Files
ARGUSandClaude Sonnet 5 c4db87af84 ARGUS WordPress Defence 7.23.2
- New: License section in Settings -- a 30-day trial with every
  feature active starts automatically, no registration required to
  start. Protection continues regardless of license status; the trial
  only affects what's shown, never what's enforced. Enter a license
  key to keep Premium features once the trial ends. This is the first
  release where the license system is actually visible anywhere --
  it existed in the codebase before but had no entry form and was
  excluded from every published build.
- Intelligence page: rewrote descriptions in plain language about what
  each thing does for your site's protection, not internal
  implementation details (was showing raw technical descriptions like
  a "signature corpus" and "RIR delegation database" range counts).

Verified end-to-end before publishing (not just code review): a real
signup and license created on the actual companion license service,
then submitted through the real Settings page form exactly as a
customer would -- status went from "TRIAL -- 30 DAYS LEFT" to
"LICENSED" on both the Settings and Overview pages. This exact ZIP was
also installed fresh and every admin page loaded with zero errors
before this commit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-09 19:37:16 +00:00

127 lines
6.0 KiB
Markdown

# ARGUS WordPress Defence
Automatic WordPress security. A local firewall, malware and file-integrity scanning,
vulnerability protection, and scheduled backups — protecting your site with zero manual
configuration required.
**Version:** 7.23.2
**Requires:** WordPress 6.0+, PHP 7.4+
**License:** GPLv2 or later
## What it does
- **Firewall** — blocks malicious requests (SQL injection, cross-site scripting, remote code
execution, XXE, SSRF, and more) before they reach your site.
- **Scanner** — regularly checks WordPress core, plugins, and themes for suspicious files
and integrity changes, and quarantines confirmed threats instead of just reporting them.
- **Vulnerability Protection** — checks your installed plugins, themes, and WordPress core
against known security issues.
- **Backups** — scheduled recovery points for your site's database and files, stored
outside the web root.
- **Cache & Performance** — an optional page cache that can make your site faster, built
to never interfere with the firewall or bans.
- **Automatic Updates** — ARGUS always keeps itself up to date, and can optionally do the
same for every other installed plugin and theme.
- **Global Threat Intelligence (optional)** — share reputation data about the IP addresses
ARGUS blocks with a global network, and benefit from what every other connected site has
already seen. Off by default — turning it on is a single click, no fields to fill in, and
its own settings page shows exactly what is and isn't shared.
Everything except Global Threat Intelligence works out of the box. There is nothing to
configure to get protected.
**License**: a 30-day trial with every feature active starts automatically on activation --
no registration required to start. Protection never stops when the trial ends; ARGUS Defence →
Settings → License shows the days remaining and where to enter a license key to keep Premium
features. This section is specific to this self-distributed build.
## Status
This is a self-distributed release: it is not listed on WordPress.org and has not gone
through that team's plugin review process (a submission is planned for the future — this
release is not it).
- **Not independently security audited.** It has been reviewed internally (code review,
static checks, a manual security pass over authentication/authorization/nonce/SQL
handling), but no third-party security audit or penetration test has been performed.
- **No CI pipeline yet.** Tests are run manually before each release, not on every commit.
- **Tested in sandbox/disposable WordPress environments.** Verification so far — install,
activation, all admin pages, deactivation, uninstall — was done on disposable WordPress
instances, not on live production sites.
- **Automatic updates for ARGUS itself are opt-in, not on by default.** The signed-update
mechanism is real and live (this release's own manifest is signed and hosted in this
repository) -- add two constants to `wp-config.php` to turn it on. See
[Updating](#updating) below for the exact lines and how to verify it's working.
Automatic updates for *other* plugins/themes on your site, if you enable that option in
Settings, use WordPress's own built-in update system and work without any extra setup.
## Installation
1. Download the latest release ZIP (see [Releases](#releases) below).
2. In your WordPress admin: **Plugins → Add New → Upload Plugin**, choose the downloaded
ZIP, then **Install Now**.
3. Click **Activate**.
That's it — ARGUS Defence begins protecting your site automatically. A short Welcome screen
walks through what's already active and a couple of optional choices (a site-type template,
Global Threat Intelligence). A new **ARGUS Defence** menu also appears in your wp-admin
sidebar with an overview of your site's protection status.
## Updating
**Automatic** — add these two lines to `wp-config.php` (above the
`/* That's all, stop editing! */` line):
```php
define( 'ARGUS_WPD_UPDATE_MANIFEST_URL', 'https://git-cloud.weboria.eu/Weboria/argus-wp-defence/raw/branch/main/manifest.json' );
define( 'ARGUS_WPD_UPDATE_PUBLIC_KEY', 'jBQFZLG+fvtW9y7kmhJa4BTBw8u3lmxbgOcF2ptEhFs=' );
```
From then on ARGUS checks for updates every few hours and installs anything newer
automatically, after verifying its Ed25519 signature and SHA-256 checksum. To check
immediately instead of waiting: **ARGUS Defence → Settings → Automatic Security Updates →
Check for Updates Now**, which also shows the current status (last check, last successful
update, last failure).
**Manual** — download the new release ZIP and upload it through **Plugins → Add New →
Upload Plugin** — WordPress will offer to replace the existing version. Works with or
without the automatic option configured.
## Uninstalling
Deactivate and delete the plugin from the **Plugins** page as you would any other
WordPress plugin. All ARGUS Defence data (settings, scan history, quarantined files,
database tables) is removed automatically — nothing is left behind.
## Releases
Each release is published as a ZIP with an accompanying SHA-256 checksum. Verify the
download before installing it on a production site:
```
sha256sum argus-wordpress-defence-X.Y.Z.zip
```
Compare the result against the checksum published alongside that release.
## Source layout
```
argus-wordpress-defence.php Plugin entry point (admin UI, cron, activation)
mu-loader/ Tamper-resistant enforcement core (installed as a Must-Use
plugin, keeps running even if the main plugin is deactivated)
includes/ Firewall, ban/policy engine, scanner, quarantine, backups,
vulnerability intelligence, cache
admin/ wp-admin dashboard and settings pages
bin/ Release packaging and signing tools (not shipped in the
plugin ZIP)
```
## Support
Please open an issue in this repository.
## License
GPLv2 or later. See [LICENSE](LICENSE).