Nexura WordPress Security Plugin Logo
Download Free

100% Free · No credit card required

Changelog

Track all the latest updates, fixes, and improvements in Nexura Security.

Version 1.0.16

  • Fix: Resolved HTTP 500 error on CGI/FastCGI hosting environments (Bluehost, HostGator, SiteGround) caused by WAF auto_prepend_file in .htaccess. The directive now only applies on Apache mod_php servers.
  • Fix: Fixed broken Global Threat Intelligence toggle in Settings page — the switch was non-functional due to a missing checkbox input.
  • New Feature: Smart Auto-Recovery — if any security rule written to .htaccess causes a server error, the plugin automatically detects it and rolls back to the previous safe state.
  • Security: Applied Apache SAPI detection safeguard to Pro Server Lock feature to prevent 500 errors on strict hosting environments.
  • Enhancement: Updated comment spam URL blocklist with 8 new spambot domains (shorturl.fm, t.ly, goo.su, qrco.de and more).

Version 1.0.15

  • Enhancement: Redesigned WAF loading with a fail-safe nexura-waf-bootstrap.php proxy file, eliminating fatal errors when plugin folder is renamed or the Pro version coexists with the free version.
  • Fix: Resolved fatal error (Failed opening required 'nexura-security-pro/nexura-waf.php') affecting sites where plugin was installed under the nexura-security folder name.
  • Fix: Fixed WAF Analytics dashboard (Pro) failing to load charts due to undefined PHP variables in the REST API endpoint.
  • Fix: Fixed Database Optimizer page (Pro) stuck on "Loading..." on certain hosting environments due to null-check issue in the table stats query.
  • Enhancement: Plugin now automatically detects and deactivates the old standalone Nexura Security Pro plugin on activation to prevent conflicts.

Version 1.0.14

  • New Feature: Enterprise WooCommerce Security Module with granular protection against checkout abuse and fake registrations.
  • New Feature: Advanced Database Malware Scanner inside wp_options, postmeta, usermeta, and Custom Tables.
  • New Feature: Ultra-Fast Local Geo-Blocking using native MaxMind GeoLite2 integration.
  • Security: Centralized Permission Engine using Nexura_Security::can_manage_security() for bulletproof access controls.
  • Security: Hardened Filesystem Operations utilizing a 3-layer security model for advanced capabilities like chattr.
  • Fix: Critical 500 Internal Server Errors on Live Servers by strictly verifying php_module support.
  • Fix: Server Lock and .htaccess locking issue ensuring rules can be safely toggled OFF.

Version 1.0.13

  • Improvement: Completely separated Free and Pro WordPress.org builds per Freemius distribution guidelines.
  • Security: Hardened Disaster Recovery script with strict cache-control, session-fixation protection, and rate limiting.
  • Security: Fixed WAF initialization priority to guarantee Pre-Boot firewall runs immediately.
  • Fix: Fixed database schema bug for Scan Results status column.
  • Fix: Updated dynamic view logic for Pro dashboard UI files.

Version 1.0.12

  • Enhancement: Streamlined the Pro license activation process for a seamless, instant upgrade experience without caching delays.
  • Enhancement: Improved menu integration with the Freemius SDK for a cleaner admin dashboard experience.
  • Fix: Resolved a critical initialization issue in the Pro module loader to ensure maximum stability on all hosting environments.
  • Fix: Restored and optimized the 3D Geo-Location Map visualization within the WAF Analytics dashboard.
  • Fix: Addressed a display issue on feature preview pages to ensure smooth navigation for Free tier users.

Version 1.0.11

  • Improvement: Refactored compound conditions into nested checks for SDK AST parsing.
  • Fix: Fixed dynamic variable assignments for Pro code obfuscation blocks.
  • Fix: General code-cleanup and performance improvements.

Version 1.0.10

  • Security: Added Base64 and Hex payload decoding to the WAF to catch obfuscated malware.
  • Security: Added Wp2shell Zero-Day blocking rule (CVE-2026-60137 / CVE-2026-63030).
  • Security: Fixed SSL verification in Rescue Script to prevent MITM attacks.
  • Security: Prevented Open Redirect attacks in 2FA login.
  • Security: Secured dynamic table names with strict sanitization in DB Backup.
  • New Feature: Ghost Admin Protection — detects and automatically demotes rogue administrator accounts.

Version 1.0.9

  • Added: Deep Malware Scanner using signature and heuristic analysis.
  • Added: Cloudflare Worker integration for distributed WAF.
  • Improved: Pre-Boot WAF performance by 12%.
  • Fixed: Conflict with specific caching plugins.

Version 1.0.8

  • Added: Google Authenticator 2FA support.
  • Improved: Brute force protection algorithms.
  • Fixed: Admin dashboard UI glitches on mobile devices.

Version 1.0.7

  • Added: IP Blacklisting and Country blocking options.
  • Improved: Log viewing interface.

Version 1.0.0

  • Release: Nexura Security 1.0. The first major stable release bringing the complete security suite to the public.


Stay Ahead of Hackers

Join our growing community of site owners who receive our weekly WordPress security alerts, vulnerability reports, and hardening tips.

SSL Secured
Privacy-focused
WP.org Verified
Proactive Defense
Secure Your Infrastructure Today