=== ScanBase - 152-FZ Website Compliance Check ===
Contributors: lego1995
Tags: 152-fz, personal data, compliance, privacy, security
Requires at least: 5.6
Tested up to: 7.1
Requires PHP: 7.2
Stable tag: 1.5.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Check your website's compliance with the Russian personal data law (152-FZ) from wp-admin: compliance score, violations and potential fines.

== Description ==

The plugin checks your website's compliance with the Russian Federal Law No. 152-FZ "On Personal Data" and related requirements, using the API of the ScanBase service (scanbase.ru). It is aimed at owners of websites that fall under Russian personal data law; the admin interface is in Russian.

Right from your WordPress dashboard you get:

* **Compliance score** of your site (0-100).
* **List of violations** with the relevant article of law and the potential fine under the Russian Administrative Code.
* **Items to verify manually** - things the automated checks could not confirm.
* A **traffic-light indicator** in the admin bar showing the current score on every admin page.
* A link to the **full report** in your ScanBase account: developer task list, document templates, remediation services.

The plugin works only in the admin area and outputs nothing to your site's visitors.

= How it works =

The plugin is a thin client of the ScanBase API. All checks run on the service side; your API key is stored only on your site and is used solely for API requests. Your tier (free, scan package or subscription) is determined by your ScanBase account.

= External service (mandatory disclosure) =

The plugin is a client of the **ScanBase** cloud service (https://scanbase.ru) and does not work without it. What is sent to scanbase.ru and when:

* **When you start a check** (button in wp-admin): your site URL and your API key. The service scans the site and returns the report.
* **During the optional one-click connect flow**: your site URL and the admin email (used to sign in to the ScanBase account via a magic link and issue an API key).
* No data about your site's visitors is collected or transmitted: the plugin runs only in the admin area.

ScanBase service documents:

* Privacy policy (personal data processing): https://scanbase.ru/legal/
* API terms of use (tiers, limits): https://scanbase.ru/api/

= Tiers =

* **Free** - 5 checks per day, condensed report.
* **Scan packages** - full report for any domain, one-time payment.
* **Subscription** - full report plus server-side monitoring.

All tiers are managed in the ScanBase account: https://scanbase.ru/cabinet/ The plugin code itself is not restricted - tiers only affect how much detail the API returns.

== Installation ==

1. Install and activate the plugin.
2. Open the **ScanBase** menu in wp-admin.
3. Click "Connect ScanBase" (one-click connect), or get a free key in the ScanBase account (Account -> API access -> "Create free key") and paste it into the plugin.
4. Click "Check site".

== Frequently Asked Questions ==

= Do I need a ScanBase account? =

Yes. Signing in is done by email (magic link), no password. A free API key is issued self-service.

= Does my API key leave my site? =

It is stored in your site's options and is sent only to the scanbase.ru API when a check is requested.

= What is checked for free? =

The compliance score, the number of violations and the total potential fine. Some violation details are hidden on the free tier - the full list is available with a scan package or a subscription.

= Does the plugin output anything to my site's visitors? =

No. The plugin works only in the admin area: no banners, links or scripts on visitor-facing pages.

= What happens when I delete the plugin? =

All settings and stored check results are removed from your site. If needed, revoke the API key in your ScanBase account.

== Screenshots ==

1. Compliance report in wp-admin: score, violations with potential fines and "how to fix" recommendations.
2. One-click connect: sign in by email, the API key returns to the plugin automatically.

== Changelog ==

= 1.5.3 =
* Fixed fine amounts display: values from the API are in rubles and were mistakenly divided by 100.

= 1.5.2 =
* Contributors field fixed to the owner's WordPress.org username.

= 1.5.1 =
* readme rewritten in English (directory requirement); Plugin Check fixes.

= 1.5.0 =
* The plugin is focused on its core: site compliance check (free and paid report). The email reminders and cookie banner modules were removed; the cron schedule left by older versions is cleaned up automatically.
* The plugin no longer outputs anything on visitor-facing pages - admin area only.

= 1.4.1 =
* Security: the last check's data is passed to the script as JSON with HTML-significant characters escaped (strings from the scanned site cannot break out of the script context).
* The "Verified by ScanBase" note enabled before 1.4.0 (when it was on by default) is no longer treated as consent - it is shown only after being explicitly enabled in settings.
* Admin page scripts and styles are enqueued via standard WordPress mechanisms instead of inline output.
* The external redirect to scanbase.ru in the connect flow goes through wp_safe_redirect with an explicit allowlist of hosts.

= 1.4.0 =
* Preparation for the wordpress.org directory: the "Verified by ScanBase" note in the cookie banner became strictly opt-in (off by default).
* Full cleanup of settings on plugin deletion (uninstall.php).
* Explicit description of transmitted data and the external service in the readme.

= 1.3.0 =
* Cookie banner for the site: cookie processing notice on all pages, visitor choice remembered, policy link, configurable text and buttons.

= 1.2.1 =
* Reminder frequency: "monthly" (recommended) and "weekly". Daily re-checks removed as excessive.

= 1.2.0 =
* Compliance traffic light in the admin bar (like the Yoast indicator) - visible on every admin page.
* Full report with "how to fix" recommendations right in WordPress; the last check is shown on page load.
* Email reminders: periodic re-check with an email when compliance degrades.

= 1.1.0 =
* One-click connect ("Connect ScanBase"): sign in by email, the key returns to the plugin automatically - no copying from the account.
* Manual key entry kept as a fallback.

= 1.0.0 =
* First release: site check from wp-admin, compliance score, violations, account status.
