Real changes since 1.0.0, all live-verified before this release:
- Firewall: rule corpus expanded 19 -> 43 rules, real OWASP-CRS-equivalent
coverage (XXE, SSRF, session fixation, Log4Shell/JNDI, scanner-tool
detection, deeper SQL injection/XSS/PHP-injection).
- Fixed a real bug: a quarantined file's severity badge and its content
analysis score could disagree with no explanation (e.g. a benign file
showing CRITICAL next to Score 0); both are now derived consistently
and shown together.
- ARGUS now always keeps itself updated, and can optionally do the same
for every other installed plugin and theme (Settings, on by default) --
uses WordPress's own native update system, nothing custom.
- Global Threat Intelligence is now opt-in, not automatic -- a single
click on its own page, with an honest, specific description of exactly
what's shared (an IP address, a reason code, a confidence score, a
country). Previously connected automatically on activation.
- New first-run Welcome screen after activation: confirms what's already
protecting the site, and surfaces the few real optional choices in one
place.
- Dashboard: running version now visible in the header; new "IPs
Tracked" and "ANIS Protections" metrics.
- Full WordPress.org Plugin Directory readiness audit performed against
this codebase. Two real compliance issues found and fixed (see above:
Global Threat Intelligence's default, and the self-update mechanism,
which is excluded from this build entirely -- WordPress.org prohibits
a plugin from using any update channel other than its own, even an
inert one). This release is still self-distributed, not a WordPress.org
submission -- that remains a future step.
Verified before publishing: this exact ZIP was installed, activated (14
admin pages loaded clean, zero PHP errors/warnings), and uninstalled
(zero leftover database tables or options) in a fresh, disposable
WordPress + MySQL environment.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
No behavior or code change -- documentation only. Makes explicit what
was previously only implied: self-distributed (not on WordPress.org),
not independently security audited, no CI pipeline yet, tested on
disposable WordPress environments rather than live production sites,
and automatic updates are inactive pending real update infrastructure.
Automatic WordPress security: local firewall, malware and file-integrity
scanning, vulnerability protection, quarantine, scheduled backups, an
optional page cache, and automatic global threat intelligence.
See README.md for installation, update, and uninstall instructions.