설명
Security Ninja는 일반적인 공격과 보안 실수로부터 사이트를 보호하는 데 도움을 주는 가벼운 워드프레스 보안 플러그인입니다. 대시보드를 조종석처럼 만들지 않습니다.
[유튜브 https://www.youtube.com/watch?v=5zzzQTPmbS0]
웹 애플리케이션 방화벽(WAF)(8G 규칙 세트 기반)으로 일반적인 악성 요청을 차단하고, 50개 이상의 보안 검사, 전체 취약점 스캐너, 그리고 위험한 설정과 예상치 못한 파일 변경을 찾아내는 핵심 무결성 스캐너를 제공합니다.
클라우드 방화벽, 멀웨어 검사/정리, 로그인 무차별 대입 공격 보호 및 2FA, 내보내기/웹훅, 예약된 검사를 사용하려면 Pro로 업그레이드하세요.
이 플러그인은 공식 WordPress 저장소에서 유료 구독 없이 무료로 다운로드할 수 있습니다.
무료 포함
– 기본 방화벽(8G 기반) – 문제가 되기 전에 흔한 악성 요청과 봇 트래픽을 차단합니다.
– 50개 이상의 보안 테스트 – 일반적인 워드프레스 보안 설정 오류를 빠르게 감사합니다.
– 취약점 스캐너 – 플러그인/테마의 알려진 문제를 강조 표시하여 더 빠르게 패치할 수 있습니다.
– 코어 스캐너 – 워드프레스 코어 폴더에서 수정되었거나 예상치 못한 파일을 감지합니다.
– 기본 이벤트 기록기 – 방화벽 이벤트와 로그인 시도(성공/실패)를 기록합니다.
– AI 보안 어드바이저(워드프레스 7) – 워드프레스 AI Connectors(LLM 제공업체는 직접 선택)를 사용해 스캔 결과로부터 AI가 생성한 감사 요약과 안내 후속 조치를 제공합니다. 선택 사항인 워드프레스 Abilities를 통해 사이트의 다른 AI 도구가 테스트 요약, 공격 활동, 최신 저장 보고서를 읽을 수 있습니다.
Pro 추가 기능
– 클라우드 방화벽 및 고급 WAF – 6억 개 이상의 알려진 악성 IP 차단, 국가별 차단, IP 관리, 그리고 더 강력한 방화벽 제어 기능을 제공합니다(무료 버전에는 8G 기반 방화벽이 포함됩니다).
– 고급 악성코드 스캐너 – 악성 코드와 의심스러운 파일을 탐지하고 정리합니다.
– 로그인 보호 및 2FA – 로그인 실패 횟수를 제한하고, 로그인 URL을 변경하며, 2단계 인증을 추가합니다.
– 원클릭 수정 – 수정 페이지에서 워드프레스 보안을 강화합니다(XML-RPC, 파일 편집기, 헤더 등).
– 전체 이벤트 로거 – 로그 내보내기, 예약 이메일 보고서, 웹훅(예: Slack/Discord), 그리고 더 세부적인 알림 기능을 제공합니다.
– 예약 검사 및 보고 – 자동화된 보안 검사와 보고서를 제공합니다.
주요 기능
Security Ninja는 잘못된 설정을 찾아내고, 일반적인 공격을 차단하며, 알려진 취약점보다 한발 앞서 대응할 수 있도록 설계된 가벼운 워드프레스 방화벽 플러그인이자 보안 툴킷입니다. 사이트 속도를 저하시키지 않습니다.
종합적인 워드프레스 보안 테스트
Security Ninja는 공격자가 이를 악용하기 전에 문제를 식별하기 위해 50개 이상의 고급 보안 테스트를 수행합니다. 여기에는 다음이 포함됩니다:
- 로그인 및 비밀번호 검사 – 취약한 비밀번호와 관련 설정을 감사합니다(프로 버전에는 로그인 실패 제한, 로그인 이름 변경, 2FA가 추가됩니다).
- 파일 무결성 모니터링 – WordPress 핵심 파일, 테마 및 플러그인에 대한 무단 변경을 감지합니다.
- 데이터베이스 보안 점검 – 약한 데이터베이스 권한 및 잠재적인 SQL 인젝션 위협을 식별합니다.
- 사용자 역할 감사 – 무단 관리자 계정이 존재하지 않도록 보장합니다.
- 보안 잘못 구성 스캔 – 보안을 위협할 수 있는 약한 설정을 식별하고 수정합니다.
향상된 취약점 스캐너
Proactively alerts you to known vulnerabilities in plugins and themes so you can patch before they are exploited.
Core Scanner – WordPress Installation Integrity
Ensures your WordPress installation remains untampered and free of unauthorized files.
- Full core file integrity check – Scans every file in core WordPress folders for modifications.
- Unknown file detection – Flags extra or unexpected files in core directories.
- Built-in file viewer – Review flagged files in the dashboard.
- Restore or delete – Restore altered core files with one click, or remove suspicious unknowns.
고급 악성코드 스캐너 – 악성코드를 즉시 탐지하고 제거합니다 (PRO)
Security Ninja는 WordPress 코어, 플러그인 및 테마를 자동으로 검사하는 고성능 악성코드 스캐너를 포함하고 있습니다:
- 악성 스크립트 및 백도어 – 숨겨진 맬웨어 및 유해한 주입을 식별합니다.
- 트로이 목마 및 바이러스 탐지 – 의심스러운 PHP 및 JavaScript 항목을 스캔합니다.
- 원클릭 악성코드 제거 – 감염된 파일을 즉시 격리하고 삭제합니다.
워드프레스 방화벽 및 실시간 위협 보호
Security Ninja에는 일반적인 악의적 요청을 차단하기 위한 기본 방화벽이 무료로 포함되어 있습니다(8G 기반). 더 고급 WAF 제어를 위해 Pro로 업그레이드하세요.
- 기본 보호(무료) – 8G 규칙은 많은 일반적인 공격 패턴과 악성 요청을 차단합니다.
- 고급 보호(Pro) – 클라우드 방화벽, 국가 차단, IP 목록 및 추가 인텔리전스/자동화.
- 로그인 무차별 대입 공격 방어(Pro) – 실패한 로그인을 제한하고 로그인 흐름을 강화합니다(무료 방화벽에는 포함되지 않음).
Automatic service whitelisting (Pro)
Cloud Firewall (Pro) whitelists known third-party service IPs so remote maintenance, optimization, and monitoring tools are less likely to be blocked. No manual IP entry is required for these built-in lists.
- WP Compress – image optimization and compression service
- MonSpark – uptime and website monitoring
- Modular DS – remote site management
- WPMU DEV – hosting and management platform
- Divi Dash – Elegant Themes site management
- Fastpixel – optimization service
- Broken Link Checker – link checking service
- GetTerms – cookie consent scanner (getterms.io)
Optional one-click whitelists (Firewall IP Management; enable per service):
– ManageWP – enabled by default on new installs
– WP Rocket – caching and optimization
– UptimeRobot – uptime monitoring
– Uptimia – uptime monitoring
You can still add your own IPs and CIDR ranges manually on the IP Management screen.
로그인 보안 및 이중 인증 (2FA) (PRO)
귀하의 WordPress 로그인 페이지는 해커의 주요 목표입니다. Security Ninja는 로그인 보안을 다음과 같이 강화합니다:
- 이중 인증 (2FA) – 더 안전한 로그인을 위해 추가 인증이 필요합니다.
- 무차별 대입 공격 보호 – 실패한 로그인 시도를 제한하여 무단 접근을 차단합니다.
- 로그인 이름 바꾸기 – 로그인 양식에 많은 요청이 들어오고 있나요? 스팸을 위해 숨기세요.
원클릭 보안 수정 및 워드프레스 강화 (PRO)
보안 문제를 수동으로 수정하는 것은 시간이 많이 소요됩니다. Security Ninja는 한 번의 클릭으로 보안을 강화하여:
- XML-RPC 비활성화 – 일반적인 DDoS 공격 및 무차별 대입 공격을 차단합니다.
- 파일 편집 제한 – 무단 테마 및 플러그인 수정을 방지합니다.
- PHP 오류 메시지 숨기기 – 해커가 민감한 오류 세부정보를 악용하는 것을 방지합니다.
그리고 여러분의 워드프레스 보안을 강화하기 위한 많은 수정 사항이 있습니다!
이벤트 로그 / 활동 추적
Security Ninja는 사이트에서 무슨 일이 일어나고 있는지 확인할 수 있도록 기본 이벤트 로거를 무료로 제공합니다.
- 무료: 대시보드에서 방화벽 이벤트 및 로그인 시도(성공/실패).
- 장점: 보안 로그 내보내기, 예약된 이메일 보고서, 웹훅(예: Slack/Discord), 더 세부적인 알림 기능.
자동화된 보안 스캔 및 보고서 (PRO)
Security Ninja는 정기적인 보안 스캔을 수행하고 보고서를 귀하의 이메일로 직접 전송합니다.
- 일일, 주간 또는 월간 보안 스캔을 설정하세요.
- 취약점 및 악성코드 감염에 대한 이메일 알림을 받으세요.
- 웹사이트를 안전하게 유지하기 위해 상세 보고서를 분석하세요.
스팸 및 악성 봇 즉시 차단 (PRO)
해커와 스팸mer는 봇을 사용하여 워드프레스 웹사이트를 악용합니다. 보안 닌자는 다음을 방지합니다:
- 가짜 회원가입 및 스팸 댓글 – 봇이 귀하의 사이트에 접근하는 것을 차단합니다.
- 악성 봇 공격 – 사이트를 해킹하려는 스크립트를 차단합니다.
- 원치 않는 트래픽 – 불필요한 봇 접근을 차단하여 서버 부하를 줄입니다.
AI 보안 자문가 – 스캔 결과에서 명확한 다음 단계까지 (워드프레스 7)
보안 스캔을 이해하는 일이 숙제처럼 느껴져서는 안 됩니다. AI Security Advisor는 연결된 LLM(WordPress 7 AI Connectors를 통해)을 사용해 Security Ninja의 결과를 읽기 쉬운 감사 보고서로 바꿔 줍니다: 경영진 요약, 우선순위가 지정된 개선 사항, 그리고 제안된 후속 프롬프트—무한히 대화하는 챗봇이 아닙니다.
보고서는 보안 테스트, 취약성 스캐너, 코어 스캐너, 최근 방화벽/로그인 이벤트, 그리고 사용 가능한 경우 Pro 사이트의 멀웨어 스캐너 결과를 바탕으로 작성됩니다. 저장된 보고서는 직접 제거할 때까지 사이트에 유지됩니다.
필요한 것
AI Security Advisor는 무료 플러그인에 포함되어 있지만 워드프레스 7이 필요합니다. 워드프레스의 설정 커넥터에서 AI/LLM 공급자를 직접 연결해야 하며, Security Ninja는 호스팅을 제공하거나 API 키를 공급하지 않습니다.
워드프레스 Abilities(선택 사항)
워드프레스 7에서는 Security Ninja가 읽기 전용 Abilities를 등록하여, 같은 사이트의 다른 AI 도구가 테스트 요약, 7일간의 공격 활동 또는 최근 저장된 감사 결과를 가져올 수 있습니다. 여러 AI 통합을 사용하는 경우 유용합니다. Security Advisor 페이지의 보고서 생성 및 후속 작업은 이 기능과 별개로 작동합니다.
일상적인 표현으로 보는 개인정보 보호
식별되지 않는 보안 맥락(테스트 결과, 스캔 상태, 이벤트 수—개인 데이터 아님)만 선택한 AI 제공업체로 전송되어 보고서를 작성하는 데 사용됩니다.
워드프레스 7을 아직 사용 중이 아니라면 AI 보안 자문 화면에서 알림이 표시됩니다. 나머지 Security Ninja는 평소처럼 계속 작동합니다.
수천 명의 만족한 사용자가 웹사이트를 안전하게 지켜주는 Security Ninja를 신뢰하고 있습니다. 지금 바로 온라인 존재를 보호하세요.
확장
MainWP – 하나의 MainWP 대시보드에서 여러 사이트의 Security Ninja를 관리하세요. 각 자식 사이트의 Security Ninja에는 MainWP 통합 기능이 내장되어 있습니다(자식 사이트에 추가 플러그인 필요 없음).
- 무료 애드온 – Security Ninja for MainWP (WordPress.org): 사이트별로 테스트 결과와 취약점을 보기, 원격 보안 스캔을 실행하고, 최신 결과를 동기화합니다. 무료 또는 Pro Security Ninja의 자식 사이트에서 작동하며, 표시된 데이터는 각 사이트에 설치된 버전이 제공하는 내용과 일치합니다.
- 프리미엄 애드온 – 연결된 모든 사이트의 이벤트 로그를 통합해 추가하고, 보안 이벤트를 검색/필터링하며, Pro 하위 사이트에서 원격 화이트 레이블 제어를 제공합니다. 로그 및 화이트 레이블 기능을 사용하려면 하위 사이트에 Security Ninja Pro가 필요합니다. WP Security Ninja 계정에서 이용할 수 있으며, 자세한 내용은 MainWP 통합을 참조하세요.
https://wordpress.org/plugins/security-ninja-for-mainwp/
Security Ninja Pro는 Cloud Firewall(6억+ 개의 알려진 악성 IP), 국가 차단, 고급 WAF 제어, 악성코드 스캐너, 로그인 보호(로그인 실패 제한, 로그인 이름 변경, 2FA), 원클릭 수정, 전체 이벤트 로거(내보내기, 웹훅, 예약 보고서), 예약 스캔을 추가합니다. 무료 플러그인에는 이미 8G 방화벽, 50개 이상의 보안 테스트, 취약점 스캐너, 코어 스캐너, 기본 이벤트 로거, 그리고 워드프레스 7의 AI 보안 어드바이저가 포함되어 있습니다.
모든 사이트를 위한 올인원 보안 솔루션. 프리미엄 지원과 지속적인 업데이트를 제공하는 Security Ninja Pro는 귀하의 사이트를 안전하게 유지하는 완벽한 도구입니다. PRO 버전이 제공하는 내용을 확인하세요
한 번의 클릭으로 6억 개 이상의 나쁜 IP를 자동으로 차단하세요! Security Ninja Pro 방화벽은 수백만 개의 공격받은 사이트의 집단적인 노하우를 활용하여 나쁜 사람들보다 한 발 앞서 나가고, 그들이 귀하의 사이트를 열기 전에 나쁜 사람들을 차단하는 데 도움을 줄 것입니다.
Pro 기능에 대한 자세한 내용은 Security Ninja 웹사이트를 참조하세요.
플러그인에 대한 다른 사람들의 의견
- Kinsta
- Hostinger
- Cloudways
- AppSumo
- Freemius
- WP Mayor: “사용하기 쉬운 워드프레스 보안 플러그인”
- WPMarmite
- WPExplorer
- WPLift
- WP Loop
- InfluenceWP
- G2
Tests
* The tests include:
* brute-force attack on user accounts to test password strength
* numerous installation parameters tests
* file permissions
* version hiding
* 0-day exploits tests
* debug and auto-update modes tests
* database configuration tests
* Apache and PHP related tests
* WP options tests
* security headers and related server response checks
- The full suite covers 50+ checks across WordPress core/plugins/themes, user accounts and passwords, file permissions, debug modes, database configuration, PHP settings, security headers, and more. Open Security Ninja in your dashboard for the complete list with explanations and fix guidance.
라이선스 정보
-
취약점 스캐너는 국가 취약점 데이터베이스 – NVD의 데이터를 사용합니다.
-
이 제품에는 https://lite.ip2location.com에서 제공되는 IP2Location LITE 데이터가 포함되어 있습니다.
-
이 플러그인은 Collins Agbonghama @collizo4sky의 Persist Admin notice Dismissals를 사용합니다.
-
방화벽 규칙은 Jeff Starr의 8G Firewall을 기반으로 합니다 – https://perishablepress.com/8g-blacklist/
보안 버그를 어떻게 신고할 수 있나요?
보안 버그는 Patchstack 취약점 공개 프로그램을 통해 신고할 수 있습니다. Patchstack 팀은 모든 보안 취약점을 유효한지 확인하고, 분류하며, 처리하는 데 도움을 줍니다. 보안 취약점을 신고하세요.
설치
워드프레스에서 설치하기
- 워드프레스 관리자에 로그인하고, 플러그인으로 이동한 후 새로 추가하기를 클릭하세요.
- 검색창에 ‘Security Ninja’를 입력하고 Enter 키를 누르세요.
- 플러그인이 목록의 첫 번째로 나타납니다. ‘지금 설치’를 클릭하세요.
- 활성화하고 도구 – 보안 닌자로 이동하여 사이트를 더 안전하게 만드세요.
수동으로 설치하기
- 플러그인을 다운로드하세요.
- 압축을 풀고 wp-content/plugin/에 업로드하세요.
- 워드프레스 관리자 열기 – 플러그인에서 플러그인 옆의 ‘활성화’를 클릭하세요.
- 활성화하고 보안 닌자에 가서 사이트를 더 안전하게 만드세요
FAQ
-
무료 버전에 워드프레스 방화벽(WAF)이 포함되어 있나요?
-
예. Security Ninja에는 8G 룰셋을 기반으로 하는 기본적인 웹 애플리케이션 방화벽(WAF)을 무료로 제공하며, 일반적인 악성 요청을 차단하고 봇 소음을 줄입니다.
-
Security Ninja가 무차별 대입 공격 및 로그인 시도를 방어하나요?
-
Pro에는 로그인 무차별 대입 공격 방지(로그인 실패 제한), 로그인 이름 변경, 2FA가 포함됩니다. 무료 버전은 Events Logger에 로그인 시도(성공/실패)를 기록하고 비밀번호 강도를 확인하는 보안 테스트를 실행하지만, 반복되는 로그인 실패를 자체적으로 차단하지는 않습니다.
-
Security Ninja에 워드프레스 취약점 스캐너가 포함되어 있나요?
-
예. 취약점 스캐너는 무료 버전에서 완전히 제공됩니다이며 플러그인/테마의 알려진 취약점을 식별하여 신속히 패치할 수 있도록 도와줍니다.
-
이 플러그인은 누구를 위한 것인가요?
-
사이트 소유자, 에이전시 및 개발자들이 사이트를 강화하고 문제를 조기에 발견하기 위해 사용하는 경량 워드프레스 보안 플러그인.
-
이 플러그인이 제 사이트를 느리게 하나요?
-
정상 작동 시에는 아니요. 다만 일부 검사(스캔)는 실행 중 일시적으로 더 많은 자원을 사용할 수 있습니다.
-
Security Ninja가 내 사이트에 어떤 변경을 할까요?
-
Security Ninja는 검사를 실행하고 권장사항을 표시합니다. 일부 Pro 기능은 방화벽/WAF 제어, 로그인 보호와 같은 활성 보호 계층을 추가할 수 있으며, 이를 구성할 수 있습니다.
-
플러그인에 문제가 발생하면 어떻게 하나요?
-
우리는 보편적인 호환성을 위해 노력하고 있지만, 문제가 발생할 경우 저희 지원 팀이 도와드릴 준비가 되어 있습니다. 새로운 스레드를 열려면 저희 지원 포럼을 방문해 주시기 바랍니다. 최대한 빨리 도와드리겠습니다.
후기
기여자 & 개발자
“Security Ninja – 워드프레스 보안 및 방화벽”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.
기여자변경이력
5.302
- 2026-09-01
- FIX: Firewall – Per-visitor reverse-DNS, ASN, and GeoIP caches no longer fill the WordPress options table with one row per IP. On busy sites without Redis/Memcached that could grow to hundreds of thousands of rows and cause intermittent downtime. After update, leftover rows are removed automatically in small batches. Thank you Davina.
- FIX: Firewall – Search-engine and crawler checks only run reverse-DNS when the User-Agent looks like a known crawler. Normal browser traffic no longer triggers a DNS lookup on every page view. AI crawlers (OpenAI, Perplexity, Claude) are checked against published IP ranges only.
- FIX: Firewall – Hostname-based “blocked hosts” matching (part of Filter Suspicious Queries) is off by default. URI, query string, user agent, and referrer rules still run. Developers can re-enable hostname checks with the secnin_cf_check_blocked_hosts filter.
- FIX: Firewall – Satellite/ASN softening (Pro) no longer calls the remote ASN API on every miss when the site has no object cache. With Redis or Memcached, results are cached there instead of in the database.
- FIX: Firewall – The list of remembered validated crawler IPs is limited to 200 entries so it cannot grow without bound.
- FIX: Fixes – Disable Username Enumeration now blocks anonymous REST user listing (/wp/v2/users and ?rest_route=), not only by removing the endpoint. The username enumeration security test checks that path as well. Thank you Elias.
5.301
- 2026-08-31
- FIX: Fixes – Saving Security Fixes with “Disable debug mode” off no longer forces WP_DEBUG to true in wp-config.php. Thank you Mike.
- IMPROVED: Vulnerability Scanner – Update notices now say we are tracking more known vulnerabilities in the database, not that vulnerabilities were “downloaded” to the site. Thank you Tom.
5.300
- 2026-08-25
- FIX: Firewall – Removed the blocked_kanagawa hostname rule again (Japanese prefecture / OCN false positives). Thank you Masahiro.
- IMPROVED: Firewall – Filter Suspicious Queries help text now states that it includes reverse-DNS hostname checks, separate from Cloud Firewall and Prevent Banned IPs.
- FIX: Scheduled Scanner – Security Testing emails no longer fire on message-only diffs or HTTP timeout Warning/Good flaps.
5.299
- 2026-08-24
- FIX: Vulnerability Scanner – Opening the Vulnerabilities tab no longer floods PHP warnings when a CVE reference is missing its display name (Undefined property stdClass::$name) or when strip-http helpers receive null (strpos deprecation on PHP 8+).
- NEW: Cloud Firewall – Claude / Anthropic crawlers (ClaudeBot, Claude-User, Claude-SearchBot) are verified against Anthropic’s published IP ranges at claude.com/crawling/bots.json, same pattern as OpenAI and Perplexity. Thank you David.
- FIX: Security Tests – Local site detection no longer strips dots from 127.0.0.1 via sanitize_key (which broke TLS skip-verify). Self-checks against .local hosts and WP_ENVIRONMENT_TYPE=local work again, so tests like debug.log accessibility stop failing with a generic transport error on Local.
- FIX: Security Tests – REST API enabled check now skips TLS verify on local sites (same as other self-checks). Local installs with self-signed certs no longer get a false “Could not determine REST API accessibility” warning.
- FIX: Security Tests – PHP ini boolean checks (allow_url_include, expose_php, display_errors, register_globals, safe_mode) no longer treat the string Off as enabled.
- IMPROVED: Security Tests – expose_php test passes when the PHP version header is already hidden via Security Headers or server config (e.g. .htaccess), not only when php.ini is editable.
- FIX: Auto Fixer – Table prefix change requires an explicit prefix, shows the applied prefix on success, and handles long runs/timeouts more clearly.
5.298
- 2026-08-18
- FIX: MainWP – Applying Malware Scanner whitelist settings no longer wipes existing file hashes when the dashboard does not send them, so ignored files stay ignored.
- IMPROVED: MainWP – White Label updates now properly report success or failure per site, so a bulk push no longer looks like it succeeded everywhere.
- IMPROVED: German – Events Logger and Overview now talk about security events (Ereignisse), not calendar events. Other leftover strings such as event details, action counts, and emptied log are corrected too.
- IMPROVED: Spanish – Admin screens read more naturally. Buttons and actions such as Close, Save, Clear, and Ban IP now mean what they say.
5.297
- 2026-08-14
- FIX: Compatibility – Removed a chillerlan Settings class_alias that broke LatePoint (and similar) booking confirmation QR codes after the 5.294 Imposter isolation fix. Thank you Daniel.
- IMPROVED: Security headers – Default Referrer-Policy is now strict-origin-when-cross-origin (browser-aligned; better embed compatibility). Existing saved settings are not changed. Thank you Heath.
- NEW: MainWP – Added the remote
update_vulnerabilitiesaction for free and Pro sites. It schedules a dedicated one-off database refresh even when the normal daily or weekly vulnerability job already exists. - IMPROVED: MainWP – Remote vulnerability refreshes now return clear scheduled, already-pending, unavailable, and scheduling-failed responses.
- IMPROVED: MainWP – Remote settings apply accepts blocked-country lists, Malware Scanner whitelist paths, and Core Scanner ignore paths with Security Ninja for MainWP 2.2.0+.
- FIX: MainWP – Copying Malware Scanner whitelist settings now keeps filename, hash, and pattern entries instead of flattening them into strings the scanner ignores.
- FIX: Core Scanner – Deactivating the plugin on a Multisite subsite no longer deletes network-wide scan results, ignore lists, or the main-site daily scan schedule.
- FIX: MainWP – Malware whitelist path sanitization now accepts the stored
filenamefield when settings are copied between sites.
5.296
- 2026-08-11
- FIX: After activating the plugin, redirect to the main Security Ninja page instead of the setup wizard so Freemius license entry is not skipped. Wizard opens after license activation when setup is still incomplete.
- FIX: Vulnerability Scanner – Rendering a WordPress CVE no longer fatals with ArgumentCountError (sprintf placeholder mismatch), which could white-screen the entire Security Ninja admin. Thank you Franck.
- FIX: Vulnerability Scanner – Vulnerability list download works whether the CDN sends gzip, already-decoded JSONL, or a stale Content-Encoding header. A failed decode no longer wipes a good local file. Local lists saved as *.jsonl_.gz (WordPress sanitize_file_name on 5.294+) are read again; new saves use *.jsonl.gz.
5.295
- 2026-08-03
- FIX: AI Security Advisor – Scheduled Core Scanner (and other background scans) no longer fatal with “Wf_Sn_Ai_Advisor_Reevaluate_Notice class not found” during WP-Cron, which could abort the rest of the cron run. Thank you Michael.
- FIX: Malware Scanner – A failed or incomplete AJAX scan no longer shows as clean (“No suspicious files found”). Failed steps stop the chain, mark the run incomplete, and show a clear warning instead of a false clean banner. Thank you Haseeb.
5.294
- 2026-08-02
- FIX: Vulnerability Scanner – Local vulnerability database files are stored compressed so host malware scanners no longer false-positive on known-issue descriptions (e.g. wp-config). Thank you Lee.
- FIX: Compatibility – Imposter-prefixed vendor autoload no longer claims unprefixed chillerlan namespaces, fixing a fatal when LatePoint (and similar plugins) generate booking QR codes. Thank you Daniel.
- FIX: Core Scanner – Scheduled (cron) scans no longer fail with “Insufficient permissions”. Manual scans were fine; background runs now complete as expected. Thank you Mirco.
- IMPROVED: Cloud Firewall – Faster visitor checks with less DNS and disk work on each page load.
- IMPROVED: Vulnerability Scanner – Lighter scheduled vulnerability list updates with lower memory use.
- FIX: AI Security Advisor – Prevent a critical error on Overview when WordPress AI Client connector checks fail (e.g. TypeError from getModelMetadataMap). Admin stays usable; thank you Tyson.
- FIX: AI Security Advisor – WordPress Abilities register on plugin load so REST and other AI tools can discover them reliably.
- FIX: AI Security Advisor – Abilities load their data when invoked outside the Advisor screen (no fatal on REST/MCP calls).
- IMPROVED: AI Security Advisor – WordPress Abilities exposure is on by default for new installs (can be turned off in AI settings).
- FIX: Vulnerability Scanner – Admin menu badge and other admin hot paths no longer load the full vulnerability database on every wp-admin request (could time out / 502 on slower hosts). Counts are served from cache; scans run in the background via WP-Cron. Thank you Christopher.
- FIX: Vulnerability Scanner – Opening Security Ninja no longer sync-downloads the vulnerability database when files are missing; updates are scheduled in the background. Pending scans no longer show a false “no vulnerabilities” message.
- IMPROVED: Vulnerability Scanner – Plugin/theme and vulnerability-database updates keep the last known results until the background rescan finishes (no empty badge gap).
- IMPROVED: Cloud Firewall – Logged-in admins skip expensive ban checks in wp-admin and admin-ajax; local banned-IP list is cached per request.
- IMPROVED: sn-global.js loads only on Security Ninja admin pages; AI Security Advisor class files load on demand instead of every request.
- IMPROVED: Cloud Firewall (Pro) – Added GetTerms cookie scanner IP (45.55.125.144) to the built-in automatic whitelist (always on; no checkbox required). Thank you Jamie.
- FIX: Cloud Firewall (Pro) – “Only block these countries from login functionality” now works when “Prevent Banned IPs from Accessing the Site” is ON. Previously, country login-only could still full-site block via the visitor check path. Thank you Jamie.
5.293
- 2026-07-22
- NEW: File Viewer – Safely preview common images (PNG, JPG, JPEG, GIF, WebP, ICO) from Core and Malware Scanner results. SVG is not supported. Images are verified before display and shown only in the admin viewer (they are not executed).
- FIX: File Viewer – Extensionless and rotated log files such as error_log and error_log.1 open more reliably, including case-insensitive name matching.
- IMPROVED: File Viewer – Very large text/log files show a truncated preview instead of failing when over the size limit.
- IMPROVED: Core Scanner – The View File button only appears when the file can actually be opened in the viewer.
- IMPROVED: Security Tests – The unused-themes check no longer treats keeping an extra default WordPress (Twenty*) theme as required. Any inactive theme can be flagged for removal, matching the auto-fixer behavior. Thank you for the feedback.
- FIX: Fixes – Disable Username Enumeration no longer blocks URLs with parameters like book_author= (e.g. store search). It now matches only the WordPress author= parameter, and skips the block for logged-in users.
5.292
- 2026-07-15
- IMPROVED: Translations – Full POT refresh and locale sync.
- IMPROVED: Translations – 2FA email and login strings covered in language packs (Spanish included).
- IMPROVED: White Label (Pro) – HTML emails use your plugin icon (when set) in branding.
- FIX: 2FA (Pro) – Login “Back to site” link uses the correct text domain so it can be translated.
- IMPROVED: 2FA (Pro) – Custom intro and enter-code texts from Login Protection now appear on the 2FA login screen.
- IMPROVED: 2FA (Pro) – Email verification codes now use the same shared email template as other Security Ninja emails.
- FIX: 2FA (Pro) – Email “Time:” label is properly registered for translation.
- NEW: Prettier interface for confirmations and overlays across free and Pro — replaces browser confirm/alert on Tools, scanners, Firewall, Events, AI Advisor, 2FA, and more. Escape closes, backdrop cancels, Enter confirms.
- NEW: Optional notes/labels on manual IP whitelist and blacklist entries (IP Management), including CIDR ranges. Notes are limited to 150 characters and stored separately so existing installs and list matching stay compatible.
- IMPROVED: Settings import/export and MainWP sync include IP notes when present.
- FIX: AI Security Advisor – Omit temperature from WordPress AI connector requests so providers that reject sampling parameters (e.g. newer Claude models) work reliably. Thank you Tyson.
- IMPROVED: Update Freemius SDK.
- IMPROVED: readme.txt – Shortened short description, description, and changelog to meet WordPress.org length limits.
- FIX: Cloud Firewall (Pro) – Avoid PHP warning when REMOTE_ADDR is missing during cron blocklist sync. Thank you Tom.
5.291
- 2026-07-06
- NEW: Overview tab – AI Security Advisor card, next best actions, what changed since your last AI review, and quick action links to key modules.
- NEW: Security Advisor – Suggested next steps and “what changed since last report” panels use scan snapshots without an extra AI call.
- FIX: AI Security Advisor – Database upgrade on update adds the snapshot column to existing AI report tables so comparisons work on upgraded sites.
- FIX: 2FA (Pro) – Email code verification works when you press Verify or Enter.
- IMPROVED: 2FA (Pro) – Login verification updates apply immediately after plugin updates.
- IMPROVED: 2FA (Pro) – Administrator is pre-selected under Required Roles when 2FA is not yet enabled; clearer grace period help for required roles.
- FIX: AI Security Advisor – Your selected AI connector applies when you generate a report.
- IMPROVED: AI Security Advisor – Model selection follows WordPress AI Client settings.
- FIX: Setup wizard – Opens automatically on first install only.
- IMPROVED: Cloud Firewall (Pro) – Added more WP Compress service IPs to the built-in automatic whitelist (always on; no checkbox required).
- FIX: Cloud Firewall – Filter Suspicious Queries no longer false-positives on s2Member loader URLs.
- NEW: Cloud Firewall (Pro) – MonSpark uptime monitoring IPs are included in the built-in automatic whitelist (always on; no checkbox required). Thank you Heath.
- IMPROVED: Core Scanner – Detects unexpected files in the WordPress root and hidden dotfiles in wp-admin and wp-includes.
- NEW: Malware Scanner (Pro) – Flags suspicious plugin and theme folder structure when wordpress.org checksums are unavailable (review recommended, separate from malware signatures).
- IMPROVED: Malware Scanner (Pro) – Clearer integrity messaging; structural findings included in issue counts, whitelist, scheduled reports, and AI advisor context.
- IMPROVED: Core Scanner – OS metadata files (e.g. .DS_Store) are excluded from scan results.
- IMPROVED: Core Scanner – Severity levels (critical, warning, notice) with guidance for phpinfo and dev-tool files; table-based results UI.
- IMPROVED: Core Scanner – Live scan results without page reload; summary stats; Overview Core Integrity widget.
- IMPROVED: White Label (Pro) – Security Advisor and Overview use your white label plugin name in the UI and AI reports. Thank you Davina.
- IMPROVED: Visitor Log (Pro) – Cleaner Refresh button on the visitor log page.
- IMPROVED: Core Scanner – Summary strip with scan context, status banner, and last-scan metadata; delete or restore individual rows without a full rescan.
- IMPROVED: Core Scanner – Findings action buttons match Malware Scanner styling (View File, Diff, Restore, Delete).
- IMPROVED: Malware Scanner (Pro) – Issue counter on the Malware tab when suspicious files are found.
- IMPROVED: Malware Scanner (Pro) – Summary strip with last-scan context, status banner, and Whitelist all; streamlined results header.
- IMPROVED: Malware Scanner (Pro) – Findings use the same table layout as Core Scanner (file, severity, guidance, actions) with location group headers.
- IMPROVED: Core Scanner and Malware Scanner – Cleaner findings list layout.
5.290
- 2026-06-30
- NEW: 2FA (Pro) – Optional mode: enable 2FA without requiring any role; leave all required roles unchecked for opt-in only (with an admin notice when saved).
- NEW: 2FA (Pro) – Users can enable 2FA from their profile (authenticator app or email, when allowed) even if their role is not required.
- NEW: 2FA (Pro) – Admins can allow authenticator app and/or email; users choose their method at login when both are enabled (preference is remembered).
- IMPROVED: 2FA (Pro) – Required roles can be fully unchecked and stay saved (previously Administrator was forced back on).
- IMPROVED: 2FA (Pro) – Grace period “Skip for now” applies only to role-required users who have not voluntarily enrolled.
- IMPROVED: 2FA (Pro) – Grace period can be set to 0 days to enforce setup immediately.
- IMPROVED: Wizard – CSS on installation.
It seems that you haven’t provided any text to translate. Please provide the text you’d like to have translated into Korean, and I’ll be happy to help!
Entire changelog can be seen here: https://wpsecurityninja.com/changelog/
