=== TugraCyber ===
Contributors: skromets
Tags: woocommerce, security, checkout, pci dss, magecart
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.2
Stable tag: 0.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Monitors third-party scripts on your WooCommerce checkout, detects tampering and produces a PCI DSS 6.4.3/11.6.1 report.

== Description ==

TugraCyber keeps an inventory of every script running on your checkout page and alerts you when a script's content changes silently, which is the signature of Magecart-style card skimming attacks.

* **Runs only on the checkout page.** This is exactly the scope of PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.
* **Script inventory.** A SHA-256 hash of each script's content is recorded, so silent changes are caught immediately.
* **Removed and returning script detection.** You get an alert when a known script disappears from the page, or reappears after being marked as removed.
* **PCI DSS 6.4.3/11.6.1 report.** Available from the dashboard in your TugraCyber account.

This plugin only adds the monitoring agent to your checkout page. The dashboard, alerts and reports live in your [TugraCyber](https://tugracyber.com) account. Setup requires an account and a collector address.

= Requirements =

* WooCommerce must be active (monitoring runs only on the WooCommerce checkout page).
* A TugraCyber account and a collector address.

== External Services ==

Through the monitoring script (agent) it places on your checkout page, this plugin sends data to the **Collector Endpoint** address you enter on the settings page. This address is empty by default: the plugin can be installed, but no data is sent anywhere until you enter an address.

For each script loaded on the checkout page, the data sent is:

* the script's URL (src),
* the SHA-256 hash of the script's content (not the content itself; the hash is an irreversible digest),
* the script type (inline or external) and your site ID.

Page content, customer data, payment information and card numbers are **never** collected or sent.

If you enter the TugraCyber hosted service at https://tugracyber.com as the Collector Endpoint, data is sent to that service and the following apply:

* Terms of Service: https://tugracyber.com/terms
* Privacy Policy: https://tugracyber.com/privacy

Alternatively, you can enter the address of a TugraCyber collector instance running on your own server. In that case data goes only to a server under your control and nothing is sent to any third party.

== Installation ==

1. Upload and activate the plugin.
2. Go to Settings > TugraCyber.
3. Enter the collector endpoint of your TugraCyber account and save.
4. Visit your checkout page once. The first script inventory is sent automatically.

== Frequently Asked Questions ==

= Which pages does this plugin run on? =

Only the WooCommerce checkout page. It does nothing on other pages.

= I don't have a TugraCyber account. Can I still install it? =

Yes, but monitoring does not start until a collector address is entered.

= What data does the plugin send? =

Only the URL and SHA-256 content hash of the scripts on the checkout page. See the "External Services" section above. Page content and customer or payment data are never sent.

== Changelog ==

= 0.1.0 =
* Initial release: agent injection on the checkout page, settings page, automatic site ID and write key generation.
