no backward compatibility promise for these API endpoints.


  • Security: Fix Hide Backend Bypass, thanks to Julio Potier for reporting the issue.
  • Tweak: Add filters to short-circuit lock APIs.
  • Tweak: Remove non-SSL fallbacks for Security Check Pro and Version Management.
  • Bug Fix: Tweak checkbox styles.
  • Bug Fix: Improved compatibility with WP Engine.
  • Bug Fix: Pass the WP_Error object to the wp_login_failed hook.
  • Bug Fix: Prevent wp_no_robots deprecation warning on WordPress 5.7.


  • Important: iThemes Security requires WordPress 5.4 or later.
  • Enhancement: Add a setting for configuring the number of bans added to the server config files (.htaccess/nginx.conf).
  • Enhancement: Store the time a ban was added, and the lockout module responsible for the ban.
  • Enhancement: Overwrite Restrict Content Pro’s detected IP address with the IP detected by iThemes Security.
  • Tweak: Disable SSL verification when performing the Security Check Loopback test. Some hosts can’t properly verify loopback requests. This verification is unnecessary in this circumstance, and disabling SSL verification aligns iThemes Security with default WordPress loopback behavior.
  • Bug Fix: PHP warnings when invalid entries are stored in the WordPress Cron storage.
  • Bug Fix: Update the list of tables added to wpdb.
  • Bug Fix: Remove default value for text columns. This caused an issue on MySQL 8 and is unnecessary.
  • Bug Fix: Missing borders in the sidebar widgets on WordPress 5.5.
  • Bug Fix: Notice actions didn’t trigger when “Hide Admin Bar” is enabled.
  • Bug Fix: Some users would be force to choose a strong password twice in a row.
  • Bug Fix: Warning when saving the Ban Users module outside of the Settings Page without passing the legacy host_list setting.
  • Bug Fix: Passwords Requirements compatibility with Restrict Content Pro.
  • Bug Fix: PHP warnings that may occur when initializing default user groups on a new installation.


  • New Feature: The new, improved WordPress Security Site Scan powered by iThemes checks if Google has detected malware and added your site to their threat list.
  • Enhancement: Remove quick bans. Persist banned hosts to .htaccess or nginx.conf on an hourly schedule.
  • Tweak: Cap banned hosts persisted to .htaccess or nginx.conf to the most recent 100. This number can be adjusted with the “itsec_ban_users_max_hosts_for_server_config” filter. Older banned hosts will be locked out after WordPress loads.
  • Tweak: Ensure randomly generated passwords are considered strong by the Strong Passwords library.
  • Tweak: Suggest a 32 character password when forcing a password change.
  • Tweak: Change insensitive language to be more inclusive.
  • Bug Fix: PHP warning when a user’s email address is updated outside of the user edit admin page.
  • Bug Fix: Fix login interstitials on WP Engine when using a front-end login form.
  • Bug Fix: PHP warning when checking opaque tokens.
  • Bug Fix: PHP warning after successfully connecting a site to iThemes Sync via the login connection flow.
  • Bug Fix: File Change Security Message would not appear for new installs.


  • Bug Fix: PHP warning when evaluating password requirements.


  • Important: iThemes Security requires PHP 5.6 or greater and WordPress 5.2 or greater.
  • New Feature: Save Time Securing WordPress With User Groups!
  • New Feature: Simplified connection flow when setting up iThemes Sync.
  • Enhancement: Add a warning if a WordPress Salt is set to an invalid value.
  • Enhancement: Include child log items in the logs list table. These are helpful for debugging issues.
  • Enhancement: Improve performance of the logs page on sites with large number of log items.
  • Enhancement: Check tables exist after completing a DB upgrade.
  • Tweak: When logging $_SERVER, only log a snapshot of available properties.
  • Bug Fix: The “Mulisite Tweaks -> Hide Updates” setting prevented auto-updates from running with WP Cron.
  • Bug Fix: Backup event was not added when the WP Cron Scheduler was reset manually.
  • Bug Fix: Admin Notices Popover was not being hidden when clicking outside the Popover on WP 5.3.
  • Bug Fix: New Password Requirements for already created accounts were not enforced until the second login.
  • Bug Fix: Update admin notices styling to be compatible with WordPress 5.4.
  • Bug Fix: Periodically clear expired opaque tokens.
  • Bug Fix: Don’t block registration page when “wp-signup.php” is the Hide Backend register slug.
  • Bug Fix: Users with weak passwords would not be forced to change their password if the strong password requirement had been enabled after their password strength was checked.
  • Bug Fix: Remove “get_magic_quotes()” call that existed for backwards compatibility with PHP versions 5.3 and earlier. This function call was causing a warning on PHP 7.4.
  • Bug Fix: Warning when loading the settings page on PHP 7.4.
  • Bug Fix: Warning when loading the debug page on PHP 7.4.


  • Bug Fix: Properly notate that iThemes Security requires PHP 5.5 or greater.


  • Breaking Change: iThemes Security requires PHP 5.5 or later.
  • New Feature: iThemes Security now includes Security Check Pro to automatically and correctly determine your visitors IP addresses. Enable this scan by running Security Check and opting in to Security Check Pro or activate the Security Check Pro module in Advanced Modules. H/t Jeremy Voisin
  • Enhancement: Run Security Check Pro IP Detection automatically once a day.
  • Enhancement: Manually re-run Security Check Pro IP Detection from the Global Settings page.


  • Breaking Change: iThemes Security requires PHP 5.4 or later.
  • Enhancement: New Lockout Template screen.
  • Enhancement: Add confirmation button to Login Interstitial Async Actions when on a different device.
  • Enhancement: Add filter to “Lookup IP” link.
  • Developer Note: There were significant changes to the internals of the iThemes Security Lockout API in this release. If you are using the ITSEC_Lockout class directly, all the API functions will continue to work, but will emit deprecation notices when legacy behavior is being used. Please update any integrations.
  • Bug Fix: Brute Force module reporting invalid logins using an email address incorrectly.
  • Bug Fix: Improve lockout compatibility with caching plugins.
  • Bug Fix: Fix admin notice not being dismissed due to a REST API route that was more narrowly defined than necessary.
  • Bug Fix: Admin Notices list did not refresh after dismissing a notice.
  • Bug Fix: Strong Passwords zxcvbn Library was not evaluating penalty strings correctly.
  • Bug Fix: Fix PHP warning if there are multiple detected proxy headers.


  • Enhancement: New iThemes Sync Verb support for File Change.
  • Tweak: Add additional information about the login attempt when calling the Network Brute Force API.
  • Bug Fix: Hide Backend Bypass.
  • Bug Fix: Strict Standards error during Sync request.
  • Bug Fix: wp_die() if a login interstitial session fails to be created instead of throwing a fatal error.


  • New: iThemes Security Admin Notices are now conveniently located in the new Security Messages Menu. Check your notices in the Security menu on the WordPress Admin Bar.
  • Enhancement: Add Security Message when a Notification Center email fails to send.
  • Enhancement: Replace Trace IP with IP Tracker Online.
  • Tweak: Remove ‘DELETE’ method from “System Tweaks -> Filter Request Methods”


  • Bug Fix: Hide backend bypass.


  • Tweak: laat de log- beschrijvingskolom toe om te breken voor URL’s of andere tekenreeksen zonder spaties.
  • Bug Fix: Hide Backend bypass on certain Apache configurations.
  • Bug Fix: Properly return error that occurs during a backup.
  • Bug Fix: Regex warning on PHP 7.3 in the File Change module.
  • Bug Fix: Resolve warning when a user is set to “No Role”.


  • Verbetering: als ITSEC_DISABLE_MODULES is ingesteld, voorkomt u dat de backend van de hide wordt uitgevoerd.
  • Bug Fix: Tabnapping: Apply noopener to links instead of using blankshield script when available to prevent new pop-up blocker behavior from killing the links.


  • Enhancement: Add Per-Content SSL toggle to the upcoming Block Editor interface.
  • Enhancement: Add filter to the recipients list for email notifications: “itsec_notification_{$notification}_email_recipients” and “itsec_notification_email_recipients”.
  • Verbetering: Voeg definitie toe “ITSEC_DISABLE_TEMP_WHITELIST” om de tijdelijke IP Whitelisting voor ingelogde beheerders uit te schakelen.
  • Verbetering: verbeter het omleiden na het verwerken van een aanmeldingsinterstitial van een front-end inlogformulier.
  • Verbetering: voeg loopback-IP-detectie toe aan beveiligingscontrole.
  • Verbetering: detecteer server-IP’s in beveiligingscontrole.
  • Tweak: voeg extra veiligheidscontroles toe wanneer je naar systeem configuratiebestanden schrijft. Dit zal een “kritieke kwestie” registreren wanneer het schrijven van een leeg of gedeeltelijk configuratiebestand wordt gedetecteerd en voorkomen.
  • Tweak: Verbetering van vergrendeling verbeteren om niet-werkende scans op sites met inconsistente cron-planning te voorkomen.
  • Tweak: Verbeter “System Tweaks – Suspicious Query Strings – SQLI” om valse positieven te verminderen.
  • Tweak: Verbeter “System Tweaks – Deactiveer PHP” om PHP-bestanden te blokkeren in apache-configuraties die bestanden met een slepende stip serveren.
  • Tweak: Verwijder “Seznam Bot” van HackRepair List omdat deze niet aanwezig is in de laatste versie.
  • Bug Fix: Include Hide Backend token when emailing a password reset URL.
  • Bugfix: Berichtencentrum – Stuur alleen meldingen naar gebruikers met een exacte rol match van geselecteerde rollen in plaats van een fuzzy match op basis van geselecteerde mogelijkheden.
  • Bug Fix: Error when trying to edit reusable blocks with per-post SSL enabled.
  • Bugfix: waarschuwingen op PHP oplossen 5.2.


  • Verbetering: toestaan dat de specifieke proxy- header wordt geselecteerd waarop een server is geconfigureerd. Verbeter de taal om aan te geven hoe belangrijk het is om deze instelling te configureren. H / t Filippo Cavallarin CEO bij
  • Verbetering: blokkeer toegang tot git- en svn-bibliotheken wanneer Systeemaanpassingen -> Bescherm systeembestanden is ingeschakeld.
  • Tweak: update de jQuery-validatiebibliotheek naar 1.17.0
  • Bug Fix: Improve detection of blocking the File Change Scan from being scheduled if one is already being run.
  • Bug Fix: Prevent infinite recursion error when trying to access directories outside of the allowed file tree.


  • Nieuwe functie: toestaan voor het globaal instellen van ontvangers voor beheerde meldingen. Alle nieuwe meldingen zijn standaard voor de ontvangers in deze lijst. Meldingen kunnen worden ingesteld om de standaardlijst te gebruiken of om naar een aangepaste lijst te schakelen.
  • Enhancement: Added a setting to enable/disable the Grade Report feature of Pro.
  • Tweak: Check if an IP is blacklisted on page load for compatibility with servers that cannot process server configuration level bans immediately.
  • Tweak: Display a time diff until the next event on the Debug page.
  • Tweak: Use Logging API for tracking Notification Center errors.
  • Tweak: Register Scheduler Events whenever the plugin build changes.
  • Tweak: Allow for filtering logs by any module recorded.
  • Tweak: account voor externe back- upplug- in bij beveiligingscontrole.
  • Bug Fix: 404 detection for plugins that mark is_404 later in the hook sequence.
  • Bugfix: REST API-beveiliging blokkeerde de Taxonomies-route voor alle gebruikers.
  • Bugfix: account voor elke CLI PHP SAPI in plaats van alleen WP-CLI in de SSL-module.
  • Bug Fix: Fixed how the Grade Report enable/disable status is stored to fix admin page loading issues on some sites.
  • Bug Fix: Fix serialization of closure error when a plugin registering a hook with a closure is in the boot-up stack and the notification center is triggered too early in the cycle.


  • Verbetering: mitigatie toevoegen voor de kwetsbaarheid van WordPress- bijlage Bestandsverplaatsing en -verwijdering.
  • Tweak: activeer een WordPress-actie wanneer instellingen worden bijgewerkt.
  • Bug Fix: Improved input sanitization on the logs page to prevent triggering warnings.


  • Veiligheid oplossing: Vaste SQL injection kwetsbaarheid in de loggings pagina . Opmerking: beheerdersrechten zijn vereist om dit beveiligingslek te misbruiken. Met dank aan Çlirim Emini, Penetration Tester op, voor het melden van dit beveiligingslek.
  • Bugfix: geef standaardwaarden voor ingeschakelde vereisten.


  • Verbetering: gebruikersinterface toevoegen om te annuleren in voortgang Bestandscontrole.
  • Enhancement: Voeg basic admin debug pagina om te helpen diagnosticeren en oplossen van problemen. Vooral met de gebeurtenissen.
  • Verbetering: voeg JSON- editor voor foutopsporinginstellingen toe .
  • Verbetering: continu de wachtwoordsterkte voor gebruikers evalueren in plaats van alleen tijdens registratie.
  • Verbetering: Introduceer wachtwoordvereistenmodule voor het beheren en afdwingen van wachtwoordvereisten .
  • Bugfix: instellingen voor wachtwoordvereisten zouden in sommige gevallen niet goed worden opgelost.
  • Bug Fix: Away Mode blokkeerde gebruikers die al waren ingelogd niet tijdens de “afwezigheidsperiode”.
  • Bugfix: forceer de vereiste sterke wachtwoorden tijdens de beveiligingscontrole.
  • Bugfix: Zorg ervoor dat de planningsvergrendeling wordt gewist door de Cron Scheduler als er geen lopende gebeurtenissen plaatsvinden.
  • Bug Fix: If a password requirement has been disabled or is no longer available, don’t consider the password as needing a change.
  • Bug Fix: Only hide “Acknowledge Weak Password” checkbox if the user was not allowed to use a weak password.
  • Bugfix: wachtwoordsterkte zou niet worden geëvalueerd als het wachtwoord was ingesteld met aangepaste PHP- of CLI-opdrachten.
  • Bugfix: voorkom dat bestandswijziging in de eerste stap vastloopt in een oneindige herplanningslus.
  • Bugfix: verwijder de gedistribueerde opslagtabel bij het ongedaan maken van de installatie.
  • Tweak: schrijf niet naar de instelling van de bijgehouden bestanden als de bestandshash niet is gewijzigd.
  • Tweak: als er geen laatste wijzigingsdatum voor het wachtwoord is vastgelegd voor de gebruiker, behandel dan de registratiedatum als laatste wijzigingsdatum.


  • Bug Fix: Fixed an “Uncaught Error: Call to undefined function esc_like()” error that could occur when exporting or erasing personal data.
  • Bug Fix: Skip recovery if File Change storage is empty.


  • New Feature: Added support for the new WordPress privacy features.
  • Enhancement: Added minimal API for adding additional entries to the Security admin menu.
  • Enhancement: File Change Scan uses a new batching mechanism to prevent crashing on hosts but still generating only one report per-day.
  • Enhancement: Introduce Distributed Storage framework for reducing the amount of data stored in the WordPress options table. This should improve performance for large sites using File Change.
  • Enhancement: Introduced Login Interstitial framework to consolidate code between Password Requirements & Two Factor.
  • Bug Fix: Added ability to show object data for classes that are not loaded to the Logs page.
  • Bug Fix: Changed the rules generated by the Filter Suspicious Query Strings feature in order to avoid blocking privacy export/erasure request confirmations.
  • Bug Fix: Ensure all users with the manage_options capability are available when selecting contacts in the Notification Center.
  • Bug Fix: Fix clearing or previous file scans results.
  • Bug Fix: Fix warnings on debug file change log items.
  • Bug Fix: Fixed logging system references to “fatal-error” that should be “fatal”.
  • Bug Fix: Improve File Change recovery system on high-traffic websites.
  • Bug Fix: Improve clearing of previous File Change file hashes.
  • Bug Fix: Improved detection of REST API requests on sites without a home dir.
  • Bug Fix: Internal links to a filtered logs page.
  • Bug Fix: Prevent PHP warning about converting an array to a string when adding notification data.
  • Bug Fix: Prevent PHP warning when completing database backups that are not emailed to any recipients.
  • Bug Fix: Properly enforce strong passwords when on the WP Login Reset Password page.
  • Bug Fix: Resolve warnings when upgrading file change settings.
  • Minor: File Scan “chunk” option is removed.
  • Minor: Make recovering file scan log smaller.
  • Minor: Page Load Scheduler: Unschedule single events before running them. This mirrors the behavior of the WP Cron scheduler.
  • Minor: Security Digest now includes all lockouts that have occurred since the last email.
  • Minor: Shrink storage size of file scans.
  • Minor: Specifying a manual file scan list has been removed.
  • Minor: Track raw memory used by the file change scanner as well.
  • Minor: Updated list of File Change excluded file types to include more media extensions.
  • Misc: Added comment to prevent Tide from marking the plugin as not compatible with PHP 5.3.
  • Tweak: Add description for File Change recovery related logs.
  • Tweak: Don’t report removed files if the removal is caused by a new file extension being excluded.
  • Tweak: File Change: Move “latest_changes” entry to a separate storage bucket to improve performance on large sites.
  • Tweak: File Change: Only scan a maximum of 10 plugins in a single chunk.


  • Bug Fix: Fixed situation that could cause lockout notifications being sent for whitelisted IPs.
  • Bug Fix: Fixed issue where saving Global Settings would be blocked by an unwritable “Path to Log Files” path when the “Log Type” is set to “Database Only”.
  • Bug Fix: Fixed issue that prevented log database entries from purging and log file entries from rotating on a schedule.


  • Security Fix: Fixed display of unescaped data on logs page.
  • Enhancement: The logging system now differentiates between WP-CLI commands, WP-Cron scheduled events, and normal page requests.
  • Bug Fix: Fixed the File Change scanner in that it previously could fail to exclude selected directories on some systems.


  • Enhancement: Updated logging system to keep track of more information and have more options to filter and sort log entries.
  • Enhancement: Improved efficiency of File Change Detection scanning.
  • Bug Fix: Fixed issue that could register loading the logging page as a failed login attempt on some sites.


  • Enhancement: Display user lockouts in Lockout Sidebar.
  • Bug Fix: Load translations on the plugins_loaded hook.
  • Bug Fix: Fixed method that could be used to discover hidden login slug on some sites.
  • Bug Fix: Fixed issue that could prevent Sync from loading Malware Scan results if a scan previously failed.
  • Bug Fix: Update to the REST API “Restricted Access” feature to protect against methods to work around the restricted access.
  • Bug Fix: Prevent login page being hidden when following the “Confirm Email Address” notification URL.
  • Bug Fix: Hide Backend notifications not being properly sent when first enabled.


  • New Feature: Introduces a scheduling framework for handling events. Cron is now used by default, and will switch to using an alternate scheduling system if it detects an error. To disable this detection set ITSEC_DISABLE_CRON_TEST in your wp-config.php file.
  • Important: The ITSEC_FILE_CHECK_CRON and ITSEC_BACKUP_CRON constants have been deprecated. Use ITSEC_USE_CRON instead.
  • Enhancement: Preserve notification settings when the responsible module is deactivated.
  • Bug Fix: Process 404 lockouts on the ‘wp’ hook to prevent a headers have already been sent warning message.
  • Bug Fix: Ensure Hide Backend emails are properly sent when activating Hide Backend before saving the Notification Center for the first time.
  • Bug Fix: Prevent warning from being issued on new installs by allowing previous settings to be preserved if they exist.
  • Bug Fix: Better handle WP_Error objects in mail errors that occurred before updating to first patch release.
  • Bug Fix: A non static method was being called statically.
  • Bug Fix: Fix occasional duplicate backups and file scans.
  • Bug Fix: Fixed issue where scheduled events could repeat on sites that do not properly support WordPress’s cron system.
  • Bug Fix: Reactivating Away Mode now replaces the active file if you had previously removed it.
  • Bug Fix: Ensure lockouts take effect immediately, even on systems where changes to server configuration files do not take effect immediately.


  • Nieuwe functie: introduceert het kenniscentrum, een centrale plaats voor het beheren en aanpassen van e- mailmeldingen verzonden door iThemes Security.
  • Verbetering: geüpdatet query’s en instructies voorbereiden om rekening te houden met wijzigingen in de functie esc_sql() in WordPress 4.8.3.
  • Bug Fix: Corrected some Javascript and CSS links not generating correctly on Windows servers.


  • Bug Fix: Fixed SQL query bug that resulted in the “Minutes to Remember Bad Login (check period)” setting being ignored.
  • Bugfix: bug opgelost die verhindert dat wp-admin / install.php blokkering correct werkt op nginx-servers.
  • Bugfix: probeer geen SSL-omleiding te doen wanneer WP CLI wordt uitgevoerd.


  • New Feature: Added a new setting in WordPress Tweaks: “Login with Email Address or Username”.
  • Enhancement: Host email images from the plugin instead of relying on iThemes servers to help email clients marking messages as spam or blocking images.
  • Bug Fix: Error when searching for modules preventing modules from appearing.
  • Bugfix: gebruik de tabel wp_options bij het verkrijgen van vergrendelingen in Multisite.
  • Bug Fix: Prevent duplicate daily digest emails on sites with high load.
  • Misc: Added Magic Links, a new Pro-only feature, to be activated by Security Check.
  • Misc: Rearranged modules to be listed alphabetically.


  • Bug Fix: Fixed logical error that prevented backups from executing.
  • Bug Fix: Fixed issue that could cause database locks to flood the database.


  • Enhancement: Simplified the SSL module to offer a simple Enable/Disable setting and simplified explanations. The legacy settings are available by selecting Advanced.
  • Enhancement: Added the itsec-get-ip filter to allow code to supply the remote IP directly.
  • Enhancement: Enabling SSL support will only log you out if you are not already on an https connection.
  • Enhancement: Improve password requirements compatibility with plugins and systems that integrate with WordPress Users.
  • Removed Old Feature: Removed the “Replace jQuery With a Safe Version” feature as its use (protecting against a specific jQuery bug: is many years old and is no longer a concern.
  • Bug Fix: Bumped version number of some scripts to ensure that they refresh properly.
  • Bug Fix: Fixed way to work around Hide Backend on some hosts.


  • Enhancement: Replaced file locking with database locking. This method of locking is compatible with all systems as it does not require the ability to write files. It also allows for locking to work on sites that have multiple front-end servers with a shared database. Since file locking is no longer used, the Global Settings > Disable File Locking setting was removed.
  • Enhancement: Add “Copy to Clipboard” functionality for server and wp-config rules.
  • Bug Fix: Prevent 404s when following links in email notifications on a site with Hide Backend enabled.
  • Bug Fix: Ensure uninstall process is not run when another version of iThemes Security is still active.
  • Bug Fix: Fixed method of working around Hide Backend.
  • Bug Fix: Warnings are no longer generated when saving a user profile with a role of “No role for this site” selected.


  • Important: The way that Hide Backend functions changes in this release. Previously, if your Hide Backend Login Slug was wplogin, going to would result in the URL remaining The new implementation of this feature results in a redirect to a URL that looks as follows: While this may not be desireable for some users, this change was necessary to fix longstanding compatibility issues with other plugins. Once you access the login page using the Login Slug page, a cookie is set with an expiration time of one hour. As long as the cookie remains, you can access without having to access the Hide Backend Login Slug first. If you wish to confirm that Hide Backend is working properly on your site, opening up a private browsing window is a quick way to test without having to log out and clear cookies.
  • New Feature: Added support for iThemes Sync to run the Security Check feature from inside the Sync service.
  • New Feature: Added support for the ITSEC_DISABLE_MODULES define.
  • Bug Fix: Removed warning: “Non-static method ITSEC_Setup::uninstall() should not be called statically”.
  • Bug Fix: Fixed the ability to manually enter a page number to navigate to on the Security > Logs page.
  • Bug Fix: Fixed source of warning that could appear when creating a backup while running a PHP version less than 5.4.
  • Bug Fix: Fixed source of notice that could appear when reseting a user’s password when the Strong Passwords Enforcement feature is enabled.
  • Bug Fix: Fixed bugs that prevented reporting of specific error messages related to updating the wp-config.php file.
  • Bug Fix: Fixed an infinite loop that could occur when expiring a cookie and Hide Backend is enabled.
  • Bug Fix: Fixed compatibility issue with the Jetpack plugin when Hide Backend is enabled which could prevent Jetpack from redirecting users to the login page.
  • Bug Fix: Fixed issue where access to wp-admin/admin-post.php when Hide Backend is enabled.
  • Bug Fix: Fixed issue that could prevent “Register” and “Lost your password?” links from working properly on the login page when Hide Backend is enabled.
  • Bug Fix: Fix fatal error when updating a profile.
  • Bug Fix: Fix strong passwords not being recognized as strong on the profile page.
  • Bug Fix: Fix fatal error when registering a new user without specifying a role ( iThemes Exchange ).
  • Bug Fix: Compatability with JetPack SSO and Password Requirements.
  • Bug Fix: Ensure viewport meta is defined when loading the password requirements update password form.
  • Bug Fix: Hide Backend is now compatible with Jetpack Single Sign On.
  • Bug Fix: Hide Backend now hides registration pages on multisite sites.
  • Bug Fix: Fixed password-protected posts not properly handling the password when Hide Backend is enabled.
  • Enhancement: Removed AhrefsBot from the HackRepair blacklist as they are legitimate bot.
  • Enhancement: Improved efficiency of Hide Backend code, increasing site performance when the feature is enabled.
  • Enhancement: Enforce strong passwords during log-in. Can be disabled via the ITSEC_DISABLE_PASSWORD_REQUIREMENTS constant.
  • Enhancement: Use canonical roles library to determine if a new user or an updated role requires a strong password.
  • Enhancement: Introduce password requirements module to centralize handling of password updates.
  • Enhancement: The Hide Backend hidden login URL is no longer leaked by password-protected content.
  • Enhancement: Allow for searching through modules and settings.
  • Enhancement: Link to other module settings pages without forcing the page to refresh.
  • Enhancement: Fire an action, “itsec_change_admin_user_id”, when the admin user id changes.
  • Enhancement: Changed default Hide Backend Register Slug from wp-register.php to wp-signup.php since WordPress switched from using wp-register.php to wp-signup.php for registrations. This will not affect existing sites.
  • Enhancement: Hide Backend functions purely in PHP code now rather than relying half on PHP code and half on .htaccess and nginx.conf modifications. This allows Hide Backend to function on web servers and server configurations that it was previously not compatible with.
  • Misc: Updated or added phpDoc to many functions.
  • Misc: Updated Disable File Locking description.


  • Bug Fix: When a requesting IP address cannot be found, default to This fixes issues with some alternate cron setups.
  • Bug Fix: Having more than one iThemes Security modification in a .htaccess, nginx.conf, or wp-config.php file will no longer result in having all the file content between each section removed when updating the file.
  • Bug Fix: Modifications to the wp-config.php file added by W3 Total Cache now have their Windows-style newlines preserved when iThemes Security updates the file.


  • Enhancement: Improved plugin performance by reducing the number of queries made on each page.
  • Enhancement: Reduced memory and CPU usage due to various code improvements.
  • Bug Fix: A database backup will no longer be created when first activating the plugin.
  • Bug Fix: Added compatibility for MySQL strict mode in database creation syntax.
  • Bug Fix: Removed warning about a “non well formed numeric value encountered” in PHP 7.1.
  • Bug Fix: Modifications to wp-config.php, .htaccess, and nginx.conf files are now properly re-added upon reactivation.
  • Bug Fix: Fixed full settings for Hide Backend being displayed after disabling the feature and saving the settings.
  • Bug Fix: Enabling or disabling the Hide Backend feature will update the “Log Out” link so that it works as expected without having to load a new page.
  • Bug Fix: Enabling or disabling the Hide Backend feature now properly updates the .htaccess/nginx.conf file on enable and disable rather than at some future point.
  • Bug Fix: Fixed issue that could cause improper database table creation on multisite sites.
  • Bug Fix: Fixed a bug that could prevent settings from saving properly if the site was migrated to a new server or a new home path on the server.


  • Bug Fix: Fixed bug that prevented Away Mode from activating on some sites.


  • Enhancement: Added logging for failed two-factor, OAuth, and REST API authentications.
  • Enhancement: Added logging details about the source of login failures and the type of authentication that failed.
  • Enhancement: Due to improvements in tracking authentication failures, brute force attempts using alternate authentication methods are more reliably found and blocked.
  • Enhancement: The server’s IP is treated as whitelisted and will not be considered for lockouts or bans.
  • Enhancement: Reduced memory usage when creating a backup.
  • Enhancement: Changed log entry description of “IP Flagged as bad by iThemes IPCheck” to “IP Flagged by Network Brute Force Protection”. This should help clarify the meaning of the log entry.
  • Enhancement: Improved efficiency of the Network Brute Force Protection feature.
  • Bug Fix: Fixed bug that prevented Network Brute Force Protection from working properly on some sites.


  • Bug Fix: Removed “comodo” from the list of user agents blocked by the blacklist. This ensures that Comodo’s AutoSSL feature of cPanel/WHM is able to function.
  • Updated Feature: Updated the “REST API” feature in the WordPress Tweaks section. The feature now has proper support for protecting privacy on your site without preventing the REST API from functioning.
  • Enhancement: Updated Security Check to enforce setting the “REST API” setting to “Restricted Access”.


  • New Feature: Added a “REST API” feature in the WordPress Tweaks section. This new feature allows you to block or restrict access to the REST API.


  • Bug Fix: Fixed issue that could cause database backup emails to be sent without the backup zip attached.


  • Enhancement: Updated the lockouts notification email to a new design. This new design also cleaned up the translation strings to allow better translations.
  • New Feature: Added a “Protect Against Tabnapping” feature in the WordPress Tweaks section. Details of what this feature protects against can be found here:—the-most-underestimated-vulnerability-ever/
  • Misc: Updated the description for the Lockout Period setting to indicate that the default value of 15 minutes is recommended.


  • Bug Fix: Remote IP is now correctly identified if the server is behind a reverse proxy that sends requests with more than one IP listed in a single header.
  • Bug Fix: Fixed the link for a user in the logs page so that it properly works on sites that are inside a subdirectory.
  • Bug Fix: Improved how Strong Password Enforcement works on password resets to improve compatibility with various plugins.
  • Bug Fix: Improved the logic for determining whether a user should have Strong Password Enforcement applied. This covers situations where the user may have a custom role, a customized default role, or added capabilities beyond their role.
  • Enhancement: Improved the logic for determing the requesting IP address to better handle situations where the site is behind a reverse proxy.
  • Enhancement: Strong Password Enforcement now uses a PHP port of zxcvbn to ensure that a strong password was selected.
  • Enhancement: All links in Security that have target=”_blank” now have added rel attributes to protect against tabnapping.
  • Misc: Updated remaining links to instead link to in keeping with other links that were previously updated to


  • Bug Fix: Fixed data save issue that could cause multiple notification emails to be sent in a short period of time.
  • Bug Fix: Fixed issue that could cause the malware scanner to fail on sites that change the arg_separator.output php.ini value from its default value.
  • Bug Fix: Removed redundant entries in the HackRepair blacklist.
  • Bug Fix: Enabling Protect System Files in System Tweaks will now only block install.php for the current site. This fixes the issue where the setting can block installation of a site in a subdirectory.
  • Bug Fix: Fixed problem that could cause requests for iThemes Security data from iThemes Sync to fail due to large amounts of log entries.
  • Bug Fix: Scheduled backups now run if the ITSEC_BACKUP_CRON define is set with a non-boolean value.
  • Bug Fix: Replaced static references to wp-includes with the WPINC define.
  • Bug Fix: Moved blocking of query strings containing %0[0-9A-F] characters from the Non-English Characters setting to the Suspicious Query Strings setting as those characters are control code characters and are not associated with a language.
  • Bug Fix: Added escaping to some translation strings.
  • Bug Fix: Removed unused files from the WordPress Tweaks module directory.
  • Bug Fix: Fixed the Daily Digest email reversing the user and host lockout counts.
  • Bug Fix: The database backup email no longer sends from the email address configured in Settings > General. It now defaults to the same from address that the wp_mail() function uses. This will fix the mail being blocked by some mail servers due to a spoofed from address.
  • Enhancement: Updated the server config rules generated by the System Tweaks settings. They are now more consistent between Apache, LiteSpeed, and nginx. They are also more efficient and have been improved to limit accidentally blocking non-targeted requests.
  • Enhancement: Updated the database backup email to a new design.
  • Enhancement: Added a note that the Filter Request Methods setting in System Tweaks should not be enabled if the WordPress REST API is used. This is becasue the DELETE HTTP method is blocked when the setting is enabled.
  • New Feature: Added setting to block requests for PHP files in the plugins directory in System Tweaks.
  • New Feature: Added setting to block requests for PHP files in the themes directory in System Tweaks.


  • Bug Fix: Fixed issue that reported invalid counts for host and user lockouts in the daily digest email.
  • Bug Fix: Fixed issue that caused the daily digest email to be sent every day, even if no lockouts occurred and no file changes were found.
  • Bug Fix: Fixed issue that could prevent saving of File Change settings, resulting in an error messages of “A validation function for file-change received data that did not have the required entry for latest_changes.”
  • Bug Fix: Fixed iThemes Security Pro logo appearing in daily digest emails.


  • Bug Fix: Removed the “Wget” user agent from the Hack Repair blacklist as it can block wp-cron jobs on some hosts.
  • Bug Fix: Fixed error “PHP message: PHP Fatal error: ‘continue’ not in the ‘loop’ or ‘switch’ context”.
  • Enhancement: Added new Daily Digest email design.


  • Security Fix: Fixed issue where a locked out but not yet blacklisted IP/user could receive different HTTP headers when testing a valid username/password combination. Thanks Leon Atkinson of 18INT for contacting us about this issue.
  • Security Fix: Updated log output to prevent specific kinds of logged requests from displaying without sanitization. Thanks to Slavco Mihajloski for contacting us about this issue.
  • Bug Fix: The Security > Security Check link now works as expected in multisite.
  • Bug Fix: Fixed bug that could prevent the “Filter Long URL Strings” feature from working properly.
  • Bug Fix: Removed restrictions in the “Filter Long URL Strings” feature that were unrelated to request length.
  • Bug Fix: Corrected a settings description typo in Global Settings.
  • Bug Fix: Fixed bug that could result in issues authenticating over XML-RPC when the WordPress Tweaks > Multiple Authentication Attempts per XML-RPC Request setting is set to “Block”.
  • Misc: Added placeholder for the Version Management module of iThemes Security Pro.
  • Misc: Updated build number to trigger some updates.


  • Bug Fix: Fixed a potential logging issue that could prevent some lockout notices from being properly logged on non-English sites.
  • Bug Fix: Prevented some notices from displaying to users who do not need to see them.
  • Bug Fix: Limited notices to only display on specific pages on the dashboard.
  • Compatibility Fix: Changed name of the $HTTP_RAW_POST_DATA variable to avoid erroneously tripping PHP 7 compatibility checks.
  • Code Cleanup: Removed legacy code that is no longer needed.
  • Enhancement: Started tracking when a user was last seen as logged in and active for future use.
  • Misc: Added a placeholder for the Pro feature “User Security Check”.


  • New Feature: Added a new Security Check section on the settings page. This new feature adds a tool to quickly ensure that the recommended features are enabled and the recommended settings are used.
  • Bug Fix: Fixed the ability to remove the itsec_away.confg file in order to disable Away Mode.
  • Enhancement: The “Ban Lists” setting of Banned Users is now enabled by default.