=== ACH Stored Payload Audit ===
Contributors: aiutocomputerhelp
Tags: security, malware, database, audit, xss
Requires at least: 6.2
Requires PHP: 7.4
Tested up to: 7.1
Stable tag: 1.2.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Read-only scan of selected WordPress database tables for possible stored XSS indicators, with safe plain-text inspection of flagged values.

== Description ==

ACH Stored Payload Audit scans existing text fields in database tables belonging to the current site's WordPress table prefix. Select all site tables, an entire detected table-name group, or individual tables. The scanner looks for potential stored XSS indicators and common encodings, then shows a table, record identifier, column, and matched rule. A separate View content action retrieves flagged cell text on demand and displays it as plain text, never HTML. For publicly viewable WordPress posts, an optional Open page link is supplied with a warning.

WordPress post revisions remain in scope. Findings in revisions are labeled with their parent post ID (for example, "Revision of post #7") so a stored historical copy is not confused with a second distinct attack.

The tool is intended for manual investigation, not automatic malware removal. A matched rule is not proof of compromise or script execution. Legitimate posts about web security and active HTML content can generate false positives. Well-formed, benign JSON-LD script blocks and strictly validated WordPress and YouTube oEmbed cache markup are ignored. YouTube exemptions apply only to normal oEmbed cache entries with fully validated iframe markup. Unfamiliar or suspicious iframes remain in scope.

The plugin does not block incoming HTTP requests, modify database records, save audit reports, or send data to external services. Scan results remain in the current browser tab. Administrator access (manage_options) and a WordPress AJAX nonce are required to scan and view flagged text. Scanned database content may contain private data. Use a trusted administrative browser session and do not share sensitive findings in public reports.

Only tables with the currently configured site's table prefix are eligible, not arbitrary databases or separately prefixed WordPress installations. Multi-site installations are audited one site at a time.

== Installation ==

1. Install and activate the plugin.
2. Navigate to Tools > ACH Payload Audit.
3. Choose "All tables with this site's WordPress prefix" or "Choose table groups or individual tables".
4. For a first scan, use the default 10,000-row limit, or reduce it to 1,000. The unlimited option may be resource-intensive.
5. Inspect flagged values using View content before visiting a potentially compromised public page.

If an unexpected PHP error blocks administration, rename wp-content/plugins/ach-stored-payload-audit via FTP to disable the plugin.

== Frequently Asked Questions ==

= Does the plugin delete suspicious content? =

No. It only reads database rows and does not write to the database.

= Does a finding prove my site is vulnerable? =

No. Every finding requires manual contextual review. A harmless code sample may match the same indicators as a malicious injected payload.

= Does the plugin scan every byte of every cell? =

No. Only the first 32,768 characters of eligible text fields are scanned. Binary data and tables using other prefixes are excluded. The results view shows up to 500 findings, while the total count continues.

= Can the scan affect performance? =

Yes. It issues database reads in batches of up to 25 rows per request. On very large tables, scanning may consume server resources. Prefer a limited first scan and a database backup.

== Privacy ==

The plugin does not transmit data to the developer or third-party services, register visitors, create its own persistent audit log, or store scan findings on the server. It retrieves matching database content only when an authorized administrator requests the View content preview. The WordPress administrator's browser temporarily holds the results during the current page session. Avoid sharing screenshots or previews that contain personal information or secrets.

== Languages ==

The administration interface is written in English and prepared for translation through the ach-stored-payload-audit text domain. A translation template is provided in languages/; WordPress.org language packs can be used once the plugin is published.

== Changelog ==

= 1.2.0 =
* Prepare administration labels, notices, AJAX messages and JavaScript findings for WordPress gettext translations.
* Keep detection rules and scanner query logic unchanged from 1.1.5.
* Use a distinct ACHSTPAA prefix for the plugin class, AJAX actions, nonce, JavaScript configuration and internal identifiers following Plugins Team feedback.
* Refine readme and privacy documentation for the WordPress.org submission process.


= 1.1.5 =
* Reduce false positives for strictly validated YouTube iframe embeds in WordPress oEmbed cache metadata.
* Keep unexpected iframe attributes, modified destinations, extra markup and encoded XSS indicators visible for review.

= 1.1.4 =
* Reduce false positives for strictly validated same-site WordPress oEmbed cache markup in wp_postmeta.
* Keep suspicious oEmbed records, unknown iframes, other domains, and additional encoded XSS indicators visible.

= 1.1.3 =
* Label findings from WordPress post revisions with the parent post ID without excluding historical content or changing finding counts.
* Show revision context in the plain-text inspection dialog.

= 1.1.2 =
* Document narrowly scoped exceptions for justified read-only SQL metadata and scan queries reported by static analysis. No change to detection rules or scan behavior.

= 1.1.1 =
* Harden database queries using WordPress identifier placeholders and validate submitted scan parameters.
* Document read-only database access for review; add the required WordPress.org readme header.

= 1.1.0 =
* Select all current-site tables or choose individual tables and table-name groups.
* Removed the WP Statistics-specific scan preset; the plugin works with any eligible site's table.
* Added standard WordPress.org readme metadata.

= 1.0.2 =
* English administration interface and read-only plain-text inspection of flagged cells.
* Optional warning before opening a published, public WordPress page.

= 1.0.1 =
* Reduce false positives for valid, benign Schema.org JSON-LD data.
