=== TugraCyber ===
Contributors: skromets
Tags: woocommerce, security, checkout, pci dss, magecart
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.2
Stable tag: 0.3.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Monitors third-party scripts on your WooCommerce checkout, detects tampering and produces a PCI DSS 6.4.3/11.6.1 report.

== Description ==

TugraCyber keeps an inventory of every script running on your checkout page and alerts you when a script's content changes silently, which is the signature of Magecart-style card skimming attacks.

* **Runs only on the checkout page.** This is exactly the scope of PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.
* **Script inventory.** A SHA-256 hash of each script's content is recorded, so silent changes are caught immediately.
* **Removed and returning script detection.** You get an alert when a known script disappears from the page, or reappears after being marked as removed.
* **Late-added script detection.** Scripts that are added to the checkout page after it has loaded are also inventoried.
* **Outbound address monitoring.** You get an alert when the checkout page starts sending requests to a new external domain, which is where skimmed card data is typically sent.
* **PCI DSS 6.4.3/11.6.1 report.** Available from the dashboard in your TugraCyber account.

This plugin only adds the monitoring agent to your checkout page. The dashboard, alerts and reports live in your [TugraCyber](https://tugracyber.com) account. Setup requires an account and a collector address.

= Requirements =

* WooCommerce must be active (monitoring runs only on the WooCommerce checkout page).
* A TugraCyber account and a collector address.

== External Services ==

Through the monitoring script (agent) it places on your checkout page, this plugin sends data to the **Collector Endpoint** address you enter on the settings page. This address is empty by default: the plugin can be installed, but no data is sent anywhere until you enter an address.

For each script loaded on the checkout page, the data sent is:

* the script's URL (src),
* the SHA-256 hash of the script's content (not the content itself; the hash is an irreversible digest),
* the script type (inline or external), your Site ID and your Write Key.

It also sends the **domain names only** (for example `api.stripe.com`) of the external addresses the checkout page makes requests to. Paths, query strings, request bodies and responses are never collected.

Page content, customer data, payment information and card numbers are **never** collected or sent.

If you enter the TugraCyber hosted service at https://tugracyber.com as the Collector Endpoint, data is sent to that service and the following apply:

* Terms of Service: https://tugracyber.com/terms
* Privacy Policy: https://tugracyber.com/privacy

Alternatively, you can enter the address of a TugraCyber collector instance running on your own server. In that case data goes only to a server under your control and nothing is sent to any third party.

== Installation ==

1. Install and activate the plugin.
2. Create a TugraCyber account at https://tugracyber.com/public/onboarding.html. After sign-up you will see three values: Collector Endpoint, Site ID and Write Key.
3. In WordPress, go to Settings > TugraCyber, enter those three values and save.
4. Visit your checkout page once. The first script inventory is sent automatically.
5. Use the "Open your TugraCyber dashboard" button on the settings page to see your scripts and alerts.

== Frequently Asked Questions ==

= Which pages does this plugin run on? =

Only the WooCommerce checkout page. It does nothing on other pages.

= I don't have a TugraCyber account. Can I still install it? =

Yes, but monitoring does not start until the Collector Endpoint, Site ID and Write Key are all entered.

= What data does the plugin send? =

The URL and SHA-256 content hash of the scripts on the checkout page, and the domain names (no paths or content) of external addresses the checkout page sends requests to. See the "External Services" section above. Page content and customer or payment data are never sent.

== Changelog ==

= 0.3.0 =
* Detects scripts that are added to the checkout page after it has loaded.
* Monitors which external domains the checkout page sends requests to and alerts you about new ones (domain names only).
* The dashboard shows these addresses so you can mark them as known or suspicious.

= 0.2.0 =
* Settings page now takes the Site ID and Write Key from your TugraCyber account, so your reports show up in your own dashboard.
* Settings page is in English and translatable.
* Added a link to create an account and a button to open your dashboard.

= 0.1.0 =
* Initial release: agent injection on the checkout page, settings page, automatic site ID and write key generation.

== Upgrade Notice ==

= 0.3.0 =
Adds detection of late-added scripts and new outbound domains. No settings change is needed.

= 0.2.0 =
After updating, enter the Site ID and Write Key from your TugraCyber account on the settings page.
