Security: Geo-location transients are now only created for valid, publicly routable IP addresses. Private, reserved, and localhost IP addresses are resolved as “Local Network” without writing a transient, preventing any transient-flooding vector via spoofed request headers.
Improvement: Reduced geo-location transient lifetime from 24 hours to 12 hours, limiting stale cache exposure while preserving the lookup-reduction benefit.
Compliance: Updated ipwho.is and freeipapi.com third-party legal URLs to their current canonical forms in the readme.
1.0.0
Initial public release.
Session limiting per user with configurable limit.
Login history tracking (up to 50 records per user).
IP address logging on each login event.
Location detection via free public geo-IP APIs (ipapi.co, ipwho.is, freeipapi.com, ip-api.com).