v1.1.9
- New: Shared files lock. wp-config.php, .htaccess, .user.ini and web.config in the WordPress root are made read-only (0444) so tenant plugins cannot rewrite them. It is on by default, including on sites that update. Turn it off with Unlock shared files on the Status page.
- New: Integrity watchdog. GrabWP keeps a snapshot of each protected file. If a tenant admin, AJAX, cron or form request changes one, the file is restored, the event is logged, and the main-site admin sees a notice.
- Enhance: GrabWP's own writes and main-site permalink saves unlock the files and lock them again automatically.
- Enhance: Tenant requests no longer rewrite the shared root .htaccess or web.config. Tenant rewrite rules still update, so routing keeps working.
- Change: If a main-site plugin (for example a cache plugin) needs to write these files, Unlock temporarily, then Lock again. The Status page shows each file's permissions.
- Change: Deactivating the plugin unlocks the files and removes the snapshots.