Suggestions:
PasskeysIf Your Site Is HackedTuning Wordfence Resource UsageV3: Accessing and Consuming the Vulnerability Data FeedAPI CallbacksVulnerability Management: Webhook NotificationsBasic Plugin SettingsAudit LogV1: Accessing and Consuming the Vulnerability Data FeedV2: Accessing and Consuming the Vulnerability Data FeedWordfence IntelligenceCompatibilityWordfence Intelligence Webhook NotificationsWordfence ResponseWordfence CareWordfence FreePlugin / Theme ConflictsUsing Wordfence Central TeamsSub-Processors ListMySQLi storage engineAccount and Billing HistoryUsing Central’s Settings pageLogin Security PluginLogin Security OptionsLegacy Two-Factor AuthenticationUsing Wordfence plugin options TemplatesUsing the Configuration pageViewing scan FindingsUsing the Dashboard pageSetting up two-factor authenticationConnecting your sites to Wordfence CentralWordfence Central ToolImport/ExportWordfence and GDPR – General Data Protection RegulationTroubleshootingTechnical DetailsWordfence 7Blocking TroubleshootingWordfence and LiteSpeedDiagnosticsWHOIS LookupBrute Force ProtectionStatisticsGlobal OptionsWordfence APIAlertsDashboardToolsRate LimitingChangelogScan TroubleshootingFirewall Optimization TroubleshootingScan ResultsConstantsTroubleshootingLicense KeyRemove or ResetSystem requirementsScan SchedulingCountry BlockingScan OptionsFirewall OptionsFirewall Learning ModeAdvanced information and configurationIncident Response ServicesTwo-Factor AuthenticationReal-Time Live TrafficScanBlockingWordfence PremiumOptimizing The FirewallWordfence Web Application Firewall (WAF)

Changelog

Historical information about previous Wordfence plugin versions.

= 9.0.0 – August 10, 2026 =

* Improvement: Added support for passkey authentication
     * Available for both free and premium installations
     * Can be enabled for any user role (multisite support is currently limited)
     * WooCommerce integration
     * Support for custom authentication integrations
* Improvement: GeoIP database updated
* Improvement: Several mobile styling and layout improvements on the login security page
* Improvement: Added diagnostics info for authentication hooks to assist with login-related troubleshooting
* Change: Hardened 2FA flow when installed next to plugins with non-standard authentication (credit: Austin Ginder of Anchor Hosting)
* Change: Hardened 2FA remember cookie handling
* Change: The scanner will now display an issue when the standalone Wordfence Login Security plugin is installed because all functionality is already provided by Wordfence itself
* Change: Updated internal libraries used by the Vue UI
* Change: Login error masking setting now also applies to the Login Security functionality

= 8.2.2 – May 13, 2026 =

* Improvement: Better presentation of Live Traffic data on wide screens
* Improvement: Increased legibility of token fields
* Improvement: Reworked the pagination of the Blocking page for a better UX
* Improvement: Country blocking token field can now expand to show all entries
* Improvement: Performance improvements for the activity log and better pause behavior on window blur/focus
* Improvement: GeoIP database updated
* Change: Removed deprecated Central endpoint
* Fix: Addressed issue where the last activity log entry could repeatedly appear
* Fix: Using the embedded shortcode for the 2FA form now correctly enqueues core JavaScript dependencies
* Fix: Modals with content that overflows on smaller viewports can now be scrolled
* Fix: The changelog link in plugin upgrade scan issues now links correctly

= 8.2.1 – May 6, 2026 =

* Fix: Fixed issue with some i18n plugins/themes when a user has no 2FA recovery codes.
* Fix: Toggled options with additional help links now correctly open the link rather than toggling the option.
* Fix: Country Blocking editing fixed when there are multiple pages of block rules.
* Fix: Added better error handling to the initial Vue data load.
* Fix: Handled error when logging in using legacy 2FA with separate prompts enabled.

= 8.2.0 – April 29, 2026 =

* Improvement: Migrated all deprecated JavaScript libraries in use to a Vue-based infrastructure.
* Improvement: GeoIP database update.
* Improvement: Better coverage of `aria-` accessibility attributes.
* Improvement: Added `translators` comments to translatable strings where previously missing.
* Fix: WordPress 7.0 compatibility fixes.
* Note: Legacy two factor authentication using SMS-based codes will be discontinued around July 1, 2026. Sites using this functionality should migrate users to the TOTP-based two factor authentication on the Login Security page of the plugin.

= 8.1.4 – December 20, 2025 =

* Fix: Fixed an issue with `inet_pton` introduced by a recent patch to PHP 8.1+ that could cause a fatal error if a malformed IP address was passed to the call.

To view a complete changelog, visit this link here