Secupress Pro icon

6 versions

Secupress Pro history.

Every release of Secupress Pro is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.

6 of 6 releases scanned clean
v2.6.3Latest
July 21, 20263.4 MBScanned
Other
  • 21 July 2026
Fixed
  • "Uncaught TypeError: str_rot13(): Argument #1 ($string) must be of type string, array given"
  • antispam.min.js error
  • is_process_running() error again.
July 5, 20263.4 MBScanned
Other
  • 25 Juin 2026
Fixed
  • Possible fatal error when the data files are not correctly extracted.
  • Users with same email domain present before the activation of the same name module were still tagged as bad.
  • Fatal error on empty JSON
  • Users from REST API still visible, it's CASE SENSITIVE!?
  • Require module tools on submodule activation
Improved
  • User secupress.me instead of google.com for testing
  • Do not unvalidate passwordless email on plugin deactivation or licence deco
April 14, 20263.4 MBScanned
Other
  • 03 April 2026
Improved
  • Remove the ping on google.com, set it to secupress.me.
  • Refactored the database scan logic in SecuPress_File_Monitoring to use background processing for scanning posts, options, and custom post types for malware patterns. Better perf, quicker scans incoming on big sites.
Fixed
  • (again) Possible fatal error "Call to undefined method SecuPress_Background_Process_Bad_Plugins::is_processing()" if WooCommerce is installed since THEY include the obsolete version of the async lib before us...
  • Warning notice when saving captcha style.
  • Re-add the "monthly" index for cron schedules.
  • Do not unvalidate passwordless email on plugin deactivation or licence deconnection
  • Remove the usage of shell_exec() and `host $ip` that can overconsume resources on your host, bringing down your site (even if this was in SecuPress since 8 years, only now this cause an issue)
v2.6Unavailable
January 19, 20263.4 MBScanned
Other
  • 16 January 2026
Added
  • GeoIP Location on Login
  • Search field in admin UI.
  • Scanner for malwares in our 35 scanners.
Improved
  • UI for Malware Scanner has been improved, and will be again ;) You'll find a "WP File Integrity" which has always been there since 1.0, just not mentionned as is.
  • Add WP 2FA compatibility to Easy Login scan
Fixed
  • Dashboard Widget not displaying graphs
  • PHP Version Scanner was saying that the last version was "ok tier"
  • PasswordLess activation checkbox was not checked after reload
  • Remove secupress-data directory on uninstall (I forgot, my bad)
  • "wp-includes/version.php" should not be tagged "different" anymore if you use a localised zip (in malware scanners)
  • Possible fatal error when deactivating the module "Disable all actions on plugins" + "disable all actions on FTP"
  • Possible fatal error "Call to undefined method SecuPress_Background_Process_Bad_Plugins::is_processing()"
v2.4Unavailable
December 24, 20253.3 MBScanned
December 3, 20253.3 MBScanned
Other
  • 02 December 2025
Added
  • Colored notices can be added up in the plugins page to help you prioritize updates by showing you since when the update is available.
  • The standalone "SF Move Login" is now renamed "SP Move Login" and since it's the same feature as the one here, it will be deactivated and this feature here activated.
  • "Move Login" feature can now display a Honeypot instead of a message or page. This is an expert setting, also, only available if you only have Admins on your site (or lusers will be banned trying to log-in, I know them)
  • Translations are now done using the new `.l10n.php` format
Improved
  • "Move login" feature will now display every other slugs, it now depends on the login one. "Register" is only available is the registration is open.
  • Dashboard widget finally get a skin, can display a graph to check evolution of monthly attacks.
  • All the messages from the "unlock yourself as an admin" on login page have been set to the same one to prevent guessing an admin email. props to Lohen Florent
Fixed
  • JS Error when Antispam Comment Timer module is active
  • Correct custom validity for roles in some cases
  • Warning for undefined SECUPRESS_INSTALLED_MUPLUGINS constant
  • Warning when the distant DB was not accessible
  • Passwords couldn't be updated when Passwordless was active, even if your role was not targeted, or module activatjon not validated yet
  • Changelogs couldn't be opened in the iframe popup in plugins.php page when "Prevent Actions on Plugins" feature was activated

Why archive

Sometimes the latest release isn't the one you need. The archive lets you pin Secupress Pro to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.