تفصیل
Polanger Admin Suite is a modular WordPress administration and security platform built around three simple goals:
Secure WordPress. Control the admin experience. Customize it your way.
Instead of installing separate plugins for admin menus, access control, login protection, two-factor authentication, firewall security, activity tracking, dashboard management, and admin customization, Polanger brings these tools together in one modular suite.
Enable only the features your website needs. Optional addons remain inactive until enabled, helping keep the system focused and lightweight.
Whether you manage your own website, build WordPress projects for clients, or maintain multiple installations, Polanger gives you one place to protect WordPress, control what users can access, and create a cleaner administration experience.
Secure. Control. Customize.
Polanger is organized around three complementary layers instead of one oversized feature set.
Secure WordPress
Build multiple layers of protection around WordPress without turning every visitor request into a heavy security scan.
- Polanger Firewall – Request protection, suspicious traffic scoring, authentication rate limiting, REST/XML-RPC hardening, IP and country access rules, integrity monitoring, upload protection, malicious outbound redirect protection, quarantine, recovery tools, and Strict server hardening.
- Two-Factor Authentication – Protect accounts with email verification codes, recovery keys, role-based enforcement, and configurable verification policies.
- Authenticator App (TOTP) – Add Google Authenticator or Microsoft Authenticator with secure enrollment, recovery keys, trusted-device support, replay protection, and safe secret rotation.
- reCAPTCHA Protection – Centralized reCAPTCHA v2/v3 protection for login, registration, password reset, and supported comment forms.
- Comment Security Layer – Protect comments with honeypot detection, timing validation, flood controls, behavior scoring, blocklists, and site-wide comment policies.
- WooCommerce Security – Extend authentication protection to WooCommerce customer login, registration, password recovery, reCAPTCHA, 2FA, and rate limiting.
- Activity Monitoring – Track important administrative and security-related activity without turning WordPress into a full request logging system.
Polanger follows a layered approach: stop common attacks at the request layer, detect trusted-file changes through integrity monitoring, apply stronger server rules where supported, and provide recovery paths for supported security actions.
Control WordPress
Decide what administrators, editors, clients, team members, and other users can see and access.
- Admin Menu Manager – Hide, rename, reorder, protect, and customize WordPress admin menus and submenus.
- Access Control – Restrict plugin and administration access for selected users and roles.
- Polanger Shield – Protect wp-admin pages, hide interface elements, add contextual notes, and create controlled read-only or demo environments.
- Frontend Content Visibility – Control access to posts, pages, and supported custom post types by login state or user role.
- Multisite Control – Define network defaults, site-level overrides, and locked policies across supported modules.
- Dashboard Center – Control widgets, notices, visibility, and the information users see when they enter WordPress.
- Admin Bar Control – Remove unwanted items, add custom links, and control frontend/backend toolbar content.
Customize WordPress
Create a cleaner administration experience without replacing WordPress itself.
- Design System – Apply admin theme presets, semantic color controls, typography, generated CSS, and WCAG-aware Smart Contrast.
- PG Aurora – A polished admin design preset with refined navigation, submenu handling, third-party compatibility, and responsive behavior.
- Login Page Customization – Customize branding, colors, backgrounds, layout, and the WordPress login experience.
- Custom Admin Menu Builder – Create your own top-level administration menus and links.
- Dashboard Customization – Remove unnecessary widgets and create focused dashboard experiences for different users.
- Maintenance Center – Manage maintenance, coming-soon, deployment, preview access, branded public pages, countdowns, and bypass rules.
Why Polanger Admin Suite?
- One Modular Platform – Replace multiple disconnected admin, access, customization, and security tools with one coordinated suite.
- Layered WordPress Security – Protect authentication, incoming requests, critical files, WordPress integrity, geographic access, and suspicious outbound behavior.
- Built with Recovery in Mind – High-risk Firewall operations use verification, rollback, quarantine, and emergency recovery paths instead of relying on destructive one-way actions.
- Designed for Compatibility – Protection modes, bounded processing, asynchronous heavy work, and cautious handling of custom code help reduce unnecessary lockouts and false positives.
- Enable Only What You Need – Optional addons can be activated independently instead of forcing every feature onto every website.
- Built for Agencies & Teams – User access controls, Shield rules, Multisite support, activity tracking, and admin customization help manage client and multi-user environments.
- Modern WordPress Admin Experience – Clean interfaces, responsive controls, localization, and consistent addon workflows across the suite.
- Free, Modular, and Extensible – Core addons are included with Polanger Admin Suite and the architecture remains open for future integrations.
Built for Real-World WordPress
Polanger is designed for:
- Agencies managing client websites
- Developers building and maintaining WordPress projects
- Teams working with multiple users and roles
- WooCommerce stores that need stronger customer authentication controls
- Multisite administrators managing shared policies
- Site owners who want stronger security without giving up control of their WordPress experience
- Administrators who want a cleaner and more organized wp-admin
Core Features
Admin Menu Manager
- Hide any admin menu or submenu item
- Role-based visibility control
- Rename menu items and submenus
- Change icons with 200+ Dashicons
- Drag & drop menu reordering
- Block direct URL access to hidden pages
- Visual indicators for hidden and modified items
- Custom admin menu builder (create your own menus)
Admin Bar Customization
- Replace or remove WordPress logo
- Hide unwanted admin bar items
- Add custom links with icons
- Manage frontend and backend admin bar
- Auto-detect plugin and theme items
Login Security & Customization
- Custom login URL (hide wp-login.php)
- Google reCAPTCHA v2 & v3 support
- Custom login page design (logo, colors, background)
- Brute-force protection with configurable login attempt limits and lockouts
- Hardened login flows with safer redirects and protected authentication routes
Email Two-Factor Authentication (2FA)
- Email-based verification codes
- Role-based enforcement
- Recovery keys for backup access
- Configurable expiration times
- Super admin protection
Authenticator App (TOTP)
- Google Authenticator and Microsoft Authenticator support
- Time-based One-Time Password (TOTP) verification
- Multi-user architecture with per-user enrollment
- Mandatory enrollment flow for users in required roles
- Profile page 2FA management (Users Profile)
- Admin visibility: enrollment status only, no secret access
- Safe secret rotation with pending secret system
- Old authenticator remains active until new setup is verified
- Secure secret storage with AES-256-CBC encryption
- Manual secret entry with provisioning URI support
- One-time recovery keys (10 keys per user, auto-regenerated on rotation)
- Email fallback option when authenticator is unavailable
- Brute-force protection with configurable lockout
- Replay attack prevention with time-slice tracking
- Seamless integration with core 2FA settings (roles, lockout, expiry)
Activity Log
- Track logins, plugin changes, content updates, and more
- Filter by user, action, and date
- Export logs (CSV)
- Email alerts for critical actions
- Privacy-conscious logging with controlled activity data collection
Dashboard Control
- Hide default WordPress widgets
- Hide third-party plugin widgets
- Control admin notices
- Create custom dashboard widgets
- Per-user dashboard visibility
Multisite Control
- Network-wide default settings for multisite installations
- Site-level override controls for supported modules
- Lock system for Menu Manager, Admin Bar, Login Security, Activity Log, and Dashboard Center
- Network-aware addon activation support
- Developer-friendly effective settings filter architecture
Access Control
- Restrict plugin access to specific users
- Read-only mode support
- Prevent unauthorized access
- Super admin safety protection
Design System
- Token-based admin theming system for consistent and scalable customization
- Customize colors across admin UI (sidebar, admin bar, background, text, surfaces)
- Sidebar background, text color, and menu item styling
- Admin bar background, text color, submenu background, and submenu text color
- Built-in presets (e.g. Dark, Minimal, Default) with one-click application
- Automatic CSS generation with cache-friendly performance
- Enhanced Smart Contrast uses WCAG-aware ratios, gradient sampling, dynamic admin-surface monitoring, icon correction, and late theme guards while preserving colors that are already readable
- Typography controls including font family and basic shape settings
- Scoped styling to avoid conflicts with WordPress core and plugins
- Extensible architecture for future themes, layouts, and design packs
Frontend Content Visibility
- Per-content frontend access control for posts, pages, and supported custom post types
- Visibility modes for public, logged-in users only, selected roles only, or hidden-from-selected-roles workflows
- Multiple denied behaviors including login redirect, 404, access denied message, and custom redirect
- Theme-friendly replacement mode or dedicated access denied page for stricter template control
- Optional hiding from archives, search results, public REST responses, and WordPress XML sitemaps
- Rich-text access denied messages with TinyMCE, HTML, and shortcode support
reCAPTCHA Protection
- Centralized Google reCAPTCHA key management (v2 and v3)
- All reCAPTCHA configuration consolidated in one dedicated addon
- Login form protection
- Registration form protection
- Lost password form protection
- Comment form protection (works with Comment Security addon)
- Configurable v3 score threshold
- Badge position customization for v3
- Automatic script loading only when needed
Firewall
- Lightweight, WordPress-aware Firewall designed to protect common attack surfaces without turning every visitor request into a heavy security scan.
- Three protection modes: Monitor Only for observation, Safe Protection for everyday websites, and Strict for more aggressive protection when stronger security is needed.
- Blocks common bot probes, exposed-file scans, suspicious paths, traversal attempts, unsafe requests, and other high-risk traffic before it can reach sensitive WordPress functionality.
- Protects native WordPress login, registration, and password-reset flows with identity and IP-based rate limiting.
- Hardens the REST API and XML-RPC against common abuse, including anonymous request pressure, user enumeration, multicall attacks, and optional anonymous write restrictions.
- Uses a request scoring engine that combines multiple suspicious signals before deciding whether traffic should be monitored or blocked.
- Malicious Outbound Redirect Protection helps protect visitors when compromised or injected frontend code attempts to open known malicious destinations or trigger unexpected external redirects and popups. Protection is enabled by default in Safe and Strict modes and can be disabled for site-specific compatibility.
- A compact local PhishTank reputation index strengthens outbound protection without sending each visitor, URL, or destination to a remote reputation API.
- Supports IP allowlists and denylists, IPv4/IPv6 CIDR ranges, trusted proxy configurations, and temporary cooldowns for repeated abusive traffic.
- Country Access Control can block visitors from selected countries using a local DB-IP Country Lite database. Visitor IP addresses are not sent to an external geolocation API.
- Country data is prepared only when country blocking is configured, checked periodically for updates, and removed when the country policy is cleared.
- Adds practical security response headers, username enumeration protection, and controls for WordPress Application Password usage.
- WordPress Core Integrity verifies the installed WordPress version against official checksums and detects modified, missing, or unauthorized core files.
- Supported WordPress.org plugins can be checked against their official package data, while premium and custom plugins/themes are monitored more cautiously so unverified custom code is not automatically treated as malware.
- Monitors executable files inside
wp-contentfor unexpected additions and changes while recognizing normal WordPress core, plugin, theme, and translation updates. - Reduces false positives by distinguishing harmless PHP guard files from files containing actual executable PHP behavior.
- Upload Protection detects executable or PHP-bearing media uploads and can prevent PHP execution inside the uploads directory on supported Apache environments.
- Uses high-confidence malware behavior signals to detect suspicious patterns such as encoded execution chains, request-driven commands or file writes, dangerous includes, hidden remote frames, forced external redirects, and click-triggered popup behavior.
- Strict Extended Server Hardening adds an additional protection layer on supported Apache/LiteSpeed servers to block sensitive-file exposure, development metadata leaks, backup/log access, directory browsing, and selected unsafe requests before WordPress/PHP handles them.
- Server hardening rules are applied with verification, health checks, automatic rollback, and safe cleanup without modifying WordPress or third-party rule blocks.
- Recommended Actions help administrators understand what to do with security findings instead of only reporting that a problem exists.
- Verified official WordPress core and supported WordPress.org plugin files can be safely restored from trusted package sources when appropriate.
- High-confidence executable threats can be moved into protected quarantine, while ambiguous custom or premium code is never automatically deleted.
- Quarantine Manager provides visibility into quarantined files with controlled restore and permanent deletion actions.
- Recovery history and an Emergency Recovery URL provide a safe way to reverse supported Firewall file operations if a remediation action causes unexpected site behavior.
- No-reload Scan Now performs a detailed integrity scan with live progress while heavier work is processed asynchronously to reduce timeout and memory pressure.
- Scheduled low-impact integrity scans and automatic post-update verification help detect later file changes without requiring constant manual full scans.
- Findings are clearly separated into Critical, Review, and Notice levels so package differences, harmless files, and custom code are not automatically presented as malware.
- Integrity results are grouped by affected component with a compact preview and a searchable, filtered findings viewer for larger reports.
- Recent Firewall Events records important security decisions using bounded storage instead of operating as a heavy full-traffic request logger.
- Firewall Diagnostics provides built-in self-tests for request protection, rate limits, REST/XML-RPC behavior, IP/CIDR rules, security headers, country access, integrity protection, uploads protection, scheduled scanning, and Strict server hardening without intentionally sending malicious traffic to the website.
- Protection presets configure sensible defaults automatically while still allowing advanced administrators to customize individual controls when needed.
WooCommerce Security
- Adds WooCommerce-specific reCAPTCHA locations for customer login, registration, and lost password forms
- Extends the existing Polanger 2FA flow into WooCommerce customer login while preserving My Account and checkout return paths
- Adds customer authentication rate limiting for login failures, account registrations, and lost password requests
- Includes Light, Balanced, and Strict protection profiles so store owners can choose safe limits without tuning every number manually
- Requires WooCommerce and uses dependency-aware loading so the addon does not run in incomplete store environments
- Reuses Polanger’s existing reCAPTCHA and 2FA systems instead of creating a disconnected WooCommerce security stack
Polanger Shield
- Blocks selected wp-admin pages for selected users with optional direct URL blocking
- Hides selected admin interface areas from the real screen using the floating Shield tool
- Adds contextual notes to admin elements so teams can document workflows directly inside wp-admin
- Demo Lock keeps selected admin screens visible while preventing save, publish, AJAX, REST, and destructive changes for demo users
- Global Demo Mode turns wp-admin into a controlled read-only demo environment for eligible administrator accounts
- Safe Mode gives authorized managers a temporary recovery path when reviewing or troubleshooting Shield rules
- Menu Manager integration shows when a menu or submenu item is already protected by Shield, helping avoid duplicate restrictions
- The Shield dashboard provides status/type filters, 25-rule pagination, localized dates and states, bulk actions, and a mobile-safe scroll region so every saved rule remains manageable
Modular Addon Architecture
Polanger Admin Suite uses a modular addon architecture so each website can enable only the functionality it actually needs.
Bundled addons share the same Admin Suite foundation and settings experience while remaining independently activatable. …
انسٹالیشن
- Upload the plugin to
/wp-content/plugins/ - Activate it from the Plugins menu
- Access via Settings -> Polanger Admin
عمومی سوالات
-
Is Polanger Admin Suite free?
-
Yes. Polanger Admin Suite and all bundled Core Addons are free to use.
-
Do I need to enable every addon?
-
No. Enable only the modules and addons your website needs. Optional functionality can remain disabled.
-
Does Polanger replace multiple WordPress plugins?
-
It can replace several common admin customization, access control, login protection, activity monitoring, 2FA, reCAPTCHA, maintenance, and basic WordPress security tools depending on your site’s requirements.
-
Is Polanger Firewall a replacement for a hosting firewall or CDN WAF?
-
No. Polanger Firewall is a WordPress-aware protection and integrity layer. Server firewalls, hosting security, CDN/WAF services, backups, updates, and good account security remain valuable parts of a complete security strategy.
-
Does Firewall automatically delete suspicious files?
-
No. Polanger intentionally avoids automatically deleting ambiguous custom or premium code. Verified official files can offer safe restoration actions, while high-confidence executable threats can be quarantined with recovery options.
-
Can Firewall recover from a security action that causes a problem?
-
Supported remediation operations include rollback and recovery safeguards. Firewall also provides quarantine history and an Emergency Recovery URL for supported journaled operations.
-
Does country blocking send visitor IP addresses to an external API?
-
No. Country Access Control uses locally stored country data. Visitor IP addresses are not sent to a remote geolocation API for each request.
-
Does outbound redirect protection send every visitor URL to a remote reputation service?
-
No. Polanger uses a compact local reputation index and browser-side behavioral protection without performing a remote reputation lookup for every visitor navigation.
-
Will Polanger slow down my website?
-
Polanger is designed to remain lightweight by keeping heavy operations away from normal visitor requests, using asynchronous processing for integrity work, bounding stored security state, and loading optional functionality only when needed. Actual performance can still vary by hosting environment, configuration, traffic, and enabled features.
-
Can I control what users see inside WordPress?
-
Yes. Menu Manager, Access Control, Shield, Dashboard Center, Frontend Content Visibility, and related modules provide different levels of user and role-based control.
-
Does Polanger support WooCommerce?
-
Yes. WooCommerce Security extends supported Polanger authentication protections to customer login, registration, password recovery, reCAPTCHA, 2FA, and rate limiting while keeping store-specific behavior separate from the main WordPress authentication layer.
-
Does Polanger support WordPress Multisite?
-
Yes. Multisite Control provides network defaults, site-level overrides, and locking behavior for supported modules.
جائزے
شراکت دار اور ڈیویلپرز
“Polanger Admin Suite – Secure, Control & Customize WordPress Admin” اوپن سورس سافٹ ویئر ہے۔ مندرجہ ذیل لوگوں نے اس پلگ ان میں حصہ لیا:
شراکت دار“Polanger Admin Suite – Secure, Control & Customize WordPress Admin” کا اپنی زبان میں ترجمہ کریں۔
ڈویلپمینٹ میں دلچسپی ہے؟
کوڈ براؤز کریں، ایس این وی ریپوزیٹری کو چیک کریں یا ڈویلپمینٹ لاگ کو سبسکرائب کریں بذریعہ آر ایس ایس۔
چینج لاگ
1.6.1
- Improved: Outbound Redirect Protection now includes administrator controls, refined mode-aware containment, and compatibility-focused opt-out behavior.
- Improved: Firewall integrity results are more precise, reducing false positives for inert PHP guard files and non-runtime WordPress package documents.
- Improved: Firewall background scanning, recovery verification, reputation loading, and uploads protection were optimized for lower resource usage and stronger failure recovery on production sites.
- Improved: PG Aurora now provides wider, wrap-safe admin submenus, clearer nested-menu indicators, reliable third-party flyout compatibility, and full-width WordPress profile hover surfaces.
1.6.0
- New: Firewall adds mode-driven malicious outbound redirect containment with a daily compact local PhishTank reputation index, high-confidence behavior blocking, privacy-bounded events, and no per-visitor remote lookup.
- New: Comment Security adds a site-wide policy to keep comments open, allow only WooCommerce product reviews, or completely block new public comments across supported WordPress entry points while preserving existing comments and settings.
- Improved: Firewall now distinguishes authenticated WordPress plugin/theme ZIP installation from media uploads, preserving strict PHP upload blocking while allowing the native replace-or-cancel update flow.
-
New: Firewall adds a no-reload Quarantine Manager with active-item visibility, authenticated restore, permanent deletion, explicit confirmation, signed journals, and post-restore integrity verification.
-
New: Firewall findings now provide evidence-aware recommended actions, transactional exact-package restoration, signed quarantine with rollback history, and a rotating emergency recovery URL that can reverse only journaled operations
- Improved: Critical Firewall integrity alerts can now be permanently dismissed per administrator while a compact toolbar status keeps unresolved findings accessible without repeating page-wide notices
1.5.9
- New: Scan Now runs a complete no-reload integrity scan with live percentage, stage, and processed-file counters; work is split into locked AJAX batches and can continue safely through WP-Cron if the page closes
- New: Country Access Control blocks selected countries through a compact local DB-IP database, displays removable live country chips, supports a customizable localized 403 page, and refreshes active data approximately every 15 days
- New: Strict Extended Server Hardening adds bounded Apache/LiteSpeed protection before PHP with transactional .htaccess writes, live health verification, rollback, diagnostics, and automatic cleanup when Strict protection leaves service
- Improved: Firewall integrity now combines exact-version WordPress core checksums, supported WordPress.org plugin verification, executable drift monitoring, high-confidence malware behavior signals, daily low-cost scans, post-update verification, and explicit verified core repair
- Improved: Integrity findings now use a compact summary, grouped components, ten-row preview, filtered AJAX-paginated modal, critical administrator alerts, and replacement of the previous report after each completed scan instead of accumulating scan history
- Improved: Firewall now includes complete Turkish, German, Spanish, Russian, Simplified Chinese, and Arabic coverage for current Firewall screens, diagnostics, findings, country names, and blocked-visitor defaults
- Improved: Firewall cards, actions, progress details, country controls, selected-country chips, and findings modal now adapt more cleanly to narrow tablet and mobile screens
- Improved: Design System Smart Contrast now evaluates WCAG contrast across solid, transparent, and gradient surfaces, protects readable existing colors, corrects icons and dynamic plugin UI, and monitors supported editor frames
- Fixed: Shield now intercepts visual selector clicks before target controls can execute, builds subdirectory-safe Test URLs, keeps Shield-only managers on the dedicated settings tab, avoids disabled Global Demo user queries, and reports missing rule actions accurately
- Improved: Shield adds filtered 25-row rule pagination, mobile-safe tables and floating tools, accessible modal focus handling, cache-safe asset versions, precise Demo control decoration, and complete current translations in all six bundled languages
1.5.8
- Improved: Country Access Control now lets administrators review and remove selected countries as live chips, customize the localized blocked-visitor page title and message, and preserve the secure HTTP 403 layout with unobtrusive DB-IP attribution
- Improved: Firewall now ships complete Turkish, German, Spanish, Russian, Simplified Chinese, and Arabic translations, including diagnostics, integrity results, Country Access Control, and localized country names
- New: Optional local Country Access Control downloads DB-IP Country Lite only after explicit country selection, enforces selected countries in every enabled Firewall mode, and checks for monthly data updates approximately every 15 days
- New: Strict Extended Server Hardening adds bounded Apache/LiteSpeed protection before PHP, transactional root .htaccess writes, post-write health verification, rollback, diagnostics, and automatic cleanup whenever Strict protection leaves service
- New: Firewall adds exact-version WordPress core integrity, official plugin SHA-256 checks, update-aware executable monitoring, uploads execution protection, malware behavior signals, scheduled scans, and explicit verified core repair with quarantine
- Fixed: Firewall rate windows no longer slide indefinitely, Monitor Only keeps threshold state, REST rate limiting is visible and migrated to its intended preset, trusted proxy chains resolve safely, and sensitive event query values are redacted
- Fixed: WooCommerce Security settings tab registration now loads reliably when WooCommerce becomes available later in the WordPress plugin bootstrap order
- Fixed: Design System PG Aurora active tab and nested navigation contrast now keeps selected settings tabs, addon subtabs, and gradient surfaces readable
- Improved: Polanger Shield admin page restrictions now block targeted users more consistently and surface Shield-controlled menu protections inside Menu Manager
- Improved: Firewall request scoring has been refined for more accurate suspicious request detection while preserving safer preset behavior
1.5.7
- New: Design System now includes the PG Aurora admin theme preset with a modern light dashboard style, gradient menu states, improved sidebar icon handling, refined submenu hierarchy, and polished classic WordPress admin screen compatibility
- Improved: Firewall request protection was refined with safer preset behavior, compatibility-aware REST handling, and clearer optional tuning boundaries for production sites
- Improved: Strict REST protection now preserves WooCommerce Store API compatibility automatically when WooCommerce is active, preventing cart, checkout, and account flows from being blocked by anonymous REST write hardening
- Improved: Menu Manager mobile layout now uses responsive card-based rows with cleaner visibility controls, submenu expansion, custom name fields, and cache-safe admin UI stylesheet loading
- Fixed: Design System preset application now updates saved theme tokens reliably, reflects changes immediately on the settings page, and includes an inline fallback so generated admin theme CSS cannot silently fail on stricter live hosting setups
1.5.6
- New: Firewall addon adds Monitor Only, Balanced, and Strict WordPress-aware request protection for common bot probes, native auth rate limits, XML-RPC hardening, REST pressure, anonymous user enumeration, IP rules, temporary cooldowns, and lightweight event logging while respecting custom administrator overrides
- Improved: Firewall defaults, Monitor Only behavior, REST compatibility, CIDR validation, proxy IP detection, and event logging safety were refined to reduce false positives and lockout risk
- Fixed: Plugin update notifications remain visible on the Plugins screen when admin notice hiding is enabled
- Improved: The Shield dashboard displays the Global Demo Mode summary only while demo protection is active
- New: Menu Manager identifies menu and submenu items already protected by active Shield page rules and shows affected users and direct URL protection details without duplicating restrictions
- Fixed: Shield user ID handling now safely normalizes administrator records returned as objects, preventing PHP warnings in protected admin and menu integration checks
- Improved: Maintenance Center preview and content editing were refined with admin-safe preview rendering, stronger preview button contrast, and richer text color controls in visual editors
1.5.5
- Improved: Admin Suite interface refined with cleaner layouts, smoother navigation, and more consistent settings screens
- Improved: Better compatibility across login security, frontend visibility, dashboard controls, and modular addon workflows
- Improved: Module loading optimized to keep the WordPress admin experience faster and lighter when only selected features are enabled
- Improved: Responsive behavior polished across key Admin Suite screens for a more comfortable tablet and mobile admin experience
- Fixed: Minor visual and settings synchronization issues reported in selected admin screens
1.5.4
- Improved: Frontend Content Visibility editing was streamlined with a clearer access-rule workflow, making role-based hiding easier to understand on posts, pages, and supported custom post types while preserving compatibility with older saved rules
- Improved: Frontend Content Visibility now serves a dedicated Polanger protected 404 screen when denied behavior is set to 404, avoiding broken or inconsistent theme-level 404 layouts
- Improved: Login Security redirect handling and protected-route interception were hardened for unauthorized access attempts to custom login and admin entry points
- Improved: The built-in protected 404 experience was refined with cleaner messaging, a simplified layout, and WordPress 6.4+ compatibility hardening for deprecated emoji style output
1.5.3
- New: Frontend Content Visibility core module for posts, pages, and supported custom post types with role-based audience control, denied behavior routing, and discovery hiding for archives, REST API, and XML sitemaps
- Improved: Admin design system and user interface components enhanced for a better user experience.
- Improved: Mobile and responsive layouts optimized across various plugin screens.
- Improved: Enhanced security measures and hardening implemented for the Two-Factor Authentication (2FA) module.
- Improved: Translation catalogs and compiled language packs were refreshed for the current release across bundled locales
1.5.2
- Improved: Menu Manager now captures late-registered and dynamically reordered top-level admin menus more reliably, fixing cases where some third-party plugin menus did not appear in the manager list
- Improved: Menu Manager list ordering now better mirrors the effective live WordPress sidebar order for plugins that reposition themselves through custom menu filters
- Improved: Design System was expanded into a richer WCAG-aware admin theming engine with semantic color tokens, advanced typography controls, and a live preview playground
- Improved: Design System presets were redesigned into curated professional themes, with stronger compatibility across admin menus, admin bar states, metaboxes, tables, widgets, and classic editor screens
- Improved: Design System Midnight compatibility was hardened for third-party admin UI, including low-contrast text recovery and dark dropdown/menu readability fixes that only activate for the Midnight preset
- Improved: Mobile admin usability refinements across settings layouts and action controls for better spacing, responsiveness, and alignment on smaller screens
1.5.1
- Fixed: Resolved an issue where reCAPTCHA could fail to appear on the custom login page under certain configurations
- Improved: Better integration and compatibility between Authenticator App (TOTP) and reCAPTCHA verification flows
- Improved: Comment Guard reCAPTCHA integration is now more stable and reliable across comment submission scenarios
- Fixed: Resolved login page logo cropping issues on responsive and custom layout configurations
- Improved: On mobile devices, the login page language selector is now displayed inside a compact drawer for a cleaner layout
- New: Added option to completely disable the language switcher on the login page
1.5.0
- New: Authenticator App (TOTP) addon – Google/Microsoft Authenticator support with multi-user architecture, mandatory enrollment flow for required roles, profile page 2FA management, safe secret rotation (pending secret system prevents lockouts), AES-256-CBC encryption, recovery keys with auto-regeneration on rotation, trusted device memory, email fallback, and brute-force protection
- New: reCAPTCHA addon – centralized Google reCAPTCHA v2/v3 key management; all reCAPTCHA configuration consolidated from multiple locations into one dedicated addon for login, registration, lost password, and comment forms
- Improved: Design System – added Sidebar Background, Sidebar Text Color, Admin Bar Background, Admin Bar Text Color, Admin Bar Submenu Background, and Admin Bar Submenu Text Color customization options
- Improved: Design System color compatibility – enhanced contrast handling and readability corrections across admin UI components
- Improved: Menu Manager – resolved conflict issues with certain third-party plugins and themes
- Improved: Mobile responsiveness – comprehensive layout and interaction improvements across all admin screens for better tablet and smartphone usability
- Improved: 2FA settings form – resolved nested form submission issue for reliable Save Settings functionality
1.4.3
-
New: Comment Security Layer addon – multi-layer comment protection with honeypot trap, HMAC-signed timing tokens, per-IP flood control (per-minute and per-hour windows), keyword and URL blocklists, behavior scoring engine with configurable thresholds, and silent action modes (spam queue, trash, or silent drop)
-
Improved: Login page design – refined mobile layout with corrected form card proportions, improved spacing around inputs and buttons on small screens, and more consistent hover and focus state rendering across breakpoints
-
Improved: Login page background rendering – smoother gradient transitions and better full-coverage rendering for background images on narrow viewports; improved visual layering between background and form card
-
Improved: Admin panel mobile responsiveness – layout and spacing adjustments across Settings, Addons, and Activity Log screens; better usability on tablet and mobile viewports with more appropriate touch target sizing
-
Improved: Sub-tab settings saves – partial save operations now only process and re-validate the submitted field group instead of the full settings object, reducing redundant sanitization passes on every tab change
-
Improved: Addon list layout – card grid now wraps and spaces more cleanly on narrow viewports; improved readability of addon status indicators on mobile
1.4.2
- New: Multisite Control addon – manage network-wide defaults, lock policies, and site-level overrides from a single system
-
New: Design System addon – token-based admin theming with presets, generated CSS, and extensible architecture
-
New: Network-aware settings engine with effective settings merging across supported modules
- New: Network lock support for core modules (Menu Manager, Admin Bar, Login Security, Activity Log, Dashboard Center)
-
New: Site-level override indicators and network-managed notices for clearer control visibility
-
New: Developer hook
polanger_admin_theme_assetsfor extending admin UI styling without modifying core files -
Improved: 2FA system stability and security
- Enhanced verification flow with stronger session and user validation
- Secure resend flow with nonce protection and stricter token handling
- Improved trusted device and IP resolution (proxy-aware validation)
- Login flow now respects "Remember Me” preference
- Safer email handling with runtime checks and fallback protection
- Automatic reset of invalid email verification states
- Prevents enabling 2FA when email delivery is not properly configured
-
Improved: Design System readability and contrast handling
- Automatic contrast correction for dark/light surfaces
- Improved text visibility across admin UI components (postbox, notices, tables, forms)
- More consistent styling across WordPress admin elements
-
Improved: Addon system architecture
- Better addon activation flow with optional network-wide activation
- Expanded developer documentation with hooks, filters, and theming examples
- Improved extensibility for future addon-based features
-
Improved: General stability, security, and internal optimizations
1.4.1
- Improved: Activity Log export flow (CSV/JSON) output handling on Settings page for more consistent downloads
- Improved: Settings export callback visibility and
admin_initlifecycle compatibility - Improved: Activity Log query hardening with validated table-name usage and allowlisted
ORDER BYhandling - Improved: 2FA verification comparison updated with timing-safe hash validation (
hash_equals) - Improved: Activity Log IP resolution now prefers
REMOTE_ADDRand supports trusted-proxy based forwarded-header parsing - Improved: Settings input validation for
allowed_userswith strict array-type guards before normalization
1.4.0
- Major update: Polanger expanded into a full Admin Suite with optional addons managed from one interface
- New: Full Admin Suite experience (menu, login, security, dashboard, activity log)
- New: Custom Admin Menu Builder
- New: Role-based access control improvements
- Improved: UI/UX across all modules
- Improved: Performance and stability
- Improved: Security layers and validation
- Fixed: Minor bugs and edge cases
1.3.1
- Fixed: Prevented foreach warning when settings are missing
- Improved: Stability improvements for fresh installs
