PluginProbe
Patchstack – WordPress & Plugins Security / 2.2.11
Patchstack – WordPress & Plugins Security v2.2.11
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
← All changes | patchstack.php +36 -32 2.1.252.2.11 View file →
@@ -1,10 +1,11 @@
1 1 <?php
2 2 /**
3 3 * Plugin Name: Patchstack Security
4 - * Plugin URI: https://patchstack.com
4 + * Plugin URI: https://patchstack.com/?utm_medium=wp&utm_source=dashboard&utm_campaign=patchstack%20plugin
5 + * Author URI: https://patchstack.com/?utm_medium=wp&utm_source=dashboard&utm_campaign=patchstack%20plugin
5 6 * Description: Patchstack identifies security vulnerabilities in WordPress plugins, themes, and core.
6 - * Version: 2.1.25
7 + * Version: 2.2.11
7 8 * Author: Patchstack
8 9 * License: GPLv3
9 10 * Text Domain: patchstack
10 11 * Domain Path: /languages
@@ -32,9 +33,9 @@
32 33
33 34 // Set up our filename.
34 35 $file_name = strtolower( str_replace( '_', '-', substr( $class_name, strlen( 'P_' ) ) ) );
35 36 $dir = trailingslashit( dirname( __FILE__ ) ) . 'includes/';
36 - $target = array( $dir . $file_name . '.php', $dir . 'admin/' . str_replace( 'admin-', '', $file_name ) . '.php' );
37 + $target = [ $dir . $file_name . '.php', $dir . 'admin/' . str_replace( 'admin-', '', $file_name ) . '.php' ];
37 38
38 39 // Attempt each target and load if it exists.
39 40 foreach ( $target as $file ) {
40 41 if ( file_exists( $file ) ) {
@@ -57,9 +58,9 @@
57 58 * The plugin version.
58 59 *
59 60 * @var string
60 61 */
61 - const VERSION = '2.1.25';
62 + const VERSION = '2.2.11';
62 63
63 64 /**
64 65 * API URL of Patchstack to communicate with.
65 66 *
@@ -113,9 +114,9 @@
113 114 * Detailed activation error messages.
114 115 *
115 116 * @var array
116 117 */
117 - protected $activation_errors = array();
118 + protected $activation_errors = [];
118 119
119 120 /**
120 121 * Singleton instance of plugin.
121 122 *
@@ -142,9 +143,8 @@
142 143 protected $hide_login;
143 144 protected $listener;
144 145 protected $event_log;
145 146 protected $multisite;
146 - protected $notice;
147 147 protected $admin_ajax;
148 148 protected $admin_general;
149 149 protected $admin_menu;
150 150 protected $admin_options;
@@ -183,9 +183,9 @@
183 183 * @return void
184 184 */
185 185 public function plugin_classes() {
186 186 // Define the array of the classes.
187 - foreach ( array(
187 + foreach ( [
188 188 'admin_options' => 'P_Admin_Options',
189 189 'cron' => 'P_Cron',
190 190 'api' => 'P_Api',
191 191 'login' => 'P_Login',
@@ -195,20 +195,20 @@
195 195 'hacker_log' => 'P_Hacker_Log',
196 196 'upload' => 'P_Upload',
197 197 'rules' => 'P_Rules',
198 198 'hide_login' => 'P_Hide_Login',
199 - 'listener' => 'P_Listener',
200 199 'event_log' => 'P_Event_Log',
201 200 'activation' => 'P_Activation',
201 + 'listener' => 'P_Listener',
202 202 'multisite' => 'P_Multisite',
203 - 'notice' => 'P_Cookie_Notice',
204 203 'admin_ajax' => 'P_Admin_Ajax',
205 204 'admin_general' => 'P_Admin_General',
206 205 'admin_menu' => 'P_Admin_Menu',
207 - ) as $var => $class ) {
206 + ] as $var => $class ) {
208 207 $this->$var = new $class( $this );
209 208 }
210 209
210 + // Load firewall base functionality.
211 211 $this->firewall_base = new P_Firewall( true, $this, true );
212 212 }
213 213
214 214 /**
@@ -227,22 +227,35 @@
227 227 * Returns an error if the connection was not successful.
228 228 *
229 229 * ## OPTIONS
230 230 *
231 - * <id>
231 + * [<id>]
232 232 * : The API client id.
233 233 *
234 - * <secret>
234 + * [<secret>]
235 235 * : The API secret key.
236 - *
236 + *
237 + * <secret-id>
238 + * : The API client id and secret key merged together, found in the App. E.g. 2b072e8b60402e30d481df351fc08183906254e0-123456
239 + *
237 240 * ## EXAMPLES
238 - *
241 + *
239 242 * $ wp patchstack activate 123456 2b072e8b60402e30d481df351fc08183906254e0
240 243 * Success: The Patchstack plugin has been successfully connected.
244 + *
245 + * or
246 + *
247 + * $ wp patchstack activate 2b072e8b60402e30d481df351fc08183906254e0-123456
248 + * Success: The Patchstack plugin has been successfully connected.
241 249 */
242 250 public function cli_activate( $args ) {
243 - $id = isset( $args[0] ) ? trim( $args[0] ) : '';
244 - $secret = isset( $args[1] ) ? trim( $args[1] ) : '';
251 + // Handle both ways to activate the plugin.
252 + if ( count( $args ) === 1 && strpos( $args[0], '-' ) !== false ) {
253 + list( $secret, $id ) = explode( '-', $args[0] );
254 + } else {
255 + $id = isset( $args[0] ) ? trim( $args[0] ) : '';
256 + $secret = isset( $args[1] ) ? trim( $args[1] ) : '';
257 + }
245 258
246 259 $result = $this->activation->alter_license( $id, $secret, 'activate' );
247 260 if ( $result['result'] == 'error' ) {
248 261 \WP_CLI::error( 'The Patchstack plugin could not be connected. Make sure the id and secret key are valid and that api.patchstack.com is not blocked.' );
@@ -262,21 +275,12 @@
262 275 $this->activation->deactivate();
263 276 }
264 277
265 278 /**
266 - * Boot Patchstack and its classes.
279 + * Boot Patchstack.
267 280 *
268 281 * @return void
269 282 */
270 - public function hooks() {
271 - add_action( 'init', array( $this, 'init' ), ~PHP_INT_MAX );
272 - }
273 -
274 - /**
275 - * Boot Patchstack
276 - *
277 - * @return void
278 - */
279 283 public function init() {
280 284 // Load translated strings for plugin.
281 285 load_plugin_textdomain( 'patchstack', false, dirname( $this->basename ) . '/languages/' );
282 286
@@ -290,9 +294,9 @@
290 294 if ( get_option( 'patchstack_api_token', '' ) == '' && get_option( 'patchstack_license_expiry', '' ) == '' ) {
291 295 $this->api->update_license_status();
292 296 }
293 297
294 - // Determine if the license is activated and not expired.
298 + // Run firewall if not disabled and license activated.
295 299 if ( get_option( 'patchstack_license_activated', 0 ) == 1 && get_option( 'patchstack_basic_firewall', 0 ) == 1 && get_option( 'patchstack_license_free', 0 ) == 0 ) {
296 300 $this->firewall = new P_Firewall( true, $this );
297 301 }
298 302 }
@@ -347,9 +351,9 @@
347 351 * @return void
348 352 */
349 353 function patchstack_uninstall() {
350 354 // Delete most of the Patchstack options.
351 - $options = array( 'patchstack_eventlog_lastid', 'patchstack_api_token', 'patchstack_dashboardlock', 'patchstack_pluginedit', 'patchstack_move_logs', 'patchstack_userenum', 'patchstack_basicscanblock', 'patchstack_hidewpcontent', 'patchstack_hidewpversionk', 'patchstack_prevent_default_file_access', 'patchstack_basic_firewall', 'patchstack_known_blacklist', 'patchstack_block_debug_log_access', 'patchstack_block_fake_bots', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_bad_query_strings', 'patchstack_advanced_character_string_filter', 'patchstack_advanced_blacklist_firewall', 'patchstack_forbid_rfi', 'patchstack_image_hotlinking', 'patchstack_add_security_headers', 'patchstack_firewall_log_lastid', 'patchstack_user_log_lastid', 'patchstack_captcha_public_key', 'patchstack_captcha_private_key', 'patchstack_scan_interval', 'patchstack_scan_day', 'patchstack_scan_time', 'patchstack_hackers_log', 'patchstack_users_log', 'patchstack_visitors_log', 'external_updates-webarx', 'patchstack_wp_stats', 'patchstack_captcha_login_form', 'patchstack_license_activated', 'patchstack_license_expiry', 'patchstack_software_data_hash', 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_googledrive_backup_is_running', 'patchstack_googledrive_upload_state', 'patchstack_googledrive_access_token', 'patchstack_googledrive_refresh_token', 'patchstack_cron_offset', 'patchstack_htaccess_rules_hash' );
355 + $options = [ 'patchstack_eventlog_lastid', 'patchstack_api_token', 'patchstack_dashboardlock', 'patchstack_pluginedit', 'patchstack_move_logs', 'patchstack_userenum', 'patchstack_basicscanblock', 'patchstack_hidewpcontent', 'patchstack_hidewpversionk', 'patchstack_prevent_default_file_access', 'patchstack_basic_firewall', 'patchstack_known_blacklist', 'patchstack_block_debug_log_access', 'patchstack_block_fake_bots', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_bad_query_strings', 'patchstack_advanced_character_string_filter', 'patchstack_advanced_blacklist_firewall', 'patchstack_forbid_rfi', 'patchstack_image_hotlinking', 'patchstack_add_security_headers', 'patchstack_firewall_log_lastid', 'patchstack_user_log_lastid', 'patchstack_captcha_public_key', 'patchstack_captcha_private_key', 'patchstack_scan_interval', 'patchstack_scan_day', 'patchstack_scan_time', 'patchstack_hackers_log', 'patchstack_users_log', 'patchstack_visitors_log', 'external_updates-webarx', 'patchstack_wp_stats', 'patchstack_captcha_login_form', 'patchstack_license_activated', 'patchstack_license_expiry', 'patchstack_software_data_hash', 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_googledrive_backup_is_running', 'patchstack_googledrive_upload_state', 'patchstack_googledrive_access_token', 'patchstack_googledrive_refresh_token', 'patchstack_cron_offset', 'patchstack_htaccess_rules_hash' ];
352 356 foreach ( $options as $option ) {
353 357 delete_option( $option );
354 358
355 359 if ( is_multisite() ) {
@@ -358,9 +362,9 @@
358 362 }
359 363
360 364 // Drop all Patchstack tables.
361 365 global $wpdb;
362 - $tables = array( 'patchstack_user_log', 'patchstack_visitor_log', 'patchstack_firewall_log', 'patchstack_file_hashes', 'patchstack_logic', 'patchstack_ip', 'patchstack_event_log' );
366 + $tables = [ 'patchstack_user_log', 'patchstack_visitor_log', 'patchstack_firewall_log', 'patchstack_file_hashes', 'patchstack_logic', 'patchstack_ip', 'patchstack_event_log' ];
363 367 foreach ( $tables as $table ) {
364 368 $wpdb->query( 'DROP TABLE IF EXISTS ' . $wpdb->prefix . $table );
365 369 }
366 370 }
@@ -377,10 +381,10 @@
377 381 }
378 382 }
379 383
380 384 // Kick it off.
381 -add_action( 'plugins_loaded', array( patchstack(), 'hooks' ) );
385 +add_action( 'plugins_loaded', [ patchstack(), 'init' ] );
382 386
383 387 // Activation and deactivation hooks.
384 -register_activation_hook( __FILE__, array( patchstack(), 'activate' ) );
385 -register_deactivation_hook( __FILE__, array( patchstack(), 'deactivate' ) );
388 +register_activation_hook( __FILE__, [ patchstack(), 'activate' ] );
389 +register_deactivation_hook( __FILE__, [ patchstack(), 'deactivate' ] );
386 390 register_uninstall_hook( __FILE__, 'patchstack_uninstall' );