diff --git a/cdn-files/plugin-info.json b/cdn-files/plugin-info.json index 9102dce..4878d76 100644 --- a/cdn-files/plugin-info.json +++ b/cdn-files/plugin-info.json @@ -1,17 +1,17 @@ { "name": "WebDecoy Bot Detection", "slug": "webdecoy", - "version": "2.10.1", + "version": "2.10.2", "author": "WebDecoy", "author_profile": "https://webdecoy.com", "requires": "6.1", "tested": "7.1", "requires_php": "7.4", - "download_url": "https://cdn.webdecoy.com/wordpress/webdecoy-2.10.1.zip", + "download_url": "https://cdn.webdecoy.com/wordpress/webdecoy-2.10.2.zip", "sections": { "description": "

WebDecoy provides enterprise-grade bot detection and fraud protection for WordPress websites. Unlike simple CAPTCHA solutions, WebDecoy uses a layered defense approach that analyzes visitors from multiple angles — including deterministic tripwires that catch scanners with zero false positives.

Key Features

", "installation": "
  1. Upload the plugin files to /wp-content/plugins/webdecoy
  2. Activate the plugin through the Plugins menu
  3. Tripwires and local protection are active out of the box — no API key required
  4. Optionally go to WebDecoy > Settings > WebDecoy Cloud to connect for centralized monitoring and enforcement
", - "changelog": "

2.10.1

2.10.0

2.9.1

2.9.0

2.3.1

2.3.0

2.1.0

2.0.0

1.3.0

", + "changelog": "

2.10.2

2.10.1

2.10.0

2.9.1

2.9.0

2.3.1

2.3.0

2.1.0

2.0.0

1.3.0

", "faq": "

Does WebDecoy slow down my site?

No. WebDecoy adds negligible latency; tripwire checks are a fast path lookup and clearance minting is idle-deferred.

Will it block search engines?

No. WebDecoy automatically allows 60+ known good bots including all major search engines, and tripwires only fire on hidden paths no legitimate crawler follows.

" }, "icons": { diff --git a/changelog.txt b/changelog.txt index 429e7ee..192e2c3 100644 --- a/changelog.txt +++ b/changelog.txt @@ -1,5 +1,9 @@ *** WebDecoy Bot Detection Changelog *** += 2.10.2 - 2026-10-02 = +* Fixed: a page view a bot scored 40 or higher on could stall for up to 20 seconds when WebDecoy Cloud was slow or down. The detection was sent inline during init, before the block decision, with a 10 second timeout, and installs without a stored organization id made a 10 second key lookup first. Detections are now queued and sent from a shutdown handler after the response (fastcgi_finish_request where available), with a 3 second timeout and the stored organization id. +* Fixed: an ingest refusal (429, 5xx, or no answer) now pauses cloud calls for 60 seconds across all requests. IP enrichment, which filter rules use during the page, skips its call while paused instead of waiting up to 2 seconds for each new IP. + = 2.10.1 - 2026-09-26 = * Fixed: 2.10.0 failed with a fatal error, "Class WebDecoy_AI_Referrals not found", on every request. AI referral counting was registered while the plugin file was being included, before the file declaring its class was loaded. It is now registered on plugins_loaded. A test now fails if the plugin's constructor calls a class that is loaded later. diff --git a/readme.txt b/readme.txt index 2bf6ac4..452c4c6 100644 --- a/readme.txt +++ b/readme.txt @@ -4,7 +4,7 @@ Donate link: https://webdecoy.com Tags: bot detection, security, spam protection, woocommerce, ai bots Requires at least: 6.1 Tested up to: 7.1 -Stable tag: 2.10.1 +Stable tag: 2.10.2 Requires PHP: 7.4 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html @@ -285,6 +285,9 @@ The bundled good-bot list (sdk/src/GoodBotList.php) stores a documentation URL f == Changelog == += 2.10.2 = +* Fixed: when WebDecoy Cloud was slow or unreachable, pages a bot scored 40 or higher on could take up to 20 seconds to load while the plugin waited to report the detection. Detections are now sent after the page has been delivered, and the plugin pauses cloud calls for a minute when WebDecoy is unavailable. Blocking and the local log never wait on the cloud. + = 2.10.1 = * Fixed: 2.10.0 stopped sites loading with a fatal error, "Class WebDecoy_AI_Referrals not found". Updating to 2.10.1 fixes it. diff --git a/webdecoy.php b/webdecoy.php index 9e7d2c2..8d841cc 100644 --- a/webdecoy.php +++ b/webdecoy.php @@ -3,7 +3,7 @@ * Plugin Name: WebDecoy Bot Detection * Plugin URI: https://webdecoy.com/wordpress * Description: Protect your WordPress site from bots, spam, and carding attacks with WebDecoy's advanced threat detection. - * Version: 2.10.1 + * Version: 2.10.2 * Requires at least: 6.1 * Requires PHP: 7.4 * Author: WebDecoy @@ -41,7 +41,7 @@ function str_starts_with(string $haystack, string $needle): bool } // Plugin constants -define('WEBDECOY_VERSION', '2.10.1'); +define('WEBDECOY_VERSION', '2.10.2'); define('WEBDECOY_PLUGIN_FILE', __FILE__); define('WEBDECOY_PLUGIN_DIR', plugin_dir_path(__FILE__)); define('WEBDECOY_PLUGIN_URL', plugin_dir_url(__FILE__));