=== Webro Security ===
Contributors: webrodk, lasseenggaard, rirasmussen
Tags: security, csp, login-protection, smtp, spam-protection
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.0.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Adds security headers, CSP, login protection, SMTP configuration and spam protection to harden your WordPress site.

== Description ==

A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam protection and more. Functionality is continuously being expanded to cover more ground.

= Features =

* Adds security headers, including configurable HSTS, X-Frame-Options, COOP and CORP
* Supports Content Security Policy (CSP), editable from the admin UI and validated against unrecognized directives
* Protects login with rate-limiting
* Blocks weak passwords, with an exemption list for individual users
* Blocks common/guessable usernames
* Validates protected brand names against required domains — self-registration blocks a brand-impersonating email outright
* Locks file editing, with a temporary admin-bar toggle that automatically relocks after a period of inactivity
* Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)
* Custom SMTP sending, with a test-email button
* Central security log with automatic retention, including new user account creation
* Removes certain default WordPress traces from `<head>`
* Blocks usernames from leaking through author URLs, the REST API and embedded author data
* English, with community translations available via translate.wordpress.org

= What does it protect against? =

* Basic login attacks
* Some forms of user enumeration
* Unwanted WordPress metadata
* Missing security headers

**Important:** it does not protect against vulnerabilities in other plugins or themes, poor server configuration, or missing updates.

= Compatibility =

Some security headers can affect elements such as iframes, embeds and third-party scripts. Some of the CSP directives may be too strict and might need loosening depending on your needs — this is done from the admin UI's CSP field (administrator role).

== Installation ==

1. Upload the plugin to `wp-content/plugins/`
2. Activate it via the WordPress admin panel

= Uninstallation =

* Removes the plugin's saved options
* Removes the plugin's transients
* Cleans up its own settings on uninstall

== Changelog ==

= 1.0.4 =
* Fixed the security headers blocking the block editor when adding a new page/post: blob: is now allowed in the frame-src and connect-src directives of the default CSP
* wp-admin and wp-login are now excluded from the .htaccess security headers without depending on the mod_setenvif Apache module, also on sites installed in a subdirectory
* The PHP fallback for the security headers no longer applies to wp-admin and wp-login
* After an update, the plugin now rewrites its .htaccess security headers itself and drops an outdated saved default CSP, so the settings no longer have to be re-saved by hand
* Hardened the honeypot: the timing check is now signed by the server, and the way the honeypot field is hidden varies between page loads
* Expanded the list of blocked usernames
* The author name and author URL are no longer exposed in oEmbed responses, and WordPress' built-in users sitemap is turned off, since both revealed usernames to visitors who are not logged in

= 1.0.0 =
* First version

== Support ==

Contact webro with questions or bug reports at len@webro.dk
