=== SiteGuard Scanner ===
Contributors: egsecuresolutions
Tags: security, verification, vulnerability
Requires at least: 5.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Companion plugin for the EG Secure Solutions vulnerability diagnostic service: signed site-ownership verification and plugin/theme inventory.

== Description ==

SiteGuard Scanner is a companion plugin for the vulnerability diagnostic service provided by EG Secure Solutions. Installing it on a site that is under a diagnostic contract enables the following two features.

1. **Site ownership verification (authentication)** — Lets the diagnostic service confirm that the target site is the one that is actually under a diagnostic contract.
2. **Installation inventory** — Provides the diagnostic service with a list of the plugins and themes installed on the target site (name, version, and activation status).

= How it communicates =

The plugin only **responds to signed requests** sent by the diagnostic service. It never sends data to any external server on its own (it does not "phone home").

* Authentication uses an **HMAC-SHA256 signature** based on a shared token. Each request includes a timestamp and a nonce (a single-use random value) to prevent replay attacks.
* Requests are received through the WordPress REST API endpoints `/wp-json/siteguard-scanner/v1/verify` and `/wp-json/siteguard-scanner/v1/collect`.
* For environments where the REST API is disabled, a custom endpoint (`/?siteguard-scanner-request=verify` and `/?siteguard-scanner-request=collect`) is provided as a fallback.

Every endpoint responds only to requests carrying a valid signature. When signature verification fails, the plugin returns HTTP 401 and no information at all.

= Data provided =

When responding to `collect`, the plugin returns the following information to the diagnostic service:

* Site URL
* WordPress core version
* List of installed plugins (slug, name, version, activation status, network-activation status)
* List of installed themes (slug, name, version, activation status, network-enabled status)

No personal data, post content, or any other data beyond the above is collected or transmitted.

= Multisite =

On a multisite network, diagnostics are performed against the main (parent) site. Because plugin and theme files are shared across the entire network, `collect` returns the network-wide inventory of installed assets and correctly reports network-activated plugins via the `network_active` flag.

== Installation ==

1. In the WordPress admin, go to "Plugins" > "Add New".
2. Click "Upload Plugin" at the top of the screen and select the plugin ZIP to install it.
3. After installation, activate the plugin.
4. Open "Settings" > "SiteGuard Scanner" in the admin menu.
5. Enter the 64-character token provided by the diagnostic service and save.

On a multisite network, set the token on the main site's Settings screen.

== Frequently Asked Questions ==

= Does this plugin send data to an external service? =
It does not send anything on its own. It only responds to signed requests from the diagnostic service.

= I cannot save the token. =
The token must be a 64-character lowercase hexadecimal string (0-9, a-f). Values that do not meet these conditions are rejected and not saved.

= Can I use it even with the REST API disabled? =
Yes. In environments where the REST API is disabled, the custom endpoint (`/?siteguard-scanner-request=...`) is used automatically as a fallback.

= Does it work on multisite? =
Yes. On multisite, diagnostics are performed against the main site, and the plugin provides the network-wide plugin and theme inventory.

== Screenshots ==

1. The settings screen (Settings > SiteGuard Scanner), where you enter the token provided by the diagnostic service.

== Changelog ==

= 1.0.0 =
* First public release on the WordPress.org plugin directory.
* Renamed the plugin to SiteGuard Scanner (slug, endpoints, and identifiers).
* Added the WordPress core version to the collect response.
* Fixed multisite so that network-activated plugins and themes are reported correctly.
* Added network_active / network_enabled / is_multisite to the collect response.
* Internationalized the admin UI and bundled a Japanese translation.
* Prepared plugin headers and readme for the WordPress.org directory.

= 0.3.0 =
* Added a custom endpoint (`/?siteguard-scanner-request=verify|collect`) as a fallback for environments where the REST API is disabled.
* Unified the signature verification logic across the REST API and the custom endpoint.

= 0.2.0 =
* Implemented request authentication using HMAC-SHA256 signatures.

= 0.1.0 =
* Initial version.

== Upgrade Notice ==

= 1.0.0 =
First public release of SiteGuard Scanner.
