FIXED: Public Shield Screens Hardened
Shield now rejects unsafe attempts to load internal screens from public routes while preserving legitimate block pages, report views, MainWP flows, and MFA login screens. MFA login messages are treated as plain text, reducing the risk of untrusted content appearing in sensitive login flows.
FIXED: Report Access Hardened
Stored security reports now open through an authenticated Shield admin page, so report content is only shown after the proper admin...