Release v5.302
Security Ninja Premium v5.302
What's new in v5.302
Security Ninja Premium v5.302 was released on . Trusted by 100,000+ WordPress Sites The All-In-One WordPress Security Plugin Block attacks. See the full changelog below and compare with the complete version history.
Release details
Released
8.9 MB
File available
Changelog
Other
- 2026-09-01
Fixed
- Firewall - Per-visitor reverse-DNS, ASN, and GeoIP caches no longer fill the WordPress options table with one row per IP. On busy sites without Redis/Memcached that could grow to hundreds of thousands of rows and cause intermittent downtime. After update, leftover rows are removed automatically in small batches. Thank you Davina.
- Firewall - Search-engine and crawler checks only run reverse-DNS when the User-Agent looks like a known crawler. Normal browser traffic no longer triggers a DNS lookup on every page view. AI crawlers (OpenAI, Perplexity, Claude) are checked against published IP ranges only.
- Firewall - Hostname-based "blocked hosts" matching (part of Filter Suspicious Queries) is off by default. URI, query string, user agent, and referrer rules still run. Developers can re-enable hostname checks with the secnin_cf_check_blocked_hosts filter.
- Firewall - Satellite/ASN softening (Pro) no longer calls the remote ASN API on every miss when the site has no object cache. With Redis or Memcached, results are cached there instead of in the database.
- Firewall - The list of remembered validated crawler IPs is limited to 200 entries so it cannot grow without bound.
- Fixes - Disable Username Enumeration now blocks anonymous REST user listing (/wp/v2/users and ?rest_route=), not only by removing the endpoint. The username enumeration security test checks that path as well. Thank you Elias.
Compatibility
- Requires WordPress
- 4.7
- Tested up to
- 7.1
- Requires PHP
- 7.4
Review recommended
Some files in v5.302 were flagged for review. Use with caution.
View full scan report