
Your secure foundation built by WordPress security experts since 2014
Stop brute force attacks in their tracks- Secure and protect the most commonly attacked part of your WordPress website — user login authentication
- Automatically lock out bad users identified by our Brute Force Protection Network and your own blacklist
- Automatically require users to create strong passwords
- Log in with Two-Factor Authentication, or, even better, passkeys
- Scan your site for vulnerabilities reported by our partners at Patchstack
- Run a WordPress Security Scan to identify vulnerable software
v8.0.3 - 2023-10-30 - Timothy Jacobs, Lisa Canini, Jared Hill
Security: Don't disclose the login URL when using Hide Backend on a site with comments enabled and comment registration required. Thanks to Naveen Muthusamy for disclosing this issue.
Hardening: Check for the promote_user capability when using Privilege Escalation in addition to edit_user.
Tweak: Remove the iThemes Security is now Solid Security banner from admin-facing email notifications.
Bug Fix: Prevent the User Security page from crashing when "Show Avatars" is disabled in the WordPress discussion settings.
Bug Fix: Fix some filters on the User Security page not working as expected.
Bug Fix: Fix spacing on the Two-Factor form when backup methods are enabled.
Update: The lib/updater library has been updated to 1.8.1
Enhancement: Add a `wp ithemes-licensing set-licensed-url` WP-CLI command.
Bug Fix: Fix fatal error when there is an error retrieving Patchstack license information.
Bug Fix: Styling issues on WordPress 6.4.
Demo: https://ithemes.com/security/