• Nullsto Rules must be read before making a post, otherwise you will get permanent warning points or a permanent ban.

    Nullsto Forum provides CLEAN and SAFE resources. You can use them for development and testing if you are on Windows and have an antivirus that alerts you about a possible infection: It is a false positive since every script is double checked by our experts. While downloading a resource, we recommend that you add Nullsto to your trusted sites/sources or temporarily disable your antivirus. "Enjoy your presence on Nullsto"
Security Ninja Pro - WordPress Security Made Easy

Security Ninja Pro - WordPress Security Made Easy v5.302 Nulled

No permission to download
Security Ninja PRO - WordPress Security Made Easy v5.302 Nulled
= 5.302 =
* 2026-09-01
* FIX: Firewall - Per-visitor reverse-DNS, ASN, and GeoIP caches no longer fill the WordPress options table with one row per IP. On busy sites without Redis/Memcached that could grow to hundreds of thousands of rows and cause intermittent downtime. After update, leftover rows are removed automatically in small batches. Thank you Davina.
* FIX: Firewall - Search-engine and crawler checks only run reverse-DNS when the User-Agent looks like a known crawler. Normal browser traffic no longer triggers a DNS lookup on every page view. AI crawlers (OpenAI, Perplexity, Claude) are checked against published IP ranges only.
* FIX: Firewall - Hostname-based "blocked hosts" matching (part of Filter Suspicious Queries) is off by default. URI, query string, user agent, and referrer rules still run. Developers can re-enable hostname checks with the secnin_cf_check_blocked_hosts filter.
* FIX: Firewall - Satellite/ASN softening (Pro) no longer calls the remote ASN API on every miss when the site has no object cache. With Redis or Memcached, results are cached there instead of in the database.
* FIX: Firewall - The list of remembered validated crawler IPs is limited to 200 entries so it cannot grow without bound.
* FIX: Fixes - Disable Username Enumeration now blocks anonymous REST user listing (/wp/v2/users and ?rest_route=), not only by removing the endpoint. The username enumeration security test checks that path as well. Thank you Elias.
Security Ninja PRO - WordPress Security Made Easy v5.297 Nulled
= 5.297 =
* 2026-08-14
* FIX: Compatibility - Removed a chillerlan Settings class_alias that broke LatePoint (and similar) booking confirmation QR codes after the 5.294 Imposter isolation fix. Thank you Daniel.
* IMPROVED: Security headers - Default Referrer-Policy is now strict-origin-when-cross-origin (browser-aligned; better embed compatibility). Existing saved settings are not changed. Thank you Heath.
* NEW: MainWP - Added the remote `update_vulnerabilities` action for free and Pro sites. It schedules a dedicated one-off database refresh even when the normal daily or weekly vulnerability job already exists.
* IMPROVED: MainWP - Remote vulnerability refreshes now return clear scheduled, already-pending, unavailable, and scheduling-failed responses.
* IMPROVED: MainWP - Remote settings apply accepts blocked-country lists, Malware Scanner whitelist paths, and Core Scanner ignore paths with Security Ninja for MainWP 2.2.0+.
* FIX: MainWP - Copying Malware Scanner whitelist settings now keeps filename, hash, and pattern entries instead of flattening them into strings the scanner ignores.
* FIX: Core Scanner - Deactivating the plugin on a Multisite subsite no longer deletes network-wide scan results, ignore lists, or the main-site daily scan schedule.
* FIX: MainWP - Malware whitelist path sanitization now accepts the stored `filename` field when settings are copied between sites.
Security Ninja PRO - WordPress Security Made Easy v5.295 Nulled
== Changelog ==

= 5.295 =
* 2026-08-03
* FIX: AI Security Advisor - Scheduled Core Scanner (and other background scans) no longer fatal with "Wf_Sn_Ai_Advisor_Reevaluate_Notice class not found" during WP-Cron, which could abort the rest of the cron run. Thank you Michael.
Security Ninja PRO - WordPress Security Made Easy v5.293 Nulled
== Changelog ==

= 5.293 =
* 2026-07-22
* NEW: File Viewer - Safely preview common images (PNG, JPG, JPEG, GIF, WebP, ICO) from Core and Malware Scanner results. SVG is not supported. Images are verified before display and shown only in the admin viewer (they are not executed).
* FIX: File Viewer - Extensionless and rotated log files such as error_log and error_log.1 open more reliably, including case-insensitive name matching.
* IMPROVED: File Viewer - Very large text/log files show a truncated preview instead of failing when over the size limit.
* IMPROVED: Core Scanner - The View File button only appears when the file can actually be opened in the viewer.
* IMPROVED: Security Tests - The unused-themes check no longer treats keeping an extra default WordPress (Twenty*) theme as required. Any inactive theme can be flagged for removal, matching the auto-fixer behavior. Thank you for the feedback.
* FIX: Fixes - Disable Username Enumeration no longer blocks URLs with parameters like book_author= (e.g. store search). It now matches only the WordPress author= parameter, and skips the block for logged-in users.
Security Ninja PRO - WordPress Security Made Easy v5.290 Nulled
== Changelog ==

= 5.290 =
* 2026-06-30 *
* NEW: 2FA (Pro) - Optional mode: enable 2FA without requiring any role; leave all required roles unchecked for opt-in only (with an admin notice when saved).
* NEW: 2FA (Pro) - Users can enable 2FA from their profile (authenticator app or email, when allowed) even if their role is not required.
* NEW: 2FA (Pro) - Admins can allow authenticator app and/or email; users choose their method at login when both are enabled (preference is remembered).
* IMPROVED: 2FA (Pro) - Required roles can be fully unchecked and stay saved (previously Administrator was forced back on).
* IMPROVED: 2FA (Pro) - Grace period "Skip for now" applies only to role-required users who have not voluntarily enrolled.
* IMPROVED: 2FA (Pro) - Grace period can be set to 0 days to enforce setup immediately
* IMPROVED: CSS on wizard installation.
Security Ninja PRO - WordPress Security Made Easy v5.289 Nulled
== Changelog ==

= 5.289 =
* 2026-06-18
* FIX: Cloud Firewall (Pro) - Visitor log retention ("Keep visitor logs for") is now enforced by a daily scheduled cleanup task.
* NEW: Tools (Pro) - "Clear visitor log" button to delete all firewall visitor log entries manually.
* NEW: Setup wizard available for all; first install opens the wizard automatically.
* IMPROVED: Cloud Firewall – The firewall master switch now consistently controls all firewall enforcement (404 Guard, WooCommerce protection, country rules, and cloud IP blocking). Login Protection (brute-force limits, rename login, 2FA, and related messages) continues to operate independently when the firewall is turned off.
* FIX: Cloud Firewall - Manual whitelist entries for localhost (127.0.0.1 / ::1) now reliably exempt requests from cloud reputation blocks; server cron and WP-CLI traffic is no longer blocked during early firewall checks. Non-public IPs are excluded from cloud blacklist matching.
* FIX: Cloud Firewall (Pro) - Country blocking now blocks the full site when "Only block these countries from login functionality" is OFF, regardless of the "Prevent Banned IPs from Accessing the Site" setting. Previously, country bans could behave like login-only blocks when that IP setting was OFF.
* IMPROVED: Wizard - single Pro overview on Welcome for free users; removed per-step upgrade buttons.
* IMPROVED: Wizard - Events Logger and Vulnerability Scanner activation steps.
* IMPROVED: Wizard - Login protection as dedicated Pro step.
* IMPROVED: Wizard - Pro badges on footer nav for Login, Fixes, and WooCommerce (hidden for licensed Pro users).
* IMPROVED: Wizard - skip wizard from intro; rerun warning only shown after wizard has been completed once.
* IMPROVED: Wizard - Dead code cleanup.
* REMOVED: WP Pointer "thank you for installing" tour and dashboard welcome banner (replaced by wizard).
* IMPROVED: Renamed review-notice dismiss nonce for clarity (`wf_sn_dismiss_review`).
* NEW: Security Tests Quick Filter - **Fixable** shows tests with one-click auto-fix available.
* NEW: Malware Scanner - **Whitelist all** button for currently flagged files (with confirmation).
* FIX: Apply Fix - after a fix completes, the test row refreshes automatically (spinner stops, status icon and score update, clear success message).
* IMPROVED: Tools page - unique form IDs and dedicated nonce fields/actions per form (Update Database, Reset 2FA, Legacy cleanup, Import, Secret URL reset).
* IMPROVED: Cloud Firewall - suspicious-query filtering now resolves visitor hostnames only when needed for blocked-hostname rules, with per-IP caching. Thank you Paul.
* IMPROVED: Cloud Firewall - Bundled data lists (ManageWP/UptimeRobot/Uptimia service IPs and the country list) are now stored as JSON data files so security scanners no longer flag them as false positives. Thank you Daryl.
* REMOVED: Unused MainWP remote actions (run_malware_scan, update_vulnerabilities, force_create_tables); malware runs via run_all_tests, tables created on activation/upgrade.
* FIX: Scheduled Scanner (Pro) - Scheduled scans now self-heal. If the scheduled event goes missing (for example after a long scan times out or a cron/optimization plugin clears it), it is recreated automatically instead of requiring you to re-save settings.
* FIX: Scheduled Scanner (Pro) - Email reports now show the correct status changes. Status labels (Good / Warning / Failed) and the "improvement" vs "security concern" wording are no longer reversed.
* IMPROVED: Security Tests - When a test cannot reach your site (e.g. a connection timeout), it now reports a "Warning / could not verify" result instead of a hard failure, so temporary network hiccups no longer look like new security problems.
* FIX: 2FA (Pro) - After verifying 2FA, the post-login redirect now mirrors WordPress core's capability handling. Users on roles that cannot access wp-admin are sent to an appropriate page instead of the dashboard (which could bounce them to the front page and appear logged out). Thank you Jason.
* IMPROVED: Updated bundled dependencies - Freemius WordPress SDK (2.13.1 → 2.13.2), phpseclib (2.0.54 → 2.0.55), and PHP Malware Scanner (1.0.30 → 1.0.31).
Security Ninja PRO - WordPress Security Made Easy v5.287 Nulled
== Changelog ==

= 5.287 =
* 2026-06-02
* FIX: Change Login URL (Pro) — Works when Cloud Firewall is disabled; only “Change login URL” and the slug need to be enabled under Login Protection.
* FIX: Change Login URL (Pro) — `/your-slug/` login URLs work even when permalinks are Plain (fixes 404 when the Preview link used a path-style URL).
* FIX: Change Login URL (Pro) — Reliable path matching for subdirectory installs; fallback serves login if WordPress resolved the request as a 404.
* FIX: Change Login URL (Pro) — wp-admin blocking applies to `/wp-admin` with or without a trailing slash.
* IMPROVED: Change Login URL (Pro) — Admin Preview shows the same URL the plugin uses (`?slug` on Plain permalinks, `/slug/` otherwise).
Security Ninja PRO - WordPress Security Made Easy v5.284 Nulled
= 5.284 =
* 2026-05-23
* FIX: Change Login URL (Pro) — Checkout and other frontend flows that use WordPress `admin-post.php` (for example FluentCart account creation during checkout) no longer show “Access Denied” for visitors. Legitimate public handlers registered with `admin_post_nopriv_*` are allowed; direct access to the rest of wp-admin stays blocked.
* IMPROVED: Rename Login (Pro) — Recognized temporary-login plugin links (Temporary Login Without Password, One Time Login, Magic Login, Login Links) are no longer blocked when accessing wp-admin before authentication completes. Extend via the `securityninja_rename_login_allow_autologin` filter.
* IMPROVED: AI Security Advisor now uses WordPress 7 structured AI responses for more reliable report output.
* IMPROVED: AI Security Advisor reports now include richer context from Security Tests, Vulnerability Scanner, Core Scanner, and recent security events.
* IMPROVED: Pro sites now include Malware Scanner findings in AI report context when available.
* NEW: WordPress 7 Abilities (optional, on by default): expose read-only security data to other WordPress AI clients—Security Test summary (passed/warning/failed), 7-day attack activity vs the previous week, and the latest saved AI Security Advisor report. Control exposure under Security Advisor → Settings; turning this off does not affect generating reports or follow-ups on the Security Advisor page.
* NEW: Added a dismissable "Re-evaluate with AI" reminder after tests, scans, and firewall setting changes (stays hidden after dismiss until a new security event occurs).
Security Ninja PRO - WordPress Security Made Easy v5.282 Nulled
== Changelog ==

= 5.282 =
* 2026-04-
* FIX: Two-factor authentication (Pro) — When 2FA is enabled but required roles were missing or invalid, login could skip the 2FA step. Security Ninja now falls back to requiring **Administrator** so the code prompt always appears for protected accounts.
* FIX: Saving 2FA status would fail if firewall not enabled. Thank you Vassos.
* Added a new Tools-page Cleanup button. Securely removes any legacy options or data. Thank you Davina for the idea.
* FIX: Cloud Firewall (Pro) — Clearing **all** countries in country blocking and saving now actually turns country blocking off. Previously, choosing “none” could leave old selections in place because empty lists were not saved correctly.
* IMPROVED: Cloud Firewall — IP whitelist entries written as **ranges** (CIDR, one per line on IP Management) now apply the same way everywhere: visitor checks, secret recovery links, and automatic whitelist logic no longer treat ranges like plain single IPs only in some code paths.
* NEW: Cloud Firewall (Pro) — Option to soften country blocking for satellite ISPs like Starlink. Easily enable or adjust under Firewall → Settings for smoother access while keeping strong protection.
* IMPROVED: Cloud Firewall (Pro) — If a country or cloud block is skipped because the visitor is using a satellite ISP (satellite ASN softening), you'll now see this clearly in the Events log.
Security Ninja PRO - WordPress Security Made Easy v5.276 Nulled
== Changelog ==

= 5.276 =
* 2026-03-27
* Maintenance release - Minor improvements and stability.
* FIX: Security Fixes — Saving the Fixes screen now applies wp-config changes only when toggles are ON: disable file editor, disable WP_DEBUG, and secure session cookies. Previously, always-present form keys made the “on” paths run even when options were OFF, which could append duplicate `define()` lines and trigger PHP notices (thanks Masahiro Kasahara for the report). `update_define` also skips appending a constant that is already defined (e.g. set from an included file).
* Setup wizard – Fixed errors in the wizard and made a few small improvements.
Top