=== Cybexsoft Shield ===
Contributors: rahul1099
Tags: security, login security, brute force, activity log, hardening
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv3 or later
License URI: https://www.gnu.org/licenses/gpl-3.0.html

WordPress security in one place: login protection, file integrity, hardening, server audit and an activity log.

== Description ==

Cybexsoft Shield protects the login form, watches your files and settings, and shows you what it found in one dashboard.

**Login protection**

* Limit login attempts, with per-account lockout for distributed attacks
* CAPTCHA — Google reCAPTCHA v2/v3, Cloudflare Turnstile or a built-in challenge — on login, registration, lost password, comments, WooCommerce and Contact Form 7, plus a `[cybex_shield_captcha]` shortcode
* An invisible honeypot field that stops bots with no puzzle for people
* IP block and allow lists, temporary and permanent bans, and rules that ban 404 scanners, known attack tools and XML-RPC abuse
* A blocked page with a reference code, and a way for real people to unblock themselves by email
* Custom login URL, with an emergency recovery link

**Sessions & passwords**

* Password rules, including a Have I Been Pwned check that never sends the password and blocking the last five passwords
* See and end every signed-in session; limit sessions per user; idle timeout and maximum session length
* Email alert when an account signs in from a new device
* A Security section on each user's profile with their sessions and devices

**Site scanning**

* File integrity: WordPress core and WordPress.org plugins against official checksums, themes against their first scan, and code hidden in uploads
* Restore the official copy, quarantine, or view a line-by-line diff
* Plugin and theme health: updates, auto-update policy, and plugins closed or abandoned on WordPress.org
* Optional Google Safe Browsing check

**Hardening, server & SSL**

* Hardening switches: file editor, PHP in uploads, directory listing, wp-config.php permissions, XML-RPC, pingbacks, user enumeration, REST API for visitors, version number, the "admin" username, application passwords. Nothing is switched on until you choose, and one button turns on the safe set.
* One-time actions: rotate security keys, change the table prefix, force a password reset. Shield's settings are snapshotted first, and wp-config.php is backed up before it is edited.
* Server audit of PHP settings, file permissions and ownership, with the exact line or command to fix each problem
* SSL certificate check with expiry emails, force HTTPS once HTTPS works, security headers, and a mixed-content check

**Activity log & overview**

* An activity log of sign-ins, account and role changes, application passwords, plugin, theme and WordPress installs and updates, changes to key site settings and to Shield's own settings, and everything Shield refused
* Filter by type, user, severity and period, search by name or IP address, and export exactly what is shown as CSV
* A security score built from checks you can see — each recommendation says what it is worth and links to the fix
* Fourteen days of threat activity, figures for blocked addresses, altered core files, waiting updates and failed sign-ins, and one-click switches for each protection
* A Dashboard widget, and a Shield item in the admin bar with your security score and a count when something needs your attention
* Country for every logged address, from Cloudflare or a free MaxMind GeoLite2 database on your own server

**Privacy**

* Shield's records are included in WordPress's Export Personal Data and Erase Personal Data tools
* Suggested wording for your privacy policy, reflecting your own retention settings
* Optionally shorten IP addresses (203.0.113.0) and drop browser strings once events are older than a few days
* No address is sent to any outside service to find its country

**Recovery**

If a protection ever locks you out:

* Add `define( 'CYBEX_SHIELD_SAFE_MODE', true );` to wp-config.php. Every protection that can stand between you and your site is suspended; logging and the settings screens keep working so you can fix the cause.
* Or, with shell access, use WP-CLI: `wp shield disable <module>`, `wp shield unblock <ip>`, `wp shield allow <ip>`.

**WP-CLI**

* `wp shield status` — version, licence, safe mode and every module's state
* `wp shield modules`, `wp shield enable <module>`, `wp shield disable <module>`
* `wp shield unblock <ip>`, `wp shield allow <ip> [--label=<label>]`
* `wp shield logout <user>`, `wp shield logout --all`
* `wp shield scan`
* `wp shield settings get|set|reset|export|import`
* `wp shield license status|activate|deactivate|refresh`
* `wp shield login-url show|reset|recovery`

**Pro** (sold separately, delivered as an add-on plugin)

Two-factor authentication with passkeys, a firewall that can start before WordPress loads, rate limiting and crawler control, geo-blocking, server rules for Apache and nginx, a malware scanner, and governance tools: a tamper-evident audit trail of Shield's settings, access levels and two-administrator approval, alerts to Slack, Teams, PagerDuty, syslog and webhooks, PDF reports, configuration profiles and a compliance map. The free plugin never needs Pro, and nothing in it is disabled or time-limited. See https://cybexsoft.com/products/cybexsoft-shield for plans.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/cybexsoft-shield`, or install it from the Plugins screen.
2. Activate it.

Shield works out where visitor IP addresses come from the first time you open its dashboard: straight from visitors, through Cloudflare, or through your host's own proxy. It only trusts a proxy it can verify from the connection itself. If it cannot tell (another CDN, for example), the setup wizard asks, and you can always change it under Settings.

== Frequently Asked Questions ==

= Does it work on multisite? =

Yes. Each site keeps its own settings, logs and block lists, and is configured by its own administrator.

= How do I see which country an address is from? =

Behind Cloudflare, Shield reads it from Cloudflare's header. Anywhere else, download the free GeoLite2 City or Country database from MaxMind, put the .mmdb file somewhere on the server outside the web root, and enter its path under Settings → Visitor location. Lookups happen on your server.

= What personal data does Shield store? =

For each security event: the time, IP address, country (when known), browser user-agent and — for sign-ins — the account or username involved. It is kept for the number of days set under Settings (30 by default). Shield's records are included in WordPress's personal-data export and erasure tools.

= What happens to my data if I delete the plugin? =

It is kept, unless you switch on "Delete all data when the plugin is deleted" under Settings. Deactivating never removes anything.

== Screenshots ==

1. Security overview: a score built from checks you can see, what to fix next and what each fix is worth, fourteen days of threat activity, and a switch for every protection.
2. Activity log: sign-ins, account, plugin and settings changes and everything Shield refused, with filters, search and CSV export.
3. Login attempts: brute-force limits, with failed sign-ins, lockouts and the account names being tried.
4. IP blocking: block and allow lists, temporary and permanent bans, and where attacks come from.
5. Sessions & passwords: password rules with a breached-password check, and every signed-in device.

== External services ==

Cybexsoft Shield contacts the services below only for the features that need them. Every one is optional; the default CAPTCHA is Shield's own built-in challenge, which contacts nobody, and country lookups use a database on your own server. No visitor data is sent anywhere unless you switch on one of these features.

= Google reCAPTCHA =

Used only if you choose "Google reCAPTCHA" as the CAPTCHA provider under Shield → CAPTCHA and enter your own keys.

The forms you protect then load a script from google.com, and Google receives each visitor's IP address, browser and device information, and their interaction with the challenge — including visitors who never submit the form. When a form is submitted, Shield sends the challenge token, your secret key and the visitor's IP address to Google to check the answer.

Service provided by Google: [terms of service](https://policies.google.com/terms), [privacy policy](https://policies.google.com/privacy).

= Cloudflare Turnstile =

Used only if you choose "Cloudflare Turnstile" as the CAPTCHA provider under Shield → CAPTCHA and enter your own keys.

The forms you protect then load a script from challenges.cloudflare.com, and Cloudflare receives each visitor's IP address, browser and device information, and their interaction with the challenge. When a form is submitted, Shield sends the challenge token, your secret key and the visitor's IP address to Cloudflare to check the answer.

Service provided by Cloudflare: [terms of service](https://www.cloudflare.com/website-terms/), [privacy policy](https://www.cloudflare.com/privacypolicy/).

= Have I Been Pwned (Pwned Passwords) =

Used only if password rules are switched on under Shield → Sessions & passwords with "Not found in known data breaches" selected.

When a password is set or changed, and at most once a month when someone signs in, Shield hashes the password with SHA-1 on your server and sends only the first five characters of that hash to `https://api.pwnedpasswords.com`. The password itself never leaves your server, and the answer is compared locally. If the service cannot be reached, the check is skipped.

Service provided by Have I Been Pwned: [acceptable use](https://haveibeenpwned.com/API/v3#AcceptableUse), [privacy policy](https://haveibeenpwned.com/Privacy).

= Google Safe Browsing =

Used only if you enter a Google Safe Browsing API key under Shield → Settings.

Once a day, Shield sends your site's home address and your API key to `https://safebrowsing.googleapis.com` to ask whether Google is warning visitors away from the site. No visitor data is sent.

Service provided by Google: [terms of service](https://developers.google.com/terms), [privacy policy](https://policies.google.com/privacy).

= WordPress.org =

Used by the file integrity scan and Plugin & theme health, which are on by default.

Shield asks api.wordpress.org and downloads.wordpress.org for the official checksums of your WordPress version and of plugins hosted on WordPress.org, and for public information about those plugins (whether they are still listed, when they were last updated). When you choose to restore a file, its official copy is downloaded from core.svn.wordpress.org or plugins.svn.wordpress.org. Each request names only the WordPress version, locale, plugin slug and version concerned.

Service provided by WordPress.org: [privacy policy](https://wordpress.org/about/privacy/).

= Cybexsoft licence server =

Used only if you have bought the Pro add-on and enter a licence key under Shield → Licence.

Your licence key and your site's home address are sent to `https://cybexsoft.com/api/licenses` when you activate or deactivate the key, and once a day afterwards to confirm it is still valid. Nothing is sent while no licence key is stored, which is the case on every free install.

Service provided by Cybexsoft: [terms of service](https://cybexsoft.com/terms-of-service), [privacy policy](https://cybexsoft.com/privacy-policy).

== Third-party code ==

The plugin is distributed under the GNU General Public License, version 3 or later. Version 3 rather than 2, because it includes code under the Apache License 2.0, which is compatible with GPLv3 but not with GPLv2.

* **MaxMind-DB-Reader-php** — Copyright (c) MaxMind, Inc., Apache License 2.0. Portions of the .mmdb reader in `includes/class-cybex-shield-mmdb-reader.php` are derived from it, in modified form. No MaxMind database is bundled; you supply your own, and it stays subject to MaxMind's terms. MaxMind and GeoLite are trademarks of MaxMind, Inc.; this plugin is not affiliated with or endorsed by them.
* **Public Sans** and **Space Grotesk** — SIL Open Font License 1.1, served from this plugin rather than a font CDN, so no administrator's IP address is handed to a third party when the dashboard loads.

Full notices are in the `NOTICE` file, and the licence itself in `LICENSE.txt`.

== Changelog ==

= 1.0.0 =
* Initial release.
* Login protection: login attempt limits with per-account lockout, CAPTCHA (built-in, reCAPTCHA or Turnstile) on WordPress, WooCommerce and Contact Form 7 forms, a honeypot field, IP block and allow lists with automatic bans, a blocked page with self-unblock, and a custom login URL with a recovery link.
* Sessions & passwords: password rules with a breached-password check, a list of every session with sign-out, session limits and timeouts, new-device alerts, and a Security section on each profile.
* Site scanning: file integrity against official checksums with restore, quarantine and a diff view; plugin and theme health; an optional Safe Browsing check.
* Hardening switches, one-time actions with settings snapshots, a server audit that says how to fix each problem, and SSL and security-header checks.
* An activity log with filters, search and CSV export; a security score with recommendations; a Dashboard widget and an admin-bar item with the score and open notifications; country lookups from Cloudflare or your own GeoLite2 database.
* Privacy: personal-data export and erasure, suggested privacy-policy text, and optional IP shortening.
* Safe mode and WP-CLI commands for getting back in if a protection locks you out.
* Six colour themes for Shield's screens on their own Appearance page (Harbor Navy, Deep Ocean, Evergreen, Merlot, Ivory & Ink, Mist), the same as Cybexsoft AI's, or your own primary and accent colours; the accent also lines the top of the band.
