=== Assist Security ===
Contributors: assistpress
Tags: security, security keys, salts, wp-config, session
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 0.1.2
License: GPL v2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Rotate your WordPress security keys and salts safely, with verified atomic writes, key health checks, and a full audit trail.

== Description ==

WordPress signs every login cookie and nonce with eight secret keys and salts stored in `wp-config.php` (`AUTH_KEY` through `NONCE_SALT`). If those secrets leak — through an old backup, a stolen config file, or a contractor who still has access — an attacker can forge valid authentication cookies for as long as the keys stay unchanged. Rotating them invalidates every existing session immediately.

Assist Security makes that rotation safe, automatic, and auditable.

= 🔑 Rotate Security Keys =

* **One-click rotation** from a clean, colorful settings screen
* **Locally generated keys** using PHP's cryptographically secure random number generator. No calls to any external API, no network dependency
* **Verified atomic writes.** The new configuration is built in memory, written to a temporary file with restricted permissions, verified, atomically swapped in, then verified again — with automatic rollback if any step fails. The writer refuses to touch your file unless all eight keys are found, so a partial rotation is impossible
* **Key health checks** for missing, weak, duplicated, or placeholder keys. Only the verdict is ever shown; your key values never leave the server
* **Audit log** recording every attempt: timestamp, result, trigger, user, optional IP, duration, and how many sessions were signed out — with filtering, pagination, and CSV export
* **Failure alerts** emailed to the site administrator if a rotation ever fails
* **Site Health test** that flags key problems and keys older than 180 days
* **WP-CLI commands** — `wp assist-security rotate` and `wp assist-security status`
* **Custom config locations** supported: `wp-salt.php`, a `wp-config.php` above the web root, or any path you choose with a filter

= Built the right way =

* Beautiful, responsive settings screen with no page reloads and no build step
* REST API under `assist-security/v1`; no admin-ajax
* No bundled SDKs, no Composer dependencies, no external HTTP requests, no telemetry
* Every input sanitized, every output escaped, every query prepared
* Multisite aware: management is restricted to network administrators
* Privacy-conscious: IP logging is optional and data removal on uninstall is opt-in
* Settings import and export as JSON
* Fully translatable, with a bundled POT file

Assist Security is built on a module architecture, so further protections can be added as self-contained modules in future releases.

== Installation ==

1. Upload the `assist-security` folder to `/wp-content/plugins/`, or install it through **Plugins → Add New**.
2. Activate **Assist Security** from the Plugins screen.
3. Open the new **Assist Security** menu in your admin sidebar.
4. Check your key health on the Security Keys tab and rotate whenever you need to.

**Note:** rotating the keys signs out every user, including you. The plugin warns you first and sends you to the login screen afterwards.

For rotation to work, `wp-config.php` (or your custom salt file) must be writable by PHP. The Security Keys tab and Site Health both report this.

== Frequently Asked Questions ==

= Will rotating the keys break my site? =

No. The writer refuses to modify your configuration file unless all eight keys are found, verifies the result before and after an atomic swap, and rolls back automatically if anything is wrong. If a rotation cannot complete safely, your original file is left untouched.

= Why is everyone logged out afterwards? =

That is the point. Invalidating existing cookies is what makes rotation a security measure. Session tokens are cleared as well.

= Where do the new keys come from? =

They are generated on your own server with PHP's cryptographically secure random number generator. The plugin makes no external requests.

= Does the plugin ever show or send my keys? =

No. Key values are never displayed, logged, exported, or transmitted. The health check reads each constant only long enough to decide whether it is missing, weak, or duplicated, and reports that verdict alone.

= My wp-config.php is outside the web root, or I use wp-salt.php. Is that supported? =

Yes. The plugin checks `wp-salt.php`, `wp-config.php`, and the parent directory automatically. You can also point it anywhere:

`add_filter( 'assist_security_config_file', function () { return '/path/to/wp-salt.php'; } );`

= Is it multisite compatible? =

Yes. On multisite, only network administrators (`manage_network_options`) can manage the plugin.

= How often should I rotate? =

Every one to three months suits most sites. Rotate immediately if you suspect a leak, after removing an administrator, or after restoring from a backup of unknown origin. The Site Health test reminds you once your keys pass 180 days.

= What data does the plugin store? =

Settings in a single option, and rotation records in its own database table. IP addresses are recorded only if you enable that option. Everything is removed on uninstall only if you opt in first, on the Tools tab.

== Screenshots ==

1. The dashboard, with protection status at a glance.
2. Key health and one-click rotation on the Security Keys tab.
3. The rotation activity log with filtering and CSV export.
4. Data, privacy, import and export settings.

== Changelog ==

= 0.1 =
* Initial release.

== Upgrade Notice ==

= 0.1 =
* Initial release.
