All-In-One Security 5.5.0 brings clearer firewall logs and stronger login protection

Posted Category Company news Topics All-In-One-Security, Releases,

All-In-One Security 5.5.0 brings clearer firewall logs and stronger login protection

All-In-One Security 5.5.0 is now available to download.

This release gives you a clearer view of your firewall with dedicated audit and debug logs, a new session mechanism and more control over audit log history. It also fixes a security flaw that allowed login lockouts to be cleared without a valid key and makes upgrades safer on larger sites.

Stronger protection for login lockouts

Section titled Stronger protection for login lockouts

If you use login lockouts to slow down brute force attempts, this is the part of the release to read.

A security researcher, Filip Kowalski, responsibly disclosed a flaw in the way All-In-One Security handled the removal of login lockouts. A lockout could be cleared by sending a request containing an empty aiowps_auth_key value, without the nonce and unlock key that should have been required.

If exploited, the issue could allow an unauthorised party to remove a login lockout and weaken the site’s protection against repeated password attempts.

Version 5.5.0 requires a valid nonce and unlock key before a lockout can be cleared. We are grateful to Filip for responsibly reporting the flaw.

If you rely on login lockouts, update to 5.5.0 promptly. Check the minimum PHP and WordPress requirements below before upgrading.

The firewall now has its own audit log to record its activity and a debug log to help you investigate problems. We have also moved appropriate error_log calls into the debug log, keeping that diagnostic information in one place.

The firewall now uses a session mechanism to associate related requests, giving its logging and request-handling logic more context when analysing activity.

A new dropdown lets you choose how many audit log entries appear on each page, making longer histories easier to review.

You can also choose how long to keep audit logs. The default is now 30 days, with a configurable retention period to suit your site.

Control where visitors go when they reach wp-admin

Section titled Control where visitors go when they reach wp-admin

Rename Login Page now accepts an optional redirect URL. When someone who is not logged in tries to access wp-admin, you can send them to a page of your choosing instead of showing a “you do not have permission” message.

We have also fixed a canonical redirect issue that could expose your renamed login page through the non-www version of your address.

Lockout and redirect responses now include no-cache headers to prevent caching plugins and CDNs from storing them and serving them to other visitors.

Our guide to protecting your WordPress admin area covers the wider setup.

A new Integration tab in All-In-One Security settings lets you connect your TeamUpdraft account. It provides the authentication used by features that connect to the TeamUpdraft cloud.

More reliable scans and safer upgrades

Section titled More reliable scans and safer upgrades

File scans no longer fail on sites with many installed plugins. A live “Downloading Checksums” step also makes scan progress easier to follow.

The InnoDB migration no longer converts database tables larger than 10 MB automatically. Instead, All-In-One Security displays manual conversion instructions to help prevent timeouts and database lockups. The migration task also handles upgrades where an automatic conversion was previously skipped.

Keep your security settings consistent

Section titled Keep your security settings consistent

Configuration fixes help you transfer settings and maintain your existing protections.

  • Importing settings from another website now asks for confirmation before carrying across CAPTCHA keys and the admin email address.
  • The firewall IP allowlist is now included in settings imports and exports.
  • Failed updates to Google or Bingbot IP ranges no longer overwrite existing ranges.
  • Google reCAPTCHA secret key validation has been fixed, and invalid configuration warnings disappear when CAPTCHA is disabled.
  • Blocking an IP address within a range is now logged correctly.
  • Cloudflare Turnstile site and secret keys are now verified when you save them.
  • On WordPress Multisite, deleted users no longer remain in the Manual Approval table. Subsite admins can also permanently block IPs from their own subsite in the spammer IP list.

The locked IP, debug log, logged-in users, smart 404 blocked IP and spammer IP tables now update without reloading the page. Filters and search remain visible when there are no records, and the bulk actions row appears immediately.

The Permanent Block List now supports filtering by block reason and applying bulk unblock actions to the filtered results.

Help text has moved into tooltips, badges are positioned more consistently and numeric settings use number inputs. The User Security user accounts tab now matches the PHP firewall rules tab. Settings sections can no longer be collapsed, and the scanner starts up faster.

The Have I Been Pwned tab and its settings have moved to User Security → Password Settings. The unused “Internet bots” and “6G firewall rules” tabs have been removed, and help links now point to TeamUpdraft documentation.

Safer file restores and updated compatibility

Section titled Safer file restores and updated compatibility

Restoring a backed-up .htaccess or wp-config.php file now includes a content hash check for added security.

Behind the scenes, audit log queries now use prepared statements, and appropriate htmlspecialchars() calls have been replaced with WordPress escaping functions. We have standardised custom hook prefixes to aios_*, moved script loading to admin_enqueue_scripts and removed unused logging code, the message store and the aios_loaded action.

Version 5.5.0 fixes a potential deprecation notice on PHP 8.1 or later. It also raises the minimum requirements to PHP 7.4 and WordPress 5.3. If your site runs an older version of either, update it before installing this release.

New options for developers and advanced users

Section titled New options for developers and advanced users

The new aios_file_scan_completed action hook passes file change scan results to other integrations.

To disable the setup wizard, add this line to wp-config.php:

define('AIOS_DISABLE_SETUP_WIZARD', true);

Take your protection further with All-In-One Security Premium

For extra protection, All-In-One Security Premium adds weekly malware scanning, uptime monitoring, country blocking and enhanced two-factor authentication, with direct support from our developers.

  • SECURITY: Prevented unauthorised clearing of login lockouts via an empty aiowps_auth_key parameter by requiring a valid nonce and unlock key. Thanks to Filip Kowalski for disclosing this defect.
  • FEATURE: Added an Integration settings tab to connect a TeamUpdraft account, providing the authentication used by features that connect to the TeamUpdraft cloud.
  • FEATURE: Added an optional redirect URL to the Rename Login Page feature, so non-logged-in visitors who try to access wp-admin can be sent to a chosen page instead of seeing a “you do not have permission” message.
  • FEATURE: Added audit and debug logging to the firewall.
  • FEATURE: Added a session mechanism to the firewall.
  • FEATURE: Added a pagination dropdown to the audit logs table, allowing users to customize the number of logs displayed per page.
  • FIX: Added confirmation when importing settings from another website for captcha keys and admin email.
  • FIX: Bulk actions row not visible on AJAX-driven list tables (e.g. Logged in users) until the page is manually reloaded.
  • FIX: Deleted users no longer remain visible in the Manual Approval table on WordPress Multisite.
  • FIX: Firewall IP allowlist setting is now included in settings import and export.
  • FIX: Google and Bingbot update failures could overwrite existing bot ranges.
  • FIX: Google reCAPTCHA secret key validation.
  • FIX: Invalid Google reCAPTCHA configuration notice still displaying after disabling CAPTCHA.
  • FIX: Improved InnoDB table migration task to handle upgrade scenarios where automatic table conversion may have been skipped.
  • FIX: Large database tables (over 10 MB) are no longer converted automatically during the InnoDB migration. Manual conversion instructions are displayed instead to help prevent timeouts and database lockups.
  • FIX: List table filters remain visible when no records exist.
  • FIX: Non-WWW wp-login.php canonical redirect exposing the renamed login page.
  • FIX: Potential PHP deprecation notice on PHP 8.1 or later.
  • FIX: Prevented file scans from failing on sites with many installed plugins, and added a live “Downloading Checksums” step so scan progress is clearer.
  • FIX: Search bar remains visible after an AJAX table refresh when no records remain.
  • FIX: Password reset email body could be truncated when REMOTE_ADDR was not a valid IP address.
  • FIX: Max file upload size setting in the .htaccess rules not reflected on the Add Media page in the admin area.
  • FIX: UpdraftCentral integration audit log event details were blank.
  • FIX: User deletion caused a HTTP 500 error on older WordPress versions leading to missing user details in audit logs.
  • FIX: Various translation and translation-help comments.
  • FIX: IP blacklisting within an IP range not being logged properly.
  • TWEAK: Updated the minimum required of PHP version to 7.4.
  • TWEAK: Updated the minimum required of WordPress version to 5.3.
  • TWEAK: Enhanced the locked IP table to work with AJAX.
  • TWEAK: Added AJAX support to debug logs table.
  • TWEAK: Added AJAX support to the logged-in users table.
  • TWEAK: Added AJAX support to the smart 404 blocked IPs list table.
  • TWEAK: Added AJAX support to the spammer IP table.
  • TWEAK: Added Cloudflare Turnstile site and secret key verification.
  • TWEAK: Added an ‘aios_file_scan_completed’ action hook with file change scan results for other integrations
  • TWEAK: Added a constant to disable the setup wizard. Add define(‘AIOS_DISABLE_SETUP_WIZARD’, true); to wp-config.php to disable it.
  • TWEAK: Added audit log data retention settings.
  • TWEAK: Added block reason filtering and filtered bulk unblock actions to the Permanent Block List table.
  • TWEAK: Added handling for deleting 404 event logs when no logs are available.
  • TWEAK: Added no-cache headers to lockout and redirect responses to prevent caching by cache plugins and CDNs.
  • TWEAK: Allow subsite admins to permanently block IPs from their subsite in the spammer IPs list.
  • TWEAK: Audit the firewall and replace appropriate error_log calls with the debug log.
  • TWEAK: Changed default audit log retention period to 30 days.
  • TWEAK: Changed script enqueue hook from admin_print_scripts/admin_print_styles to the more standard admin_enqueue_scripts.
  • TWEAK: Changed the UI for User Security > user accounts tab to match the UI for the PHP firewall rules tab.
  • TWEAK: Disabled the ability to collapse UI sections.
  • TWEAK: Drop a redundant user_id index from the logged in users table.
  • TWEAK: Enhance the security for .htaccess and wp-config.php restore by matching file content hash.
  • TWEAK: Improved scanner start up time.
  • TWEAK: Improved PHPCS naming convention compliance by standardizing custom hook prefixes to aios_* and adding PHPCS ignore comments where appropriate for WordPress core hooks.
  • TWEAK: Improved badge positioning to be more consistent across admin pages.
  • TWEAK: Moved “More info” help text to tooltips.
  • TWEAK: Moved the Have I Been Pwned “HIBP” tab & related settings to User Security → Password Settings.
  • TWEAK: Refactored comment commands class to use response helper method.
  • TWEAK: Refactored the 404 log export to work with AJAX.
  • TWEAK: Refactored user command class to use new AJAX response helper method.
  • TWEAK: Replace htmlspecialchars() with WordPress escaping functions where appropriate.
  • TWEAK: Updated AIOS documentation links to the TeamUpdraft Docusaurus documentation routes.
  • TWEAK: Updated audit log SQL queries to use prepared statements, resolving unescaped database parameter warnings.
  • TWEAK: Updated the review request notice design.
  • TWEAK: Updated some help texts for better readability.
  • TWEAK: Updated numeric settings to use HTML number inputs.
  • TWEAK: Removed unnecessary stripslashes() usage to improve code consistency.
  • TWEAK: Removed unused ‘aios_loaded’ action.
  • TWEAK: Removed the legacy security log files and logs directory as they’re no longer used.
  • TWEAK: Removed the message store as it’s no longer needed.
  • TWEAK: Removed unused “Internet bots” and “6G firewall rules” tabs.

About the author

Picture of Alexandru Bucsa, the product manager for All-In-One Security

Alexandru Bucsa

Alex is our All-In-One Security Product Manager. With more than six years of WordPress experience, he listens closely to what users need and works hard to make AIOS even better. Drawing on his background in forensic investigations, Alex loves diving into problems to understand their causes and find practical fixes that truly help our community.

AIOS

Get every feature and fix ever implemented plus access to future releases by subscribing to AIOS Premium.

From just $44.50 for the year.

More stories

Our plugins

Try TeamUpdraft’s full suite of WordPress plugins.

  • UpdraftPlus

    Back up, restore and migrate your WordPress website with UpdraftPlus

  • WP-Optimize

    Speed up and optimize your WordPress website. Cache your site, clean the database and compress images

  • UpdraftCentral

    Centrally manage all your WordPress websites’ plugins, updates, backups, users, pages and posts from one location

  • Burst Statistics

    Privacy-friendly analytics for your WordPress site. Get insights without compromising your visitors’ privacy