=== Vortix Web Security ===
Contributors: MohtamimNayeem
Tags: wordpress security, web security, login security, hardening, brute force
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 2.1.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Free WordPress security hardening: login protection, XML-RPC and file editor controls, upload protection, bot blocking and update controls.

== Description ==

Vortix Web Security bundles eleven practical security features that you can switch on and off individually from one screen. Everything is free, works offline, and needs no account, license key or trial. Nothing expires.

= Free features =

1. **Basic Hardening** - generic login error messages, no public username discovery (`?author=N` and the REST users list for logged-out visitors), `X-Content-Type-Options: nosniff`.
2. **Login Protection** - temporary lockouts after repeated failed logins, per IP address and per username.
3. **Disable XML-RPC** - blocks `xmlrpc.php` and removes the related headers and links.
4. **Bad Bot Blocker** - blocks requests from well-known scanner tools by User-Agent.
5. **Upload Protection** - denies access to script files in the uploads folder (Apache and LiteSpeed).
6. **Disable File Editor** - removes the theme and plugin code editors.
7. **Hide WP Version** - removes the WordPress version from the generator tag and asset URLs.
8. **Disable Directory Browsing** - adds `Options -Indexes` (Apache and LiteSpeed).
9. **Strong Password Enforcement** - strong passwords for users who can edit posts.
10. **Automatic Plugin Updates** - for plugin packages served by WordPress.org over HTTPS.
11. **Automatic Theme Updates** - for theme packages served by WordPress.org over HTTPS.

A **Security Scan** screen runs sixteen local configuration checks. Each feature's screen entry explains what it protects and exactly what it changes.

Features that edit `.htaccess`, may interfere with third-party services, or install updates start switched **off** on a new install. Basic Hardening, Login Protection, Disable File Editor, Hide WP Version and Strong Password Enforcement start on.

= Premium =

An optional, separately distributed product called Vortix Web Security Pro exists. It is not included in this plugin, and this plugin contains no locked or hidden premium code. The free features never depend on it. Information about it appears only on this plugin's own screens: an "Upgrade to Premium" screen and a small card beside the feature list. There are no banners or notices elsewhere in the dashboard.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/vortix-web-security/`, or install it from the Plugins screen.
2. Activate **Vortix Web Security**.
3. Open **Vortix Web Security** in the admin menu and review the features.
4. If your site is behind a CDN or reverse proxy, open **Settings** and choose the trusted proxy.

== Frequently Asked Questions ==

= Does anything expire, or do I need a license key? =

No. There is no trial, license, registration or license server.

= Why are some features off after activation? =

Turning on automatic updates, rewriting `.htaccess`, or disabling XML-RPC can affect your site or other plugins, so those are your choice. The Free Features screen explains each one.

= Disable XML-RPC broke Jetpack or an app. =

Jetpack, the legacy WordPress mobile apps and some remote publishing tools use XML-RPC. Switch the feature off again.

= My site shows an error after enabling an `.htaccess` feature. =

Before keeping a change, the plugin checks that your server still answers, and reverts it if the server returns HTTP 500. If a host blocks that check, connect by FTP and delete the block between `# BEGIN WPSM Upload Protection` and `# END WPSM Upload Protection` (or `WPSM Directory Browsing Protection`) from the relevant `.htaccess` file, then disable the feature.

= Everyone gets locked out together. =

Your site is probably behind a proxy or CDN, so all visitors appear to share one IP address. Open **Settings > Trusted proxy** and choose Cloudflare or add your proxy's addresses.

= Can login lockouts be abused? =

Login Protection also limits attempts per username (20 in 15 minutes by default), which means someone who knows a username could keep that account locked for a while. The limits can be changed with the filters `wpsm_login_max_attempts`, `wpsm_login_window`, `wpsm_login_lockout`, `wpsm_login_max_attempts_per_user`, `wpsm_login_window_per_user` and `wpsm_login_lockout_per_user`.

= Does the bot blocker block search engines? =

No. It only matches names of security-scanner tools. User-Agents can be spoofed, so it is not a firewall.

= Does this work on multisite? =

Yes. Modules are configured per site. The directory-browsing rule edits the shared root `.htaccess`, so only super admins can change it.

= Does it work on Nginx? =

The features that do not use `.htaccess` do. Upload Protection and Disable Directory Browsing need an equivalent rule in your Nginx configuration and will refuse to switch on.

== Privacy ==

Blocked requests (failed logins, blocked scanner requests, blocked XML-RPC requests) are recorded in a table in your own database: IP address, requested page path without the query string, event type and time. Entries are deleted after the retention period you set (90 days by default) and when the plugin is uninstalled. Login-attempt counters use keyed hashes rather than raw IP addresses or usernames and expire automatically.

The plugin sets no cookies and sends no data to the author or any third party. Suggested privacy-policy text is added under Settings > Privacy.

== External services ==

Vortix Web Security does not connect to any external service.

* The Security Scan and the `.htaccess` safety check request pages from **your own site** (loopback requests). No other server is contacted.
* When Cloudflare is the selected trusted proxy, the plugin reads the `CF-Connecting-IP` request header. It does not contact Cloudflare. The Cloudflare address ranges it compares against are stored in the plugin.
* The "View Premium Plans" button is an ordinary link. Nothing is requested or sent unless you click it, and the link opens the Pro product website in a new tab.

== Support ==

Use the support forum for this plugin on WordPress.org.

== Changelog ==

= 2.1.1 =
* Refreshed admin design: colour-coded status (green active/pass, red inactive/needs attention, yellow warnings), header banner, feature filter, score ring on the Security Scan screen.

= 2.1.0 =
* First WordPress.org release of the free edition. No license, trial or remote licensing code.
* Added the missing Basic Hardening and Disable XML-RPC features.
* Rebuilt the Modules screen: free features first, optional upgrade card beside it. Added Free Features and Upgrade to Premium screens.
* Automatic updates, `.htaccess` edits and XML-RPC blocking are now opt-in on new installs.
* `.htaccess` changes are verified with a loopback request and reverted if the server rejects them; the rules are simplified to avoid server errors on restrictive hosts.
* Fixed strong-password enforcement on the password-reset form.
* Fixed the log-retention setting being ignored by the daily cleanup.
* Trusted-proxy handling: Cloudflare mode now trusts only CF-Connecting-IP; a Settings screen lets you configure custom proxies.
* Security log stores the request path only, is rate-limited per IP and capped at 50,000 rows.
* Scanner: checks that cannot be verified are reported as such and excluded from the score; no longer calls `wp_head()`.
* Removed the admin-bar item and unused code.
