12 versions
Really Simple Security pro history.
Every release of Really Simple Security pro is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.
11 of 12 releases scanned clean
v9.8.2Latest
September 10, 20267.4 MB
Fixed
- A JavaScript error on user profile pages when passkeys were disabled.
- Users required to use 2FA could extend their own grace period.
- A fatal error caused by an invalid author query parameter.
- 2FA onboarding after logging in through WooCommerce.
- Horizontal scrolling in Content Security Policy and region blocking tables.
- The firewall could reference `advanced-headers.php` when the file did not exist.
- Possible fatal errors caused by invalid data in public CSP and 2FA requests.
Improved
- Updated the default Content Security Policy for WordPress 7.1 compatibility.
- Improved database table checks.
July 21, 20267.4 MBScanned
Fixed
- The firewall event log now shows the correct region and country names.
- The dashboard now shows the correct number of hardening tasks that still need attention.
- Prevented a possible PHP warning during plugin activation.
Improved
- Moved the code for deactivating other Really Simple Security versions.
- Removed unused code.
- Removed an empty directory from the plugin ZIP file.
- Updated the color used for Metricool in the Other Plugins section.
July 1, 20267.4 MBScanned
Fixed
- Password expiration now works correctly with 2FA and passkeys.
- Button styling in Content Security Policy and Permissions Policy tables.
- Alignment of the e-mail validation status icon.
- Vulnerability data is included in uninstall cleanup.
Improved
- Updated translations to use the l10n PHP format.
- User agent blocking now supports wildcard matching.
- Removed an unused passkey log message.
- Updated the Other Plugins section in onboarding and settings.
v9.6.0Unavailable
June 9, 202610.8 MBScanned
Fixed
- 2FA grace period reminder emails could be sent unexpectedly.
- Content Security Policy now follows the setting toggle correctly.
- PHP 8.4 deprecation warning.
- DNS verification issue in the Let's Encrypt wizard.
Improved
- Vulnerability details now load only for the plugin or theme being activated.
- Improved rule writing with file locking to avoid race conditions.
- Uninstall cleanup now removes plugin options and transients more reliably.
- Added a login page notice for invalid login sessions.
- Improved 2FA user lookup performance on multisite.
- Improved license check reliability.
- Improved DirectAdmin Let's Encrypt certificate generation.
- Improved several interface texts.
- Event logs now support larger log tables.
- Added RSSSL_INFO_LOG for extra debugging details.
- Added more prerequisite checks before features can be enabled.
v9.5.10Unavailable
April 14, 20269.5 MBScanned
Fixed
- An issue that could cause a crash when activating alongside the Perfmatters plugin.
- Some styling (CSS) issues to improve compatibility with WordPress 7.0.
Improved
- Removed an unused AJAX callback.
- Tested up to WordPress 7.0.
v9.5.9Unavailable
March 24, 20269.5 MBScanned
Fixed
- A fatal error that could occur when activating Pro in a multisite environment.
- An issue where logging in with a username and password on multisite did not trigger a passkey prompt when using a standalone passkey.
- Improved and future-proofed the plugin updater.
Improved
- Updated the event log cleanup cron hook.
- Reworked vulnerability detection and measures logic.
v9.5.8.1Unavailable
March 4, 20269.3 MBScanned
Fixed
- An issue where TOTP codes starting with a 0 were not properly recognized.
- Prevent using "Do Not Ask Again" for user roles where 2FA is required.
Improved
- Various improvements to authentication flow.
Why archive
Sometimes the latest release isn't the one you need. The archive lets you pin Really Simple Security pro to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.