Shield v1.3.5
FILE shield.c-istudios.com/changelog CURRENT v1.3.5 7 RELEASES
Version History

Changelog.

All releases and updates for CI Security Shield.

v1.3.5 July 2, 2026 Fix
  • The daily security digest now re-checks each issue at the moment the email is sent, so it no longer reports a “critical needing review” for a problem that was already automatically resolved earlier in the day (for example, a flagged PHP file that Shield had already quarantined). The email now matches what you see in the dashboard.
  • No configuration changes required.
v1.3.4 June 30, 2026 Fix
  • Security alert emails now show your website’s name as the sender, so you can tell at a glance which site each report is for.
  • The “Fix Now” button for file-permission issues now applies a more secure setting for wp-config.php (never world-readable). When a file is owned by a different system user and can’t be changed automatically, the plugin now shows the exact one-line command to run instead of a generic error.
  • No configuration changes required.
v1.3.3 June 26, 2026 Fix
  • The daily security digest email now clearly separates routine, automatically-blocked attacks — such as bot probes for /.env or xmlrpc.php — from the issues that actually need your attention. Blocked attacks are now reported as a single “attacks blocked” figure instead of inflating the warning count.
  • The digest no longer lists the same recurring finding multiple times — repeated issues are collapsed into one line with an occurrence count, so the email matches what you see on the dashboard.
  • The “Fix Now” button now works for PHP files flagged inside the uploads folder. One click safely quarantines the file — it’s moved out of harm’s way (recoverable, not deleted) and can no longer execute.
  • No configuration changes required.
v1.3.2 June 17, 2026 New
  • The Brute Force Protection settings now expand and collapse with a smooth animation. When the feature is turned off, its detailed options — maximum login attempts, lockout duration, and progressive lockout — stay tucked out of the way and slide into view the moment you enable it, for a cleaner, less cluttered settings panel.
  • Honors your system’s reduced-motion accessibility preference.
  • Fixed an issue where admin interface updates could be masked by browser or page caching — the dashboard now always loads the latest styles and scripts.
  • No configuration changes required.
v1.3.1 June 10, 2026 Fix
  • Fixed a firewall false positive that could return a 403 “Forbidden” on legitimate URLs containing marketing or social tracking parameters — including utm_content, fbclid, and Instagram/Facebook click IDs. Campaign and link-in-bio links now load reliably.
  • Refined the cross-site scripting (XSS) event-handler rule so it no longer matches tracking parameter names mid-word, while continuing to block genuine onerror/onclick/onload injection attempts.
  • No configuration changes required — security coverage is unchanged.
v1.2.2 April 7, 2026 New
  • Added license activation and management system
  • Added license-based feature activation
  • Added License tab in admin dashboard
  • Added Stripe subscription billing integration
  • Added weekly license verification (phone-home)
  • Added 7-day grace period for expired licenses
  • Added 30-day offline tolerance for unreachable license server
  • Added license status badge in admin header
v1.2.0 March 25, 2026 New
  • Initial release of CI Security Shield
  • 12 security modules: hardening, login protection, firewall, REST API, image protection, file manager, comments, site analysis, file integrity, notifications, auto-updates, activity tracker
  • Admin dashboard with security score and A+ grading
  • Event log with filtering, pagination, and export
  • Site analysis with compatibility scanning
  • Wordfence coexistence verified
  • WP Rocket, WooCommerce, Gravity Forms, WPBakery compatibility

Secure site. Sleep better.

Twelve modules, one plugin file, one flat price.