=== Ensomedia Security powered by shieldwave.io ===
Contributors: shieldwave
Tags: security, malware scanner, file integrity, vulnerability scanner, hardening
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.1.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Finds malware, tampered files, known vulnerabilities, injected content and risky settings, and explains each fix in plain words.

== Description ==

Ensomedia Security, powered by shieldwave.io, scans your site from the inside and tells you, in plain language, what is wrong and how to fix it. It is built around one idea: **an alert has to be worth your attention**. Every check, the scheduled scans and the email alerts are free, work without an account and have no limits.

= Why owners switch to it =

* **Official checksums first.** WordPress core, directory plugins and directory themes are compared with the exact files WordPress.org published for your version. A file that matches is trusted and never "looks suspicious"; a file that differs is reported with the reason.
* **Malware detection that needs real evidence.** One weak signal, such as base64 in a file, is never a finding. The scanner looks for code that runs what a visitor sends, executes hidden payloads, hides function names, fetches remote code or creates hidden administrators. Findings it is not sure about go under "Ask your developer to check" and never send email.
* **Change monitoring for what WordPress.org cannot verify.** Premium plugins, custom themes, must-use plugins and drop-ins are recorded as a baseline. Changes that come with an update are accepted; a new PHP file that appears without one is reported.
* **Alerts that do not cry wolf.** One email per scan, only for problems that are new or got worse, never twice for the same one, at most four a day. A check that could not run never sends an email and never marks anything as fixed.
* **Login protection and two-factor login.** Password guessers are locked out for a while, user names stay private, and an optional one-time code from an authenticator app makes a stolen password not enough.
* **Light on your server.** Scans never run while a visitor's page loads: they run in the background in short steps that fit hosts with a 30-second limit, and files that did not change are not analyzed again.
* **Never rewrites your site.** The plugin never edits, moves or deletes your files, users or settings. It explains each fix. The only things it ever refuses are a bad login, a stranger asking for your user list, and the file editor and XML-RPC if you switch them off.

= The checks =

* **Malware and backdoors** in every PHP, JavaScript and .htaccess file that WordPress.org cannot vouch for: web shells, request-to-execute code, decode-and-execute chains, obfuscated function names, remote code loaders, PHP hidden in images, spam mailers, hidden administrators, injected JavaScript and malicious redirects.
* **Core, plugin and theme files** against the WordPress.org checksums or release packages of your versions, plus PHP files those releases do not contain.
* **File changes** outside those releases against the recorded baseline, and plugin or theme folders that appear without going through the WordPress installer.
* **PHP files in uploads**, and .htaccess or .user.ini rules that make the server run uploads as PHP.
* **Known vulnerabilities** (opt-in) in plugins, themes and WordPress, premium ones included, with the version that fixes each one. Free and without an account; see External services.
* **Closed, abandoned and unused plugins and themes**, **WordPress, plugin and theme updates** and **PHP version** support.
* **Injected content**: scripts, hidden iframes and spam links in posts, widgets and options. Ordinary embeds and tracking codes are left alone.
* **Exposed files** that your web server hands out to anyone (copies of wp-config.php, database dumps, backups, .git folders, .env files, logs), confirmed by requesting them from your own site; leftover installers and database tools; folder listings.
* **Accounts and configuration**: administrators, user registration, wp-config.php, debug output, file editor, XML-RPC, HTTPS, user list exposure and suspicious scheduled tasks.

Each issue has a severity, what it means, how to fix it and the files, plugins or settings involved. Problems of the same kind are grouped, so a site never faces hundreds of lines. You can ignore a problem; an ignored file comes back if it changes again.

Live protection (both opt-in, off until you turn them on):

* **Live threat feed**: new malware rules and file signatures from ShieldWave reach your site within about three hours, verified by signature. It sends nothing about your site.
* **AI second opinion**: for a file the local rules cannot judge, a redacted excerpt gets a verdict in plain words. wp-config.php is never sent. See External services.

= Login protection and two-factor login =

* After five failed logins from one address (you choose), that address waits a cooldown you set. The lock is always temporary, and trusted addresses, including the one that turned the feature on, are never locked. Only the connection's own address counts, never a header a request can fake.
* User names stay private: the login form, the ?author=N trick, the REST API user list, embeds and the users sitemap stop giving them to visitors who are not logged in.
* Two-factor login is opt-in for each administrator and works with any authenticator app on every login form. Ten recovery codes and `wp shieldwave two-factor disable <user>` make sure nobody is locked out. Apps sign in with an application password.
* Login protection is on by default for new installs and off after an upgrade until you turn it on. Every lockout goes to History and can raise an alert.

= Hardening =

Turn off the plugin and theme file editor and XML-RPC with one switch each, without editing wp-config.php or any other file. ShieldWave warns you first if a plugin you use, such as Jetpack, needs XML-RPC. Both are off until you turn them on.

= Alerts =

Email after scheduled scans for new or more serious issues at or above your threshold, in real time when an account becomes administrator (naming who did it), and a weekly summary if you want one.

= ShieldWave dashboard (optional) =

Press **Connect with shieldwave.io** under ShieldWave > Settings, sign in or create a free account, and the site shows up in your dashboard at [shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme) with its score and open issues, next to ShieldWave's outside scan. A free account shows one site; Pro and Enterprise show every site. The connection sends results only and confirms that the domain is yours; the dashboard cannot change anything on the site. See External services.

= What this plugin does not do =

It is not a full web application firewall and it does not remove malware for you. It finds, explains, alerts, stops brute-force logins, adds two-factor login and can switch off the file editor and XML-RPC; you, your developer or your host make the rest of the change. Visitors see nothing of it.

= Credits =

The admin screens use the Inter typeface by The Inter Project Authors, licensed under the SIL Open Font License 1.1 (`assets/fonts/inter-license.txt`). It is loaded from the plugin itself, only on the ShieldWave screens.

== Installation ==

1. Install the plugin from Plugins > Add New, or upload the `ensomedia-security` folder to `/wp-content/plugins/`.
2. Activate it.
3. Open **ShieldWave** and press **Scan now**. The first scan records the baseline and usually takes a few minutes; later scans are faster.
4. Scheduled scans run daily at 03:00 (site time). Change that, the alerts and the options under **ShieldWave > Settings**.
5. Optional: turn on the known-vulnerability lookup under **ShieldWave > Settings > Live protection**.
6. Optional: to see the site in the ShieldWave dashboard, press **Connect with shieldwave.io** under **ShieldWave > Settings > ShieldWave account**.

== Frequently Asked Questions ==

= Do I need a ShieldWave account? =

No. All 23 checks, scheduled scans, email alerts and the vulnerability lookup work without one, with no limits.

= Can I hide ShieldWave from the toolbar? =

Yes. Under ShieldWave > Settings > Toolbar, turn off "Show ShieldWave in the toolbar". The choice is per administrator. Visitors never see it.

= How is this different from other security scanners? =

It trusts the files WordPress.org can vouch for, needs real evidence before it calls something malware, and emails only about problems that are new or got worse. The goal is that every alert you get is one you would want.

= What does "Ask your developer to check" mean? =

The scanner found something unusual that is often harmless: for example a new PHP file in a premium plugin without an update. It is listed so someone who knows the site can look at it, and it never sends an email on its own. Problems under "Fix now" are the ones with clear evidence.

= A finding is about a file I changed on purpose. =

Open the item and press "Ignore". It stays out of the score and the alerts, and an ignored file comes back by itself if it changes again. Ignored items stay under the "Ignored" link below the to-do list, where "Restore" brings one back.

= Will it slow my site down? =

No. Scans never run while a visitor's page loads: they work in the background in steps of a few seconds, and later scans skip files that were clean and did not change. On a busy shared host you can choose the low scan speed in Settings.

= What happens to the scheduled scan when the clocks change? =

It stays on the hour you chose, in the time zone set under Settings > General, and it follows a change of that time zone at once. On the one day a year the clocks skip the chosen hour, the scan runs right after the skipped hour. On the day an hour happens twice, it runs once, the first time the clock shows it.

= Which outside requests does it make? =

Only when scans run: to WordPress.org for checksums, theme packages and plugin information, and to your own site. With the vulnerability lookup, live threat feed or AI second opinion on: to shieldwave.io. With an account connected: to shieldwave.io. Each of those is off until you turn it on, and the External services section below lists exactly what is sent.

= Why does the plugin register a public AJAX action? =

The AJAX action `shieldwave_worker` lets a running scan continue in the background; it does nothing without the random token of the running scan. The plugin's REST routes answer administrators only.

= My headless front end reads authors from the REST API. =

With login protection on, the REST API user list answers only logged-in requests, so an anonymous request for an author gets an error. To keep the list public, add `add_filter( 'shieldwave_hide_user_list', '__return_false' );` to a small plugin or to your theme's functions.php. The same filter also brings back the author fields in embeds and the users sitemap.

= Does it work on multisite? =

Yes, network-wide. Scanning, the schedule, alerts, the settings screens and the optional ShieldWave account all live on the main site, in the Network Admin, for network administrators only. Every other site of the network enforces the same choice made there: when login protection, two-factor or a hardening switch is on, it is on for that site too, with no separate settings screen to set up. A lockout after failed logins is shared by the whole network, not counted per site, so an address cannot dodge the limit by trying a different site.

= Does it work without WP-Cron? =

Yes. If WP-Cron is disabled or loopback requests are blocked, scans still run while the ShieldWave screen is open, and scheduled scans run whenever your server cron calls wp-cron.php.

= How is the score calculated? =

It starts at 100. For each check, the most serious open issue takes off points: critical 30, high 15, medium 8, low 3. Ignored issues, hints and checks that could not run take nothing off.

= Which languages does it speak? =

English, Arabic, Chinese (Simplified), Dutch, French, German, Indonesian, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Turkish and Vietnamese. The screens, the login protection and the alert emails follow the language of your WordPress admin, and Arabic gets a right-to-left layout. Regional variants such as Spanish (Mexico), German (Switzerland) or French (Canada) use the main language. A translation from translate.wordpress.org, once one is complete, takes precedence.

= The old ShieldWave Security from shieldwave.io is installed too. =

Builds downloaded from shieldwave.io before the directory listing were called ShieldWave Security, numbered up to 3.6.6, and live in the folder shieldwave-security. They cannot update themselves to this plugin. Keep Ensomedia Security active, deactivate ShieldWave Security, then delete it on the Plugins screen: the settings, results and two-factor set-ups carry over, because Ensomedia Security keeps them while the old copy's clean-up runs. The Plugins screen shows a notice while an old copy is installed.

= What does connecting to shieldwave.io do? =

It shows the site in your shieldwave.io dashboard with its score and open problems, next to the outside scan of shieldwave.io, and confirms that the domain is yours, which the full outside scan needs. A free account shows one site. Everything in the plugin works the same without it.

= I think a finding is wrong. =

Open a topic in this plugin's support forum with the check name and what you see. False positives are treated as bugs.

= How do I report a security problem in the plugin? =

Follow https://shieldwave.io/legal/en/vulnerability-disclosure?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme. Please do not post it in the public support forum.

== External services ==

The plugin makes no outside requests when it is activated or when admin pages load. Requests happen when a scan runs (by hand or on the schedule), when you use the account actions, and, with an account connected, in an hourly check-in. Requests to WordPress.org and to your own site use the WordPress HTTP API's default user agent, which includes your WordPress version and site address, exactly as WordPress itself does for its update checks. Requests to ShieldWave send a neutral user agent (ShieldWave-Security and the plugin version) and never your site address in their headers. Like any web request, each one comes from your server's IP address.

**WordPress.org core checksums** (api.wordpress.org/core/checksums/1.0/)
Used by the "WordPress core files" check. Sent: your WordPress version and package language. Cached for a day.

**WordPress.org plugin checksums** (downloads.wordpress.org/plugin-checksums/)
Used by the "Plugin files" check. Sent: the folder name and version of each installed plugin, one request per plugin. Cached for a week.

**WordPress.org theme packages** (downloads.wordpress.org/theme/)
Used by the "Theme files" check. The release package of each installed directory theme is downloaded to a temporary file, hashed and deleted at once. Sent: the theme's folder name and version. The result is cached for a week.

**WordPress.org plugin information** (api.wordpress.org/plugins/info/1.2/)
Used by the "Closed and abandoned plugins" check. Sent: the folder name of each installed plugin. Cached for a week.

All four are provided by WordPress.org: [privacy policy](https://wordpress.org/about/privacy/).

**Your own site**
The XML-RPC, debug output and exposed files checks request a few URLs of your own site (xmlrpc.php, the debug.log URL, backup files found on disk, the uploads folder). While a scan runs, the plugin also calls your own admin-ajax.php to continue the scan in the background.

**ShieldWave vulnerability lookup** (shieldwave.io, endpoint /api/plugin/vulnerabilities), off until you turn it on
Used by the "Known vulnerabilities" check. Sent when that check runs: your WordPress version and the folder name and version of each installed plugin and theme, premium ones included. A premium plugin's product name is compared on your site, never sent. No site address, no account, no personal data. The answer lists the vulnerabilities that apply to those versions; the data comes from Wordfence Intelligence, and each result links to its record with its copyright notice. Cached for a few hours.

**ShieldWave threat feed** (shieldwave.io, endpoint /api/plugin/intel), off until you turn it on
Used by the "Live threat feed" option. The plugin downloads a signed file of extra malware rules and known-bad and known-good file signatures, roughly every three hours, so detection improves between plugin updates. Sent: nothing about your site; the only thing that leaves is your plugin version, which every request already carries. The file is verified with a cryptographic signature before it is used.

**ShieldWave AI second opinion** (shieldwave.io, endpoint /api/plugin/ai/review), off until you turn it on
Used by the "AI second opinion" option, and only for a file the local rules cannot judge on their own. Sent: an excerpt of up to 6,000 characters around the suspicious code, with your site address, email addresses and anything that looks like a password, key or token removed (other web and IP addresses stay), plus the file's SHA-256 and MD5 fingerprints and size, the folder name of its plugin or theme, the matched rule identifiers, the site language, the plugin version and a salted hash of the site. wp-config.php and similar files are never sent. shieldwave.io passes the excerpt to its AI provider, named in the ShieldWave privacy policy; the verdict is kept by the file's fingerprint and shared across sites.

**Link to the outside check** (shieldwave.io)
After a scan, the Overview shows one line with a link to the free outside check at shieldwave.io. It is an ordinary link: nothing is sent when the page loads. If you click it, your browser opens shieldwave.io with this site's domain name in the address (shieldwave.io/?check=yourdomain.com), the same as if you typed it. It is not shown once the site is connected to an account. Every link from the plugin to shieldwave.io carries the tags utm_source=wordpress, utm_medium=plugin and utm_campaign=(the screen the link is on).

**ShieldWave account** (shieldwave.io), only after an administrator connects the site under ShieldWave > Settings

* Connecting: "Connect with shieldwave.io" opens shieldwave.io/connect in your browser with this site's address, the address to come back to and a random value. Back on the site, the plugin sends the single-use code, this site's id and address, and the plugin, WordPress and PHP versions to /api/plugin/connect/exchange and receives a key for this site. With a pasted API key instead, /api/license/verify receives the key and /api/plugin/connect the same site facts. These endpoints answer only a request that carries a code or key; they are not pages.
* While connected, the home page carries a meta tag named shieldwave-verify with a code of your account, and /api/plugin/verify-domain asks shieldwave.io to read it, after connecting and every few hours until the domain is confirmed.
* Hourly and after each scan: /api/plugin/heartbeat receives the scan status, the score and issue counts. Nothing in the answer changes the site.
* After each scan (if sending is on), for a site the dashboard shows: /api/plugin/sync receives the scan summary, score, active theme, site language, the open and ignored issues (severity, title, message, fix, and the file, plugin or setting involved) and the installed plugins and themes with versions.
* Never sent: posts, pages, comments, user names, email addresses or passwords. Issues about administrator accounts go with their title and fix only.
* A free account shows one site. For another site of a free account ShieldWave stores no results, and the plugin pauses these calls for 12 hours.
* "Disconnect" calls /api/plugin/disconnect, which removes this site and its results from shieldwave.io; a key made for this site stops working.

ShieldWave [terms of service](https://shieldwave.io/legal/en/terms-of-service?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme) and [privacy policy](https://shieldwave.io/legal/en/privacy-policy?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme).

== Screenshots ==

1. Overview: whether the site is safe, what to do next, and what protects it.
2. A problem opened: what was found, how to fix it, and a button to the right WordPress screen.
3. Signs of a break-in: what to do now, and the file, rule and code that matched.
4. A scan running in the background.
5. History: every scan and every change that matters, in plain sentences.
6. Settings: automatic scans, email alerts, extra checks and the optional ShieldWave account.
7. The optional ShieldWave account: connect the site to shieldwave.io with one click, or with an API key.

== Changelog ==

= 1.1.1 =
* The automatic scan stays on the hour you chose. It kept its old clock time after the clocks changed or after you picked another time zone under Settings > General, so "At 03:00" could sit beside "Next scan at 02:00". Every run now plans the next one from your site's own time. On the one day the clocks skip the chosen hour, the scan runs right after it; when an hour happens twice, it runs once, the first time.
* The update replaces the schedule of 1.1.0 at once, and nothing is scheduled twice.
* The weekly summary follows your site's clock in the same way.
* The hours in the list under "At" use your site's time format, the same as "Next scan", and "today" and "tomorrow" are right on the days the clocks change.
* "See plans" opens the pricing page with the Pro plan selected.
* After a scan, the Overview shows one plain line about the free outside check at shieldwave.io, with your domain filled in. There is nothing to dismiss, and nothing is sent unless you click it.
* Every link from the plugin to shieldwave.io carries the tags utm_source=wordpress, utm_medium=plugin and utm_campaign=(the screen the link is on), which tell shieldwave.io only which link a visit came from.

= 1.1.0 =
* Connect with shieldwave.io in one click, from Settings or the Overview: sign in or create a free account there, press "Connect this site" and you are back. Pasting an API key still works, under "Use an API key instead".
* A free shieldwave.io account shows one site in the dashboard, with its score and open problems.
* While connected, shieldwave.io confirms that the domain is yours from an invisible tag on the home page, so its full outside scan can run on the site.
* Disconnecting removes the site and its results from shieldwave.io, and a copy of the site at another address (a staging copy) shows as a site of its own.
* The dashboard shows the AI second opinion on a file, and problems you ignored as ignored.
* Known vulnerabilities: plugins whose folder name has capital letters are matched again, and one plugin the lookup cannot read no longer stops the check for all the others.
* The old ShieldWave Security from shieldwave.io and this plugin can be installed side by side without losing anything: deactivating or deleting one leaves the settings, results, schedule and two-factor set-ups of the other alone, and a notice says how to remove the old copy.
* Problems about administrator accounts are sent to the dashboard without the account names, and the texts about what is sent say exactly that.
* "Turn all of it on" beside Live protection on the Overview works without JavaScript too.

= 1.0.3 =
* A clearer Overview: every group of problems has its own heading above its list, a row shows the name of the problem, and everything else opens with a click.
* The tabs in the header are easier to see, and the Settings tab shows how many protections are still off.
* The look of shieldwave.io: its colours, and its planet beside the status of your site. The planet marks where your site is and shows a simulation of typical bot traffic; a button beside it stops the motion.
* The screens grow with the window on large monitors, and buttons are easier to hit on phones.
* "New" marks a problem only when some problems are new and others are not.
* When a problem has no WordPress screen to open, "Copy for your developer" is the main button.
* No request for a review while something urgent is open.
* "Turn on" beside Known vulnerabilities opens the right part of Settings, and the time of an AI second opinion no longer says "ago" twice.
* In the dark theme the hour of the automatic scan stays readable while its list is open, and switches that are off have a visible edge.

= 1.0.2 =
* Emails display correctly in Outlook on Windows: the button keeps its padding, the fonts stay the same in every part of the message, and a long file path wraps instead of widening the message.
* The ShieldWave mark in emails is in the brand colour, so it shows in Outlook's dark mode too.

= 1.0.1 =
* Translated into Arabic, Chinese (Simplified), Dutch, French, German, Indonesian, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Turkish and Vietnamese.
* Right-to-left layout for Arabic and other right-to-left admin languages.
* The ShieldWave mark in the plugin's header and admin menu, the same as on shieldwave.io.
* Alert emails carry the ShieldWave mark (embedded in the email, nothing is loaded from outside), a clearer layout and a right-to-left layout for Arabic.
* After a few scans, the Overview asks once whether you would review the plugin on WordPress.org. "Later" and "Do not ask again" are remembered per administrator.

= 1.0.0 =
* First release in the WordPress.org directory.
* Builds downloaded earlier from shieldwave.io were numbered up to 3.6.6. To switch, deactivate and delete that copy, then install this one; the first scan starts the file history again.

== Upgrade Notice ==

= 1.1.1 =
The automatic scan keeps the hour you chose when the clocks change or you switch the time zone. Update before the clocks change.

= 1.1.0 =
Connect with shieldwave.io in one click, one free site in the dashboard, and a safe way to remove the old ShieldWave Security.

= 1.0.3 =
A clearer Overview, the look of shieldwave.io, and screens that fit large monitors and phones.

= 1.0.2 =
Alert emails now display correctly in Outlook on Windows, in light and dark mode.

= 1.0.1 =
The plugin now speaks 16 languages besides English, including Arabic with a right-to-left layout.

= 1.0.0 =
First release in the WordPress.org directory.
