Skip to content

Releases: tobiashaas/Etch-Security

Etch Security 1.1.1

Choose a tag to compare

@tobiashaas tobiashaas released this 21 Jul 07:29

Self-Updater von der GitHub-API (60 Req/h pro IP → auf Shared-Hosting 403 rate-limit) auf raw.githubusercontent.com (CDN, kein Limit) umgestellt. Quelle = die Datei auf main.

Etch Security 1.1.0

Choose a tag to compare

@tobiashaas tobiashaas released this 21 Jul 07:22

Neues Modul Core Updates: erzwingt WordPress-Minor-/Security-Auto-Updates, auch wenn ein Management-Tool (z. B. Installatron) sie per Filter abschaltet. Nur Point-Releases derselben X.Y-Reihe; Major-Versionssprünge bleiben unberührt. Toggle unter Werkzeuge → Etch Security (Default an), Audit-Log-Eintrag bei jedem Core-Auto-Update. Motiviert vom Vorfall (geblockter Forced-Update auf 7.0.2 / CVE-2026-63030).

Etch Security 1.0.0

Choose a tag to compare

@tobiashaas tobiashaas released this 21 Jul 06:42

Erste Release. User Guard (Domain-Allowlist + Backstop), Audit Log (Actor/IP/Request, CSV, 180 Tage), GitHub-Self-Updater, Einstellungsseite unter Werkzeuge → Etch Security. Als mu-plugin (wp-content/mu-plugins/etch-security.php) oder reguläres Plugin. Sichere Defaults: Admin-Domain immer erlaubt, Enforcement aus bis konfiguriert.