• Nullsto Rules must be read before making a post, otherwise you will get permanent warning points or a permanent ban.

    Nullsto Forum provides CLEAN and SAFE resources. You can use them for development and testing if you are on Windows and have an antivirus that alerts you about a possible infection: It is a false positive since every script is double checked by our experts. While downloading a resource, we recommend that you add Nullsto to your trusted sites/sources or temporarily disable your antivirus. "Enjoy your presence on Nullsto"
Security Ninja Pro - WordPress Security Made Easy

Security Ninja Pro - WordPress Security Made Easy v5.297

No permission to download
Security Ninja PRO - WordPress Security Made Easy v5.270 Nulled
== Changelog ==

= 5.270 =
* 2026-02-22
* FIX: Secure cookies fix now writes ini_set lines before any closing PHP tag in wp-config.php, preventing "headers already sent" and cookie/login issues. Thanks to Olga for the detailed report that made this fix possible.
* NEW: Core Scanner – You can now open a printable report when the scan finds issues. Use "Print / Download report" to open the report in a new window and print or save as PDF for your records or support.
* IMPROVED: Core Scanner – The report button is always visible; when no issues are detected it shows a short notice so you know the option is available after the next scan with findings.
* IMPROVED: Core Scanner – Original WordPress core files are cached for one day when restoring or comparing, so repeat operations are faster and put less load on external servers.
* IMPROVED: Core Scanner – "View differences" now opens in the same unified File Viewer layout as "View File", with consistent styling, file metadata, and shared security validation instead of a separate standalone page.
* FIX: Firewall enable modal – "Send email" (activate and send unblock link) now works. The unblock-email AJAX action was not registered and the handler expected the email in GET; the action is now registered and all unblock-email requests use POST only.
* TECH: All internal script and style references now use non-minified JS and CSS only; minified copies have been removed to simplify the codebase.
* FIX: Fixed PHP 8.1 deprecation notice "Implicit conversion from float to int loses precision" in Cloud Firewall IPv6 CIDR matching. Thanks to Lesford for the report.
Security Ninja PRO - WordPress Security Made Easy v5.264 Nulled
= 5.264 =
* 2026-01-31
* FIX: Fixed wpdb::prepare() error during plugin uninstallation when dropping database tables.
* FIX: Vulnerability scanner no longer blocks wp-admin after deactivating and reactivating the plugin. If the vulnerability data files are missing or unreadable (e.g. after reactivation or server changes), the plugin now recovers automatically: it shows the vulnerability count as zero until the data is restored in the background, and the dashboard continues to load normally.
* IMPROVED: Vulnerability module now recreates and re-downloads its data files when they are missing, so you no longer need to reinstall the plugin to fix a "JSONL file not readable" error.
* FIX: Hardened vulnerability JSONL file handling: guard fclose() on stream and catch all errors when counting records, so missing or unreadable files never cause a fatal in wp-admin.
* FIX: Login Protection - "Failed login warnings" toggle now correctly saves when disabled (was reverting to enabled because unchecked checkbox is omitted from form POST).
* FIX: 2FA – Disabling 2FA in settings now persists correctly; toggle uses a hidden input so unchecked state is saved.
Security Ninja PRO - WordPress Security Made Easy v5.263
= v5.263 =
* Improved bandwidth usage getting vulnerabilities for all users.
* Improved: Vulnerability scanner now reads vulnerability feeds in a streaming, memory-efficient way to reduce peak memory usage.
Security Ninja PRO - WordPress Security Made Easy v5.261
= 5.261 = 2025-11-17
* Fixed: 2FA - Changed key name format from "site_url (username):email" to "site_url:username" - Thank you Davina.
* Fixed: Compatibility warning with WordPress 6.7 regarding translation loading timing
* Fixed: Server security restriction warning when checking wp-config.php file location
* Fixed: Fixed critical bug where database prefix changer added an extra underscore when updating wp-config.php, causing WordPress to look for non-existent tables with double underscores (e.g., wp_12345__posts instead of wp_12345_posts). Thank you Tchai.
* Fixed: Database prefix changer to properly update option names and meta keys when changing from custom prefixes (not just "wp_").
* IMPROVED: Database prefix changer now works with any prefix, not just the default "wp_". Can now rename tables when changing from one custom prefix to another. All plugin tables are automatically included in the renaming process.
Security Ninja PRO - WordPress Security Made Easy v5.260 Nulled
== Changelog ==

= 5.260 =
* 2025-11-12
* NEW: Failed login email warnings - administrators receive email notifications when someone attempts to log in with their username and fails. Can be enabled in Login Form Protection settings.
* NEW: Admin IPs are automatically whitelisted on plugin activation and successful admin login to prevent administrators from being blocked. Thank you Val.
* FIX: Fixed country blocking to respect "only block backend" setting when enabled. Thank you Guru for the tip.
* IMPROVED: Secret access URL processing has been moved up in the request cycle to make sure IP whitelisting happens before any ban checks, so blocked visitors should be able to get back on the site more reliably.
* IMPROVED: wp-config.php backups are stored in encrypted format (AES-256-CBC) to ensure data security. Each backup uses a unique encryption key and initialization vector. This was introduced in a previous release, but was not added to the changelog.
* Update 3rd party libraries - Freemius SDK 2.13.0 among others.
Security Ninja PRO - WordPress Security Made Easy v5.259 Nulled
== Changelog ==

= 5.259 =
* 2025-11-xx
* IMPROVED: Made the dashboard widget visible when white label mode is enabled. Previously the widget was hidden instead. Thank you for the suggestion, Dmitry.
* IMPROVED: Added count-based limit (5000 entries) to visitor log pruning to prevent database bloat on high-traffic sites.
* IMPROVED: Removed deprecated X-XSS-Protection header from REST API - modern browsers ignore this header and Content-Security-Policy is the recommended replacement. Thank you Dmitry for the suggestions.
* IMPROVED: More information on CSP in our knowledgebase.
* FIX: Fixed typo in Permissions-Policy description (explitly → explicitly).
* FIX: Updated Permissions-Policy documentation link from Feature-Policy to Permissions-Policy URL.
* FIX: Corrected Nginx example in Content-Security-Policy test descriptions (was showing X-Frame-Options instead of CSP).
* Preparing for plugin rewrite -> improving the free version and streamlining the premium and free feature set.
Security Ninja PRO - WordPress Security Made Easy v5.257 Nulled
No changelogs found!

Security Ninja Pro v5.256 - WordPress Security Made Easy
= 5.256 =

* Fix for recommendation engine "wp-config.php not found in the wordpress root directory" - now properly checks for when the config file has been moved up on level. Thank you Eric.
* Fix - 2FA email, user reported emails were sent twice with two different codes. Thank you Eric.
* Improved 2FA setup page stability and performance across different WordPress configurations.
* 2FA - naming of the accounts are now a little more intuitive. Thank you Davina.
Security Ninja Pro v5.255 - WordPress Security Made Easy
Changelog Not Found!
Security Ninja Pro v5.254 - WordPress Security Made Easy
= 5.254 =

* NEW: Add secret key display and copy functionality to 2FA module in frontend and backend. Allowing users to easier add the key to their system.
* FIX: Timezone on Overview page was incorrect, thank you for spotting Ivar.
* FIX: Resolved JavaScript conflicts that prevented 2FA functionality from working with ARMember and other plugins
* FIX: 2FA QR code/key generation now works reliably across all site configurations, even if other scripts have errors. "Skip for now" link, "Generate new QR code" button, code input validation, and temporary secret usage during setup all function correctly.
* FIX: 2FA setup UI and logic are now robust—QR code generation.
* IMPROVED: Enhanced 2FA JavaScript with robust error handling and DOM ready protection
* IMPROVED: Added inline JavaScript handlers as fallback to ensure 2FA works even when external scripts fail
* IMPROVED: Better error messages and user feedback during 2FA setup process
Top