=== NullState Security™ ===
Contributors: SalesPC
Tags: security, firewall, malware, two-factor, scanner
Requires at least: 5.0
Tested up to: 7.1
Stable tag: 3.4.7
License: GPLv2 or later

Short Description: Free WordPress security plugin – malware scanning, brute-force protection, two-factor authentication, and more.

== Description ==

NullState Security™ is a free WordPress security plugin with modular hardening, threat interception, forensic logging, a live traffic monitor (90-day retention), two-factor authentication (TOTP), and a vulnerability scanner.

Key free features:

* **Core hardening** – disables XML-RPC, hides version leaks, protects the uploads directory
* **Brute-force protection** – automatic IP lockout after repeated failed logins
* **IP blacklist** – block attackers manually or from the Live Traffic feed, with CSV import/export
* **Request filtering** – blocks directory traversal, SQL injection, XSS, eval() and other attack payloads
* **User-Agent Bouncer** – blocks known malicious scanners and bots (e.g. Nuclei, sqlmap)
* **Emergency lockdown** – temporarily disable non-admin logins and block the site
* **Session terminator** – end all other sessions with one click
* **Cache & temp purge** – clear caches and kill memory-resident shells
* **Admin creation lockdown** – detect and delete rogue administrator accounts
* **Uploads shield** – block script execution in the uploads directory
* **Forensic logging** – every security event recorded with full request context
* **Live traffic monitor (90-day)** – real-time view of every request, classified as human, bot, or attack, with country flags and one-click IP blocking
* **Two-factor authentication** – TOTP-based 2FA (Google Authenticator, Authy, …) with backup codes
* **Vulnerability scanner** – checks plugins, themes and core for known vulnerabilities (optional free WPScan API token for detailed data)
* **Manual malware sweeps** – C2 trojan cleanup, JS dropshell removal, trojanized CSS stripping, fake dependency removal, transient drop-shell cleanup
* **Security scorecard** – 0–100 score with actionable recommendations

For advanced security solutions, enterprise-grade protection, and expert support,
visit <a href="https://nullstatesecurity.net/">nullstatesecurity.net</a>.

== Installation ==

1. Upload the `nullstate-security` folder to `/wp-content/plugins/`
2. Activate the plugin
3. Go to NullState Security™ → Settings to configure
4. Enable features you want to use

== External Services ==

This plugin connects to the following external services:

1. **WPScan API (wpscan.com)** – Optional
   - Purpose: Vulnerability database queries
   - Data sent: Plugin/theme/core version information
   - When: During vulnerability scans (user-initiated)
   - Terms: https://wpscan.com/terms
   - Privacy: https://automattic.com/privacy/

2. **AbuseIPDB (abuseipdb.com)** – Optional
   - Purpose: IP reputation and threat scoring
   - Data sent: Visitor IP addresses
   - When: When viewing IP details in Live Traffic
   - Terms: https://www.abuseipdb.com/legal
   - Privacy: https://www.abuseipdb.com/privacy

3. **ip-api.com**
   - Purpose: Geolocation, ISP, and location data
   - Data sent: Visitor IP addresses
   - When: For country flags and IP lookup details
   - Terms: https://ip-api.com/terms
   - Privacy: https://ip-api.com/privacy

4. **WordPress.org API**
   - Purpose: Checking for outdated plugins/themes/core
   - Data sent: Installed version numbers
   - When: During vulnerability scans
   - Terms: https://wordpress.org/about/privacy/

== Changelog ==

= 3.4.6 =
* All code prefixes renamed to the nullstatesecurity_ / NULLSTATESECURITY_ / nullstatesecurity- convention (options, transients, user meta, hooks, classes, constants, handles, slugs, nonces, CSS classes)
* Automatic one-time migration on activation/update moves existing settings, transients, user meta and log files to the new prefix
* $_SERVER request data sanitized (esc_url_raw / sanitize_text_field) before use and logging
* Various sanitization and hardening fixes

= 3.4.5 =
* No license keys, license checks, tiers or registration API – plugin runs fully without any activation
* All shipped features are available to every user; no feature gating or upgrade prompts
* Live Traffic retention fixed at 90 days for all installations
* Removed the License admin page and license tracker
* Removed all premium-feature promotion from the admin UI and readme
* External services documented (WPScan, AbuseIPDB, ip-api.com, WordPress.org API)
* Storage consolidated under wp-content/uploads/nullstate-security/ with direct-access protection
* Various sanitization and hardening fixes

= 3.4.0 =
* NEW: Two-Factor Authentication (TOTP) – added as a free feature
* NEW: Vulnerability Scanner – checks plugins, themes, and core for known vulnerabilities (free)

= 3.3.0 =
* IMPROVED: IP blacklist enforcement now works on all requests (including admin)
* FIX: Brute-force lockout now correctly auto-blocks IPs
* FIX: CSV export/import now works as expected

= 3.2.2 =
* NEW: Country flags in Live Traffic – see the origin country of each visitor
* NEW: IP Lookup Tool – view ISP, location, and threat score for any IP in the Live Traffic details modal
* NEW: Bulk IP Import/Export – import and export IP blacklists via CSV
* FIX: Local/private IPs are now excluded from IP blacklist and Live Traffic
* IMPROVED: Dashboard redesign with security scorecard, charts, and recommendations
* IMPROVED: Dark mode toggle in admin bar
* IMPROVED: First-run onboarding wizard
* IMPROVED: Tooltips with documentation links throughout the UI
* IMPROVED: Notification center with bell icon and unread badge

= 3.0.0 =
* Rebranded from WP Sentinel Guard to NullState Security™
* All code prefixes migrated: classes/constants (WPSG_ → NSS_), functions and hooks (wpsg_ → nss_), text domain (wp-sentinel-guard → nullstate-security)
* Main plugin file renamed to nullstate-security.php; admin module files renamed to class-nss-*.php
* All storage migrated from wpsg_* to nss_*: options, transients, user meta keys, JSON data files and data directories
* Automatic one-time migration on activation – existing settings, fingerprints, logs, backups and scan history are preserved
* Admin menu pages and URLs updated to the new naming

= 2.5.0 =
* NEW: Live Traffic Monitor – real-time view of every request to your site
* Auto-refresh every 5 seconds with pause/resume (AJAX polling)
* Filter by IP, method, status, URL and user agent + pagination (50 per page)
* Block IP directly from the traffic table (adds to the IP blacklist)
* Request details modal (headers, referer, size, response time, user ID, AJAX/REST flags)
* Storage in JSON file capped at 10,000 entries (oldest 10% trimmed)
* Skips admin-ajax, admin-post, wp-cron and login pages by default (filterable)
* Exclude IPs and user agents from logging
* Response time + final HTTP status patched in on shutdown

= 2.0.0-2.0.5 =
* Complete admin dashboard rebuild with 5 subpages
* New UI with Tailwind CSS (dark mode ready)
* Scan page with "Run All Scans" button and progress bar
* Logs page with date filter, pagination, and per-page dropdown
* Settings page with toggles for XML-RPC, User-Agent Bouncer, Login Error Hiding
* Brute-force threshold and lockout duration settings
* Emergency lockdown toggle on dashboard
* Automatic .htaccess deployment on plugin activation
* IP whitelist and trusted proxies settings

= 1.5.3 =
* Added "Run All Scans" button with progress bar
* Redesigned logs page with date filter and pagination
* Added settings page with toggles and thresholds
* Fixed performance issues (moved sweeps to manual)
* Fixed IP spoofing vulnerability
* Fixed double-encoding bypass
* Fixed admin-ajax false positives
* Added IP whitelist and trusted proxies

= 1.0.0 =
* Initial release
* Core hardening (XML-RPC disable, version hiding, uploads protection)
* Brute-force protection with IP lockout
* Forensic logging with JSON format
* Request filtering and malware signature detection
* Rogue script blocking
* Header evaluation shield
* XOR/Hex payload defender
* C2 interceptor and spoofing defender
* User-agent bouncer
* Session terminator
* Emergency lockdown mode
* Uploads execution shield
* Cache and temp purge
* Admin creation lockdown
