WordPress News
Wordfence Security 9.0.2 Released
What’s new in Wordfence Security 9.0.2
Released: September 30, 2026
Active installations: 5,000,000
Tested up to WordPress 7.1.2
Requires PHP 7.0
Changelog
- Change: Changed IPv6 diagnostics result to be informational only
- Change: Added help link to increased attack rate emails
- Improvement: Increased compatibility with WordPress Playground
- Improvement: Harden REST API user enumeration protection
- Fix: Upgraded virtualizer dependency to fix Firefox tab crash on screens with a lot of DOM elements (e.g., a running scan)
- Fix: Better detection and handling of “module” script tagging to avoid conflict with renamed plugin directories
- Fix: Add missed return value from upgrader_pre_install audit log filter
- Fix: PHP 8.1 deprecation notice fixes
- Fix: Fixed translation support on login page
- Fix: Improve handling of WAF JSON processing to better handle array values
- Fix: Address early translation calls to avoid _load_textdomain_just_in_time notices
- Fix: Changed a few translated strings to avoid containing HTML due to a broken CZ translation
Previous releases
9.0.1 — September 8, 2026
- Improvement: UX enhancements for passkey authentication and general login security
- Improvement: GeoIP database updated
- Fix: Improved error handling in WAF request handlers and XML-RPC parser
- Fix: Fixed an issue with translations not showing on the Login Security Settings tab
- Fix: Addressed several potential PHP 8.5+ deprecation notices
9.0.0 — August 10, 2026
- Improvement: Added support for passkey authentication
Available for both free and premium installations
- Can be enabled for any user role (multisite support is currently limited)
- WooCommerce integration
- Support for custom authentication integrations
- Improvement: GeoIP database updated