Bypass all resource restrictions, passwords, and keys? Read here!
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.2.0 Nulled
9.2.0 (2026.09.28) - ASE Free and Pro
- [ADDED in Free and Pro] Utilities >> Plugins and Themes Rollback: New module to easily rollback plugins and themes to previous versions. ASE Free enables rollback of free plugins and themes hosted in wordpress.org. ASE Pro enabls rollback of paid / premium plugins not hosted in wordpress.org. Props to Yoshihiro T. and Justin T. for suggesting this feature.
- [IMPROVED in Free and Pro] Content Management >> Open All External Links in New Tab: implemented an option to not add rel="nofollow" attribute, and use this as a gate for the domain exclusion section for nofollow. Props to Sunny T. for prompting this improvement.
- [FIXED in Free and Pro] Utilities >> Password Protection:
- Wordfence Login Security (2FA, CAPTCHA, and passkeys) can complete login while password protection is enabled. Other admin-ajax.php requests and the REST API still return 401 for guests. Props to Craig for reporting the issue in detail.
- Unexpected asenha_password_protection cookie values are rejected before password verification, which stops a visitor-supplied hash from forcing a very long bcrypt run on each request. Props to @okparfait for reporting the issue in detail.
- [CHANGED in Pro] Admin Interface >> Admin Logo: admin menu logo now opens in the same browser tab, similar to admin bar logo. Props to Henry R. for prompting this change.
- [IMPROVED in Pro] Content Management >> Custom Content Types >> Custom Field Groups: added height settings for WYSIWYG field. Props to Stijn V. for prompting this improvement.
- [IMPROVED and FIXED in Pro] Utilities >> Site Backup and Migration:
- Sync posts: Added an option to keep posts that exist only in the destination site. Added an option to assign post author on the destination site. Rearrange and reword the sync UI for better clarity.
- Fixed an issue where high-compatibility backup policy run fails due to missing chunk during backup archive creation. Props to Tiago P. for reporting the issue in detail.
- [FIXED in Pro] Utilities >> Disable REST API, Password Protection, Maintenance Mode: Site Backup and Migration module's sync operation is no longer blocked while either module is enabled.
- [TRANSLATION in Free and Pro] ASE is now being translated into 38 languages:
- Added new/improved translationfor:
- ASE Free: Updted Slovak, Serbian, Portuguese (Brazil), Polish, Norwegian, Italian.
- ASE Pro: Updated Norwegian, Polish, Portuguese (Brazil).
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.4 Nulled
= 9.1.4 (2026.09.28) - ASE Free and Pro
- [FIXED in Free and Pro] Utilities >> Maintenance Mode: Wordfence Login Security (2FA, CAPTCHA, and passkeys) can complete login while maintenance mode is enabled. Other admin-ajax.php requests and the REST API still return 503 for guests. Props to Julian M. and ErinGibsonCo for reporting the issue.
- [FIXED in Free and Pro] Utilities >> Password Protection & Maintenance Mode: Fixed Novamira connection issue via oAuth when Password Protection or Maintenance Mode is enabled. Props to Antoine L. for reporting the issue.
- [FIXED in Free and Pro] Optimizations >> Image Upload Control: Fixed an issue preventing Elementor demo content import from completing successfully. Props to @mztechsnc for reporting this in detail with the error log entry.
- [IMPROVED and FIXED in Pro] Custom Code >> Code Snippets Manager: Improved the robustness of active PHP snippets executions and more reliable, in-context retrieval of post ID, so the snippet works as intended. Props to Stéphane N. for prompting this improvement.
- [IMPROVED in Pro] Site Backup and Migration:
- During migration operation, plugins in destination site that is not present in the origin site's backup archive can sometimes be cleaned up partially, leaving an empty plugin folder and subfolders that contains only hidden files (filename starts with dot). This causes plugin reinstallation to fail. This fix makes sure plugin clean up completely removes such hidden files. Props to David M.C. for reporting the issue in detail.
- WordPress core themes will now be properly carried over and restored during migration via full backup archive import. Props to David M.C. for reporting the issue in great detail.
- Improved handling of attachments remap to their parent post during sync. Props David M.C. for reporting the issue and facilitating the troubleshooting process.
- [FIXED in Pro] Content Management >> Custom Content Types >> Custom Field Groups: Fixed changes not properly being saved on CFG with a lot of fields, that can occur in a site where PHP max_input_vars is on the lower end. Props to Zubair for reporting the issue and facilitating the troubleshooting process.
- [TRANSLATION in Free and Pro] ASE is now being translated into 38 languages:
- Added new/improved translationfor:
- ASE Free: Updated Spanish (Spain), Spanish (Chile), Portuguese (Brazil), Polish, Dutch (Netherlands), Chinese (Taiwan).
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.3.1 Nulled
= 9.1.3.1 (2026.09.22) - ASE Free and Pro
- [FIXED in Free and Pro] Log In/Out & Register >> Change Login URL: Fixed a regression in v9.1.3 causing log out from the admin bar profile menu to redirect back to /wp-admin/ (still logged in). Props to Toby B., Jan S. and John K. for reporting the issue.
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.3 Nulled
= 9.1.3 (2026.09.21) - ASE Free and Pro
- [SECURITY FIX in Free and Pro] Log In/Out & Register >> Change Login URL: Requests to //wp-login.php (leading double slash) no longer skip redirection to the not-found URL. Props to @jlop77 for reporting this in great detail.
- [IMPROVED in Free and Pro] Content Management >> Content Duplication: Prevent Elementor placeholder.php from being sideloaded into the media library on duplicating Elementor pages/templates. Props to Rajan D. for reporting the issue in detail.
- [FIXED in Free and Pro] Admin Interface >> Admin Menu Organizer:
- Fixed conflict with WP Vivid Pro plugin causing their snapshot UI to be shown at the bottom of the Admin Menu Organizer page. Props to Stéphane N. for reporting the issue and facilitating the troubleshooting process.
- Fixed SureCart submenu items, e.g. "Orders >> Abandoned" wrongly placed towards the end of the SureCart menu, instead of right below their parent. Also fixed "Dashboard", "Customers" and "Custom Forms" showing up blank in AMO page. Props to Kenneth S. for reporting the issue with screenshots.
- [IMPROVED in Free and Pro] Utilities >> Password Protection:
- ASE Free: Logged-in users can use the REST API while Password Protection is on. Guests remain gated. Props to Manfred A. for prompting this change.
- ASE Pro: Added a REST API route whitelist so selected endpoints remain accessible while the rest of the site is password-protected. Props to Axel D. and Manfred A. for prompting this improvement.
- [FIXED in Pro] Security >> CAPTCHA Protection: ALTCHA verification now works when Password Protection or Maintenance Mode is enabled.
- [IMPROVED and FIXED in Pro] Utilities >> Site Backup and Migration:
- Sync now refreshes destination term post counts after scoped posts sync, so terms no longer keep a stale pre-sync count. Props to David M.C. for prompting this improvement.
- Fix high-compatibility mode returning "database.sql was never confirmed" error. Props to Curt M. for reporting the issue.
- Made some changes so that class-site-backup-admin.php will not trigger false positives with malware scanners. Props to Craig L., John C., Oliver S., Tiago P., Andrew W. and Bent F. for reporting the issue.
- [FIXED in Pro] Content Management >> Custom Content Types: Fixed a fatal PHP error that can occur in a certain scenario involving Elementor and deleting a post meta. Props to George N. for reporting the issue.
- [FIXED in Pro] Custom Code >> Code Snippets Manager: On new snippet screen, keep the keyboard focus on the title input field, not on the code editor. Props to Ole P. for reporting the issue.
- [TRANSLATION in Free and Pro] ASE is now being translated into 38 languages:
- Added new/improved translationfor:
- ASE Free: Updated Spanish (Spain), Spanish (Chile), Slovak, Serbian, Portuguese (Brazil), Indonesian, Norwegian, Dutch (Netherlands), Chinese (Taiwan).
- ASE Pro: Updated Norwegian, Portuguese (Brazil).
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.2 Nulled
= 9.1.2 (2026.09.14) - ASE Free and Pro
- [IMPROVED in Free and Pro] Security Hardening: Various changes were made to harden the security of the following modules: SVG Upload, AVIF Upload, Admin Menu Organizer, Limit Login Attempts, Custom Admin / Frontend CSS, Insert <head>, <body> and <footer> Code, Obfuscate Author Slugs, Email Delivery, Contact Form, Password Protection, Maintenance Mode.
- [IMPROVED in Free and Pro] Utilities >> Password Protection:
- REST API (/wp-json/...) and admin-ajax.php are now gated by the password protection. Only after a valid password is entered, will these become accessible again.
- Added rate-limiting for wrong password guesses (about 5 tries/ 10 minutes per IP)
- Unlock cookies are now HttpOnly and Secure on HTTPS, so they are not readable by frontend JS and are not sent over HTTP.
- Site Backup and Migration loopback workers (HMAC-authenticated admin-ajax actions and the REST backup/worker route) are excluded from the gate so server-side backup operations can run.
- [IMPROVED in Free and Pro] Utilities >> Maintenance Mode:
- REST API (/wp-josn/...), admin-ajax.php and XML-RPC now returns 503 HTTP response ("This site is currently under maintenance") when maintenance mode is enabled.
- Site Backup and Migration loopback workers (HMAC-authenticated admin-ajax actions and the REST backup/worker route) are excluded from the gate so server-side backup operations can run.
- [IMPROVED in Free and Pro] Utilities >> Contact Form: Added submission retention period settings inside "Advanced Settings", including a "Do not store" option that still sends notification emails. The default is "Forever".
- [FIXED in Free] Optimizations >> Image Upload Control: Fixed a regression introduced in v9.1.1 that causes transparent PNGs to be converted to JPG when WebP conversion is not enabled. Props to Richard S. and Brady M. for reporting the issue.
- [FIXED and IMPROVED in Pro] Content Management >> Media Replacement:
- Fixed serialized postmeta corruption during media replacement in pages/posts handled by page builders, e.g. Bricks builder. Props to Michael L. and Katrine K. for reporting the issue in great detail.
- [FIXED and Improved in Pro] Utilities >> Site Backup and Migration:
- Improved the reliability of backup, restore and migrate operations in localhost sites, specifically WordPress Studio sites. Props to Matija S. for prompting this improvement.
- Fix restore/migration fatals from Composer autoload by extracting each plugin off to the side and replacing the live folder only after that plugin is fully extracted. Props to Nils L. for reporting the issue in detail and facilitating the troubleshooting process.
- Fixed runaway wp-cron.php processes that can occur in a specific scenario, which can cause consistently high CPU load and PHP fatal error. Props to Bram C. for reporting the issue in detail.
- [FIXED in Pro] Custom Code >> Code Snippets Manager:
- Fixed an error in Breakdance builder preview caused by a code snippet post being the selected post for doing the preview. Code snippet posts now are registered with "public => false". Props to Christian S. for reporting the error and facilitating the troubleshooting process.
- Fixed vertical alignment issues in the snippets listing page. Props to Nils L. for reporting the issue in detail.
- [TRANSLATION in Free and Pro] ASE is now being translated into 38 languages:
- Added new/improved translationfor:
- ASE Free: Updated Spanish (Spain), Portuguese (Brazil), Polish, Norwegian, Dutch (Netherlands), Chinese (Taiwan)
- ASE Pro: Updated Czech, Portuguese (Brazil)
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.1.1 Nulled
### 9.1.1 (2026.09.07) - ASE Free and Pro
* **[IMPROVED in Free and Pro] Optimizations >> Image Upload Control**: add compatibility with [client-side media processing](https://make.wordpress.org/core/2026/07/22/client-side-media-processing-in-wordpress-7-1/) for block editor uploads in WP 7.1+. This shows up as a new checkbox option in the module's settings, that if unchecked, will turn that processing off and use the server-side processing (GD or Imagick). Props @visedfaq for prompting this improvement.
* **[IMPROVED in Pro] Security >> Email Address Obfuscator**: auto-obfuscation of email addresses in post content now also applies to Bricks builder elements (Basic Text, Rich Text, Heading, and other text-outputting elements). Props to Patric S. for prompting this improvement.
* **[IMPROVED in Pro] Utilities >> Site Backup and Migration**:
* Added the ability to sync posts and the associated data (attachments/images, taxonomy terms, revisions, along with the configuration for custom post type, custom taxonomies and custom field groups). Currently supports four providers: WP Core (pages, posts), ASE, ACF and Meta Box.
* Added a mechanism to automatically clean up leftover, sensitive DB runner scripts from restore and migration operations. An admin notice will also be shown if such leftover scripts are found before the scheduled clean up runs, which has a button to perform manual clean up. Props to Leigh H. for prompting this improvement.
* Added a mechanism to prevent leftover database tables with `wp_` prefix from overwriting database tables during migration on the destination site. Props to Uli L. for prompting the improvement.
* **[FIXED in Pro] Security >> CAPTCHA Protection**: fixed a regression introduced in v9.0.1 that causes fail-open bypasses via crafted POST requests. Props to Kenny D. and John E. for reporting two inter-related issues.
* **[TRANSLATION in Free and Pro]** ASE is now being translated into [38 languages](https://translate.wpase.com/):
* **Added new/improved translation** for:
* ASE Free: Updated Spanish, Slovak, Portuguese (Brazil), Polish, Persian, Norwegian, Italian, German (Formal), Dutch (Netherlands), Chinese (Taiwan)
* ASE Pro: Updated Polish
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.1 Nulled
* **[IMPROVED in Free and Pro] Optimizations >> Image Upload Control**: add compatibility with [client-side media processing](https://make.wordpress.org/core/2026/07/22/client-side-media-processing-in-wordpress-7-1/) for block editor uploads in WP 7.1+. This shows up as a new checkbox option in the module's settings, that if unchecked, will turn that processing off and use the server-side processing (GD or Imagick). Props @visedfaq for prompting this improvement.
* **[IMPROVED in Pro] Security >> Email Address Obfuscator**: auto-obfuscation of email addresses in post content now also applies to Bricks builder elements (Basic Text, Rich Text, Heading, and other text-outputting elements). Props to Patric S. for prompting this improvement.
* **[IMPROVED in Pro] Utilities >> Site Backup and Migration**:
* Added the ability to sync posts and the associated data (attachments/images, taxonomy terms, revisions, along with the configuration for custom post type, custom taxonomies and custom field groups). Currently supports four providers: WP Core (pages, posts), ASE, ACF and Meta Box.
* Added a mechanism to automatically clean up leftover, sensitive DB runner scripts from restore and migration operations. An admin notice will also be shown if such leftover scripts are found before the scheduled clean up runs, which has a button to perform manual clean up. Props to Leigh H. for prompting this improvement.
* Added a mechanism to prevent leftover database tables with `wp_` prefix from overwriting database tables during migration on the destination site. Props to Uli L. for prompting the improvement.
* **[FIXED in Pro] Security >> CAPTCHA Protection**: fixed a regression introduced in v9.0.1 that causes fail-open bypasses via crafted POST requests. Props to Kenny D. and John E. for reporting two inter-related issues.
* **[TRANSLATION in Free and Pro]** ASE is now being translated into [38 languages](https://translate.wpase.com/):
* **Added new/improved translation** for:
* ASE Free: Updated Spanish, Slovak, Portuguese (Brazil), Polish, Persian, Norwegian, Italian, German (Formal), Dutch (Netherlands), Chinese (Taiwan)
* ASE Pro: Updated Polish
Decryption key:
Admin and Site Enhancements (ASE) Pro v9.1.0 Nulled
= 9.1.0 (2026.08.31) - ASE Free and Pro
- [ADDED in Free and Pro] Security >> Password Policy: enforce a minimum length and optional complexity rules (uppercase, lowercase, digits, special characters, unique characters) when users register, reset, or update their password. Props to Francois G., David M.C. and Marv D. for prompting this addition.
- [FIXED in Free and Pro] Admin Interface >> Wider Admin Menu:
- [FIXED in Free and Pro] Admin Interface >> Admin Menu Organizer: Sticky "Collapse Menu" now works in SureCart Products page. Props to Kenneth S. for reporting the issue in details (with screenshots).
- [IMPROVED in Pro] Utilities >> Display System Summary: Added async, background process with cron fallback to calculate the various directory / component sizes. This helps prevents slow down / time out / critical error when opening the dashboard of a very large site. Props to Carsten D. for prompting this improvement.
- [IMPROVED in Pro] Security >> CAPTCHA Protection: Site and secret keys will now be obfuscated in the module settings and in HTML. Props to Matt D. for prompting this improvement.
- [TRANSLATION in Free and Pro] ASE is now being translated into 38 languages:
- Added new/improved translationfor:
- ASE Free: Updated Spanish (Spain), Portuguese (Brazil), Polish, Norwegian, German (Formal), Dutch (Netherlands)
- ASE Pro: Updated Indonesian, Portuguese (Brazil), Polish
Admin and Site Enhancements (ASE) Pro v9.0.2 Nulled
= 9.0.2 (2026.08.24) - ASE Free and Pro
- [IMPROVED in Free and Pro] Disable Components >> Disable Smaller Components >> Disable the plugin and theme editor: this now detects existing DISALLOW_FILE_EDIT definition in wp-config.php, and when it's already set to true, will disable the checkbox/feature and show a warning note to manage the value directly in wp-config.php. Props to Diiamo for reporting this in detail.
- [IMPROVED in Free and Pro] Custom Code >> Manage ads.txt and app-ads.txt: replaced $_SERVER['SERVER_NAME'] with site_url(), which is more reliable to construct URL structure for validating ads.txt content. Props to @robman87 for reporting this along with the code improvement.
- [FIXED and IMPROVED in Free and Pro] Security >> Limit Login Attempts: add compatibility with login from WPEngine by lengthening username and request_uri columns in the database. Props to Adam H. for reporting the issue along with suggestions for the fix.
- [FIXED in Free and Pro] ASE Settings: Added a mechanism to prevent other plugins from loading TinyMCE plugins in ASE Settings page, which is not needed and may cause a Javascript error when an adblocker is active in the browser.
- [IMPROVED in Pro] Content Management >> Media Replacement: implement advanced replacement process that will also replace references to the media file, including image sub-sizes (thumbnail, medium, etc.), in post content across all post types and also in wp_options table (widgets, customizer). This new replacement process allows for replacemeng using a different file type, e.g. JPG with WEBP, DOC with PDF, etc. A replacement confirmation screen is presented upon clicking "Perform Replacement", that will provide an overview of current media (and relevant file(s)), replacement media (and relevant file(s)) and content that use the media. Props to Jake H., Filip, @betaplus and Rodlens H. for prompting this improvement.
- [IMPROVED in Pro] Custom Code >> Code Snippets Manager:
- Fixed a bug with older PHP snippets where in a certain scenario, the code execution settings is / remains empty and do not fallback to the correct default, especially when active code snippets tree is being rebuilt during saving of a / another snippet. This may cause the snippet to stop being executed. Props to Nils L. for reporting the issue in detail and facilitating the troubleshooting process.
- Added more hook options for PHP snippets: wp_enqueue_scripts, admin_enqueue_scripts and enqueue_block_assets. Props to Stijn V. for prompting this improvement.
- [FIXED in Pro] Activation: Fixed a fatal error caused by the dreamhost-panel-login.php single-file plugin that interferes with wordpress.org plugins update-check API during ASE Pro activation. Props to Espo D. for reporting the issue and facilitating the troubleshooting process.
- [FIXED in Pro] Content Management >> Custom Content Types >> Custom Field Groups:
- Added an improved fix for WPML integration when translating repeater field row/sub-field values. Props to Stijn V. for the continued reporting and testing of this issue.
- Fixed an issue where certain post types are not being listed as eligible post types to relate to in a relationship field. Props to Paul R. for reporting the issue in detail and facilitating the troubleshooting process.
- Fixed slow query issues related to WPML integration. Props to Stijn V. for reporting the issue with screenshots.
- [FIXED in Pro] Utilities >> Site Backup and Migration: Fixed an issue where administrator is being locked out on the destination site once a migration operation has completed. This can occur in a certain scenario where the database table prefix is different between the two sites where the source site uses wp_ prefix.
- [TRANSLATION in Free and Pro] ASE is now being translated into 38 languages:
- Added new/improved translationfor:
- ASE Free: Updated Portuguese (Brazil), Polish, Norwegian, German (Formal), Dutch (Netherlands)
- ASE Pro: Updated Portuguese (Brazil), Indonesian.
Admin and Site Enhancements (ASE) Pro v9.0.1 Nulled
### 9.0.1 (2026.08.17) - ASE Free and Pro
* **[SECURITY FIX in Free and Pro] Content Management >> SVG Upload**:
* Fixed a bypass of the CVE-2025-9487 Stored XSS fix in v7.9.8, where a user with SVG upload privilege could store an unsanitised SVG via XML-RPC by supplying a `post_id` they cannot edit. The request still returns 401, but the file is sanitized before that capability check. Props to Mohammed Abd Alrahman for responsibly disclosing the vulnerability via WPScan Security.
* SVG sanitizer exceptions are now caught and failed destination files, which may be script-bearing and served as image/svg+xml, are deleted instead of remaining on disk. Props WPScan Security for the responsible disclosure.
* **[IMPROVED in Free] Admin Interface >> Admin Menu Organizer**: added a "Reset Menu" link/feature that let's you start fresh.
* **[IMPROVED in Free and Pro] Utilities >> Contact Form**: added form styling customization options which includes layout (default vs stacked), label position (left vs right), field style (box vs underline), color scheme (dark vs light), button position (left vs right) and button color.
* **[FIXED in Free and Pro] Log In/Out | Register >> Login ID Type**: fixed a conflict with Wordfence 9.0.0 new passkey authentication when Login ID Type is set to "Email address only", which caused passkey authentication error, i.e. failed login. Props to Maan D. for reporting the issue and proposing the code fix that this fix is based on.
* **[IMPROVED in Pro] Utilities >> Site Backup and Migration**: allow custom start date selection when backup policy uses "Once every 2 weeks", "Once every week" or "Once every 3 days" frequencies. Props to Benjamin N. for prompting this improvement.
* **[IMPROVED in Pro] Utilities >> File Manager**: when compressing a single folder or a single file, the folder/file name will now be used for the resulting archive/zip file.
* **[IMPROVED in Pro] Security >> Two-Factor Authentication (2FA)**: when using `two_factor_token_email_message` filter hook, you can now use HTML and it will be rendered as such, not as raw HTML. The outgoing email now is sent with the 'Content-Type: text/html; charset=UTF-8' header by default. Props to Jayron C. for prompting this improvement.
* **[FIXED and IMPROVED in Pro] Security >> CAPTCHA Protection**:
* Fixed a conflict with plugins that combines javascript files, e.g. SiteGround Speed Optimizer, when ALTCHA is enabled. This, for example, caused the ALTCHA widget to not render and function properly on the login screen/form at wp-login.php, and ended up blocking first-round login attempts. Props to Jenny L. for reporting the isssue and facilitating the troubleshooting process.
* Turnstile, reCAPTCHA and ALTCHA widgets now only verifies ASE’s own WordPress login, password-reset, and registration forms, so third-party forms that reuse the same CAPTCHA fields are no longer double-verified or blocked. Props to Tony B. for reporting the issue in detail along with proposing spot-on solutions.
* **[TRANSLATION in Free and Pro]** ASE is now being translated into [38 languages](https://translate.wpase.com/):
* **Added new/improved translation** for:
* ASE Free: Updated Swedish, Spanish (Spain), Spanish (Chile), Portuguese (Brazil), Polish, Norwegian, German (Formal), Dutch, Chinese (Taiwan).
* ASE Pro: Updated Polish.