-
v7.42.0 Stable
released this
2026-09-17 12:12:39 +00:00 | 11 commits to main since this release- If this site is connected to a WAD account, findings shown there now include ARGUS's full
explanation -- what was found, why it matters, and what to check -- not just the recommended
fix, so you no longer need to open wp-admin to see the complete picture.
Downloads
- If this site is connected to a WAD account, findings shown there now include ARGUS's full
-
v7.41.0 Stable
released this
2026-09-17 11:36:01 +00:00 | 12 commits to main since this release- Findings now have a complete lifecycle: Resolve, Reopen, Accept Risk, False Positive/Suppress,
Archive and Restore are all real, tracked actions (who did it, when, and why), available here in
wp-admin and, if this site is connected to a WAD account, from there too -- WAD is never a
separate copy of this data, every action there is carried out on this site the same way. - Contact Form 7's public feedback submission endpoint is now correctly recognised as an
intentional, documented part of that plugin's own public API, the same way WooCommerce's Store
API and Jetpack's public endpoints already were -- it no longer creates an unnecessary finding.
Downloads
- Findings now have a complete lifecycle: Resolve, Reopen, Accept Risk, False Positive/Suppress,
-
v7.40.0 Stable
released this
2026-09-17 10:42:47 +00:00 | 13 commits to main since this release- Security hardening: this site's IP-based protections (firewall, brute-force login protection,
REST/API abuse protection, WooCommerce checkout guard, two-factor) now correctly recognise real
visitor IP addresses when this site runs behind a reverse proxy, load balancer, or CDN, using the
same trusted-proxy configuration already available under Form Protection. Previously, sites in
that setup could see every visitor as the same address, weakening these protections. - Hardened the replay protection added in 7.39.0 further: it now remembers a short history of
recently-applied WAD actions instead of only the single most recent one.
Downloads
- Security hardening: this site's IP-based protections (firewall, brute-force login protection,
-
v7.39.9 Stable
released this
2026-09-16 22:55:39 +00:00 | 14 commits to main since this release- Security hardening: disconnecting this site from WAD (or uninstalling the plugin) now also
invalidates its connection secret on WAD's side, not just locally -- previously the secret stayed
valid indefinitely. This site also now detects if a WAD account disconnects it remotely and shows
a clear notice instead of retrying silently.
Downloads
- Security hardening: disconnecting this site from WAD (or uninstalling the plugin) now also
-
v7.39.8 Stable
released this
2026-09-16 22:23:57 +00:00 | 15 commits to main since this release- Fixed a serious bug where a scan started remotely from your WAD account could get stuck showing
"Preparing" forever and never actually run, even though a scan started from this plugin's own
Scanner page worked fine. A scan already stuck this way on your site is automatically resumed.
Downloads
- Fixed a serious bug where a scan started remotely from your WAD account could get stuck showing
-
v7.39.7 Stable
released this
2026-09-16 21:32:32 +00:00 | 16 commits to main since this release- If this site is connected to a WAD account, its Overview there now shows whether this site is
connected to ARGUS Network Intelligence (ANIS), instead of always saying that isn't visible from
WAD.
Downloads
- If this site is connected to a WAD account, its Overview there now shows whether this site is
-
v7.39.6 Stable
released this
2026-09-16 21:29:44 +00:00 | 17 commits to main since this release- Improved Form Protection's comment-spam detection to also catch promotional comments that repeat
their own submitted website or email domain in the message body, a common pattern automated
comment spam wasn't previously being flagged for.
Downloads
- Improved Form Protection's comment-spam detection to also catch promotional comments that repeat
-
v7.39.4 Stable
released this
2026-09-16 20:32:20 +00:00 | 18 commits to main since this release- If this site is connected to a WAD account, its findings now also report their category there, so
WAD can show the same "Top Threat Types" breakdown this plugin's own Threats page shows.
Downloads
- If this site is connected to a WAD account, its findings now also report their category there, so
-
v7.39.3 Stable
released this
2026-09-16 18:30:51 +00:00 | 19 commits to main since this release- If this site is connected to a WAD account, its Audit Log now correctly appears there too, the
same fix as 7.39.2 below but for the Audit Log tab instead of Findings.
Downloads
- If this site is connected to a WAD account, its Audit Log now correctly appears there too, the
-
v7.39.2 Stable
released this
2026-09-16 18:06:18 +00:00 | 20 commits to main since this release- If this site is connected to a WAD account, its findings now correctly appear there. Findings
were always visible here in wp-admin, but a sync gap meant they sometimes weren't showing up in
WAD's Findings tab even though WAD's own summary counts already reflected them.
Downloads
- If this site is connected to a WAD account, its findings now correctly appear there. Findings