Sucuri Security – Auditing, Malware Scanner and Security Hardening

Wordpress Plugin
Download latest - 1.8.36

Download Stats

Today 6,310
Yesterday 8,526
Last Week 35,105
All Time 3,370,158
Banner 772x250


Releases (85 )

Version Release Date Change Log
1.8.36 2022-12-12
  • Changed Branding fonts, colors and images to match the current Sucuri brand
1.8.35 2022-09-08
  • Fixed "Early referer checks on admin hooks"
1.8.34 2022-09-08
  • Added referer check on admin hooks
1.8.33 2022-08-05
  • Fixed "Added option to clear cache by path"
1.8.32 2022-07-01
  • Fixed "Empty wp-config file after automatic secret key updates"
1.8.31 2022-06-08
  • Fixed "Path cannot be empty" error
1.8.30 2022-01-27

Daniel is no longer maintaining the Sucuri plugin at GoDaddy. We have transferred it to a dedicated team to maintain and improve it.

=

1.8.29 2021-09-27

= 1.8.19 = This version adds an option to refresh the malware scan results on demand, as well as several small bug fixes and improvements.

1.8.28 2021-08-12
  • Silence fopen warning
1.8.27 2021-07-26
  • Add support for PHP 8
  • Reduce memory requirements when reading a log file
  • Fix DISALLOW_FILE_EDIT related notice
1.8.26 2021-03-26
  • Replace the word "blacklist" with "blocklist" in the codebase
  • Replace the word "whitelist" with "allowlist" in the codebase
1.8.25 2021-01-19
  • Fix notice about MONTH_IN_SECONDS in WP < 4.4
  • Update reset password workflow
1.8.24 2020-02-17
  • Fix warning caused by humanTime function
  • Fix fatal error caused by cron jobs with nested arguments
1.8.23 2020-02-10
  • Add Automatic Secret Keys Updater
  • Improve button's and link's messaging on Last Logins sections
  • Improve messaging on Hardening page
  • Improve messaging on IP Access page
1.8.22 2019-11-25
  • Add "SSL existence check" to WordPress Security Recommendations
  • Add "Salt & Security Keys existence check" to WordPress Security Recommendations
  • Add "Salt & Security Keys age check" to WordPress Security Recommendations
  • Add "Admin account check" to WordPress Security Recommendations
  • Add "Single super-admin check" to WordPress Security Recommendations
  • Add "Too many plugins check" to WordPress Security Recommendations
  • Add "File editing check" to WordPress Security Recommendations
  • Add "WordPress debug check" to WordPress Security Recommendations
  • Add "Basic hardening check" to WordPress Security Recommendations
  • Add a delete button on Last Logins sections
  • Add register of logs removal on Audit Logs
  • Fix display of Access File Integrity on NGINX/IIS servers
  • Remove PHP version check from hardening page
1.8.21 2019-05-09
  • Add WordPress Security Recommendations section in the dashboard
  • Add PHP version check
  • Fix goo.gl links
  • Fix post_type pattern match to allow numbers and max of 20 chars
  • Fix Audit Logs queue timezone issue
  • Fix regex in template string replacement
  • Update translation file to include WordPress Security Recommendations section fields
  • Make the menu icon use the menu color styling
  • Remove block button from failed logins page
1.8.20 2019-02-20
  • Add dynamic core directories in the hardening whitelist options
  • Modify scheduled tasks panel to load the table via Ajax
  • Allow hosting details display to be filterable
  • Preparation for translations
1.8.19 2019-01-17

This version adds an option to refresh the malware scan results on demand, as well as several small bug fixes and improvements.

=

1.8.18 2018-07-03
  • Keep settings when the plugin is deactivated, unless the plugin is uninstalled
1.8.17 2018-05-29
  • Update Terms of Service and Privacy Policy
1.8.16 2018-05-22
  • Update Terms of Service for GDPR compliancy
1.8.15 2018-04-25

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.14 2018-03-29

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.13 2018-03-23

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.12 2018-02-15

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.11 2017-09-03

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.10 2017-08-31

= 1.8.9 = This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

1.8.9 2017-08-31

= 1.8.8 = This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

1.8.8 2017-07-26

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.7 2017-06-29

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.6 2017-06-27

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.5 2017-06-27

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.4 2017-06-26

This version adds support for the latest version of WordPress. Introduces new features and fixes some bugs reported by the WordPress community as well as bugs found by our automated testing system.

=

1.8.3 2016-10-07
  • Fixed fatal error when PHPMailer failed
  • Fixed incorrect selected value in settings
  • Fixed kb links and content.
  • Added SiteCheck for arbitrary domain
  • Various code cleanup
1.8.1 2016-07-08
  • Modified default setting for the core integrity alerts
  • Added more files to the core integrity ignore list
  • Fixed support for custom data storage directory
  • Fixed admin notices after changing alert settings
  • Fixed settings and audit logs for the firewall page
  • Fixed regression with clear cache in firewall page
1.8.0 2016-07-06
  • Added error message when storage is not writable
  • Fixed option getter to migrate plugin settings if possible
  • Fixed base directory name without PHP DIR constant
  • Fixed user authentication denial when no blocked users
  • Fixed htaccess standard rules checker with no WP_Rewrite
1.7.19 2016-07-05
  • Added function to rescue HTTP requests using sockets
  • Fixed mishandled JSON data in audit logs Ajax request
  • Modified list of CloudProxy features and promo video
1.7.18 2016-07-05
  • Added options library using external file instead of the database
  • Modified API calls using custom HTTP request using Curl
  • Fixed core files marked as broken in a Windows server
  • Fixed pagination links in last and failed logins page
  • Fixed password with ampersands in email notification
  • Fixed whitelist hardening using the authz_core module
  • Removed unnecessary emails to reduce spam
  • Added constant to stop execution of admin init hooks
  • Added explanation for invalid emails and no MX records
  • Added link to open the form to insert the API key manually
  • Added more options in the IP discoverer setting
  • Added option to configure malware scanner timeout
  • Added option to configure the API communication protocol
  • Added option to reset the malware scanner cache
  • Added scheduled task and email alert for available updates
  • Added tool to block user accounts from attempting a login
  • Added tool to debug HTTP requests to the API services
  • Various minor adjustments and fixes
1.7.17 2016-01-08
  • Added API service failback mechanism
  • Added core integrity email on force scan
  • Slight interface redesign
  • Various bugfixes and improvements
1.7.16 2015-11-25
  • Fixing a low severity XSS (needs admin access to create it)
1.7.15 2015-11-25
  • Fixed XSS in core integrity checks panel
1.7.14 2015-11-24
  • Added alternative method to send email alerts
  • Added button to reset options with explanation
  • Added suggestion for new users to check plugin settings
  • Allow mark as fixed non-writable core files
  • Fixed display menus items single or network panels
  • Fixed handle boolean values in PHP config retrieval
  • Fixed non-standard content location in core integrity
  • Fixed user identifier as integer on password reset
  • Modified css and js files to reduce size
  • Modified do not load resources on hidden sidebar
  • Modified fully redesign of general settings page
  • Modified hide update warning if versions are the same
  • Modified wording of post-types alert settings
  • Removed ellipsis of long IPv6 addresses in last logins
  • Removed unnecessary dns lookups in infosys page
  • Removed unnecessary monospace fonts in settings status
  • Removed unnecessary ssl verification option processor
1.7.13 2015-07-30
  • Fixed issue affecting site performance
  • Fixed clear hardening of previous versions
  • Modified report and block non-processable ajax actions
  • Added configure DNS lookups for reverse proxy detection
  • Added option to configure comment monitor and logs
  • Added option to configure the XHR monitor and logs
1.7.12 2015-07-29
  • Improved hardening options
  • Added more logging events
  • Various bugfixes and improvements
1.7.11 2015-06-19
  • Reverted change for CloudProxy detection to protect legacy users
1.7.10 2015-06-16
  • Added better checks for SSL issues
  • Fix for audit log timezones
  • Various bugfixes and improvements
1.7.9 2015-05-11
  • Improved reinstallation process
  • Updated sidebar banners
  • Various bugfixes and improvements
1.7.8 2015-03-29
  • Fixed bug on the secret keys hardening.
1.7.7 2015-03-27
1.7.6 2015-02-10
  • Added audit log reporting.
  • Added more settings for better control.
  • Added support for more actions.
  • Improved multisite support.
  • Added support for reverse proxies.
  • Various bugfixes and improvements.
1.7.5 2014-12-03
  • Added better handling of API responses of remote scanner.
1.7.4 2014-12-02
  • Added option for keeping failed logins until the user removes them.
  • Bugfixes for user reported issues.
1.7.3 2014-11-27
1.7.2 2014-10-10
  • Messaging and FAQ updates.
1.7.1 2014-09-18
  • Fixed remote scanning that was not loading automatically on some installs.
1.7.0 2014-09-12
  • Added Hardening option to remove error log files
  • Bug fixes on some new registrations.
  • Changed format of the internal logs to json.
1.6.9 2014-09-04
  • Multiple bug fixes (as reported on the support forums).
  • Added heartbeat for the file scans.
  • Code cleanup.
1.6.8 2014-08-19
  • Fixing interface.
1.6.6 2014-08-14
  • Internal code cleanup and re-organization.
  • More white lists for the integrity checks.
  • Additional settings to customize some of the warnings.
1.6.5 2014-07-31
  • Fixed integrity checking display.
1.6.4 2014-07-29
  • Fixed API generation bug.
1.6.1 2014-07-15
  • Initial release with new auditing options.
1.6.0 2014-06-03
  • A new dashboard to welcome users to the new features of the plugin.
  • Overall design of the interface of all the pages were modified.
  • SiteCheck scanner results were filled with more information.
  • SiteCheck scanner results markers when the site is infected/clean.
  • System Info page were simplified with tabulation containers.
  • Integrity check for administrator accounts was optimized.
  • Integrity check for outdated plugins/themes was optimized and merged.
  • IPv6 support in last logins statistics.
1.5.7 2014-04-23
  • WordPress 3.9 compatibility
1.5.6 2014-03-27
  • Added IPv6 support.
  • Fixed links and messaging.
1.5.5 2014-02-28
  • Added list of logged in users.
  • Added system page.
  • Change the integrity checking to use WP API.
1.5.2 2013-12-12
  • Adding additional information about .htaccess hacks and the server environment.
1.5.1 2013-11-01
1.5.0 2013-10-16
  • Fixing last login and giving better warns on permission errors.
  • Making the integrity check messages more clear.
1.4.9 2013-10-07
1.4.8 2013-09-30
  • New and clean design for the scan results.
  • Adding a web firewall check on our hardening page.
1.4.7 2013-09-28
  • Cleaning up the code a bit.
  • Only displaying last login messages to admin users.
  • Storing the logs into a log file instead of the db.
1.4.6 2013-09-11
  • Increasing last login table to the last 100 entries.
1.4.5 2013-08-27
  • Fixing some issues on the last login and allowing the option to disable it.
1.4.4 2013-08-23
  • Small bug fixes + forcing a re-scan on every scan attempt (not using the cache anymore).
1.4.3 2013-08-22
  • Fixing a few PHP warnings.
1.4.2 2013-08-21
  • Fixing a few PHP warnings.
1.4.1 2013-08-20
  • Small bug fixes.
  • Adding last IP to the last login page.
1.4 2013-08-19
  • Added post-hack options (reset all passwords).
  • Added last-login.
  • Added more hardening and the option to revert any hardening done.
1.3 2013-08-16
  • Removed some PHP warnings and code clean up.
  • Added WordPress integrity checks.
  • Added plugin/theme/user checks.
1.1.6 2011-12-14
  • Upgrading for WP 3.3.
1.1.5 2011-11-29
  • Removing PHP warnings / code cleaning.
1.1.4 2011-11-22
1.1.3 2011-11-22
  • Cleaning up the results.
    • Added 1-click hardening.
1.1.2 2011-11-18
  • First release that is good to be used (debugging code removed).