WP Cerber Security icon

Release v9.9

WP Cerber Security v9.9

Latest version

What's new in v9.9

WP Cerber Security v9.9 was released on . Defends WordPress against hacker attacks, spam, trojans, and malware. See the full changelog below and compare with the complete version history.

Release details

Released
1.3 MB
File available

Changelog

Added
  • WP Cerber now automatically maintains a backup copy of the last known valid plugin settings. The backup is refreshed after successful settings updates, settings imports, plugin upgrades, and during daily maintenance.
  • If the stored plugin settings become corrupted, WP Cerber now restores them automatically from the settings backup and shows a dismissible admin notice explaining what happened, what action was taken, and what the administrator should review.
  • The "System Readiness" widget now shows an advisory notice on servers where PHP is built without the modern `mysqlnd` database driver. The notice confirms that WP Cerber keeps working and recommends enabling `mysqlnd` for full compatibility and better performance.
Improved
  • Traffic Inspector now detects additional high-confidence JavaScript obfuscation patterns, including fully escaped strings that use `\uNNNN` and `\u{...}` escape sequences and dangerous execution, DOM, network, and system code decoded from explicit `fromCharCode()` calls, while preserving its low false-positive detection model.
Other
  • Compatibility: WP Cerber now runs correctly on legacy hosting environments where PHP is built without the modern `mysqlnd` database driver. On such servers, database query results are retrieved through a slower compatible method instead of triggering a fatal error.
Fixed
  • A corrupted WP Cerber configuration value stored in the database could cause a fatal `TypeError` in `array_merge()` at plugin load time on PHP 8, taking the whole website down. WP Cerber now detects the unreadable stored value, falls back to the default settings, and reports the failure as a critical issue until the administrator re-saves the settings.
  • A regression in the detection of obfuscated JavaScript by Traffic Inspector. JavaScript strings built entirely of `\xNN` hex escape sequences were not decoded, so obfuscated code such as `eval`, `script`, and `XMLHttpRequest` could go undetected when request fields were inspected.

Compatibility

Requires WordPress
5.8
Tested up to
7.0
Requires PHP
7.4

Verified safe

WP Cerber Security v9.9 scanned clean with no security threats detected.

View full scan report