| @@ -1,10 +1,11 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | /** |
| 3 | 3 | * Plugin Name: Patchstack Security |
| 4 | - * Plugin URI: https://patchstack.com | |
| 4 | + * Plugin URI: https://patchstack.com/?utm_medium=wp&utm_source=dashboard&utm_campaign=patchstack%20plugin | |
| 5 | + * Author URI: https://patchstack.com/?utm_medium=wp&utm_source=dashboard&utm_campaign=patchstack%20plugin | |
| 5 | 6 | * Description: Patchstack identifies security vulnerabilities in WordPress plugins, themes, and core. |
| 6 | - * Version: 2.1.25 | |
| 7 | + * Version: 2.2.11 | |
| 7 | 8 | * Author: Patchstack |
| 8 | 9 | * License: GPLv3 |
| 9 | 10 | * Text Domain: patchstack |
| 10 | 11 | * Domain Path: /languages |
| @@ -32,9 +33,9 @@ | ||
| 32 | 33 | |
| 33 | 34 | // Set up our filename. |
| 34 | 35 | $file_name = strtolower( str_replace( '_', '-', substr( $class_name, strlen( 'P_' ) ) ) ); |
| 35 | 36 | $dir = trailingslashit( dirname( __FILE__ ) ) . 'includes/'; |
| 36 | - $target = array( $dir . $file_name . '.php', $dir . 'admin/' . str_replace( 'admin-', '', $file_name ) . '.php' ); | |
| 37 | + $target = [ $dir . $file_name . '.php', $dir . 'admin/' . str_replace( 'admin-', '', $file_name ) . '.php' ]; | |
| 37 | 38 | |
| 38 | 39 | // Attempt each target and load if it exists. |
| 39 | 40 | foreach ( $target as $file ) { |
| 40 | 41 | if ( file_exists( $file ) ) { |
| @@ -57,9 +58,9 @@ | ||
| 57 | 58 | * The plugin version. |
| 58 | 59 | * |
| 59 | 60 | * @var string |
| 60 | 61 | */ |
| 61 | - const VERSION = '2.1.25'; | |
| 62 | + const VERSION = '2.2.11'; | |
| 62 | 63 | |
| 63 | 64 | /** |
| 64 | 65 | * API URL of Patchstack to communicate with. |
| 65 | 66 | * |
| @@ -113,9 +114,9 @@ | ||
| 113 | 114 | * Detailed activation error messages. |
| 114 | 115 | * |
| 115 | 116 | * @var array |
| 116 | 117 | */ |
| 117 | - protected $activation_errors = array(); | |
| 118 | + protected $activation_errors = []; | |
| 118 | 119 | |
| 119 | 120 | /** |
| 120 | 121 | * Singleton instance of plugin. |
| 121 | 122 | * |
| @@ -142,9 +143,8 @@ | ||
| 142 | 143 | protected $hide_login; |
| 143 | 144 | protected $listener; |
| 144 | 145 | protected $event_log; |
| 145 | 146 | protected $multisite; |
| 146 | - protected $notice; | |
| 147 | 147 | protected $admin_ajax; |
| 148 | 148 | protected $admin_general; |
| 149 | 149 | protected $admin_menu; |
| 150 | 150 | protected $admin_options; |
| @@ -183,9 +183,9 @@ | ||
| 183 | 183 | * @return void |
| 184 | 184 | */ |
| 185 | 185 | public function plugin_classes() { |
| 186 | 186 | // Define the array of the classes. |
| 187 | - foreach ( array( | |
| 187 | + foreach ( [ | |
| 188 | 188 | 'admin_options' => 'P_Admin_Options', |
| 189 | 189 | 'cron' => 'P_Cron', |
| 190 | 190 | 'api' => 'P_Api', |
| 191 | 191 | 'login' => 'P_Login', |
| @@ -195,20 +195,20 @@ | ||
| 195 | 195 | 'hacker_log' => 'P_Hacker_Log', |
| 196 | 196 | 'upload' => 'P_Upload', |
| 197 | 197 | 'rules' => 'P_Rules', |
| 198 | 198 | 'hide_login' => 'P_Hide_Login', |
| 199 | - 'listener' => 'P_Listener', | |
| 200 | 199 | 'event_log' => 'P_Event_Log', |
| 201 | 200 | 'activation' => 'P_Activation', |
| 201 | + 'listener' => 'P_Listener', | |
| 202 | 202 | 'multisite' => 'P_Multisite', |
| 203 | - 'notice' => 'P_Cookie_Notice', | |
| 204 | 203 | 'admin_ajax' => 'P_Admin_Ajax', |
| 205 | 204 | 'admin_general' => 'P_Admin_General', |
| 206 | 205 | 'admin_menu' => 'P_Admin_Menu', |
| 207 | - ) as $var => $class ) { | |
| 206 | + ] as $var => $class ) { | |
| 208 | 207 | $this->$var = new $class( $this ); |
| 209 | 208 | } |
| 210 | 209 | |
| 210 | + // Load firewall base functionality. | |
| 211 | 211 | $this->firewall_base = new P_Firewall( true, $this, true ); |
| 212 | 212 | } |
| 213 | 213 | |
| 214 | 214 | /** |
| @@ -227,22 +227,35 @@ | ||
| 227 | 227 | * Returns an error if the connection was not successful. |
| 228 | 228 | * |
| 229 | 229 | * ## OPTIONS |
| 230 | 230 | * |
| 231 | - * <id> | |
| 231 | + * [<id>] | |
| 232 | 232 | * : The API client id. |
| 233 | 233 | * |
| 234 | - * <secret> | |
| 234 | + * [<secret>] | |
| 235 | 235 | * : The API secret key. |
| 236 | - * | |
| 236 | + * | |
| 237 | + * <secret-id> | |
| 238 | + * : The API client id and secret key merged together, found in the App. E.g. 2b072e8b60402e30d481df351fc08183906254e0-123456 | |
| 239 | + * | |
| 237 | 240 | * ## EXAMPLES |
| 238 | - * | |
| 241 | + * | |
| 239 | 242 | * $ wp patchstack activate 123456 2b072e8b60402e30d481df351fc08183906254e0 |
| 240 | 243 | * Success: The Patchstack plugin has been successfully connected. |
| 244 | + * | |
| 245 | + * or | |
| 246 | + * | |
| 247 | + * $ wp patchstack activate 2b072e8b60402e30d481df351fc08183906254e0-123456 | |
| 248 | + * Success: The Patchstack plugin has been successfully connected. | |
| 241 | 249 | */ |
| 242 | 250 | public function cli_activate( $args ) { |
| 243 | - $id = isset( $args[0] ) ? trim( $args[0] ) : ''; | |
| 244 | - $secret = isset( $args[1] ) ? trim( $args[1] ) : ''; | |
| 251 | + // Handle both ways to activate the plugin. | |
| 252 | + if ( count( $args ) === 1 && strpos( $args[0], '-' ) !== false ) { | |
| 253 | + list( $secret, $id ) = explode( '-', $args[0] ); | |
| 254 | + } else { | |
| 255 | + $id = isset( $args[0] ) ? trim( $args[0] ) : ''; | |
| 256 | + $secret = isset( $args[1] ) ? trim( $args[1] ) : ''; | |
| 257 | + } | |
| 245 | 258 | |
| 246 | 259 | $result = $this->activation->alter_license( $id, $secret, 'activate' ); |
| 247 | 260 | if ( $result['result'] == 'error' ) { |
| 248 | 261 | \WP_CLI::error( 'The Patchstack plugin could not be connected. Make sure the id and secret key are valid and that api.patchstack.com is not blocked.' ); |
| @@ -262,21 +275,12 @@ | ||
| 262 | 275 | $this->activation->deactivate(); |
| 263 | 276 | } |
| 264 | 277 | |
| 265 | 278 | /** |
| 266 | - * Boot Patchstack and its classes. | |
| 279 | + * Boot Patchstack. | |
| 267 | 280 | * |
| 268 | 281 | * @return void |
| 269 | 282 | */ |
| 270 | - public function hooks() { | |
| 271 | - add_action( 'init', array( $this, 'init' ), ~PHP_INT_MAX ); | |
| 272 | - } | |
| 273 | - | |
| 274 | - /** | |
| 275 | - * Boot Patchstack | |
| 276 | - * | |
| 277 | - * @return void | |
| 278 | - */ | |
| 279 | 283 | public function init() { |
| 280 | 284 | // Load translated strings for plugin. |
| 281 | 285 | load_plugin_textdomain( 'patchstack', false, dirname( $this->basename ) . '/languages/' ); |
| 282 | 286 | |
| @@ -290,9 +294,9 @@ | ||
| 290 | 294 | if ( get_option( 'patchstack_api_token', '' ) == '' && get_option( 'patchstack_license_expiry', '' ) == '' ) { |
| 291 | 295 | $this->api->update_license_status(); |
| 292 | 296 | } |
| 293 | 297 | |
| 294 | - // Determine if the license is activated and not expired. | |
| 298 | + // Run firewall if not disabled and license activated. | |
| 295 | 299 | if ( get_option( 'patchstack_license_activated', 0 ) == 1 && get_option( 'patchstack_basic_firewall', 0 ) == 1 && get_option( 'patchstack_license_free', 0 ) == 0 ) { |
| 296 | 300 | $this->firewall = new P_Firewall( true, $this ); |
| 297 | 301 | } |
| 298 | 302 | } |
| @@ -347,9 +351,9 @@ | ||
| 347 | 351 | * @return void |
| 348 | 352 | */ |
| 349 | 353 | function patchstack_uninstall() { |
| 350 | 354 | // Delete most of the Patchstack options. |
| 351 | - $options = array( 'patchstack_eventlog_lastid', 'patchstack_api_token', 'patchstack_dashboardlock', 'patchstack_pluginedit', 'patchstack_move_logs', 'patchstack_userenum', 'patchstack_basicscanblock', 'patchstack_hidewpcontent', 'patchstack_hidewpversionk', 'patchstack_prevent_default_file_access', 'patchstack_basic_firewall', 'patchstack_known_blacklist', 'patchstack_block_debug_log_access', 'patchstack_block_fake_bots', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_bad_query_strings', 'patchstack_advanced_character_string_filter', 'patchstack_advanced_blacklist_firewall', 'patchstack_forbid_rfi', 'patchstack_image_hotlinking', 'patchstack_add_security_headers', 'patchstack_firewall_log_lastid', 'patchstack_user_log_lastid', 'patchstack_captcha_public_key', 'patchstack_captcha_private_key', 'patchstack_scan_interval', 'patchstack_scan_day', 'patchstack_scan_time', 'patchstack_hackers_log', 'patchstack_users_log', 'patchstack_visitors_log', 'external_updates-webarx', 'patchstack_wp_stats', 'patchstack_captcha_login_form', 'patchstack_license_activated', 'patchstack_license_expiry', 'patchstack_software_data_hash', 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_googledrive_backup_is_running', 'patchstack_googledrive_upload_state', 'patchstack_googledrive_access_token', 'patchstack_googledrive_refresh_token', 'patchstack_cron_offset', 'patchstack_htaccess_rules_hash' ); | |
| 355 | + $options = [ 'patchstack_eventlog_lastid', 'patchstack_api_token', 'patchstack_dashboardlock', 'patchstack_pluginedit', 'patchstack_move_logs', 'patchstack_userenum', 'patchstack_basicscanblock', 'patchstack_hidewpcontent', 'patchstack_hidewpversionk', 'patchstack_prevent_default_file_access', 'patchstack_basic_firewall', 'patchstack_known_blacklist', 'patchstack_block_debug_log_access', 'patchstack_block_fake_bots', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_bad_query_strings', 'patchstack_advanced_character_string_filter', 'patchstack_advanced_blacklist_firewall', 'patchstack_forbid_rfi', 'patchstack_image_hotlinking', 'patchstack_add_security_headers', 'patchstack_firewall_log_lastid', 'patchstack_user_log_lastid', 'patchstack_captcha_public_key', 'patchstack_captcha_private_key', 'patchstack_scan_interval', 'patchstack_scan_day', 'patchstack_scan_time', 'patchstack_hackers_log', 'patchstack_users_log', 'patchstack_visitors_log', 'external_updates-webarx', 'patchstack_wp_stats', 'patchstack_captcha_login_form', 'patchstack_license_activated', 'patchstack_license_expiry', 'patchstack_software_data_hash', 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_googledrive_backup_is_running', 'patchstack_googledrive_upload_state', 'patchstack_googledrive_access_token', 'patchstack_googledrive_refresh_token', 'patchstack_cron_offset', 'patchstack_htaccess_rules_hash' ]; | |
| 352 | 356 | foreach ( $options as $option ) { |
| 353 | 357 | delete_option( $option ); |
| 354 | 358 | |
| 355 | 359 | if ( is_multisite() ) { |
| @@ -358,9 +362,9 @@ | ||
| 358 | 362 | } |
| 359 | 363 | |
| 360 | 364 | // Drop all Patchstack tables. |
| 361 | 365 | global $wpdb; |
| 362 | - $tables = array( 'patchstack_user_log', 'patchstack_visitor_log', 'patchstack_firewall_log', 'patchstack_file_hashes', 'patchstack_logic', 'patchstack_ip', 'patchstack_event_log' ); | |
| 366 | + $tables = [ 'patchstack_user_log', 'patchstack_visitor_log', 'patchstack_firewall_log', 'patchstack_file_hashes', 'patchstack_logic', 'patchstack_ip', 'patchstack_event_log' ]; | |
| 363 | 367 | foreach ( $tables as $table ) { |
| 364 | 368 | $wpdb->query( 'DROP TABLE IF EXISTS ' . $wpdb->prefix . $table ); |
| 365 | 369 | } |
| 366 | 370 | } |
| @@ -377,10 +381,10 @@ | ||
| 377 | 381 | } |
| 378 | 382 | } |
| 379 | 383 | |
| 380 | 384 | // Kick it off. |
| 381 | -add_action( 'plugins_loaded', array( patchstack(), 'hooks' ) ); | |
| 385 | +add_action( 'plugins_loaded', [ patchstack(), 'init' ] ); | |
| 382 | 386 | |
| 383 | 387 | // Activation and deactivation hooks. |
| 384 | -register_activation_hook( __FILE__, array( patchstack(), 'activate' ) ); | |
| 385 | -register_deactivation_hook( __FILE__, array( patchstack(), 'deactivate' ) ); | |
| 388 | +register_activation_hook( __FILE__, [ patchstack(), 'activate' ] ); | |
| 389 | +register_deactivation_hook( __FILE__, [ patchstack(), 'deactivate' ] ); | |
| 386 | 390 | register_uninstall_hook( __FILE__, 'patchstack_uninstall' ); |