=== UX3 Security ===
Contributors: ux3security
Tags: security, firewall, waf, bot, spam
Requires at least: 5.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Cloud-managed firewall, bot protection, and threat monitoring. Manage rules, bans, and allow-lists from a central dashboard.

== Description ==

**UX3 Security** connects your WordPress site to the UX3 Security cloud dashboard for centralized firewall management. Block SQL injection attempts, XSS attacks, malicious bots, spam submissions, and more — with rules managed from a single place across all your sites.

= Key features =

* **Web Application Firewall** — blocks SQLi, XSS, and other common attack patterns
* **Bot protection** — detects and blocks bad bots, fake search-engine crawlers, anonymous bot traffic
* **Spam protection** — honeypot + content-based detection for forms
* **Word filter** — block requests matching custom keyword lists
* **Geo-blocking** — block traffic from specific countries
* **Rate limiting** — prevents brute-force and scraping
* **Smart filter** — one-click allow-list for false positives
* **Centralized dashboard** — all your sites in one place at central.ux3security.com
* **Real-time alerts** — email notifications for attacks, disconnections, disk warnings, etc.

= How it works =

1. Sign up at [central.ux3security.com](https://central.ux3security.com/) and add your site
2. Copy the API URL and token from your dashboard
3. Install this plugin and paste them into Settings → UX3 Security
4. Enable protection — done. Manage rules from the dashboard.

== External services ==

This plugin connects to two external services in order to function. Each is described below in line with WordPress.org's third-party service disclosure guideline.

= 1. UX3 Security API =

What it is and what it is used for: The cloud dashboard at central.ux3security.com is the central management plane for the plugin. It distributes firewall rules to the agent, receives logs of blocked attacks, and tracks site connection status.

When and what data is sent:

* On every blocked request: visitor IP, country (resolved server-side), request URL and method, user-agent, attack type that triggered the block, timestamp.
* On every approximately 5 minutes: a rules-version check (lightweight) and an agent heartbeat with site identifier.
* On every approximately 60 minutes: server diagnostics (PHP version, server software, OS, disk usage, OpenSSL version, cURL version, memory peak, platform/install-method detection).

What is NOT sent: post or page content, user names, passwords, email addresses, database content, file content.

Service URL: the URL you configure in Settings -> UX3 Security (typically https://central.ux3security.com/api/v1).
Provider: UX3 Security.
Terms of service: https://central.ux3security.com/terms
Privacy policy: https://central.ux3security.com/privacy

= 2. ip-api.com =

What it is and what it is used for: ip-api.com is a third-party IP geolocation service. The plugin queries it to resolve the country, city, ISP, and approximate latitude/longitude of visitor IPs. Geo data is used for country-based blocking rules, the geographic view of attack traffic on the dashboard, and proxy/hosting detection.

When and what data is sent: only the visitor's IP address, when a request hits the firewall and the IP has not been resolved within the last 24 hours. The IP is the only piece of data transmitted in the request URL. ip-api.com does not receive any other request details, headers, or content.

Service URL: http://ip-api.com/json/{ip} (free tier: 45 requests per minute, no API key required).
Provider: ip-api.com.
Terms of service: https://members.ip-api.com/legal
Privacy policy: https://ip-api.com/docs/legal

== Installation ==

1. Upload the plugin files to `/wp-content/plugins/ux3-security/`, or install via the Plugins screen in WordPress
2. Activate the plugin through the 'Plugins' screen
3. Visit Settings → UX3 Security
4. **Review the Data Processing Consent section** — this explains exactly what data the plugin sends to the UX3 Security API and to ip-api.com. Tick the consent checkbox only if you agree.
5. Paste your API URL and API Token (from your UX3 Security dashboard)
6. Tick "Enable UX3 Security protection" and Save

The plugin ships with protection **disabled by default** and will not send any data to external services until you have both given consent and enabled protection.

For maximum protection on supported hosts, you can additionally configure `auto_prepend_file` in your php.ini — see the Settings page for the exact directive.

== Frequently Asked Questions ==

= Do I need an account on central.ux3security.com? =

Yes. The plugin is the agent — it works in conjunction with the central dashboard where you create accounts, add sites, and configure rules.

= What happens if my site can't reach the API? =

The agent caches firewall rules locally for 5 minutes. If the API is unreachable, it continues using the cached rules — your site stays protected even during brief network blips. After cache expiry, the agent skips silently rather than break your site.

= Will this plugin slow down my site? =

The agent is highly optimized — typical overhead is 1-3ms per request. Rules are cached on disk so most requests don't even need a database lookup.

= Can I temporarily disable protection? =

Yes — uncheck "Enable UX3 Security protection" on the settings page. No need to deactivate the plugin.

= How do I withdraw consent? =

Uncheck the consent checkbox on Settings → UX3 Security and save. The agent stops making outbound requests immediately.

= How does the plugin display warning pages when a request is blocked? =

Blocked visitors see a warning page served in an iframe from central.ux3security.com. The plugin does not cache warning-page HTML in your WordPress database or filesystem — the styled page is served live from Central each time.

= Where are my settings stored? =

In the WordPress options table — same place as other plugin settings. They're cleaned up automatically if you delete (not just deactivate) the plugin.

== Screenshots ==

1. Secure sign-in — access your UX3 Security dashboard with multi-site management and 24/7 monitoring built in.
2. Admin Dashboard — see every protected site at a glance: total sites, live connection state, disk, database and platform storage in one view.
3. Site Overview — real numbers for each site: visitors, unique visits, bots, proxies, blocked requests, spam and SQL-injection attempts, plus full server info.
4. Traffic snapshot — live traffic chart, threats by country, and device / browser / OS breakdowns, with one-click access to bots, threats, protection and whitelist.
5. Live Traffic — active visitors right now, humans vs bots, blocked attempts, hourly trend, top pages and top countries in real time.
6. Visitors by Country — see where your legitimate traffic comes from on an interactive world map, ranked by share.
7. Traffic Graph — humans vs bots over any date range, so you can spot attack spikes and traffic patterns instantly.
8. Threats by Country — an interactive threat-origins map with a ranked list of every country attacking your site, updated live.

== Changelog ==

= 1.0.0 =
* Initial release
* WordPress wrapper for the UX3 Security agent (v1.1.0)
* Settings page for API URL / token / enable toggle
* Auto-detect existing auto_prepend_file config and recommend if not set
* Reports install_method = 'wp_plugin' to the dashboard

== Upgrade Notice ==

= 1.0.0 =
First release — install and configure your API credentials to enable protection.
