Changelog
Track all the latest updates, fixes, and improvements in Nexura Security.
Version 1.0.16
- Fix: Resolved HTTP 500 error on CGI/FastCGI hosting environments (Bluehost, HostGator, SiteGround) caused by WAF auto_prepend_file in .htaccess. The directive now only applies on Apache mod_php servers.
- Fix: Fixed broken Global Threat Intelligence toggle in Settings page — the switch was non-functional due to a missing checkbox input.
- New Feature: Smart Auto-Recovery — if any security rule written to .htaccess causes a server error, the plugin automatically detects it and rolls back to the previous safe state.
- Security: Applied Apache SAPI detection safeguard to Pro Server Lock feature to prevent 500 errors on strict hosting environments.
- Enhancement: Updated comment spam URL blocklist with 8 new spambot domains (shorturl.fm, t.ly, goo.su, qrco.de and more).
Version 1.0.15
- Enhancement: Redesigned WAF loading with a fail-safe
nexura-waf-bootstrap.phpproxy file, eliminating fatal errors when plugin folder is renamed or the Pro version coexists with the free version. - Fix: Resolved fatal error (
Failed opening required 'nexura-security-pro/nexura-waf.php') affecting sites where plugin was installed under thenexura-securityfolder name. - Fix: Fixed WAF Analytics dashboard (Pro) failing to load charts due to undefined PHP variables in the REST API endpoint.
- Fix: Fixed Database Optimizer page (Pro) stuck on "Loading..." on certain hosting environments due to null-check issue in the table stats query.
- Enhancement: Plugin now automatically detects and deactivates the old standalone Nexura Security Pro plugin on activation to prevent conflicts.
Version 1.0.14
- New Feature: Enterprise WooCommerce Security Module with granular protection against checkout abuse and fake registrations.
- New Feature: Advanced Database Malware Scanner inside wp_options, postmeta, usermeta, and Custom Tables.
- New Feature: Ultra-Fast Local Geo-Blocking using native MaxMind GeoLite2 integration.
- Security: Centralized Permission Engine using Nexura_Security::can_manage_security() for bulletproof access controls.
- Security: Hardened Filesystem Operations utilizing a 3-layer security model for advanced capabilities like chattr.
- Fix: Critical 500 Internal Server Errors on Live Servers by strictly verifying php_module support.
- Fix: Server Lock and .htaccess locking issue ensuring rules can be safely toggled OFF.
Version 1.0.13
- Improvement: Completely separated Free and Pro WordPress.org builds per Freemius distribution guidelines.
- Security: Hardened Disaster Recovery script with strict cache-control, session-fixation protection, and rate limiting.
- Security: Fixed WAF initialization priority to guarantee Pre-Boot firewall runs immediately.
- Fix: Fixed database schema bug for Scan Results status column.
- Fix: Updated dynamic view logic for Pro dashboard UI files.
Version 1.0.12
- Enhancement: Streamlined the Pro license activation process for a seamless, instant upgrade experience without caching delays.
- Enhancement: Improved menu integration with the Freemius SDK for a cleaner admin dashboard experience.
- Fix: Resolved a critical initialization issue in the Pro module loader to ensure maximum stability on all hosting environments.
- Fix: Restored and optimized the 3D Geo-Location Map visualization within the WAF Analytics dashboard.
- Fix: Addressed a display issue on feature preview pages to ensure smooth navigation for Free tier users.
Version 1.0.11
- Improvement: Refactored compound conditions into nested checks for SDK AST parsing.
- Fix: Fixed dynamic variable assignments for Pro code obfuscation blocks.
- Fix: General code-cleanup and performance improvements.
Version 1.0.10
- Security: Added Base64 and Hex payload decoding to the WAF to catch obfuscated malware.
- Security: Added Wp2shell Zero-Day blocking rule (CVE-2026-60137 / CVE-2026-63030).
- Security: Fixed SSL verification in Rescue Script to prevent MITM attacks.
- Security: Prevented Open Redirect attacks in 2FA login.
- Security: Secured dynamic table names with strict sanitization in DB Backup.
- New Feature: Ghost Admin Protection — detects and automatically demotes rogue administrator accounts.
Version 1.0.9
- Added: Deep Malware Scanner using signature and heuristic analysis.
- Added: Cloudflare Worker integration for distributed WAF.
- Improved: Pre-Boot WAF performance by 12%.
- Fixed: Conflict with specific caching plugins.
Version 1.0.8
- Added: Google Authenticator 2FA support.
- Improved: Brute force protection algorithms.
- Fixed: Admin dashboard UI glitches on mobile devices.
Version 1.0.7
- Added: IP Blacklisting and Country blocking options.
- Improved: Log viewing interface.
Version 1.0.0
- Release: Nexura Security 1.0. The first major stable release bringing the complete security suite to the public.
