Release v9.9
WP Cerber Security v9.9
Latest versionWhat's new in v9.9
WP Cerber Security v9.9 was released on . Defends WordPress against hacker attacks, spam, trojans, and malware. See the full changelog below and compare with the complete version history.
Release details
Released
1.3 MB
File available
Changelog
Added
- WP Cerber now automatically maintains a backup copy of the last known valid plugin settings. The backup is refreshed after successful settings updates, settings imports, plugin upgrades, and during daily maintenance.
- If the stored plugin settings become corrupted, WP Cerber now restores them automatically from the settings backup and shows a dismissible admin notice explaining what happened, what action was taken, and what the administrator should review.
- The "System Readiness" widget now shows an advisory notice on servers where PHP is built without the modern `mysqlnd` database driver. The notice confirms that WP Cerber keeps working and recommends enabling `mysqlnd` for full compatibility and better performance.
Improved
- Traffic Inspector now detects additional high-confidence JavaScript obfuscation patterns, including fully escaped strings that use `\uNNNN` and `\u{...}` escape sequences and dangerous execution, DOM, network, and system code decoded from explicit `fromCharCode()` calls, while preserving its low false-positive detection model.
Other
- Compatibility: WP Cerber now runs correctly on legacy hosting environments where PHP is built without the modern `mysqlnd` database driver. On such servers, database query results are retrieved through a slower compatible method instead of triggering a fatal error.
Fixed
- A corrupted WP Cerber configuration value stored in the database could cause a fatal `TypeError` in `array_merge()` at plugin load time on PHP 8, taking the whole website down. WP Cerber now detects the unreadable stored value, falls back to the default settings, and reports the failure as a critical issue until the administrator re-saves the settings.
- A regression in the detection of obfuscated JavaScript by Traffic Inspector. JavaScript strings built entirely of `\xNN` hex escape sequences were not decoded, so obfuscated code such as `eval`, `script`, and `XMLHttpRequest` could go undetected when request fields were inspected.
Compatibility
- Requires WordPress
- 5.8
- Tested up to
- 7.0
- Requires PHP
- 7.4
Verified safe
WP Cerber Security v9.9 scanned clean with no security threats detected.
View full scan report