Fixes a real bug: a normal (non-critical) update was previously detected and shown as available, but nothing ever actually installed it -- there was no button, cron path, or any other code that did. Automatic updates only ever worked for updates flagged critical, which isn't what "automatic" means. Now any newer, compatible, signature-verified update installs on its own. This is also the first release where the self-update mechanism itself ships in this self-distributed channel -- it was unconditionally excluded from every previous build (a WordPress.org-only restriction that doesn't apply here, since this channel isn't WordPress.org). manifest.json in this repo is the real, live update manifest: signed with Ed25519 (public key documented in README.md's Updating section), pointing at this exact release's ZIP and its real SHA-256. Verified end-to-end before publishing -- not just "the code looks right": ran a full real update cycle (an older installed version checking this manifest, downloading this exact package, verifying its signature and hash, replacing itself, and the site continuing to work with zero errors afterward) using the actual signing key and the actual package this commit ships. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
69 lines
2.9 KiB
Plaintext
69 lines
2.9 KiB
Plaintext
=== ARGUS WordPress Defence ===
|
|
Contributors: argus
|
|
Tags: security, firewall, malware, vulnerability, backup
|
|
Requires at least: 6.0
|
|
Tested up to: 7.0
|
|
Requires PHP: 7.4
|
|
Stable tag: 7.23.1
|
|
License: GPLv2 or later
|
|
License URI: https://www.gnu.org/licenses/gpl-2.0.html
|
|
|
|
Automatic, intelligent WordPress security. A local firewall, malware and file-integrity scanning,
|
|
vulnerability protection, and scheduled backups -- protecting your site with zero manual
|
|
configuration required.
|
|
|
|
== Description ==
|
|
|
|
ARGUS Defence protects your WordPress website automatically:
|
|
|
|
* **Firewall** -- blocks malicious requests (SQL injection, cross-site scripting, and more) before
|
|
they reach your site.
|
|
* **Scanner** -- regularly checks WordPress core, plugins, and themes for suspicious files and
|
|
integrity changes.
|
|
* **Vulnerability Protection** -- automatically checks your installed components against known
|
|
security issues.
|
|
* **Backups** -- scheduled recovery points for your website, stored securely.
|
|
* **Global Threat Intelligence** -- continuously updated, automatically connected, no setup
|
|
required.
|
|
|
|
Everything works out of the box. There is nothing to configure to get protected.
|
|
|
|
== Installation ==
|
|
|
|
1. Upload the plugin to your WordPress site (or install directly from the WordPress admin).
|
|
2. Activate the plugin.
|
|
3. That's it -- ARGUS Defence begins protecting your site automatically.
|
|
|
|
== Frequently Asked Questions ==
|
|
|
|
= Do I need to configure anything? =
|
|
|
|
No. ARGUS Defence is designed to work automatically. Advanced settings are available for
|
|
administrators who want them, but nothing is required to get protected.
|
|
|
|
= Will this slow down my website? =
|
|
|
|
No. ARGUS Defence's firewall and scanning run efficiently in the background, and the optional
|
|
page-cache feature can make your site faster, not slower.
|
|
|
|
= How do I update the plugin? =
|
|
|
|
Like any other WordPress.org plugin: you'll see an update notification right in your WordPress
|
|
dashboard whenever a new version is available, and you can update it in one click from there.
|
|
|
|
== Changelog ==
|
|
|
|
= 7.23.1 =
|
|
* Automatic updates: fixed a bug where a normal (non-critical) update would be detected and
|
|
shown as available, but never actually installed -- now any newer, compatible, verified
|
|
update installs automatically, the same way updates to other plugins already do.
|
|
|
|
= 7.23.0 =
|
|
* Firewall: broadened local rule coverage (XXE, SSRF, session fixation, Log4Shell/JNDI, scanner-tool
|
|
detection, and deeper SQL injection / XSS / PHP injection signatures).
|
|
* Scanner: fixed a case where a quarantined file's severity label and its content-analysis score
|
|
could disagree; both are now always shown together and derived consistently.
|
|
* Console: the running plugin version is now shown in the admin header.
|
|
* First production release: firewall, scanner, quarantine, vulnerability protection, backups,
|
|
cache & performance, and automatic global threat intelligence.
|