=== WP Malware Guard ===
Contributors: swadhinkhan
Tags: security, malware, firewall, audit, hardening
Requires at least: 6.0
Tested up to: 6.6
Requires PHP: 7.4
Stable tag: 0.4.20
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

WordPress malware protection, audit logging, firewall controls, file scanning, hardening, reports, and commercial licensing.

== Description ==

WP Malware Guard helps site owners monitor and respond to WordPress security threats.

Features include:

* SOC-grade security audit event log with IP, method, URI, user agent, severity, category, risk score, MITRE, and OWASP context.
* SQL injection, XSS, RCE, file inclusion, scanner, enumeration, and web-shell request detection.
* Monitor or block firewall modes with active-defense IP blocking.
* Manual IP/CIDR blocks with bulk management and Cloudflare edge push.
* Rate limiting.
* Login brute-force protection.
* Malware/file scanner with paginated findings, bulk export, and bulk quarantine.
* WordPress core checksum checks.
* File quarantine, restore, and delete response controls.
* XML-RPC, REST API, version-signal, custom login URL, directory indexing, security header, author-enumeration, and permission hardening.
* Form CAPTCHA protection with built-in math CAPTCHA, Google reCAPTCHA v2, and Cloudflare Turnstile for login, registration, lost password, comments, and WooCommerce forms.
* Email alerts and SIEM webhook routing.
* SOC dashboard, live view, charts, and session timeline correlation.
* Threat simulator for brute force, SQL injection, XSS, and malicious upload drills.
* Cloudflare edge blocking.
* HTML and A4 PDF security reports.
* Evidence backup exports plus full-site backup and restore controls.
* CSV/JSON compliance exports, retention cleanup, pagination, and bulk actions.
* Commercial license activation and validation.

== Installation ==

1. Upload the plugin ZIP from the `dist` folder.
2. Activate WP Malware Guard.
3. Open Malware Guard in wp-admin.
4. Run a file scan and review firewall settings.

== Changelog ==

= 0.4.20 =
* Added relevant icons to dashboard, SOC, scanner, timeline, and tool metric cards while keeping the existing colored stat shapes.
* Rebuilt the Free and Pro packages for the icon-enhanced admin dashboard release.

= 0.4.19 =
* Split release packaging into Free and Pro ZIP flows. Free shows upgrade packages only; Pro handles Dodo license activation.
* Improved license status display with inferred site limits and clearer subscription fallback labels when Dodo public validation omits fields.
* Added Free-build guards so license forms and Pro activation messages only appear in the Pro package.

= 0.4.18 =
* Restored the public landing page to use the website theme header and footer instead of the standalone product navigation and footer.
* Updated public download links for the 0.4.18 release package.

= 0.4.17 =
* Hardened Pro license enforcement so expired returned dates, suspended, inactive, past-due, cancelled, revoked, and disabled states keep Pro workflows locked.
* Added the current license status reason to Pro-gated screens so admins can see why a paid workflow is unavailable.
* Added daily background license revalidation that can pull remote Dodo status changes without disabling valid customers on transient HTTP failures.

= 0.4.16 =
* Fixed landing page feature-card text alignment by scoping WordPress wrapper padding resets away from inner product cards.
* Improved feature anchor spacing and title scale so the features section opens cleanly on desktop and mobile.

= 0.4.15 =
* Redesigned the public landing page with a responsive Hallmark Bento Grid structure.
* Improved mobile text wrapping, standalone landing navigation, feature presentation, and image layout stability.

= 0.4.14 =
* Clarified Free, Pro, 10 Site Pro, and Agency feature availability in the plugin License page and public landing page.
* Added an in-admin feature matrix showing which workflows are included in Free versus paid plans.

= 0.4.13 =
* Added form CAPTCHA protection with built-in math CAPTCHA, Google reCAPTCHA v2 checkbox, and Cloudflare Turnstile.
* Added CAPTCHA targeting for WordPress login, registration, lost password, comments, WooCommerce login, WooCommerce registration, and WooCommerce checkout forms.
* Added a [wpmg_captcha] shortcode and WPMG_Captcha::verify_request("custom") helper for custom form integrations.

= 0.4.12 =
* Added recommended-action guidance to Last Scan Results for file-limit hits, high finding counts, critical findings, upload PHP, core integrity issues, file permissions, and suspicious PHP review.

= 0.4.11 =
* Fixed the internal Tools menu layout so focused tool links open as a compact plugin dropdown without breaking the main navigation row.

= 0.4.10 =
* Added an internal Tools group in the WP Malware Guard navigation with direct links to Suspicious Files, Sensitive Files, File Monitoring, Obfuscated PHP, File Permissions, Core Integrity, and Quarantine Manager.
* Added a focused security tools grid on the plugin Tools page for quicker access to the same investigation screens.

= 0.4.9 =
* Added Events over Time visualization with chart type controls, remembered browser preferences, range chips, stacked mode, and rich tooltips.
* Added Log Correlation and Attack Timeline controls with grouping, search, date range filtering, risk bands, scatter timeline, and expandable session logs.
* Added focused Tools pages for suspicious files, sensitive files, monitoring, obfuscated PHP, permissions, core integrity, and quarantine management.

= 0.4.8 =
* Rebuilt the public landing page with a Hallmark Workbench layout, cleaner professional styling, and live Dodo purchase calls to action.
* Updated public download links for the 0.4.8 release package.

= 0.4.7 =
* Connected admin and landing pricing actions to live Dodo checkout products for monthly, yearly, and lifetime plans.
* Added Dodo license ID, subscription ID, activation limit, and site usage display when returned by Dodo validation.
* Added built-in product ID tier mapping for the live WP Malware Guard Dodo products.

= 0.4.6 =
* Hid third-party onboarding popovers on WP Malware Guard admin pages so dashboard charts stay unobstructed.

= 0.4.5 =
* Added richer dashboard and SOC chart cards for severity mix and category volume.
* Added organized session timeline cards with risk meters and event steps.
* Added the last 10 report exports with HTML and PDF download actions.
* Added license package cards with Free, Single Site Pro, 10 Site Pro, and Agency purchase links.
* Changed simulator success feedback to a green-on-black terminal process log.

= 0.4.4 =
* Added console-style Threat Simulator drill output with richer safe synthetic evidence.
* Added simulator drill IDs, request samples, detector summaries, and safety notes to recent events and reports.
* Added dedicated Threat Simulator Drill Evidence sections to HTML and A4 PDF reports.

= 0.4.3 =
* Suppressed unrelated third-party notices inside WP Malware Guard pages while preserving native WP Malware Guard notices.

= 0.4.2 =
* Kept third-party WordPress admin notices out of the custom title card while preserving the refreshed dashboard UI.

= 0.4.1 =
* Refreshed the admin UI with a light analytics dashboard style, coral action accents, cleaner cards, improved tables, and section navigation.

= 0.4.0 =
* Added explicit Basic, Active, and Under Attack security modes with effective firewall/rate-limit profiles.
* Added SOC status pills, Tools page, and centralized Settings page to match the requested admin workflow.
* Improved compatibility with Dodo Payments license activation responses that return an activated instance without a literal status field.

= 0.3.1 =
* Improved compatibility with Dodo Payments license activation responses that return an activated instance without a literal status field.

= 0.3.0 =
* Added Pro SOC dashboard with lightweight charts, live view, and session correlator.
* Added Alert Center with email severity controls and SIEM webhook routing.
* Added A4 PDF report generation with site identity, footer, timestamp, hardening status, scan details, and framework mappings.
* Added pagination, per-page controls, CSV/JSON exports, and bulk actions for row-heavy admin pages.
* Added threat simulator for brute force, SQL injection, XSS, and malicious upload training drills.
* Added complete backup and restore controls with database SQL, files, evidence, and controlled restore scopes.
* Added hardening controls for custom login URL, directory indexing, security headers, author enumeration, and file permissions.
* Added quarantine restore/delete controls and active-defense IP blocks for high-risk web attacks.
* Fixed admin notice color inheritance inside the plugin UI.

= 0.2.1 =
* Added explicit Cloudflare token clearing.
* Reduced browser password-manager autofill risk on Cloudflare credential fields.

= 0.2.0 =
* Added session timeline correlation.
* Added Cloudflare edge blocking settings and push workflow.
* Added HTML report generation.
* Added evidence backup exports.
* Updated public copy and versioning.

= 0.1.0 =
* Initial product build.
