Skip to content

Releases: Melapress/wp-security-audit-log

Logging for variable products in WooCommerce

26 Feb 14:30
Compare
Choose a tag to compare

Release notes: Activity Log Coverage of WooCommerce Variable Products

  • New Activity Log Events for WooCommerce

    • Event ID 9078: Changed the option to include / exclude taxes in product prices.
    • Event ID 9079: Changed the option on what type of shipping to calculate tax on.
    • Event ID 9080: Changed the shipping tax class.
    • Event ID 9081: Enabled / Disabled the rounding of the sub total.
    • Event ID 9082: Added / Deleted / Modified a shipping zone on WooCommerce.
  • Plugin Improvements

    • Better handling of plugin activation on multisite - plugin can only be activated from the network dashboard.
  • Bug Fixes

    • Updated Freemius SDK which includes a security fix.

Introducing infinite scroll and performance enhancements

07 Feb 09:13
Compare
Choose a tag to compare

Release notes: Introducing infinite scroll and performance enhancements

  • New Features

  • Plugin Improvements

    • Improved the search filters - now they are much faster.
    • Improved user session handling to better handle >1,000 sessions.
    • Replaced PHP severity with event log severity in the list of Events.
  • Bug Fixes

Major WooCommerce coverage update

29 Jan 05:31
Compare
Choose a tag to compare

Release notes: Major Activity Log Improvement in WooCommerce Coverage

  • New Events for WooCommerce Orders

    • ID 9035: New order placed in WooCommerce.
    • ID 9036: Changed the status of a WooCommerce order.
    • ID 9037: Moved a WooCommerce order to trash.
    • ID 9038: Restored a WooCommerce order from the trash.
    • ID 9039: Permanently deleted an order.
    • ID 9040: Changed the orders details.
    • ID 9041: Refunded a WooCommerce order
  • New Events for WooCommerce Product Admin & Attributes Changes

    • ID 9042: Changed the catalog visibility of a product.
    • ID 9043: Changed the Featured product setting of a product.
    • ID 9044: Changed the allow backorders setting of a product.
    • ID 9045: Changed the the Upsells of a product.
    • ID 9046: Changed the Cross-sells of a product.
    • ID 9047: Added a new attribute of a product.
    • ID 9048: Modified the value of a product attribute.
    • ID 9049: Renamed a product attribute.
    • ID 9050: Deleted a product attribute.
    • ID 9051: Changed the visibility of a product attribute.
  • New Events for WooCommerce Categories

    • ID 9052: Deleted a product category.
    • ID 9053: Changed the slug of a product category.
    • ID 9054: Changed the parent of a product category.
    • ID 9055: Changed display type of a product category.
    • ID 9056: Changed the name of a product category.
  • New Events for WooCommerce Payment Gateways

    • ID 9074: Enabled a payment gateway.
    • ID 9075: Disabled a payment gateway.
    • ID 9076: Modified a payment gateway.
  • New Events for WooCommerce Coupons:

    • ID 9063: Published a new coupon.
    • ID 9064: Changed the discount type of a coupon.
    • ID 9065: Changed the coupon amount.
    • ID 9066: Changed the coupon expire date.
    • ID 9067: Changed the Usage Restriction settings of a coupon.
    • ID 9068: Changed the Usage Limits settings of a coupon.
    • ID 9069: Changed the description of a coupon.
    • ID 9070: Changed the status of a coupon.
    • ID 9071: Renamed the WooCommerce coupon.
  • New Events for WooCommerce Attributes:

    • ID 9057: User created a new attribute.
    • ID 9058: User deleted an attribute.
    • ID 9059: User changed the slug of an attribute.
    • ID 9060: User changed the name of an attribute.
    • ID 9061: User changed the default sort order of an attribute.
    • ID 9062: User enabled/disabled the option Enable Archives of an attribute.
  • New Features

    • Email notification to site admin when the plugin is deactivated.
    • New setting to control refreshing of the live notifications in the admin bar.
    • Three new hooks in the activity log plugin that allow for event data manipulation.
  • Plugin Improvements

    • Major performance enhancement to the Event Viewer
    • Updated the text of some settings.
    • Event severities are now saved as meta data (we can now build filters for them).
    • Added the product status in all WooCommerce events.
    • Event 9011 (modified draft WooCommerce product) made obsolete with event 9010.
    • Event 9020 changed to report the different product types (simple, grouped, external, variable, downloadable, virtual)
    • Updated Freemius SDK
    • Better handling of incorrect database privileges when installing plugin.
    • Excluded the default WordPress cache directory from the default WordPress File Integrity Scans
  • Bug Fixes

    • Events 2027 and 2011 incorrectly logged hen saving a draft post in Gutenberg.
    • Plugin logged event 5019 by mistake when the front end editor of WP Bakery was used.
    • When files bigger than the file size limit were scanned for the first time the plugin wrongly reported them as modified.
    • In some cases where WordPress was not upgraded to 5.0 the plugin was not recognizing content changes.

Hotfix for login sensor

07 Jan 07:41
f1c6b43
Compare
Choose a tag to compare
  • Improvements

    • Better support for custom login pages.
  • Bug Fixes

    • Fixed an issue where the visitor logs sensor remains disabled when activity log level is switched to guru.

Hotfix for Users Sessions

26 Dec 09:17
1cba500
Compare
Choose a tag to compare
  • New Feature

    • A setting to configure the number of logged in sessions the plugin retrieves when checking for logged in sessions.
  • Improvements

    • Improved handling of logged in users sessions data.
    • Terminate All Sessions button now also purges sessions data from the WordPress database.
    • Improved the events for when saving a draft post in the Gutenberg editor.
    • Checks for the Papertrail activity log mirroring connectivity improved.
  • Bug Fixes

    • Fixed an issue in which the plugin was sending two daily activity log summary.
    • Removed code for backward compatibility but was not PHP 7.2 compatible (Support Ticket).
    • Updated the list of website visitor events in Enable/Disable events section.
    • Fixed an issue with the auto refresh of users sessions.

Slack Support & New External Connections UI

13 Dec 09:23
5a6170a
Compare
Choose a tag to compare

Release Notes: Slack Support & New External Connections UI

  • New Features

  • Improvements

    • Maximum file size for WordPress file integrity scans is now configurable.

    • Updated the Freemius SDK to 2.2.2 (addresses a MainWP conflict fix).

    • Plugin access can now be restricted to super administrators only on a multisite network.

    • Multiple scan started / stopped events per directory merged into one.

    • Added 1 and 4 hours option to terminate idle users sessions setting.

    • Plugin now always keeps a log a post updates, even if update is not done via the editor.

    • Better handling of terminated users sessions (in hung state, blocking legit logins).

    • Access to plugin now can be restricted to super admin role on multisite networks.

    • User info in daily activity log summary email is now variable - the same as configured in the plugin settings.

    • Limited Freemius user messages to users who can view & manage the plugin.

    • Addded support for a dot in the time format (e.g: d.-m-Y G:i)

    • Bug Fixes

    • Better handling of data from the REST API Support ticket.

    • Fixed: two daily activity log emails were being sent instead of one.

    • Restricted the starter license (had access to some pro features).

    • Fixed a number of minor warnings when running the plugin on PHP7.

    • Logins when using the Two-Factor plugin are now logged properly.

    • Fixed - first time setup wizard prompt not always showing.

3.2.5

15 Nov 07:09
2a6e579
Compare
Choose a tag to compare

Release Notes: Announcing Activity Log for MainWP

  • New Events for the activity log

    • Event ID 2127: Changed the name of a category
    • Event ID 2128: Changed the slug of a category
  • New Functionality

  • Bug Fixes

    • Fixed an issue in the licensing which allowed users with Starter plan to access features from the professional plan.

3.2.4

05 Oct 10:50
586c05b
Compare
Choose a tag to compare

Release Notes: click here

  • New Activity Log Features

  • Plugin Improvements

    • Revamped the Users management module and settings - part of the easy to use updates.
    • Error message for blocked simultaneous users sessions can now be configured.
    • Updated the order of the plugin menu entries to a more convenient one.
    • Invalid usernames used in failed logins are now kept for 30 days in the database.
    • Improved WordPress menu sensor - added coverage and improved accuracy.
    • Changed Event Code to Event ID in email notifications trigger builder.
    • Improved MainWP Child Site Stealth Mode for premium edition.
    • Sidebar admin notification on first install now only shown to the first user accessing the activity log.
    • Removed in activity log adverts.
    • Updated top banner adverts in activity log - now users can hide them.
    • Updated WordPress icon used to report system events in activity log.
  • Bug Fixes

    • Added support for arrays in ACF Support Ticket
    • Handled an exception error in which user has same event ID. Now instead plugin shows an show error and disable custom sensor.
    • Fixed an issue in which the startup wizard was shown twice on the free edition of the plugin.
    • Fixed an issue in which reports were not generated because of non-standard paths.

3.2.3.3

11 Sep 19:12
58a9df4
Compare
Choose a tag to compare

Release Notes: click here

  • New Feature

  • New Activity Log Events

    • Event 6006: User reset the plugin settings to default
    • Event 6033: WordPress file integrity scans status updates (started & stopped)
    • Event 6034: User purged the activity log
  • Improvements

    • Added sub categories to Enable/Disable Events section to segregate long lists.
    • Improved the sensor for the detection of plugins activations and deactivations.
    • Removed the startup wizard from upgrade - now only triggered on new installs.
    • Improved the premium trial message with a Start Free Trial button.
    • Added notification response to purging old data from the event log manually.
    • Added a pop-up notification to confirm activity log level was applied successfully.
    • Improved error messages in the Exclude Objects setting page.
    • Removed Mcrypt completely (was previously used for external DB connection).
    • Updated the Freemius SDK to the latest version.
    • Removed use of GLOB_BRACE - it is no longer needed.
  • Bug Fixes

    • Fixed an issue in which notifications with specific post IDs was not working on multisite.
    • Fixed some security issues highlighted by RIPS tech.
    • Removed nodes of premium features for users who have VIEW ONLY access to the WordPress activity log.

3.2.3

13 Aug 10:31
Compare
Choose a tag to compare

Release Notes: click here

  • New Features

  • Improvements

    • Performance improvement: optimized the logic of the plugin sensors to load only required ones during user action.
    • Redesigned all the settings pages and included more help text, making them more user friendly.
    • Added links to plugin knowledge base where possible in the plugin settings.
    • Improved the WordPress activity log pruning setting so now it is possible to configure retention based on a period of time.
    • Database improvement: changed the option_value column in the plugin tables to long text.
    • WordPress website file changes results are now stored in the plugin's options table.
    • Improved the list of excluded file extensions in the WordPress file changes scanner.
    • Added sorting in the logged in WordPress users view.
    • Added more checks to ensure opt-in and other plugin messages are shown when needed only.
    • Removed affiliate network message in plugin.
  • Bug Fixes

    • Fixed an issue where stored passwords might have been changed because of change from Mcrypt to OpenSSL.
    • Fixed an issue in which retention settings were reset when moved to archiving settings.