Skip to content

v3.2.3

Latest

Choose a tag to compare

@oussjarrousse oussjarrousse released this 16 Aug 22:04
· 2 commits to main since this release
7119670

Changelog

  • Added Wordfence 9.0.0 passkey metrics while keeping existing two-factor metrics strict to TOTP/2FA secrets.
  • Added combined login-protection metrics for administrators and users protected by 2FA, passkeys, either method, or both methods.
  • Added authentication_failures_window with bounded password, passkey, passkey_required, two_factor, and other labels.
  • Kept the aggregate failed-login metric compatible while preventing passkey-required failures from being counted as password brute force.
  • Added Wordfence-version pinning support to Docker smoke scripts for current-version and 8.x compatibility checks.

Upgrade Notice

  • Wordfence 9.0.0 passkeys are reported separately from strict 2FA metrics; use wordpress_wordfence_admin_users_without_login_protection_total for combined admin login-protection alerts.