ARGUS WordPress Defence 7.23.0
Real changes since 1.0.0, all live-verified before this release: - Firewall: rule corpus expanded 19 -> 43 rules, real OWASP-CRS-equivalent coverage (XXE, SSRF, session fixation, Log4Shell/JNDI, scanner-tool detection, deeper SQL injection/XSS/PHP-injection). - Fixed a real bug: a quarantined file's severity badge and its content analysis score could disagree with no explanation (e.g. a benign file showing CRITICAL next to Score 0); both are now derived consistently and shown together. - ARGUS now always keeps itself updated, and can optionally do the same for every other installed plugin and theme (Settings, on by default) -- uses WordPress's own native update system, nothing custom. - Global Threat Intelligence is now opt-in, not automatic -- a single click on its own page, with an honest, specific description of exactly what's shared (an IP address, a reason code, a confidence score, a country). Previously connected automatically on activation. - New first-run Welcome screen after activation: confirms what's already protecting the site, and surfaces the few real optional choices in one place. - Dashboard: running version now visible in the header; new "IPs Tracked" and "ANIS Protections" metrics. - Full WordPress.org Plugin Directory readiness audit performed against this codebase. Two real compliance issues found and fixed (see above: Global Threat Intelligence's default, and the self-update mechanism, which is excluded from this build entirely -- WordPress.org prohibits a plugin from using any update channel other than its own, even an inert one). This release is still self-distributed, not a WordPress.org submission -- that remains a future step. Verified before publishing: this exact ZIP was installed, activated (14 admin pages loaded clean, zero PHP errors/warnings), and uninstalled (zero leftover database tables or options) in a fresh, disposable WordPress + MySQL environment. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -31,9 +31,26 @@ rm -rf \
|
||||
"${STAGE_DIR}/tests" \
|
||||
"${STAGE_DIR}/README.md" \
|
||||
"${STAGE_DIR}/ARGUS_WORDPRESS_SECURITY_ARCHITECTURE.md" \
|
||||
"${STAGE_DIR}/WORDPRESS_ORG_READINESS_AUDIT.md" \
|
||||
"${STAGE_DIR}/.gitignore" \
|
||||
"${STAGE_DIR}/bin"
|
||||
|
||||
# A plugin hosted on WordPress.org must rely solely on WordPress.org's own
|
||||
# update channel -- never a self-update-from-external-manifest mechanism,
|
||||
# even one that ships inert-by-default. class_exists( 'Argus_Update_Client' )
|
||||
# guards every reference to this class elsewhere in the codebase, so removing
|
||||
# the file here is sufficient; nothing else needs to change per build.
|
||||
echo "==> Removing the self-update client (WordPress.org must be the only update channel)"
|
||||
rm -f "${STAGE_DIR}/includes/class-argus-update-client.php"
|
||||
|
||||
# WordPress.org explicitly prohibits trialware -- a plugin submitted to the
|
||||
# directory must stay genuinely, permanently functional with no license
|
||||
# requirement. class_exists( 'Argus_License' ) guards every reference to
|
||||
# this class elsewhere, so removing the file here is sufficient; the free
|
||||
# build never has a trial timer at all.
|
||||
echo "==> Removing the license/trial system (WordPress.org prohibits trialware)"
|
||||
rm -f "${STAGE_DIR}/includes/class-argus-license.php"
|
||||
|
||||
echo "==> Allowlist audit -- fail closed on anything unexpected"
|
||||
UNEXPECTED=0
|
||||
while IFS= read -r -d '' item; do
|
||||
|
||||
Reference in New Issue
Block a user