9 versions
Really Simple Security pro history.
Every release of Really Simple Security pro is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.
9 of 9 releases scanned clean
v9.6.1Latest
July 1, 20267.4 MBScanned
Fixed
- Password expiration now works correctly with 2FA and passkeys.
- Button styling in Content Security Policy and Permissions Policy tables.
- Alignment of the e-mail validation status icon.
- Vulnerability data is included in uninstall cleanup.
Improved
- Updated translations to use the l10n PHP format.
- User agent blocking now supports wildcard matching.
- Removed an unused passkey log message.
- Updated the Other Plugins section in onboarding and settings.
June 9, 202610.8 MBScanned
Fixed
- 2FA grace period reminder emails could be sent unexpectedly.
- Content Security Policy now follows the setting toggle correctly.
- PHP 8.4 deprecation warning.
- DNS verification issue in the Let's Encrypt wizard.
Improved
- Vulnerability details now load only for the plugin or theme being activated.
- Improved rule writing with file locking to avoid race conditions.
- Uninstall cleanup now removes plugin options and transients more reliably.
- Added a login page notice for invalid login sessions.
- Improved 2FA user lookup performance on multisite.
- Improved license check reliability.
- Improved DirectAdmin Let's Encrypt certificate generation.
- Improved several interface texts.
- Event logs now support larger log tables.
- Added RSSSL_INFO_LOG for extra debugging details.
- Added more prerequisite checks before features can be enabled.
v9.5.10Unavailable
April 14, 20269.5 MBScanned
Fixed
- An issue that could cause a crash when activating alongside the Perfmatters plugin.
- Some styling (CSS) issues to improve compatibility with WordPress 7.0.
Improved
- Removed an unused AJAX callback.
- Tested up to WordPress 7.0.
v9.5.9Unavailable
March 24, 20269.5 MBScanned
Fixed
- A fatal error that could occur when activating Pro in a multisite environment.
- An issue where logging in with a username and password on multisite did not trigger a passkey prompt when using a standalone passkey.
- Improved and future-proofed the plugin updater.
Improved
- Updated the event log cleanup cron hook.
- Reworked vulnerability detection and measures logic.
v9.5.8.1Unavailable
March 4, 20269.3 MBScanned
Fixed
- An issue where TOTP codes starting with a 0 were not properly recognized.
- Prevent using "Do Not Ask Again" for user roles where 2FA is required.
Improved
- Various improvements to authentication flow.
v9.5.7Unavailable
February 3, 20269.5 MBScanned
Fixed
- scenario where users were stuck after an expired 2FA grace period due to missing authentication methods.
- Support for `wss://` URLs in CSP `connect-src`.
- MemberPress login compatibility with Limit Login Attempts.
Improved
- event logging by generating messages dynamically instead of storing translated text.
- Email 2FA user experience by making Enter submit the verification code instead of resending it.
- Simplified service bootstrapping by removing the Provider layer and registering all services directly in the App container.
v9.5.6Unavailable
January 15, 20269.6 MBScanned
Fixed
- compromised password check compatibility with Thrive Architect
- fatal error on multisite subsite profile pages with passkeys enabled
- user role demotion issue on multisite
- passkey settings appearing twice on profile page
- 2FA users list not displaying all users
- Cloudflare cache not clearing after SSL activation
- passkey strings not translatable
- uploads .htaccess using incorrect Apache syntax for some versions
Improved
- deferred header detection on activation to prevent timeouts
- improved deactivation process
- more robust firewall code generation
Why archive
Sometimes the latest release isn't the one you need. The archive lets you pin Really Simple Security pro to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.