You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changelog
Added Wordfence 9.0.0 passkey metrics while keeping existing two-factor metrics strict to TOTP/2FA secrets.
Added combined login-protection metrics for administrators and users protected by 2FA, passkeys, either method, or both methods.
Added authentication_failures_window with bounded password, passkey, passkey_required, two_factor, and other labels.
Kept the aggregate failed-login metric compatible while preventing passkey-required failures from being counted as password brute force.
Added Wordfence-version pinning support to Docker smoke scripts for current-version and 8.x compatibility checks.
Upgrade Notice
Wordfence 9.0.0 passkeys are reported separately from strict 2FA metrics; use wordpress_wordfence_admin_users_without_login_protection_total for combined admin login-protection alerts.