=== DCI Admin Security ===
Contributors: dreamcodeinfotech
Donate link: https://ko-fi.com/dreamcodeinfotech
Tags: security, login security, ip whitelist, admin security, custom login
Requires at least: 6.0
Requires PHP: 7.4
Tested up to: 7.1
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email OTP, rate limiting, CAPTCHA, logging and alerts.

== Features ==

* Allow exact IPv4/IPv6 addresses and CIDR ranges.
* Accept IPv4 shorthand such as `171.61`, stored as `171.61.0.0/16`.
* Change the WordPress login URL.
* Protect the normal `wp-login.php` endpoint.
* Restrict `wp-admin` by IP while keeping `admin-ajax.php` available.
* Optional Cloudflare `CF-Connecting-IP` detection.
* Optional trusted `X-Forwarded-For` detection for known reverse-proxy setups.
* Optional localhost/loopback bypass for local development.
* Brute-force rate limiting and temporary lockouts.
* Email OTP verification for administrators, delivered to each administrator's WordPress profile email address.
* Administrator-configured emergency fallback code for environments where email cannot be delivered.
* Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login form.
* Security event logging with an administrator viewer and configurable retention.
* Optional email and Slack alerts for repeated blocked-IP or brute-force events.

== Installation ==

1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin.
2. Activate DCI Admin Security.
3. Open Settings > DCI Admin Security.
4. Add at least one IP address or CIDR range that should be allowed to reach the protected login/admin area.
5. Set the custom login slug.
6. Save the General settings.
7. Test the custom login URL before enabling strict IP protection on a production site.
8. Configure Email OTP, CAPTCHA, rate limiting and alerts as required.

== Important ==

Keep at least one known administrator IP in the allowlist before enabling IP protection.

Only enable Cloudflare IP detection when the site is actually behind Cloudflare. Only enable trusted `X-Forwarded-For` when the server is behind a trusted reverse proxy that sets that header.

On localhost, PHP commonly sees `127.0.0.1` or `::1` rather than the browser's public VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.

The emergency fallback code is stored as a password hash and is never displayed after saving.

== External Services ==

This plugin can optionally communicate with third-party CAPTCHA verification services when CAPTCHA is enabled:

* Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the submitted CAPTCHA token to Google's verification endpoint. See https://policies.google.com/privacy and https://policies.google.com/terms.
* hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA token to hCaptcha's verification endpoint. See https://www.hcaptcha.com/privacy and https://www.hcaptcha.com/terms.

The plugin does not contact these services when CAPTCHA is disabled.

== Changelog ==

= 1.0.0 =
* Resolved Plugin Check database-query and nonce warnings.
* Sanitized emergency fallback-code input.
* Added explicit versions to CAPTCHA provider scripts.
* Kept IP allowlist, email OTP, and WordPress.org compatibility fixes from 1.0.0.

= 1.0.0 =
* Removed the obsolete TOTP/two-factor authentication implementation and related files.
* Fixed WordPress coding-standard issues in IP handling, AJAX actions, CAPTCHA output and custom database queries.
* Added proper login CAPTCHA script enqueueing and a CAPTCHA nonce.
* Improved PHP 7.4 compatibility by removing PHP 8-only string helper usage.
* Updated documentation and feature list for the email OTP implementation.

= 2.4.10 =
* Improved IP allowlist matching and localhost development controls.
* Added IP diagnostics and test tools.

= 2.4.6 =
* Added explicit trusted proxy handling for `X-Forwarded-For`.
* Normalized IPv4-mapped IPv6 client addresses.

= 2.0.0 =
* Added brute-force rate limiting, CAPTCHA, security logging and alerts.
* Added administrator email OTP verification.

= 1.0.0 =
* Initial release with IP allowlist and custom login URL protection.

== IP access examples ==

Exact IP: `186.189.26.220`

IPv4 /16 shorthand: `171.61`

CIDR: `171.61.0.0/16`

== Email OTP ==

After a successful WordPress administrator password check, a six-digit OTP is generated and sent to that administrator's WordPress profile email address.

If email delivery is unavailable, an administrator-configured emergency fallback code can be used.
