- New: License section in Settings -- a 30-day trial with every feature active starts automatically, no registration required to start. Protection continues regardless of license status; the trial only affects what's shown, never what's enforced. Enter a license key to keep Premium features once the trial ends. This is the first release where the license system is actually visible anywhere -- it existed in the codebase before but had no entry form and was excluded from every published build. - Intelligence page: rewrote descriptions in plain language about what each thing does for your site's protection, not internal implementation details (was showing raw technical descriptions like a "signature corpus" and "RIR delegation database" range counts). Verified end-to-end before publishing (not just code review): a real signup and license created on the actual companion license service, then submitted through the real Settings page form exactly as a customer would -- status went from "TRIAL -- 30 DAYS LEFT" to "LICENSED" on both the Settings and Overview pages. This exact ZIP was also installed fresh and every admin page loaded with zero errors before this commit. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
127 lines
6.0 KiB
Markdown
127 lines
6.0 KiB
Markdown
# ARGUS WordPress Defence
|
|
|
|
Automatic WordPress security. A local firewall, malware and file-integrity scanning,
|
|
vulnerability protection, and scheduled backups — protecting your site with zero manual
|
|
configuration required.
|
|
|
|
**Version:** 7.23.2
|
|
**Requires:** WordPress 6.0+, PHP 7.4+
|
|
**License:** GPLv2 or later
|
|
|
|
## What it does
|
|
|
|
- **Firewall** — blocks malicious requests (SQL injection, cross-site scripting, remote code
|
|
execution, XXE, SSRF, and more) before they reach your site.
|
|
- **Scanner** — regularly checks WordPress core, plugins, and themes for suspicious files
|
|
and integrity changes, and quarantines confirmed threats instead of just reporting them.
|
|
- **Vulnerability Protection** — checks your installed plugins, themes, and WordPress core
|
|
against known security issues.
|
|
- **Backups** — scheduled recovery points for your site's database and files, stored
|
|
outside the web root.
|
|
- **Cache & Performance** — an optional page cache that can make your site faster, built
|
|
to never interfere with the firewall or bans.
|
|
- **Automatic Updates** — ARGUS always keeps itself up to date, and can optionally do the
|
|
same for every other installed plugin and theme.
|
|
- **Global Threat Intelligence (optional)** — share reputation data about the IP addresses
|
|
ARGUS blocks with a global network, and benefit from what every other connected site has
|
|
already seen. Off by default — turning it on is a single click, no fields to fill in, and
|
|
its own settings page shows exactly what is and isn't shared.
|
|
|
|
Everything except Global Threat Intelligence works out of the box. There is nothing to
|
|
configure to get protected.
|
|
|
|
**License**: a 30-day trial with every feature active starts automatically on activation --
|
|
no registration required to start. Protection never stops when the trial ends; ARGUS Defence →
|
|
Settings → License shows the days remaining and where to enter a license key to keep Premium
|
|
features. This section is specific to this self-distributed build.
|
|
|
|
## Status
|
|
|
|
This is a self-distributed release: it is not listed on WordPress.org and has not gone
|
|
through that team's plugin review process (a submission is planned for the future — this
|
|
release is not it).
|
|
|
|
- **Not independently security audited.** It has been reviewed internally (code review,
|
|
static checks, a manual security pass over authentication/authorization/nonce/SQL
|
|
handling), but no third-party security audit or penetration test has been performed.
|
|
- **No CI pipeline yet.** Tests are run manually before each release, not on every commit.
|
|
- **Tested in sandbox/disposable WordPress environments.** Verification so far — install,
|
|
activation, all admin pages, deactivation, uninstall — was done on disposable WordPress
|
|
instances, not on live production sites.
|
|
- **Automatic updates for ARGUS itself are opt-in, not on by default.** The signed-update
|
|
mechanism is real and live (this release's own manifest is signed and hosted in this
|
|
repository) -- add two constants to `wp-config.php` to turn it on. See
|
|
[Updating](#updating) below for the exact lines and how to verify it's working.
|
|
Automatic updates for *other* plugins/themes on your site, if you enable that option in
|
|
Settings, use WordPress's own built-in update system and work without any extra setup.
|
|
|
|
## Installation
|
|
|
|
1. Download the latest release ZIP (see [Releases](#releases) below).
|
|
2. In your WordPress admin: **Plugins → Add New → Upload Plugin**, choose the downloaded
|
|
ZIP, then **Install Now**.
|
|
3. Click **Activate**.
|
|
|
|
That's it — ARGUS Defence begins protecting your site automatically. A short Welcome screen
|
|
walks through what's already active and a couple of optional choices (a site-type template,
|
|
Global Threat Intelligence). A new **ARGUS Defence** menu also appears in your wp-admin
|
|
sidebar with an overview of your site's protection status.
|
|
|
|
## Updating
|
|
|
|
**Automatic** — add these two lines to `wp-config.php` (above the
|
|
`/* That's all, stop editing! */` line):
|
|
|
|
```php
|
|
define( 'ARGUS_WPD_UPDATE_MANIFEST_URL', 'https://git-cloud.weboria.eu/Weboria/argus-wp-defence/raw/branch/main/manifest.json' );
|
|
define( 'ARGUS_WPD_UPDATE_PUBLIC_KEY', 'jBQFZLG+fvtW9y7kmhJa4BTBw8u3lmxbgOcF2ptEhFs=' );
|
|
```
|
|
|
|
From then on ARGUS checks for updates every few hours and installs anything newer
|
|
automatically, after verifying its Ed25519 signature and SHA-256 checksum. To check
|
|
immediately instead of waiting: **ARGUS Defence → Settings → Automatic Security Updates →
|
|
Check for Updates Now**, which also shows the current status (last check, last successful
|
|
update, last failure).
|
|
|
|
**Manual** — download the new release ZIP and upload it through **Plugins → Add New →
|
|
Upload Plugin** — WordPress will offer to replace the existing version. Works with or
|
|
without the automatic option configured.
|
|
|
|
## Uninstalling
|
|
|
|
Deactivate and delete the plugin from the **Plugins** page as you would any other
|
|
WordPress plugin. All ARGUS Defence data (settings, scan history, quarantined files,
|
|
database tables) is removed automatically — nothing is left behind.
|
|
|
|
## Releases
|
|
|
|
Each release is published as a ZIP with an accompanying SHA-256 checksum. Verify the
|
|
download before installing it on a production site:
|
|
|
|
```
|
|
sha256sum argus-wordpress-defence-X.Y.Z.zip
|
|
```
|
|
|
|
Compare the result against the checksum published alongside that release.
|
|
|
|
## Source layout
|
|
|
|
```
|
|
argus-wordpress-defence.php Plugin entry point (admin UI, cron, activation)
|
|
mu-loader/ Tamper-resistant enforcement core (installed as a Must-Use
|
|
plugin, keeps running even if the main plugin is deactivated)
|
|
includes/ Firewall, ban/policy engine, scanner, quarantine, backups,
|
|
vulnerability intelligence, cache
|
|
admin/ wp-admin dashboard and settings pages
|
|
bin/ Release packaging and signing tools (not shipped in the
|
|
plugin ZIP)
|
|
```
|
|
|
|
## Support
|
|
|
|
Please open an issue in this repository.
|
|
|
|
## License
|
|
|
|
GPLv2 or later. See [LICENSE](LICENSE).
|