Releases: SilverAssist/silver-assist-security
Releases · SilverAssist/silver-assist-security
Release list
v1.5.1
What's Changed
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.33 to 2.10.34 in the npm-minor-patch group by @dependabot[bot] in #86
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #87
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.37 to 2.10.38 in the npm-minor-patch group by @dependabot[bot] in #88
- 🔧(deps): Bump softprops/action-gh-release from 3.0.0 to 3.0.1 by @dependabot[bot] in #89
- 🔧(deps): Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in #90
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #91
- 🔧(deps): Bump actions/cache from 5 to 6 by @dependabot[bot] in #92
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.40 to 2.10.42 in the npm-minor-patch group by @dependabot[bot] in #93
- 🔧(deps): Bump actions/cache from 5.1.0 to 6.1.0 by @dependabot[bot] in #94
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #95
- 🔧(deps): Bump softprops/action-gh-release from 3.0.1 to 3.0.2 by @dependabot[bot] in #96
- 🔧(deps-dev): Bump postcss from 8.5.19 to 8.5.20 in the npm-minor-patch group by @dependabot[bot] in #97
- 🔧(deps): Bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot[bot] in #99
- 🔧(deps): Bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot[bot] in #98
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #100
- 🔧(deps-dev): Bump svgo from 4.0.1 to 4.0.2 by @dependabot[bot] in #101
- 🔧(deps-dev): Bump the npm-minor-patch group with 3 updates by @dependabot[bot] in #102
- 🔧(deps-dev): Bump brace-expansion from 1.1.12 to 1.1.18 by @dependabot[bot] in #106
- 🔧(deps-dev): Bump the npm-minor-patch group with 3 updates by @dependabot[bot] in #107
- feat(103): Add REST API batch endpoint protection and rate limiting by @miguelcolmenares with @Copilot in #104
- Adopt SilverAssistWP coding standard by @miguelcolmenares in #108
- Migrate to silverassist/wp-plugin-kernel by @miguelcolmenares in #109
- chore: Adopt shared install-wp-tests.sh from wp-coding-standards by @miguelcolmenares in #110
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #111
Full Changelog: v1.4.0...v1.5.1
v1.4.0
What's Changed
- 🔧(deps): Bump actions/setup-node from 4.4.0 to 6.3.0 by @dependabot[bot] in #55
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.8 to 2.10.10 in the npm-minor-patch group by @dependabot[bot] in #59
- 🔧(deps): Bump picomatch by @dependabot[bot] in #60
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #61
- 🔧(deps): Bump dependabot/fetch-metadata from 2.5.0 to 3.0.0 by @dependabot[bot] in #62
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.12 to 2.10.16 in the npm-minor-patch group by @dependabot[bot] in #63
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #64
- 🔧(deps): Bump actions/upload-artifact from 7.0.0 to 7.0.1 by @dependabot[bot] in #67
- 🔧(deps): Bump softprops/action-gh-release from 2.6.1 to 3.0.0 by @dependabot[bot] in #66
- 🔧(deps): Bump actions/github-script from 8.0.0 to 9.0.0 by @dependabot[bot] in #65
- 🔧(deps-dev): Bump the npm-minor-patch group with 4 updates by @dependabot[bot] in #68
- 🔧(deps): Bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 by @dependabot[bot] in #69
- 🔧(deps-dev): Bump the npm-minor-patch group with 3 updates by @dependabot[bot] in #71
- 🔧(deps-dev): Bump the npm-minor-patch group with 3 updates by @dependabot[bot] in #72
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.27 to 2.10.29 in the npm-minor-patch group by @dependabot[bot] in #73
- 🔧(deps-dev): Bump cssnano from 7.1.9 to 8.0.1 by @dependabot[bot] in #74
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.29 to 2.10.31 in the npm-minor-patch group by @dependabot[bot] in #75
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #77
- 🔧(deps-dev): Update php-stubs/wordpress-tests-stubs requirement from ^6.6 to ^7.0 by @dependabot[bot] in #76
- 🔧(deps): Bump actions/setup-node from 6.3.0 to 6.4.0 by @dependabot[bot] in #70
- refactor: Remove Under Attack Mode entirely by @Copilot in #79
- fix: Upgrade lodash to ^4.18.0 to resolve CVE-2026-2950 and CVE-2026-4800 by @miguelcolmenares in #80
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.32 to 2.10.33 in the npm-minor-patch group by @dependabot[bot] in #81
- 🔧(deps): Bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in #82
- feat: Custom login page branding with split-layout design by @miguelcolmenares in #84
- Release v1.4.0 by @miguelcolmenares in #85
Full Changelog: v1.3.1...v1.4.0
v1.3.1
What's Changed
- 🔧(deps-dev): Bump baseline-browser-mapping from 2.10.0 to 2.10.8 in the npm-minor-patch group by @dependabot[bot] in #54
- 🔧(deps): Bump softprops/action-gh-release from 2.5.0 to 2.6.1 by @dependabot[bot] in #56
- fix: Resolve GraphQL API key authentication failures by @miguelcolmenares in #57
Full Changelog: v1.3.0...v1.3.1
v1.3.0
What's Changed
- feat: Add GraphQL endpoint authentication requirement with API key support by @miguelcolmenares in #53
Full Changelog: v1.2.1...v1.3.0
v1.2.1
What's Changed
- 🔧(deps-dev): Bump svgo from 4.0.0 to 4.0.1 by @dependabot[bot] in #47
- 🔧(deps-dev): Bump the npm-minor-patch group with 2 updates by @dependabot[bot] in #48
- 🔧(deps): Bump actions/setup-node from 6.2.0 to 6.3.0 by @dependabot[bot] in #50
- 🔧(deps): Bump actions/checkout from 4.3.1 to 6.0.2 by @dependabot[bot] in #49
Full Changelog: v1.2.0...v1.2.1
v1.2.0
Silver Assist Security Essentials v1.1.16
Changes in v1.1.16
♻️ Refactoring & Architecture
- Settings Hub Integration: Renamed plugin tab from "Security" to "Security Essentials" for clearer identification
- Update Check Delegation: Simplified update checking by delegating to
wp-github-updaterv1.3.0 built-inenqueueCheckUpdatesScript(), removing custom AJAX handler andupdate-check.js - Removed
update-check.js: Eliminated standalone update check script in favor of centralized wp-github-updater functionality - Removed duplicate
<h1>title: AdminPageRenderer no longer renders standalone page title (handled by Settings Hub) - Version badge CSS: Added
.version-badgecomponent style using CSS design system variables
📦 Dependencies
- wp-github-updater: Updated from
^1.0to^1.3for built-in update check UI support - wp-settings-hub: Updated from
^1.1.3to^1.2forplugin_fileregistration support - Updater config: Added
text_domainparameter for localized update notifications
🔧 CI/CD
- Copilot Setup Steps: Added
.github/workflows/copilot-setup-steps.ymlfor automated PHP dependency setup in Copilot coding agents
Package Information
- File: silver-assist-security-v1.1.16.zip
- Size: ~232KB
- License: Polyform Noncommercial License 1.0.0
Installation
- Download the ZIP file below
- Go to WordPress Admin → Plugins → Add New → Upload Plugin
- Choose the downloaded ZIP file and click "Install Now"
- Activate the plugin
- Go to Settings → Security Essentials to configure
For detailed installation instructions, see the README.md file.
Security Features
- HTTPOnly cookie protection
- GraphQL security with rate limiting
- Login attempt limiting and session management
- WordPress hardening (XML-RPC blocking, version hiding)
- Real-time security dashboard with live statistics
- Multi-language support with comprehensive admin panel
- Automatic GitHub Updates - Powered by silverassist/wp-github-updater package
Silver Assist Security Essentials v1.1.15
Changes in v1.1.15
🚨 Under Attack Mode & CAPTCHA Protection
- Login CAPTCHA: Math-based CAPTCHA challenge on WordPress login page when Under Attack Mode is active
- Validates CAPTCHA answer server-side before authentication
- Accessible design with ARIA labels and screen reader support
- CF7 CAPTCHA: CAPTCHA challenge injected into Contact Form 7 forms during Under Attack Mode
- Automatic injection via
wpcf7_form_elementsfilter - Server-side validation via
wpcf7_validatehook
- Automatic injection via
- Shared Template System:
templates/captcha-field.phprenders consistent CAPTCHA across all entry pointsSecurityHelper::render_template()for output-buffered template rendering- JavaScript-powered refresh without page reload
- Dedicated
captcha.cssandcaptcha.jsassets with build pipeline integration
- Remember Me Removal: "Remember Me" checkbox hidden via CSS on login page
- Session cookie lifetime enforced to match configured session timeout
- Prevents users from bypassing session timeout policies
- Singleton Pattern:
UnderAttackModeconverted to singleton matchingIPBlacklistpatterngetInstance()used consistently acrossLoginSecurity,ContactForm7Integration, andSecurityDataProvider
📊 Dashboard Card Enhancements
- Under Attack Mode Status: Real-time Active/Inactive indicator in General Security dashboard card
- IP Blacklisting Status: Enabled/Disabled indicator in General Security dashboard card
- Session Timeout Stat: Displays configured timeout value (minutes) in Admin Security card
- Dashboard Auto-Refresh: Switching to dashboard tab automatically refreshes security status and login stats
- Bot Protection Selector Fix: Updated JS selector from
:last-childto:nth-child(2)after Session Timeout stat addition
🐛 Autosave Indicator Fix
- Persistent Indicator Bug: Fixed
showSavingIndicator()only showing visual feedback on first save- Root cause:
.fadeOut()left indicator in DOM withdisplay:none, subsequent calls found existing div and did nothing - Fix:
.stop(true, true).html(savingText).removeClass("error").show()on existing indicator - Changed
$("form").append()to$("form").first().append()to prevent duplicates
- Root cause:
🌍 Translations Update
- POT Regenerated:
wp i18n make-pot— 791 → 1087 lines, all new translatable strings captured - Spanish (es_ES): 82 new strings translated, 61 fuzzy flags resolved, 4 format errors fixed
- Binary Compiled:
.mofile regenerated withmsgfmt --checkvalidation (234 translated messages)
📚 Documentation
- README.md: Added Under Attack Mode, CAPTCHA, IP Blacklisting, Session Timeout, Remember Me removal sections
- Test Coverage: Updated counts to reflect current test suite (350+ unit, 50+ integration)
🎨 Dashboard UI Overhaul
- Card-Based Layout: Complete redesign of the security dashboard with status cards
- Login Security, Admin Security, GraphQL Security, General Security, and Form Protection cards
stat-value/stat-labelcomponents for consistent data display- Feature-status rows with enabled/disabled indicators and
::beforeicons - Security Statistics section: Blocked IPs, Failed Attempts (24h), Security Events (7d)
- Activity Tabs: New tabbed interface (Blocked IPs / Security Logs) in Recent Activity section
- Loading spinners and loading-text placeholders for async content
- Interactive tab switching with smooth transitions
- Settings Tabs Card Migration: All 4 settings tabs now use
.status-cardwith.card-header/.card-content- Login Protection, GraphQL Security, Contact Form 7, and IP Management sections wrapped in styled cards
- Consistent card structure with header icons across all tabs
- Status Indicator Semantics: Renamed
.disabledto.inactivefor clarity - Toggle Switch Refactor: Native
:checkedselector with.toggle-sliderclass instead of JS class toggling
🛡️ Admin Hide Security Restored
- Toggle switch to enable/disable admin URL hiding
- Custom admin path input with real-time validation and preview
- Security warning notice with recovery instructions
- Path validation fallback for undefined error messages
📊 Security Logs & IP Management
- Security Logs Panel: New logs viewer in dashboard Recent Activity
- AJAX-loaded table with timestamp, event type, and details columns
- Secure DOM construction using jQuery
.text()to prevent XSS
- IP Unblock Functionality: Unblock IPs directly from IP Management tab
unblock_ipAJAX endpoint inSecurityAjaxHandler- Full table view with per-IP unblock buttons
- Compact dashboard summary (last 3 IPs) with "View all" link
- Blocked IPs Display: Split into compact dashboard summary and full IP Management table
🔒 Security Hardening
- DOM XSS Prevention: Added
escapeHtml()helper to admin.js for all user-data DOM insertion- Blocked IPs table: IP addresses, reasons, timestamps all escaped
- Security logs: Rebuilt with jQuery DOM construction (
.text()) instead of template literals - CF7 blocked IPs: Table headers use
esc_html__(), cell values useesc_html()
- AJAX Scope Fix: Resolved
ReferenceError—ajaxurl/noncenow destructured in correct scope for unblock button handlers - Smart Logging System: Severity-based security event logging
- 58 event types classified as error (13), warning (33), or info (12)
WP_DEBUGgate — no log output when debugging is disabled- Test environment filtering — only errors logged during tests
[ERROR]/[WARNING]/[INFO]severity prefixes in log format- Eliminated ~70 noisy log lines from test output
🧩 New Components
- RenderHelper Utility Class (
src/Admin/Renderer/RenderHelper.php): Shared static methods for UI renderingrender_feature_status()— Feature enabled/disabled rowsrender_stat()— Numeric stat values with label and optional suffixrender_async_stat()— AJAX-loaded stat cards with loading spinner
- SecurityDataProvider Expanded: Added
form_protection, GraphQL detail fields (query_depth_limit,query_complexity_limit,query_timeout,introspection_disabled),xmlrpc_disabled,version_hiding, and overall statistics - StatisticsProvider: Cross-component stats with inlined log file reading to avoid circular dependency
- DashboardRenderer Refactored: All repetitive HTML blocks replaced with
RenderHelpercalls (8 feature-status, 7 stat, 3 async-stat)
🔒 Autosave / Submit Race-Condition Guard
- Submit buttons disabled with "Saving..." label during autosave
- Manual submit cancels pending autosave timer
- 15s fallback timeout re-enables buttons if autosave hangs
- CSS
.is-savingclass for visual feedback
🐛 Bug Fixes
- CF7 Detection (CF7 v6.x): Removed deprecated
function_exists('wpcf7_get_contact_form_by_id')check — this function was removed in CF7 v6.x, causing the CF7 tab to not appear - CF7 Blocked IPs Loading:
loadCF7BlockedIPs()now targets both#cf7-blocked-ips-contentand#cf7-blocked-ips-container - CF7 Tab Data Loading: Added
cf7-securitycase toswitchToTabfor CF7 tab activation - CF7 Empty State Styling: Changed to
.no-threatsclass for consistent green styling - Admin Path Validation: Added fallback
"Invalid path"for undefined error messages; removed static div (JS creates it dynamically) - Toggle Switch Initialization: Skip checkboxes already inside
.toggle-switchlabels to prevent double-wrapping - Blocked IPs Data Extraction: Handle both array and object response formats
- GraphQL Timeout Option Key: Fixed
silver_assist_graphql_timeout→silver_assist_graphql_query_timeoutto show correct dashboard value - PHP Function Prefixes: Added
\towp_json_encode(), removed unnecessary\fromround()(PHP built-in) - SecurityDataProvider PHPDoc: Fixed mis-indented docblock for
$stats_providerproperty - Noisy Log Removed: Removed
IP_CLEANUP_INITIALIZEDlog from Plugin.php
🧪 Test Suite
- AjaxTestHelper Trait: Reusable AJAX testing infrastructure
AjaxTestDieError extends \Errorbypasses WordPress die handlers in testssetup_ajax_environment(),call_ajax_handler(),teardown_ajax_environment()methods
- 36 Pre-Existing Test Failures Fixed across 5 categories:
- UI structure mismatches — updated tab IDs, CSS classes, text labels
- Removed/refactored methods — rewired tests to
SettingsHandler::save_security_settings() - Hook registration issues — fixed test isolation and explicit component creation
- Singleton/void/input ID —
getInstance(),ob_start()buffering, correct field IDs
- 283 Tests Passing: Unit (122), Functional (42), Security (62), Integration (57+)
🎨 Code Quality
- PHPCS Compliance: Auto-fixed 223 violations via PHPCBF (0 errors, 3 pre-existing warnings remaining)
SettingsRenderer.php: 200 fixes (spacing, brace placement, indentation)SecurityDataProvider.php: 23 fixes
- PHPStan Level 8: Resolved all 37 static analysis errors (100% compliance)
📚 Documentation & AI Config
- Copilot Instructions Updated: Documentation rule now distinguishes between project docs and Copilot config files
.github/skills/— Copilot Skills (domain knowledge).github/prompts/— Copilot Prompt Files (reusable workflows).github/instructions/— Copilot Instruction Files (scoped context)
- Dashboard Styles Skill:
.github/skills/dashboard-styles/SKILL.md— CSS classes, HTML patterns, component usage guide - Dependabot Auto-Merge: Documented GitHub Actions limitation for workflow file modifications
Changed
- 📦 Contact Form 7 Stubs: Added
miguelcolmenares/cf7-stubs^6.1 for PHPStan static analysis - 🔧 GitHub Workflow Permissions: Added
contents: writeandpull-requests: writeto quality-checks workflow - 🚀 Quality Checks Script...
Silver Assist Security Essentials v1.1.14
Changes in v1.1.14
See CHANGELOG.md for detailed changes.
Package Information
- File: silver-assist-security-v1.1.14.zip
- Size: ~160KB
- License: Polyform Noncommercial License 1.0.0
Installation
- Download the ZIP file below
- Go to WordPress Admin → Plugins → Add New → Upload Plugin
- Choose the downloaded ZIP file and click "Install Now"
- Activate the plugin
- Go to Settings → Security Essentials to configure
For detailed installation instructions, see the README.md file.
Security Features
- HTTPOnly cookie protection
- GraphQL security with rate limiting
- Login attempt limiting and session management
- WordPress hardening (XML-RPC blocking, version hiding)
- Real-time security dashboard with live statistics
- Multi-language support with comprehensive admin panel
- Automatic GitHub Updates - Powered by silverassist/wp-github-updater package
Silver Assist Security Essentials v1.1.13
Changes in v1.1.13
🎯 Major Feature: Settings Hub Integration
⚠️ BREAKING CHANGES
- Menu Structure Changed: Plugin now registers under centralized "Silver Assist" menu via Settings Hub
- Before: Standalone menu in WordPress Settings → "Security Essentials"
- After: Top-level "Silver Assist" menu → "Security" submenu
- URL Change: Admin page URL structure modified for hub integration
- Backward Compatibility: Automatic fallback to standalone menu when Settings Hub unavailable
🚀 New Features
-
Settings Hub Integration (
silverassist/wp-settings-hub v1.1.0):- Centralized admin interface for all Silver Assist plugins
- Professional plugin dashboard with cards and metadata display
- Cross-plugin navigation via tabs (when multiple plugins installed)
- Dynamic action buttons support
- Enhanced user experience with consistent UI across Silver Assist ecosystem
-
"Check Updates" Button:
- New action button in Settings Hub plugin card
- One-click update checking via AJAX
- Automatic redirection to WordPress Updates page when update available
- Real-time feedback with user-friendly messages
- Seamless integration with existing wp-github-updater package
-
Removed Plugin Updates Section:
- Eliminated redundant "Plugin Updates" card from admin page
- Update functionality consolidated into Settings Hub action button
- Cleaner admin interface with reduced UI clutter
- Maintained all update checking capabilities
🔧 Technical Implementation
-
New Methods in AdminPanel:
register_with_hub(): Main hub registration with automatic fallbackget_hub_actions(): Configures action buttons for plugin cardrender_update_check_script(): JavaScript callback for update buttonajax_check_updates(): AJAX handler for update verificationadd_admin_menu(): Fallback method for standalone menu registration
-
Settings Hub Registration:
$hub->register_plugin( 'silver-assist-security', __('Security', 'silver-assist-security'), [$this, 'render_admin_page'], [ 'description' => __('Security configuration for WordPress', 'silver-assist-security'), 'version' => SILVER_ASSIST_SECURITY_VERSION, 'tab_title' => __('Security', 'silver-assist-security'), 'actions' => [ [ 'label' => __('Check Updates', 'silver-assist-security'), 'callback' => [$this, 'render_update_check_script'], 'class' => 'button button-primary', ] ] ] );
-
Intelligent Fallback System:
- Automatic detection of Settings Hub availability
- Graceful degradation to standalone menu when hub absent
- Zero functionality loss in fallback mode
- Exception handling with security event logging
🧪 Comprehensive Testing
- New Test Suite:
tests/Integration/SettingsHubTest.php(10 test cases):- Settings Hub class detection and availability
- Fallback menu registration verification
- Update button configuration validation
- AJAX handler functionality tests
- Security validation for update checks
- Update script rendering verification
- Hub registration metadata validation
- Actions array structure tests
- Admin hooks registration checks
- Integration testing with wp-github-updater
🔒 Security Enhancements
- AJAX Security:
- Nonce validation for all update check requests
- User capability verification (
manage_options) - Comprehensive error handling and logging
- Sanitized JavaScript output with
esc_js(),esc_url() - SecurityHelper integration for event logging
📊 Impact Assessment
-
User Experience:
- ✅ Unified admin interface for Silver Assist plugins
- ✅ Professional dashboard with plugin cards
- ✅ Quick access to update checking
- ✅ Consistent UI across plugin ecosystem
⚠️ URL change may affect bookmarks (acceptable for major version)
-
Developer Experience:
- ✅ Modular architecture with clean separation
- ✅ Easy to extend with additional action buttons
- ✅ Comprehensive test coverage
- ✅ Well-documented integration patterns
-
Compatibility:
- ✅ Works with or without Settings Hub
- ✅ Maintains all existing functionality
- ✅ Backward compatible via fallback mechanism
- ✅ No data migration required
🎨 Code Quality
- Standards Compliance: Full WordPress coding standards adherence
- Type Safety: Strict PHP 8+ type declarations throughout
- Documentation: Complete PHPDoc for all new methods
- Error Handling: Comprehensive try-catch blocks with logging
- Internationalization: All user-facing strings properly translated
📦 Dependencies
- Added:
silverassist/wp-settings-hub^1.1 (production dependency) - Maintained: All existing dependencies (wp-github-updater, PHPUnit, etc.)
🔄 Migration Guide
For End Users:
- Update plugin to v1.1.13
- Admin menu location changes automatically
- Find plugin under "Silver Assist" → "Security" (or Settings if hub not installed)
- Update bookmarks if accessing settings directly
For Developers:
- Install/update via Composer:
composer update - Settings Hub automatically detected if installed
- Fallback mechanism ensures compatibility
- No code changes required in consuming applications
Package Information
- File: silver-assist-security-v1.1.13.zip
- Size: ~156KB
- License: Polyform Noncommercial License 1.0.0
Installation
- Download the ZIP file below
- Go to WordPress Admin → Plugins → Add New → Upload Plugin
- Choose the downloaded ZIP file and click "Install Now"
- Activate the plugin
- Go to Settings → Security Essentials to configure
For detailed installation instructions, see the README.md file.
Security Features
- HTTPOnly cookie protection
- GraphQL security with rate limiting
- Login attempt limiting and session management
- WordPress hardening (XML-RPC blocking, version hiding)
- Real-time security dashboard with live statistics
- Multi-language support with comprehensive admin panel
- Automatic GitHub Updates - Powered by silverassist/wp-github-updater package