Title: Polanger Admin Suite – Secure, Control &amp; Customize WordPress Admin
Author: Polanger
Published: <strong>27 Yanvar 2026</strong>
Last modified: 22 Avqust 2026

---

Qoşmaları axtar

![](https://ps.w.org/polanger-admin-menu-manager/assets/banner-772x250.jpg?rev=3520334)

![](https://ps.w.org/polanger-admin-menu-manager/assets/icon-128x128.jpg?rev=3447804)

# Polanger Admin Suite – Secure, Control & Customize WordPress Admin

 By [Polanger](https://profiles.wordpress.org/polangersoft/)

[Download](https://downloads.wordpress.org/plugin/polanger-admin-menu-manager.1.6.1.zip)

 * [Details](https://az.wordpress.org/plugins/polanger-admin-menu-manager/#description)
 * [Reviews](https://az.wordpress.org/plugins/polanger-admin-menu-manager/#reviews)
 *  [Installation](https://az.wordpress.org/plugins/polanger-admin-menu-manager/#installation)
 * [Development](https://az.wordpress.org/plugins/polanger-admin-menu-manager/#developers)

 [Dəstək](https://wordpress.org/support/plugin/polanger-admin-menu-manager/)

## Description

**Polanger Admin Suite** is a modular WordPress administration and security platform
built around three simple goals:

**Secure WordPress. Control the admin experience. Customize it your way.**

Instead of installing separate plugins for admin menus, access control, login protection,
two-factor authentication, firewall security, activity tracking, dashboard management,
and admin customization, Polanger brings these tools together in one modular suite.

Enable only the features your website needs. Optional addons remain inactive until
enabled, helping keep the system focused and lightweight.

Whether you manage your own website, build WordPress projects for clients, or maintain
multiple installations, Polanger gives you one place to protect WordPress, control
what users can access, and create a cleaner administration experience.

 * [Live Demo](https://polanger.com/polanger-admin-suite/wp-admin)

#### Secure. Control. Customize.

Polanger is organized around three complementary layers instead of one oversized
feature set.

### Secure WordPress

Build multiple layers of protection around WordPress without turning every visitor
request into a heavy security scan.

 * **Polanger Firewall** – Request protection, suspicious traffic scoring, authentication
   rate limiting, REST/XML-RPC hardening, IP and country access rules, integrity
   monitoring, upload protection, malicious outbound redirect protection, quarantine,
   recovery tools, and Strict server hardening.
 * **Two-Factor Authentication** – Protect accounts with email verification codes,
   recovery keys, role-based enforcement, and configurable verification policies.
 * **Authenticator App (TOTP)** – Add Google Authenticator or Microsoft Authenticator
   with secure enrollment, recovery keys, trusted-device support, replay protection,
   and safe secret rotation.
 * **reCAPTCHA Protection** – Centralized reCAPTCHA v2/v3 protection for login, 
   registration, password reset, and supported comment forms.
 * **Comment Security Layer** – Protect comments with honeypot detection, timing
   validation, flood controls, behavior scoring, blocklists, and site-wide comment
   policies.
 * **WooCommerce Security** – Extend authentication protection to WooCommerce customer
   login, registration, password recovery, reCAPTCHA, 2FA, and rate limiting.
 * **Activity Monitoring** – Track important administrative and security-related
   activity without turning WordPress into a full request logging system.

Polanger follows a layered approach: stop common attacks at the request layer, detect
trusted-file changes through integrity monitoring, apply stronger server rules where
supported, and provide recovery paths for supported security actions.

### Control WordPress

Decide what administrators, editors, clients, team members, and other users can 
see and access.

 * **Admin Menu Manager** – Hide, rename, reorder, protect, and customize WordPress
   admin menus and submenus.
 * **Access Control** – Restrict plugin and administration access for selected users
   and roles.
 * **Polanger Shield** – Protect wp-admin pages, hide interface elements, add contextual
   notes, and create controlled read-only or demo environments.
 * **Frontend Content Visibility** – Control access to posts, pages, and supported
   custom post types by login state or user role.
 * **Multisite Control** – Define network defaults, site-level overrides, and locked
   policies across supported modules.
 * **Dashboard Center** – Control widgets, notices, visibility, and the information
   users see when they enter WordPress.
 * **Admin Bar Control** – Remove unwanted items, add custom links, and control 
   frontend/backend toolbar content.

### Customize WordPress

Create a cleaner administration experience without replacing WordPress itself.

 * **Design System** – Apply admin theme presets, semantic color controls, typography,
   generated CSS, and WCAG-aware Smart Contrast.
 * **PG Aurora** – A polished admin design preset with refined navigation, submenu
   handling, third-party compatibility, and responsive behavior.
 * **Login Page Customization** – Customize branding, colors, backgrounds, layout,
   and the WordPress login experience.
 * **Custom Admin Menu Builder** – Create your own top-level administration menus
   and links.
 * **Dashboard Customization** – Remove unnecessary widgets and create focused dashboard
   experiences for different users.
 * **Maintenance Center** – Manage maintenance, coming-soon, deployment, preview
   access, branded public pages, countdowns, and bypass rules.

#### Why Polanger Admin Suite?

 * **One Modular Platform** – Replace multiple disconnected admin, access, customization,
   and security tools with one coordinated suite.
 * **Layered WordPress Security** – Protect authentication, incoming requests, critical
   files, WordPress integrity, geographic access, and suspicious outbound behavior.
 * **Built with Recovery in Mind** – High-risk Firewall operations use verification,
   rollback, quarantine, and emergency recovery paths instead of relying on destructive
   one-way actions.
 * **Designed for Compatibility** – Protection modes, bounded processing, asynchronous
   heavy work, and cautious handling of custom code help reduce unnecessary lockouts
   and false positives.
 * **Enable Only What You Need** – Optional addons can be activated independently
   instead of forcing every feature onto every website.
 * **Built for Agencies & Teams** – User access controls, Shield rules, Multisite
   support, activity tracking, and admin customization help manage client and multi-
   user environments.
 * **Modern WordPress Admin Experience** – Clean interfaces, responsive controls,
   localization, and consistent addon workflows across the suite.
 * **Free, Modular, and Extensible** – Core addons are included with Polanger Admin
   Suite and the architecture remains open for future integrations.

#### Built for Real-World WordPress

Polanger is designed for:

 * Agencies managing client websites
 * Developers building and maintaining WordPress projects
 * Teams working with multiple users and roles
 * WooCommerce stores that need stronger customer authentication controls
 * Multisite administrators managing shared policies
 * Site owners who want stronger security without giving up control of their WordPress
   experience
 * Administrators who want a cleaner and more organized wp-admin

#### Core Features

### Admin Menu Manager

 * Hide any admin menu or submenu item
 * Role-based visibility control
 * Rename menu items and submenus
 * Change icons with 200+ Dashicons
 * Drag & drop menu reordering
 * Block direct URL access to hidden pages
 * Visual indicators for hidden and modified items
 * Custom admin menu builder (create your own menus)

### Admin Bar Customization

 * Replace or remove WordPress logo
 * Hide unwanted admin bar items
 * Add custom links with icons
 * Manage frontend and backend admin bar
 * Auto-detect plugin and theme items

### Login Security & Customization

 * Custom login URL (hide wp-login.php)
 * Google reCAPTCHA v2 & v3 support
 * Custom login page design (logo, colors, background)
 * Brute-force protection with configurable login attempt limits and lockouts
 * Hardened login flows with safer redirects and protected authentication routes

### Email Two-Factor Authentication (2FA)

 * Email-based verification codes
 * Role-based enforcement
 * Recovery keys for backup access
 * Configurable expiration times
 * Super admin protection

### Authenticator App (TOTP)

 * Google Authenticator and Microsoft Authenticator support
 * Time-based One-Time Password (TOTP) verification
 * Multi-user architecture with per-user enrollment
 * Mandatory enrollment flow for users in required roles
 * Profile page 2FA management (Users  Profile)
 * Admin visibility: enrollment status only, no secret access
 * Safe secret rotation with pending secret system
 * Old authenticator remains active until new setup is verified
 * Secure secret storage with AES-256-CBC encryption
 * Manual secret entry with provisioning URI support
 * One-time recovery keys (10 keys per user, auto-regenerated on rotation)
 * Email fallback option when authenticator is unavailable
 * Brute-force protection with configurable lockout
 * Replay attack prevention with time-slice tracking
 * Seamless integration with core 2FA settings (roles, lockout, expiry)

### Activity Log

 * Track logins, plugin changes, content updates, and more
 * Filter by user, action, and date
 * Export logs (CSV)
 * Email alerts for critical actions
 * Privacy-conscious logging with controlled activity data collection

### Dashboard Control

 * Hide default WordPress widgets
 * Hide third-party plugin widgets
 * Control admin notices
 * Create custom dashboard widgets
 * Per-user dashboard visibility

### Multisite Control

 * Network-wide default settings for multisite installations
 * Site-level override controls for supported modules
 * Lock system for Menu Manager, Admin Bar, Login Security, Activity Log, and Dashboard
   Center
 * Network-aware addon activation support
 * Developer-friendly effective settings filter architecture

### Access Control

 * Restrict plugin access to specific users
 * Read-only mode support
 * Prevent unauthorized access
 * Super admin safety protection

### Design System

 * Token-based admin theming system for consistent and scalable customization
 * Customize colors across admin UI (sidebar, admin bar, background, text, surfaces)
 * Sidebar background, text color, and menu item styling
 * Admin bar background, text color, submenu background, and submenu text color
 * Built-in presets (e.g. Dark, Minimal, Default) with one-click application
 * Automatic CSS generation with cache-friendly performance
 * Enhanced Smart Contrast uses WCAG-aware ratios, gradient sampling, dynamic admin-
   surface monitoring, icon correction, and late theme guards while preserving colors
   that are already readable
 * Typography controls including font family and basic shape settings
 * Scoped styling to avoid conflicts with WordPress core and plugins
 * Extensible architecture for future themes, layouts, and design packs

### Frontend Content Visibility

 * Per-content frontend access control for posts, pages, and supported custom post
   types
 * Visibility modes for public, logged-in users only, selected roles only, or hidden-
   from-selected-roles workflows
 * Multiple denied behaviors including login redirect, 404, access denied message,
   and custom redirect
 * Theme-friendly replacement mode or dedicated access denied page for stricter 
   template control
 * Optional hiding from archives, search results, public REST responses, and WordPress
   XML sitemaps
 * Rich-text access denied messages with TinyMCE, HTML, and shortcode support

### reCAPTCHA Protection

 * Centralized Google reCAPTCHA key management (v2 and v3)
 * All reCAPTCHA configuration consolidated in one dedicated addon
 * Login form protection
 * Registration form protection
 * Lost password form protection
 * Comment form protection (works with Comment Security addon)
 * Configurable v3 score threshold
 * Badge position customization for v3
 * Automatic script loading only when needed

### Firewall

 * Lightweight, WordPress-aware Firewall designed to protect common attack surfaces
   without turning every visitor request into a heavy security scan.
 * Three protection modes: **Monitor Only** for observation, **Safe Protection**
   for everyday websites, and **Strict** for more aggressive protection when stronger
   security is needed.
 * Blocks common bot probes, exposed-file scans, suspicious paths, traversal attempts,
   unsafe requests, and other high-risk traffic before it can reach sensitive WordPress
   functionality.
 * Protects native WordPress login, registration, and password-reset flows with 
   identity and IP-based rate limiting.
 * Hardens the REST API and XML-RPC against common abuse, including anonymous request
   pressure, user enumeration, multicall attacks, and optional anonymous write restrictions.
 * Uses a request scoring engine that combines multiple suspicious signals before
   deciding whether traffic should be monitored or blocked.
 * **Malicious Outbound Redirect Protection** helps protect visitors when compromised
   or injected frontend code attempts to open known malicious destinations or trigger
   unexpected external redirects and popups. Protection is enabled by default in
   Safe and Strict modes and can be disabled for site-specific compatibility.
 * A compact local PhishTank reputation index strengthens outbound protection without
   sending each visitor, URL, or destination to a remote reputation API.
 * Supports IP allowlists and denylists, IPv4/IPv6 CIDR ranges, trusted proxy configurations,
   and temporary cooldowns for repeated abusive traffic.
 * **Country Access Control** can block visitors from selected countries using a
   local DB-IP Country Lite database. Visitor IP addresses are not sent to an external
   geolocation API.
 * Country data is prepared only when country blocking is configured, checked periodically
   for updates, and removed when the country policy is cleared.
 * Adds practical security response headers, username enumeration protection, and
   controls for WordPress Application Password usage.
 * **WordPress Core Integrity** verifies the installed WordPress version against
   official checksums and detects modified, missing, or unauthorized core files.
 * Supported **WordPress.org plugins** can be checked against their official package
   data, while premium and custom plugins/themes are monitored more cautiously so
   unverified custom code is not automatically treated as malware.
 * Monitors executable files inside `wp-content` for unexpected additions and changes
   while recognizing normal WordPress core, plugin, theme, and translation updates.
 * Reduces false positives by distinguishing harmless PHP guard files from files
   containing actual executable PHP behavior.
 * **Upload Protection** detects executable or PHP-bearing media uploads and can
   prevent PHP execution inside the uploads directory on supported Apache environments.
 * Uses high-confidence malware behavior signals to detect suspicious patterns such
   as encoded execution chains, request-driven commands or file writes, dangerous
   includes, hidden remote frames, forced external redirects, and click-triggered
   popup behavior.
 * **Strict Extended Server Hardening** adds an additional protection layer on supported
   Apache/LiteSpeed servers to block sensitive-file exposure, development metadata
   leaks, backup/log access, directory browsing, and selected unsafe requests before
   WordPress/PHP handles them.
 * Server hardening rules are applied with verification, health checks, automatic
   rollback, and safe cleanup without modifying WordPress or third-party rule blocks.
 * **Recommended Actions** help administrators understand what to do with security
   findings instead of only reporting that a problem exists.
 * Verified official WordPress core and supported WordPress.org plugin files can
   be safely restored from trusted package sources when appropriate.
 * High-confidence executable threats can be moved into protected quarantine, while
   ambiguous custom or premium code is never automatically deleted.
 * **Quarantine Manager** provides visibility into quarantined files with controlled
   restore and permanent deletion actions.
 * Recovery history and an **Emergency Recovery URL** provide a safe way to reverse
   supported Firewall file operations if a remediation action causes unexpected 
   site behavior.
 * No-reload **Scan Now** performs a detailed integrity scan with live progress 
   while heavier work is processed asynchronously to reduce timeout and memory pressure.
 * Scheduled low-impact integrity scans and automatic post-update verification help
   detect later file changes without requiring constant manual full scans.
 * Findings are clearly separated into **Critical**, **Review**, and **Notice** 
   levels so package differences, harmless files, and custom code are not automatically
   presented as malware.
 * Integrity results are grouped by affected component with a compact preview and
   a searchable, filtered findings viewer for larger reports.
 * **Recent Firewall Events** records important security decisions using bounded
   storage instead of operating as a heavy full-traffic request logger.
 * **Firewall Diagnostics** provides built-in self-tests for request protection,
   rate limits, REST/XML-RPC behavior, IP/CIDR rules, security headers, country 
   access, integrity protection, uploads protection, scheduled scanning, and Strict
   server hardening without intentionally sending malicious traffic to the website.
 * Protection presets configure sensible defaults automatically while still allowing
   advanced administrators to customize individual controls when needed.

### WooCommerce Security

 * Adds WooCommerce-specific reCAPTCHA locations for customer login, registration,
   and lost password forms
 * Extends the existing Polanger 2FA flow into WooCommerce customer login while 
   preserving My Account and checkout return paths
 * Adds customer authentication rate limiting for login failures, account registrations,
   and lost password requests
 * Includes Light, Balanced, and Strict protection profiles so store owners can 
   choose safe limits without tuning every number manually
 * Requires WooCommerce and uses dependency-aware loading so the addon does not 
   run in incomplete store environments
 * Reuses Polanger’s existing reCAPTCHA and 2FA systems instead of creating a disconnected
   WooCommerce security stack

### Polanger Shield

 * Blocks selected wp-admin pages for selected users with optional direct URL blocking
 * Hides selected admin interface areas from the real screen using the floating 
   Shield tool
 * Adds contextual notes to admin elements so teams can document workflows directly
   inside wp-admin
 * Demo Lock keeps selected admin screens visible while preventing save, publish,
   AJAX, REST, and destructive changes for demo users
 * Global Demo Mode turns wp-admin into a controlled read-only demo environment 
   for eligible administrator accounts
 * Safe Mode gives authorized managers a temporary recovery path when reviewing 
   or troubleshooting Shield rules
 * Menu Manager integration shows when a menu or submenu item is already protected
   by Shield, helping avoid duplicate restrictions
 * The Shield dashboard provides status/type filters, 25-rule pagination, localized
   dates and states, bulk actions, and a mobile-safe scroll region so every saved
   rule remains manageable

#### Modular Addon Architecture

Polanger Admin Suite uses a modular addon architecture so each website can enable
only the functionality it actually needs.

Bundled addons share the same Admin Suite foundation and settings experience while
remaining independently activatable. …

## Installation

 1. Upload the plugin to `/wp-content/plugins/`
 2. Activate it from the Plugins menu
 3. Access via **Settings -> Polanger Admin**

## FAQ

### Is Polanger Admin Suite free?

Yes. Polanger Admin Suite and all bundled Core Addons are free to use.

### Do I need to enable every addon?

No. Enable only the modules and addons your website needs. Optional functionality
can remain disabled.

### Does Polanger replace multiple WordPress plugins?

It can replace several common admin customization, access control, login protection,
activity monitoring, 2FA, reCAPTCHA, maintenance, and basic WordPress security tools
depending on your site’s requirements.

### Is Polanger Firewall a replacement for a hosting firewall or CDN WAF?

No. Polanger Firewall is a WordPress-aware protection and integrity layer. Server
firewalls, hosting security, CDN/WAF services, backups, updates, and good account
security remain valuable parts of a complete security strategy.

### Does Firewall automatically delete suspicious files?

No. Polanger intentionally avoids automatically deleting ambiguous custom or premium
code. Verified official files can offer safe restoration actions, while high-confidence
executable threats can be quarantined with recovery options.

### Can Firewall recover from a security action that causes a problem?

Supported remediation operations include rollback and recovery safeguards. Firewall
also provides quarantine history and an Emergency Recovery URL for supported journaled
operations.

### Does country blocking send visitor IP addresses to an external API?

No. Country Access Control uses locally stored country data. Visitor IP addresses
are not sent to a remote geolocation API for each request.

### Does outbound redirect protection send every visitor URL to a remote reputation service?

No. Polanger uses a compact local reputation index and browser-side behavioral protection
without performing a remote reputation lookup for every visitor navigation.

### Will Polanger slow down my website?

Polanger is designed to remain lightweight by keeping heavy operations away from
normal visitor requests, using asynchronous processing for integrity work, bounding
stored security state, and loading optional functionality only when needed. Actual
performance can still vary by hosting environment, configuration, traffic, and enabled
features.

### Can I control what users see inside WordPress?

Yes. Menu Manager, Access Control, Shield, Dashboard Center, Frontend Content Visibility,
and related modules provide different levels of user and role-based control.

### Does Polanger support WooCommerce?

Yes. WooCommerce Security extends supported Polanger authentication protections 
to customer login, registration, password recovery, reCAPTCHA, 2FA, and rate limiting
while keeping store-specific behavior separate from the main WordPress authentication
layer.

### Does Polanger support WordPress Multisite?

Yes. Multisite Control provides network defaults, site-level overrides, and locking
behavior for supported modules.

## Reviews

![](https://secure.gravatar.com/avatar/a33ccbdaf75ba1ca689933b1fd2563f9ada4a1e32c9a3db9cb8bb544722abdd0?
s=60&d=retro&r=g)

### 󠀁[Simply an amazing plugin](https://wordpress.org/support/topic/simply-an-amazing-plugin/)󠁿

 [kckable](https://profiles.wordpress.org/kckable/) 15 Avqust 2026

It was exactly the solution I was looking for to clean up the admin panel, ensure
security, and keep my client sites organized. Fast, seamless, and very easy to use.
Thanks to the Polanger team for this great plugin

![](https://secure.gravatar.com/avatar/3bc8fed11614e9fcff75003050fe2f80b046178d258a5085cd96c2a6cc30a64e?
s=60&d=retro&r=g)

### 󠀁[Finally found it](https://wordpress.org/support/topic/finally-found-it-9/)󠁿

 [borkatta](https://profiles.wordpress.org/borkatta/) 01 May 2026

Finaly found a plugin that has all the admin settings in one place:)

 [ Read all 2 reviews ](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/)

## Contributors & Developers

“Polanger Admin Suite – Secure, Control & Customize WordPress Admin” is open source
software. The following people have contributed to this plugin.

Contributors

 *   [ Polanger ](https://profiles.wordpress.org/polangersoft/)

[Translate “Polanger Admin Suite – Secure, Control & Customize WordPress Admin” into your language.](https://translate.wordpress.org/projects/wp-plugins/polanger-admin-menu-manager)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/polanger-admin-menu-manager/),
check out the [SVN repository](https://plugins.svn.wordpress.org/polanger-admin-menu-manager/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/polanger-admin-menu-manager/)
by [RSS](https://plugins.trac.wordpress.org/log/polanger-admin-menu-manager/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.6.1

 * Improved: Outbound Redirect Protection now includes administrator controls, refined
   mode-aware containment, and compatibility-focused opt-out behavior.
 * Improved: Firewall integrity results are more precise, reducing false positives
   for inert PHP guard files and non-runtime WordPress package documents.
 * Improved: Firewall background scanning, recovery verification, reputation loading,
   and uploads protection were optimized for lower resource usage and stronger failure
   recovery on production sites.
 * Improved: PG Aurora now provides wider, wrap-safe admin submenus, clearer nested-
   menu indicators, reliable third-party flyout compatibility, and full-width WordPress
   profile hover surfaces.

#### 1.6.0

 * New: Firewall adds mode-driven malicious outbound redirect containment with a
   daily compact local PhishTank reputation index, high-confidence behavior blocking,
   privacy-bounded events, and no per-visitor remote lookup.
 * New: Comment Security adds a site-wide policy to keep comments open, allow only
   WooCommerce product reviews, or completely block new public comments across supported
   WordPress entry points while preserving existing comments and settings.
 * Improved: Firewall now distinguishes authenticated WordPress plugin/theme ZIP
   installation from media uploads, preserving strict PHP upload blocking while 
   allowing the native replace-or-cancel update flow.
 * New: Firewall adds a no-reload Quarantine Manager with active-item visibility,
   authenticated restore, permanent deletion, explicit confirmation, signed journals,
   and post-restore integrity verification.
 * New: Firewall findings now provide evidence-aware recommended actions, transactional
   exact-package restoration, signed quarantine with rollback history, and a rotating
   emergency recovery URL that can reverse only journaled operations
 * Improved: Critical Firewall integrity alerts can now be permanently dismissed
   per administrator while a compact toolbar status keeps unresolved findings accessible
   without repeating page-wide notices

#### 1.5.9

 * New: Scan Now runs a complete no-reload integrity scan with live percentage, 
   stage, and processed-file counters; work is split into locked AJAX batches and
   can continue safely through WP-Cron if the page closes
 * New: Country Access Control blocks selected countries through a compact local
   DB-IP database, displays removable live country chips, supports a customizable
   localized 403 page, and refreshes active data approximately every 15 days
 * New: Strict Extended Server Hardening adds bounded Apache/LiteSpeed protection
   before PHP with transactional .htaccess writes, live health verification, rollback,
   diagnostics, and automatic cleanup when Strict protection leaves service
 * Improved: Firewall integrity now combines exact-version WordPress core checksums,
   supported WordPress.org plugin verification, executable drift monitoring, high-
   confidence malware behavior signals, daily low-cost scans, post-update verification,
   and explicit verified core repair
 * Improved: Integrity findings now use a compact summary, grouped components, ten-
   row preview, filtered AJAX-paginated modal, critical administrator alerts, and
   replacement of the previous report after each completed scan instead of accumulating
   scan history
 * Improved: Firewall now includes complete Turkish, German, Spanish, Russian, Simplified
   Chinese, and Arabic coverage for current Firewall screens, diagnostics, findings,
   country names, and blocked-visitor defaults
 * Improved: Firewall cards, actions, progress details, country controls, selected-
   country chips, and findings modal now adapt more cleanly to narrow tablet and
   mobile screens
 * Improved: Design System Smart Contrast now evaluates WCAG contrast across solid,
   transparent, and gradient surfaces, protects readable existing colors, corrects
   icons and dynamic plugin UI, and monitors supported editor frames
 * Fixed: Shield now intercepts visual selector clicks before target controls can
   execute, builds subdirectory-safe Test URLs, keeps Shield-only managers on the
   dedicated settings tab, avoids disabled Global Demo user queries, and reports
   missing rule actions accurately
 * Improved: Shield adds filtered 25-row rule pagination, mobile-safe tables and
   floating tools, accessible modal focus handling, cache-safe asset versions, precise
   Demo control decoration, and complete current translations in all six bundled
   languages

#### 1.5.8

 * Improved: Country Access Control now lets administrators review and remove selected
   countries as live chips, customize the localized blocked-visitor page title and
   message, and preserve the secure HTTP 403 layout with unobtrusive DB-IP attribution
 * Improved: Firewall now ships complete Turkish, German, Spanish, Russian, Simplified
   Chinese, and Arabic translations, including diagnostics, integrity results, Country
   Access Control, and localized country names
 * New: Optional local Country Access Control downloads DB-IP Country Lite only 
   after explicit country selection, enforces selected countries in every enabled
   Firewall mode, and checks for monthly data updates approximately every 15 days
 * New: Strict Extended Server Hardening adds bounded Apache/LiteSpeed protection
   before PHP, transactional root .htaccess writes, post-write health verification,
   rollback, diagnostics, and automatic cleanup whenever Strict protection leaves
   service
 * New: Firewall adds exact-version WordPress core integrity, official plugin SHA-
   256 checks, update-aware executable monitoring, uploads execution protection,
   malware behavior signals, scheduled scans, and explicit verified core repair 
   with quarantine
 * Fixed: Firewall rate windows no longer slide indefinitely, Monitor Only keeps
   threshold state, REST rate limiting is visible and migrated to its intended preset,
   trusted proxy chains resolve safely, and sensitive event query values are redacted
 * Fixed: WooCommerce Security settings tab registration now loads reliably when
   WooCommerce becomes available later in the WordPress plugin bootstrap order
 * Fixed: Design System PG Aurora active tab and nested navigation contrast now 
   keeps selected settings tabs, addon subtabs, and gradient surfaces readable
 * Improved: Polanger Shield admin page restrictions now block targeted users more
   consistently and surface Shield-controlled menu protections inside Menu Manager
 * Improved: Firewall request scoring has been refined for more accurate suspicious
   request detection while preserving safer preset behavior

#### 1.5.7

 * New: Design System now includes the PG Aurora admin theme preset with a modern
   light dashboard style, gradient menu states, improved sidebar icon handling, 
   refined submenu hierarchy, and polished classic WordPress admin screen compatibility
 * Improved: Firewall request protection was refined with safer preset behavior,
   compatibility-aware REST handling, and clearer optional tuning boundaries for
   production sites
 * Improved: Strict REST protection now preserves WooCommerce Store API compatibility
   automatically when WooCommerce is active, preventing cart, checkout, and account
   flows from being blocked by anonymous REST write hardening
 * Improved: Menu Manager mobile layout now uses responsive card-based rows with
   cleaner visibility controls, submenu expansion, custom name fields, and cache-
   safe admin UI stylesheet loading
 * Fixed: Design System preset application now updates saved theme tokens reliably,
   reflects changes immediately on the settings page, and includes an inline fallback
   so generated admin theme CSS cannot silently fail on stricter live hosting setups

#### 1.5.6

 * New: Firewall addon adds Monitor Only, Balanced, and Strict WordPress-aware request
   protection for common bot probes, native auth rate limits, XML-RPC hardening,
   REST pressure, anonymous user enumeration, IP rules, temporary cooldowns, and
   lightweight event logging while respecting custom administrator overrides
 * Improved: Firewall defaults, Monitor Only behavior, REST compatibility, CIDR 
   validation, proxy IP detection, and event logging safety were refined to reduce
   false positives and lockout risk
 * Fixed: Plugin update notifications remain visible on the Plugins screen when 
   admin notice hiding is enabled
 * Improved: The Shield dashboard displays the Global Demo Mode summary only while
   demo protection is active
 * New: Menu Manager identifies menu and submenu items already protected by active
   Shield page rules and shows affected users and direct URL protection details 
   without duplicating restrictions
 * Fixed: Shield user ID handling now safely normalizes administrator records returned
   as objects, preventing PHP warnings in protected admin and menu integration checks
 * Improved: Maintenance Center preview and content editing were refined with admin-
   safe preview rendering, stronger preview button contrast, and richer text color
   controls in visual editors

#### 1.5.5

 * Improved: Admin Suite interface refined with cleaner layouts, smoother navigation,
   and more consistent settings screens
 * Improved: Better compatibility across login security, frontend visibility, dashboard
   controls, and modular addon workflows
 * Improved: Module loading optimized to keep the WordPress admin experience faster
   and lighter when only selected features are enabled
 * Improved: Responsive behavior polished across key Admin Suite screens for a more
   comfortable tablet and mobile admin experience
 * Fixed: Minor visual and settings synchronization issues reported in selected 
   admin screens

#### 1.5.4

 * Improved: Frontend Content Visibility editing was streamlined with a clearer 
   access-rule workflow, making role-based hiding easier to understand on posts,
   pages, and supported custom post types while preserving compatibility with older
   saved rules
 * Improved: Frontend Content Visibility now serves a dedicated Polanger protected
   404 screen when denied behavior is set to 404, avoiding broken or inconsistent
   theme-level 404 layouts
 * Improved: Login Security redirect handling and protected-route interception were
   hardened for unauthorized access attempts to custom login and admin entry points
 * Improved: The built-in protected 404 experience was refined with cleaner messaging,
   a simplified layout, and WordPress 6.4+ compatibility hardening for deprecated
   emoji style output

#### 1.5.3

 * New: Frontend Content Visibility core module for posts, pages, and supported 
   custom post types with role-based audience control, denied behavior routing, 
   and discovery hiding for archives, REST API, and XML sitemaps
 * Improved: Admin design system and user interface components enhanced for a better
   user experience.
 * Improved: Mobile and responsive layouts optimized across various plugin screens.
 * Improved: Enhanced security measures and hardening implemented for the Two-Factor
   Authentication (2FA) module.
 * Improved: Translation catalogs and compiled language packs were refreshed for
   the current release across bundled locales

#### 1.5.2

 * Improved: Menu Manager now captures late-registered and dynamically reordered
   top-level admin menus more reliably, fixing cases where some third-party plugin
   menus did not appear in the manager list
 * Improved: Menu Manager list ordering now better mirrors the effective live WordPress
   sidebar order for plugins that reposition themselves through custom menu filters
 * Improved: Design System was expanded into a richer WCAG-aware admin theming engine
   with semantic color tokens, advanced typography controls, and a live preview 
   playground
 * Improved: Design System presets were redesigned into curated professional themes,
   with stronger compatibility across admin menus, admin bar states, metaboxes, 
   tables, widgets, and classic editor screens
 * Improved: Design System Midnight compatibility was hardened for third-party admin
   UI, including low-contrast text recovery and dark dropdown/menu readability fixes
   that only activate for the Midnight preset
 * Improved: Mobile admin usability refinements across settings layouts and action
   controls for better spacing, responsiveness, and alignment on smaller screens

#### 1.5.1

 * Fixed: Resolved an issue where reCAPTCHA could fail to appear on the custom login
   page under certain configurations
 * Improved: Better integration and compatibility between Authenticator App (TOTP)
   and reCAPTCHA verification flows
 * Improved: Comment Guard reCAPTCHA integration is now more stable and reliable
   across comment submission scenarios
 * Fixed: Resolved login page logo cropping issues on responsive and custom layout
   configurations
 * Improved: On mobile devices, the login page language selector is now displayed
   inside a compact drawer for a cleaner layout
 * New: Added option to completely disable the language switcher on the login page

#### 1.5.0

 * New: Authenticator App (TOTP) addon – Google/Microsoft Authenticator support 
   with multi-user architecture, mandatory enrollment flow for required roles, profile
   page 2FA management, safe secret rotation (pending secret system prevents lockouts),
   AES-256-CBC encryption, recovery keys with auto-regeneration on rotation, trusted
   device memory, email fallback, and brute-force protection
 * New: reCAPTCHA addon – centralized Google reCAPTCHA v2/v3 key management; all
   reCAPTCHA configuration consolidated from multiple locations into one dedicated
   addon for login, registration, lost password, and comment forms
 * Improved: Design System – added Sidebar Background, Sidebar Text Color, Admin
   Bar Background, Admin Bar Text Color, Admin Bar Submenu Background, and Admin
   Bar Submenu Text Color customization options
 * Improved: Design System color compatibility – enhanced contrast handling and 
   readability corrections across admin UI components
 * Improved: Menu Manager – resolved conflict issues with certain third-party plugins
   and themes
 * Improved: Mobile responsiveness – comprehensive layout and interaction improvements
   across all admin screens for better tablet and smartphone usability
 * Improved: 2FA settings form – resolved nested form submission issue for reliable
   Save Settings functionality

#### 1.4.3

 * New: Comment Security Layer addon – multi-layer comment protection with honeypot
   trap, HMAC-signed timing tokens, per-IP flood control (per-minute and per-hour
   windows), keyword and URL blocklists, behavior scoring engine with configurable
   thresholds, and silent action modes (spam queue, trash, or silent drop)
 * Improved: Login page design – refined mobile layout with corrected form card 
   proportions, improved spacing around inputs and buttons on small screens, and
   more consistent hover and focus state rendering across breakpoints
 * Improved: Login page background rendering – smoother gradient transitions and
   better full-coverage rendering for background images on narrow viewports; improved
   visual layering between background and form card
 * Improved: Admin panel mobile responsiveness – layout and spacing adjustments 
   across Settings, Addons, and Activity Log screens; better usability on tablet
   and mobile viewports with more appropriate touch target sizing
 * Improved: Sub-tab settings saves – partial save operations now only process and
   re-validate the submitted field group instead of the full settings object, reducing
   redundant sanitization passes on every tab change
 * Improved: Addon list layout – card grid now wraps and spaces more cleanly on 
   narrow viewports; improved readability of addon status indicators on mobile

#### 1.4.2

 * New: Multisite Control addon – manage network-wide defaults, lock policies, and
   site-level overrides from a single system
 * New: Design System addon – token-based admin theming with presets, generated 
   CSS, and extensible architecture
 * New: Network-aware settings engine with effective settings merging across supported
   modules
 * New: Network lock support for core modules (Menu Manager, Admin Bar, Login Security,
   Activity Log, Dashboard Center)
 * New: Site-level override indicators and network-managed notices for clearer control
   visibility
 * New: Developer hook `polanger_admin_theme_assets` for extending admin UI styling
   without modifying core files
 * Improved: 2FA system stability and security
    - Enhanced verification flow with stronger session and user validation
    - Secure resend flow with nonce protection and stricter token handling
    - Improved trusted device and IP resolution (proxy-aware validation)
    - Login flow now respects “Remember Me” preference
    - Safer email handling with runtime checks and fallback protection
    - Automatic reset of invalid email verification states
    - Prevents enabling 2FA when email delivery is not properly configured
 * Improved: Design System readability and contrast handling
    - Automatic contrast correction for dark/light surfaces
    - Improved text visibility across admin UI components (postbox, notices, tables,
      forms)
    - More consistent styling across WordPress admin elements
 * Improved: Addon system architecture
    - Better addon activation flow with optional network-wide activation
    - Expanded developer documentation with hooks, filters, and theming examples
    - Improved extensibility for future addon-based features
 * Improved: General stability, security, and internal optimizations

#### 1.4.1

 * Improved: Activity Log export flow (CSV/JSON) output handling on Settings page
   for more consistent downloads
 * Improved: Settings export callback visibility and `admin_init` lifecycle compatibility
 * Improved: Activity Log query hardening with validated table-name usage and allowlisted`
   ORDER BY` handling
 * Improved: 2FA verification comparison updated with timing-safe hash validation(`
   hash_equals`)
 * Improved: Activity Log IP resolution now prefers `REMOTE_ADDR` and supports trusted-
   proxy based forwarded-header parsing
 * Improved: Settings input validation for `allowed_users` with strict array-type
   guards before normalization

#### 1.4.0

 * Major update: Polanger expanded into a full Admin Suite with optional addons 
   managed from one interface
 * New: Full Admin Suite experience (menu, login, security, dashboard, activity 
   log)
 * New: Custom Admin Menu Builder
 * New: Role-based access control improvements
 * Improved: UI/UX across all modules
 * Improved: Performance and stability
 * Improved: Security layers and validation
 * Fixed: Minor bugs and edge cases

#### 1.3.1

 * Fixed: Prevented foreach warning when settings are missing
 * Improved: Stability improvements for fresh installs

## Meta

 *  Version **1.6.1**
 *  Last updated **2 həftə öncə**
 *  Active installations **50+**
 *  WordPress version ** 5.7 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 7.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/polanger-admin-menu-manager/)
 * Tags
 * [2FA](https://az.wordpress.org/plugins/tags/2fa/)[customize](https://az.wordpress.org/plugins/tags/customize/)
   [firewall](https://az.wordpress.org/plugins/tags/firewall/)[login security](https://az.wordpress.org/plugins/tags/login-security/)
   [menu manager](https://az.wordpress.org/plugins/tags/menu-manager/)
 *  [Advanced View](https://az.wordpress.org/plugins/polanger-admin-menu-manager/advanced/)

## Reytinqlər

 5 out of 5 stars.

 *  [  2 5-star reviews     ](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/polanger-admin-menu-manager/reviews/)

## Contributors

 *   [ Polanger ](https://profiles.wordpress.org/polangersoft/)

## Dəstək

Şərhiniz varmı? Yardım lazımdırmı?

 [Dəstək forumuna bax](https://wordpress.org/support/plugin/polanger-admin-menu-manager/)