=== Stalza Security ===
Contributors: fuadkm
Tags: security, malware, firewall, brute force, integrity
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Smart WordPress security without the bloat: integrity, malware, vulnerability and brute-force protection, explained and prioritized.

== Description ==

Stalza Security protects your site without weighing it down. Instead of hundreds of generic warnings, it tells you **what changed, why it matters, how confident the detection is, and what to do**.

**Detect → Correlate → Assess Risk → Explain → Protect → Verify**

= Free features =

* **File & WordPress integrity** — core, plugin and theme checksums plus a local baseline for everything else.
* **Malware detection** — heuristic analysis of PHP, JS and .htaccess files; no signature database needed.
* **Vulnerability detection** — daily check of your installed components against known advisories (opt-in).
* **Brute-force protection** — login, XML-RPC and REST user-enumeration limits with escalating lockouts.
* **Security hardening** — one-click fixes and clear advisories for common misconfigurations.
* **Security events & reports** — a single timeline of what happened, with a weekly digest.

= Designed to be light =

* Zero frontend queries unless a login attempt is being evaluated.
* Scans run in small resumable chunks with CPU and memory budgets.
* No autoloaded option bigger than 50 KB. No bundled React runtime — uses the one WordPress already ships.

= Premium =

[Stalza Security Pro](https://stalza.com/stalza-security) extends the same engine with cloud threat intelligence, real-time protection, behavioral analysis, automatic remediation, IP reputation and advanced alerting.

== External services ==

This plugin works fully offline by default. **Nothing is sent anywhere until you opt in.**

If you enable *Vulnerability intelligence* in Settings, the plugin sends the slugs and version numbers of your installed WordPress core, plugins and themes, plus your site URL, to `https://stalza.com/api/stalza-security/v1/vulnerabilities/match` once per day to receive matching security advisories. No user data, content or visitor information is included. See the [Stalza privacy policy](https://stalza.com/privacy) and [terms](https://stalza.com/terms).

Integrity checks fetch official checksums from WordPress.org (`api.wordpress.org`, `downloads.wordpress.org`), the same service WordPress core uses for updates.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/stalza-security/` or install it from the Plugins screen.
2. Activate it.
3. Go to **Stalza Security** in the admin menu and run your first scan.

== Frequently Asked Questions ==

= Does it slow down my site? =

No. On the frontend the plugin does nothing unless a login, XML-RPC or user-listing request is being evaluated. Scans run in the background in small chunks.

= Does it send data to Stalza? =

Only if you enable vulnerability intelligence, and then only component names and versions. See "External services" above.

= Is it compatible with other security plugins? =

Yes, but running two brute-force limiters can double-count attempts. Disable one.

== Screenshots ==

1. Dashboard
2. Scan results with risk and confidence
3. Hardening checklist

== Changelog ==

= 1.1.0 =
Features:

* login: add free-tier two-factor authentication
* login: free-tier two-factor authentication
* vuln: allow filtering the live vulnerability match URL
* vuln: live match URL filter + fixture fallback docs


Bug Fixes:

* ci: satisfy prettier and PHPCS for live-vuln merge
* ci: stylelint empty-line rules in style.scss
* vuln: use offline label for fixture source

= 1.0.1 =
Fixes:

* WordPress.org review prep: declare submitter as contributor; confirm Plugin URI and privacy/terms links on stalza.com
* Admin list tables use shared DataTable + server pagination

= 1.0.0 =
Features:

* admin: Settings, Dashboard, and Scan UX for v1 launch (Epic E7) (#9)
* integrity: pause/resume/cancel scans; skip Hardening-removed core docs noise
* malware: heuristic scan job + Scan-tab findings triage
* vuln: opt-in match client with fixture fallback filtered to installed inventory
* reports: weekly digest builder and cron
* Free modules: Integrity M2, Login M2, Hardening, Malware, Vulnerabilities, Reports, Events

Bug Fixes:

* vuln: do not surface fixture advisories for patched/absent components
* integrity: silent-reseed own plugin baseline on version bump; keep same-version tamper
* admin: hash navigation for TabPanel; Plugin Check ABSPATH on helpers
* build: exclude `.worktrees` and agent dirs from release zips

= 0.1.1 =
Features:

* admin: add Events tab with filters, table, and context drawer
* admin: add Login Protection tab with allowlist and unlock
* core: add Settings helper for nested plugin options
* core: scaffold plugin kernel, admin shell, build pipeline and CI
* core: seed login protection settings defaults
* events: add Repository, Recorder, and retention Pruner
* events: add Severity map and TypeRegistry allowlist
* events: register the module, REST list, and upgrade hook after boot
* hardening: Epic E3 Hardening module (#2)
* integrity: Integrity M2 — plugins, baseline, uploads, Accept (#4)
* integrity: ship M1 Queue, Findings, core scan, REST, and admin tab
* login: add Guard for lockout policy and events
* login: add lockouts repository with window and escalate helpers
* login: add login status, allowlist, and unlock REST endpoints
* login: Login Protection M2 — proxies, enum blocks, editable thresholds (#3)
* login: register LoginProtectionModule and login event types
* support: add Fs, Hashing, Http, and Budget helpers
* support: add Ip helper (REMOTE_ADDR + pack/unpack)


Bug Fixes:

* admin: clear login refresh error after successful retry
* admin: separate login unlock errors from list refresh
* core: rename reserved-word column scans.cursor to cursor_state
* integrity: ignore wp-content paths in core checksum scan
* integrity: keep dotted scan types; record deactivate events
* login: avoid null lockout row offsets
* login: harden lockout persistence
* login: ignore failures while IP already locked


Performance:

* core: autoload db_version option so upgrade check costs no query

= 0.1.0 =
Features:

* core: plugin kernel, container, module contract, feature flags, schema installer
* admin: single-page React admin shell with dashboard and status endpoint

Full history: https://stalza.com/docs/stalza-security/changelog
