PluginProbe
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… / 2.9.9
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… v2.9.9
3.0.0 2.11.12 2.11.11 2.11.10 2.11.9 2.11.7 2.11.8 2.11.6 2.11.5 2.11.4 2.11.3 2.11.1 2.11.2 2.11.0 2.10.5 2.10.4 2.10.3 2.10.2 2.10.1 2.10.0 2.9.9 2.9.8 2.9.6 2.9.7 2.9.5 All 88 releases
vigilante / vigilante.php

vigilante.php in Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… 2.9.9, at vigilante.php

795 lines 29.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Plugin Name: Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
4 * Plugin URI: https://servicios.ayudawp.com
5 * Description: Complete security solution for WordPress. Firewall, 2FA, security headers, login protection, file integrity monitoring, activity logging and more.
6 * Version: 2.9.9
7 * Author: Fernando Tellado
8 * Author URI: https://ayudawp.com
9 * Text Domain: vigilante
10 * Requires at least: 6.2
11 * Tested up to: 7.1
12 * Requires PHP: 7.4
13 * License: GPL v2 or later
14 * License URI: https://www.gnu.org/licenses/gpl-2.0.html
15 *
16 * @package Vigilante
17 */
18
19 // Prevent direct access
20 if ( ! defined( 'ABSPATH' ) ) {
21 exit;
22 }
23
24 /**
25 * Plugin constants
26 */
27 define( 'VIGILANTE_VERSION', '2.9.9' );
28 define( 'VIGILANTE_PLUGIN_FILE', __FILE__ );
29 define( 'VIGILANTE_PLUGIN_DIR', plugin_dir_path( __FILE__ ) );
30 define( 'VIGILANTE_PLUGIN_URL', plugin_dir_url( __FILE__ ) );
31 define( 'VIGILANTE_PLUGIN_BASENAME', plugin_basename( __FILE__ ) );
32 define( 'VIGILANTE_INCLUDES_DIR', VIGILANTE_PLUGIN_DIR . 'includes/' );
33 define( 'VIGILANTE_ADMIN_DIR', VIGILANTE_PLUGIN_DIR . 'admin/' );
34 define( 'VIGILANTE_ASSETS_URL', VIGILANTE_PLUGIN_URL . 'assets/' );
35
36 // Backup directory outside plugin folder (persists through updates)
37 define( 'VIGILANTE_BACKUP_DIR', WP_CONTENT_DIR . '/vigilante-backups/' );
38
39 // Minimum requirements
40 define( 'VIGILANTE_MIN_PHP_VERSION', '7.4' );
41 define( 'VIGILANTE_MIN_WP_VERSION', '5.0' );
42
43 /**
44 * Check minimum requirements before loading
45 *
46 * @return bool True if requirements are met
47 */
48 function vigilante_check_requirements() {
49 $meets_requirements = true;
50
51 // Check PHP version
52 if ( version_compare( PHP_VERSION, VIGILANTE_MIN_PHP_VERSION, '<' ) ) {
53 $meets_requirements = false;
54 }
55
56 // Check WordPress version
57 global $wp_version;
58 if ( version_compare( $wp_version, VIGILANTE_MIN_WP_VERSION, '<' ) ) {
59 $meets_requirements = false;
60 }
61
62 if ( ! $meets_requirements ) {
63 add_action( 'admin_notices', 'vigilante_requirements_notice' );
64 }
65
66 return $meets_requirements;
67 }
68
69 /**
70 * Display requirements notice - called at admin_notices (after init)
71 */
72 function vigilante_requirements_notice() {
73 global $wp_version;
74 $errors = array();
75
76 if ( version_compare( PHP_VERSION, VIGILANTE_MIN_PHP_VERSION, '<' ) ) {
77 $errors[] = sprintf(
78 /* translators: 1: Current PHP version, 2: Required PHP version */
79 __( 'Vigilant requires PHP %2$s or higher. You are running PHP %1$s.', 'vigilante' ),
80 PHP_VERSION,
81 VIGILANTE_MIN_PHP_VERSION
82 );
83 }
84
85 if ( version_compare( $wp_version, VIGILANTE_MIN_WP_VERSION, '<' ) ) {
86 $errors[] = sprintf(
87 /* translators: 1: Current WordPress version, 2: Required WordPress version */
88 __( 'Vigilant requires WordPress %2$s or higher. You are running WordPress %1$s.', 'vigilante' ),
89 $wp_version,
90 VIGILANTE_MIN_WP_VERSION
91 );
92 }
93
94 foreach ( $errors as $error ) {
95 printf(
96 '<div class="notice notice-error"><p>%s</p></div>',
97 esc_html( $error )
98 );
99 }
100 }
101
102 /**
103 * Load plugin files
104 */
105 function vigilante_load_plugin() {
106 // Check requirements first
107 if ( ! vigilante_check_requirements() ) {
108 return;
109 }
110
111 // Load core classes (no translations used in these)
112 require_once VIGILANTE_INCLUDES_DIR . 'class-database.php';
113 require_once VIGILANTE_INCLUDES_DIR . 'class-settings.php';
114 require_once VIGILANTE_INCLUDES_DIR . 'class-ip-utils.php';
115 require_once VIGILANTE_INCLUDES_DIR . 'class-backup-manager.php';
116 require_once VIGILANTE_INCLUDES_DIR . 'class-activator.php';
117 require_once VIGILANTE_INCLUDES_DIR . 'class-deactivator.php';
118
119 // Load security module files (just loading, not initializing)
120 require_once VIGILANTE_INCLUDES_DIR . 'class-firewall.php';
121 require_once VIGILANTE_INCLUDES_DIR . 'class-security-headers.php';
122 require_once VIGILANTE_INCLUDES_DIR . 'class-htaccess-protection.php';
123 require_once VIGILANTE_INCLUDES_DIR . 'class-wpconfig-security.php';
124 require_once VIGILANTE_INCLUDES_DIR . 'class-https-enforcer.php';
125 require_once VIGILANTE_INCLUDES_DIR . 'class-rest-api-security.php';
126 require_once VIGILANTE_INCLUDES_DIR . 'class-user-security.php';
127 require_once VIGILANTE_INCLUDES_DIR . 'class-login-security.php';
128 require_once VIGILANTE_INCLUDES_DIR . 'class-two-factor-email.php';
129 require_once VIGILANTE_INCLUDES_DIR . 'class-two-factor-totp.php';
130 require_once VIGILANTE_INCLUDES_DIR . 'class-email-template.php';
131 require_once VIGILANTE_INCLUDES_DIR . 'class-comment-security.php';
132 require_once VIGILANTE_INCLUDES_DIR . 'class-head-cleaner.php';
133 require_once VIGILANTE_INCLUDES_DIR . 'class-feed-manager.php';
134 require_once VIGILANTE_INCLUDES_DIR . 'class-activity-log.php';
135 require_once VIGILANTE_INCLUDES_DIR . 'class-audit-alerts.php';
136 require_once VIGILANTE_INCLUDES_DIR . 'class-file-integrity.php';
137 require_once VIGILANTE_INCLUDES_DIR . 'class-plugin-status.php';
138 require_once VIGILANTE_INCLUDES_DIR . 'class-under-attack.php';
139 require_once VIGILANTE_INCLUDES_DIR . 'class-database-backup.php';
140 require_once VIGILANTE_INCLUDES_DIR . 'class-database-prefix.php';
141 require_once VIGILANTE_INCLUDES_DIR . 'class-security-analyzer.php';
142
143 // Load admin classes
144 if ( is_admin() ) {
145 require_once VIGILANTE_ADMIN_DIR . 'class-admin-analyzer-ajax.php';
146 require_once VIGILANTE_ADMIN_DIR . 'class-admin-audit-alerts-ajax.php';
147 require_once VIGILANTE_ADMIN_DIR . 'class-admin.php';
148 }
149
150 // Weekly Security Analyzer cron (registered even outside admin so it fires on cron hit).
151 add_action( 'vigilante_analyzer_weekly_scan', 'vigilante_run_analyzer_cron' );
152
153 // Daily plugin status check (closed-in-wp.org detection).
154 add_action( 'vigilante_plugin_status_check', 'vigilante_run_plugin_status_check' );
155
156 // Post-Under Attack scan (one-shot, scheduled by Vigilante_Under_Attack::deactivate).
157 add_action( 'vigilante_under_attack_post_scan', 'vigilante_run_post_under_attack_scan' );
158
159 // Initialize core components only - modules will be initialized at init
160 add_action( 'init', 'vigilante_init_plugin', 1 );
161 }
162
163 /**
164 * Initialize plugin at init hook (translations are ready)
165 */
166 function vigilante_init_plugin() {
167 Vigilante_Main::get_instance();
168 }
169
170 /**
171 * Main plugin class - Singleton pattern
172 */
173 final class Vigilante_Main {
174
175 /**
176 * Single instance of the class
177 *
178 * @var Vigilante_Main|null
179 */
180 private static $instance = null;
181
182 /**
183 * Settings instance
184 *
185 * @var Vigilante_Settings
186 */
187 public $settings;
188
189 /**
190 * Database instance
191 *
192 * @var Vigilante_Database
193 */
194 public $database;
195
196 /**
197 * Activity log instance
198 *
199 * @var Vigilante_Activity_Log
200 */
201 public $activity_log;
202
203 /**
204 * Get single instance of the class
205 *
206 * @return Vigilante_Main
207 */
208 public static function get_instance() {
209 if ( null === self::$instance ) {
210 self::$instance = new self();
211 }
212 return self::$instance;
213 }
214
215 /**
216 * Constructor - private to enforce singleton
217 */
218 private function __construct() {
219 $this->init_core();
220 $this->init_modules();
221 $this->init_hooks();
222 }
223
224 /**
225 * Prevent cloning
226 */
227 private function __clone() {}
228
229 /**
230 * Prevent unserializing
231 *
232 * @throws Exception Always throws exception.
233 */
234 public function __wakeup() {
235 throw new Exception( 'Cannot unserialize singleton' );
236 }
237
238 /**
239 * Initialize core components
240 */
241 private function init_core() {
242 $this->database = new Vigilante_Database();
243 $this->settings = new Vigilante_Settings();
244 $this->activity_log = new Vigilante_Activity_Log( $this->settings, $this->database );
245
246 // Auto-create/update tables when DB version is outdated (handles file-only updates)
247 if ( $this->database->needs_update() ) {
248 $this->database->create_tables();
249 }
250
251 // One-time cleanup: versions before 2.7.0 wrote config backups (including
252 // wp-config.php) as files under wp-content/vigilante-backups/. Those now
253 // live in the database, so remove anything left on disk.
254 if ( ! get_option( 'vigilante_legacy_backups_cleaned' ) ) {
255 Vigilante_Backup_Manager::cleanup_legacy_files();
256 update_option( 'vigilante_legacy_backups_cleaned', 1, false );
257 }
258
259 // One-time migration (2.9.0): add '.css' to File Integrity's excluded
260 // extensions on existing installs. Stylesheets are rewritten so often by
261 // themes and optimizer plugins that they were the main post-update false
262 // positive. New installs get it from the defaults; this brings existing
263 // sites in line without touching any other setting. Additive, idempotent.
264 if ( ! get_option( 'vigilante_css_exclusion_migrated' ) ) {
265 $fi = $this->settings->get_section( 'file_integrity' );
266 if ( is_array( $fi ) ) {
267 $ext = ( isset( $fi['excluded_extensions'] ) && is_array( $fi['excluded_extensions'] ) )
268 ? $fi['excluded_extensions']
269 : array();
270 if ( ! in_array( '.css', $ext, true ) ) {
271 $ext[] = '.css';
272 $fi['excluded_extensions'] = $ext;
273 $this->settings->update_section( 'file_integrity', $fi );
274 }
275 }
276 update_option( 'vigilante_css_exclusion_migrated', 1, false );
277 }
278
279 // One-time on upgrade to 2.9.0: drop any cached WordPress.org checksum
280 // manifests. The new comparison is array-aware and self-corrects a cached
281 // array-md5 value, but a manifest cached by an older version while wp.org
282 // was still propagating a new release could otherwise keep producing
283 // false "modified" results until it expires (up to 24h). Flushing on
284 // upgrade guarantees a clean slate on the very release that fixes them;
285 // the next scan refetches fresh manifests. One-time, bulk, no caching.
286 if ( ! get_option( 'vigilante_checksum_cache_flushed_290' ) ) {
287 global $wpdb;
288 $wpdb->query( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- one-time 2.9.0 migration dropping stale checksum transients so the new comparison starts clean.
289 "DELETE FROM {$wpdb->options}
290 WHERE option_name LIKE '\\_transient\\_vigilante\\_plugin\\_checksums\\_%'
291 OR option_name LIKE '\\_transient\\_timeout\\_vigilante\\_plugin\\_checksums\\_%'
292 OR option_name LIKE '\\_transient\\_vigilante\\_theme\\_checksums\\_%'
293 OR option_name LIKE '\\_transient\\_timeout\\_vigilante\\_theme\\_checksums\\_%'
294 OR option_name LIKE '\\_transient\\_vigilante\\_core\\_checksums\\_%'
295 OR option_name LIKE '\\_transient\\_timeout\\_vigilante\\_core\\_checksums\\_%'"
296 );
297 update_option( 'vigilante_checksum_cache_flushed_290', 1, false );
298 }
299 }
300
301 /**
302 * Initialize security modules based on settings
303 */
304 private function init_modules() {
305 $options = $this->settings->get_all_options();
306
307 // Self-heal: a UI bug in earlier 2.4.x betas could leave a section's
308 // top-level 'enabled' flag set to false because the section forms do
309 // not render a checkbox for that field — saving any tab caused the
310 // generic save handler to treat the missing field as "unchecked" and
311 // store it as false. If the master module toggle on the Dashboard is
312 // on but the section flag is off, restore it here so the module's
313 // hooks can attach. Idempotent: noop on healthy installs.
314 $sections = array(
315 'firewall',
316 'security_headers',
317 'login_security',
318 'rest_api_security',
319 'user_security',
320 'wp_hardening',
321 'file_integrity',
322 'activity_log',
323 );
324 $heal_changed = false;
325 foreach ( $sections as $section_name ) {
326 if ( ! empty( $options['modules'][ $section_name ] )
327 && isset( $options[ $section_name ] )
328 && is_array( $options[ $section_name ] )
329 && array_key_exists( 'enabled', $options[ $section_name ] )
330 && empty( $options[ $section_name ]['enabled'] ) ) {
331 $options[ $section_name ]['enabled'] = true;
332 $heal_changed = true;
333 }
334 }
335 if ( $heal_changed ) {
336 update_option( Vigilante_Settings::OPTION_NAME, $options );
337 $this->settings->clear_cache();
338 $options = $this->settings->get_all_options();
339 }
340
341 // Firewall - runs early to block threats
342 if ( ! empty( $options['modules']['firewall'] ) ) {
343 new Vigilante_Firewall( $this->settings, $this->activity_log );
344 }
345
346 // Security Headers - rules are applied via .htaccess, no runtime hooks needed
347 // HTTPS Enforcer still needs runtime hooks
348 if ( ! empty( $options['modules']['security_headers'] ) ) {
349 new Vigilante_Https_Enforcer( $this->settings );
350 }
351
352 // REST API Security
353 if ( ! empty( $options['modules']['rest_api_security'] ) ) {
354 new Vigilante_Rest_Api_Security( $this->settings );
355 }
356
357 // User Security
358 if ( ! empty( $options['modules']['user_security'] ) ) {
359 new Vigilante_User_Security( $this->settings, $this->activity_log );
360 }
361
362 // Login Security
363 if ( ! empty( $options['modules']['login_security'] ) ) {
364 $login_security = new Vigilante_Login_Security( $this->settings, $this->database, $this->activity_log );
365
366 // Two-Factor Authentication (only if login security module is active)
367 new Vigilante_Two_Factor_Email( $this->settings, $this->database, $this->activity_log, $login_security );
368 new Vigilante_Two_Factor_TOTP( $this->settings, $this->database, $this->activity_log, $login_security );
369 }
370
371 // WordPress Hardening (includes comments, head cleaner, feeds)
372 if ( ! empty( $options['modules']['wp_hardening'] ) ) {
373 new Vigilante_Comment_Security( $this->settings );
374 new Vigilante_Head_Cleaner( $this->settings );
375 new Vigilante_Feed_Manager( $this->settings );
376 }
377
378 // File Integrity Scanner
379 if ( ! empty( $options['modules']['file_integrity'] ) ) {
380 new Vigilante_File_Integrity( $this->settings, $this->database, $this->activity_log );
381 new Vigilante_Plugin_Status( $this->settings, $this->activity_log );
382 }
383
384 // Activity Log is always initialized (core component)
385 // Logging is gated by the modules.activity_log toggle and per-type flags
386
387 // Audit Alerts engine - an alerting layer on top of Security Audit.
388 // Only instantiated when Security Audit is on, because it reacts to the
389 // events the activity log records (a passive subscriber, no per-module
390 // coupling). Both alert legs are opt-in, off by default.
391 if ( ! empty( $options['modules']['activity_log'] ) ) {
392 new Vigilante_Audit_Alerts( $this->settings, $this->activity_log );
393 }
394
395 // Under Attack mode - always loaded (independent of modules)
396 new Vigilante_Under_Attack( $this->settings, $this->activity_log );
397
398 // Admin interface
399 if ( is_admin() ) {
400 new Vigilante_Admin( $this->settings, $this->database, $this->activity_log );
401 }
402 }
403
404 /**
405 * Initialize WordPress hooks
406 */
407 private function init_hooks() {
408 // Plugin action links
409 add_filter( 'plugin_action_links_' . VIGILANTE_PLUGIN_BASENAME, array( $this, 'add_action_links' ) );
410
411 // Scheduled tasks
412 add_action( 'vigilante_daily_maintenance', array( $this, 'daily_maintenance' ) );
413 add_action( 'vigilante_hourly_checks', array( $this, 'hourly_checks' ) );
414
415 // AJAX handlers
416 add_action( 'wp_ajax_vigilante_dismiss_notice', array( $this, 'ajax_dismiss_notice' ) );
417
418 // Regenerate critical file baseline after Vigilante modifies wp-config.php or .htaccess
419 add_action( 'vigilante_critical_file_written', array( $this, 'on_critical_file_written' ) );
420
421 // Keep the server layer in step with the installed version.
422 add_action( 'init', array( $this, 'maybe_sync_server_files' ), 20 );
423 }
424
425 /**
426 * Rewrite the .htaccess block when the installed version has moved on
427 *
428 * Updating the plugin did not touch the file: the block was only rewritten
429 * on activation or when the Headers or Firewall tab was saved. So a fix
430 * that lives inside those rules never reached a site that merely updated,
431 * which is exactly what happened with the connect-src of 2.9.6: the browser
432 * kept receiving the old policy, and image uploads kept failing on
433 * WordPress 7.1 until someone pressed Save. This rewrites the block once
434 * per version, and picks up the rules that an activation from WP-CLI had to
435 * leave pending because it could not tell what server it was on.
436 *
437 * Only the content between the plugin markers is rewritten, the same part
438 * any save has always rewritten.
439 *
440 * @since 2.9.9
441 */
442 public function maybe_sync_server_files() {
443 $pending = (bool) get_option( 'vigilante_server_files_pending' );
444
445 if ( ! $pending && VIGILANTE_VERSION === get_option( 'vigilante_server_files_version' ) ) {
446 return;
447 }
448
449 // A failed write is not retried on every request.
450 if ( (int) get_option( 'vigilante_server_files_retry_after' ) > time() ) {
451 return;
452 }
453
454 // In a network the file belongs to every site, and the main site writes it.
455 if ( ! Vigilante_Settings::can_write_shared_files() ) {
456 $this->mark_server_files_synced();
457 return;
458 }
459
460 require_once VIGILANTE_INCLUDES_DIR . 'class-htaccess-manager.php';
461 $manager = Vigilante_Htaccess_Manager::get_instance();
462
463 if ( ! $manager->is_apache() ) {
464 // Still on the command line with nothing to learn from: stay pending.
465 if ( $manager->server_is_unknown() ) {
466 return;
467 }
468
469 // Not Apache: there is no block to keep in step.
470 $this->mark_server_files_synced();
471 return;
472 }
473
474 $options = get_option( Vigilante_Settings::OPTION_NAME, array() );
475 $headers = isset( $options['security_headers'] ) ? (array) $options['security_headers'] : array();
476 $failed = false;
477 $rewrote = false;
478
479 $needs_protection_block = ! empty( $options['modules']['firewall'] )
480 || ! empty( $headers['hide_server_signature'] )
481 || ! empty( $headers['remove_fingerprinting_headers'] );
482
483 if ( $needs_protection_block ) {
484 require_once VIGILANTE_INCLUDES_DIR . 'class-htaccess-protection.php';
485 $result = ( new Vigilante_Htaccess_Protection( $this->settings ) )->apply_rules();
486 $failed = $failed || is_wp_error( $result );
487 $rewrote = true;
488 }
489
490 if ( ! empty( $options['modules']['security_headers'] ) ) {
491 require_once VIGILANTE_INCLUDES_DIR . 'class-security-headers.php';
492 $result = ( new Vigilante_Security_Headers( $this->settings ) )->apply_rules();
493 $failed = $failed || is_wp_error( $result );
494 $rewrote = true;
495 }
496
497 if ( $failed ) {
498 update_option( 'vigilante_server_files_retry_after', time() + HOUR_IN_SECONDS );
499
500 // A refusal to write the server rules is exactly the kind of thing
501 // that used to happen in silence, so it is recorded and retried in
502 // an hour instead of being forgotten.
503 if ( $this->activity_log ) {
504 $this->activity_log->log(
505 'system',
506 'server_rules_write_failed',
507 __( 'The .htaccess rules could not be rewritten after the update. Vigilant will try again in an hour; if the file is read only, fix its permissions or save the Firewall or Headers tab once.', 'vigilante' ),
508 array( 'version' => VIGILANTE_VERSION ),
509 'warning'
510 );
511 }
512
513 return;
514 }
515
516 $this->mark_server_files_synced();
517
518 if ( $rewrote && $this->activity_log ) {
519 $this->activity_log->log(
520 'system',
521 'server_rules_refreshed',
522 sprintf(
523 /* translators: %s: plugin version. */
524 __( 'The .htaccess rules were rewritten to match Vigilant %s.', 'vigilante' ),
525 VIGILANTE_VERSION
526 ),
527 array( 'version' => VIGILANTE_VERSION ),
528 'info'
529 );
530 }
531 }
532
533 /**
534 * Record that the server layer matches the installed version
535 *
536 * @since 2.9.9
537 */
538 private function mark_server_files_synced() {
539 update_option( 'vigilante_server_files_version', VIGILANTE_VERSION );
540 delete_option( 'vigilante_server_files_pending' );
541 delete_option( 'vigilante_server_files_retry_after' );
542 }
543
544 /**
545 * Update the critical file baseline after Vigilante writes to a monitored file
546 *
547 * @param string $filename File that was modified (e.g. 'wp-config.php').
548 */
549 public function on_critical_file_written( $filename ) {
550 if ( ! class_exists( 'Vigilante_File_Integrity' ) ) {
551 require_once VIGILANTE_INCLUDES_DIR . 'class-file-integrity.php';
552 }
553
554 $fi = new Vigilante_File_Integrity( $this->settings, $this->database, $this->activity_log );
555 $fi->update_critical_file_baseline( $filename );
556 }
557
558 /**
559 * Add plugin action links
560 *
561 * @param array $links Existing links.
562 * @return array Modified links.
563 */
564 public function add_action_links( $links ) {
565 $plugin_links = array(
566 '<a href="' . esc_url( admin_url( 'admin.php?page=vigilante' ) ) . '">' . esc_html__( 'Security Settings', 'vigilante' ) . '</a>',
567 );
568 return array_merge( $plugin_links, $links );
569 }
570
571 /**
572 * Daily maintenance tasks
573 */
574 public function daily_maintenance() {
575 // Clean old activity logs
576 $this->activity_log->cleanup_old_logs();
577
578 // Clean old login attempts
579 $this->database->cleanup_old_login_attempts();
580
581 // Clean expired 2FA codes and trusted devices
582 $this->database->cleanup_expired_2fa_codes();
583 $this->database->cleanup_expired_trusted_devices();
584
585 // Remove sensitive files (readme.html, license.txt, licencia.txt)
586 // WordPress core updates recreate these files, so we clean them daily
587 $advanced = $this->settings->get_section( 'advanced' );
588 if ( ! empty( $advanced['remove_readme'] ) ) {
589 $readme_path = ABSPATH . 'readme.html';
590 if ( file_exists( $readme_path ) ) {
591 wp_delete_file( $readme_path );
592 }
593 }
594 if ( ! empty( $advanced['remove_license'] ) ) {
595 $license_files = array( 'license.txt', 'licencia.txt' );
596 foreach ( $license_files as $license_file ) {
597 $license_path = ABSPATH . $license_file;
598 if ( file_exists( $license_path ) ) {
599 wp_delete_file( $license_path );
600 }
601 }
602 }
603
604 // Log maintenance
605 $this->activity_log->log( 'system', 'maintenance', __( 'Daily maintenance completed', 'vigilante' ) );
606 }
607
608 /**
609 * Hourly checks
610 */
611 public function hourly_checks() {
612 // File integrity scans are handled by the File_Integrity class own cron schedule
613 // based on the configured scan_frequency (daily/weekly).
614 }
615
616 /**
617 * AJAX handler for dismissing notices
618 */
619 public function ajax_dismiss_notice() {
620 check_ajax_referer( 'vigilante_dismiss_notice', 'nonce' );
621
622 if ( ! current_user_can( 'manage_options' ) ) {
623 wp_die( -1 );
624 }
625
626 $notice_id = isset( $_POST['notice_id'] ) ? sanitize_key( $_POST['notice_id'] ) : '';
627
628 if ( $notice_id ) {
629 $dismissed = get_option( 'vigilante_dismissed_notices', array() );
630 $dismissed[ $notice_id ] = time();
631 update_option( 'vigilante_dismissed_notices', $dismissed );
632 }
633
634 wp_send_json_success();
635 }
636 }
637
638 /**
639 * Cron handler for the weekly Security Analyzer scan.
640 *
641 * Resolves the shared Vigilante_Security_Analyzer (lazily; no cost when the
642 * cron is not firing) and lets it run the scan + regression email logic.
643 */
644 function vigilante_run_analyzer_cron() {
645 if ( ! class_exists( 'Vigilante_Security_Analyzer' ) ) {
646 require_once VIGILANTE_INCLUDES_DIR . 'class-security-analyzer.php';
647 }
648 if ( ! class_exists( 'Vigilante_Settings' ) ) {
649 require_once VIGILANTE_INCLUDES_DIR . 'class-settings.php';
650 }
651
652 $settings = new Vigilante_Settings();
653 $activity_log = null;
654 if ( class_exists( 'Vigilante_Activity_Log' ) && class_exists( 'Vigilante_Database' ) ) {
655 $database = new Vigilante_Database();
656 $activity_log = new Vigilante_Activity_Log( $settings, $database );
657 }
658
659 $analyzer = new Vigilante_Security_Analyzer( $settings, $activity_log );
660 $analyzer->cron_weekly_scan();
661 }
662
663 /**
664 * Cron handler for the daily plugin status check.
665 *
666 * Resolves the shared Vigilante_Plugin_Status lazily so the daily cron has no
667 * cost while it is not firing.
668 */
669 function vigilante_run_plugin_status_check() {
670 if ( ! class_exists( 'Vigilante_Plugin_Status' ) ) {
671 require_once VIGILANTE_INCLUDES_DIR . 'class-plugin-status.php';
672 }
673 if ( ! class_exists( 'Vigilante_Settings' ) ) {
674 require_once VIGILANTE_INCLUDES_DIR . 'class-settings.php';
675 }
676
677 $settings = new Vigilante_Settings();
678 $activity_log = null;
679 if ( class_exists( 'Vigilante_Activity_Log' ) && class_exists( 'Vigilante_Database' ) ) {
680 $database = new Vigilante_Database();
681 $activity_log = new Vigilante_Activity_Log( $settings, $database );
682 }
683
684 $checker = new Vigilante_Plugin_Status( $settings, $activity_log );
685 $checker->run_scheduled_check();
686 }
687
688 /**
689 * Run a Security Analyzer full scan after Under Attack mode deactivates.
690 *
691 * Scheduled one-shot from Vigilante_Under_Attack::deactivate() so the dashboard
692 * reflects the restored configuration with the slow HTTP/header probes the
693 * mode prevented from running safely while it was active.
694 */
695 function vigilante_run_post_under_attack_scan() {
696 if ( ! class_exists( 'Vigilante_Under_Attack' ) ) {
697 require_once VIGILANTE_INCLUDES_DIR . 'class-under-attack.php';
698 }
699 if ( ! class_exists( 'Vigilante_Settings' ) ) {
700 require_once VIGILANTE_INCLUDES_DIR . 'class-settings.php';
701 }
702
703 $settings = new Vigilante_Settings();
704 $activity_log = null;
705 if ( class_exists( 'Vigilante_Activity_Log' ) && class_exists( 'Vigilante_Database' ) ) {
706 $database = new Vigilante_Database();
707 $activity_log = new Vigilante_Activity_Log( $settings, $database );
708 }
709
710 $under_attack = new Vigilante_Under_Attack( $settings, $activity_log );
711 $under_attack->run_analyzer_scan( 'all' );
712 }
713
714 /**
715 * Plugin activation hook
716 */
717 function vigilante_activate() {
718 require_once VIGILANTE_INCLUDES_DIR . 'class-database.php';
719 require_once VIGILANTE_INCLUDES_DIR . 'class-settings.php';
720 require_once VIGILANTE_INCLUDES_DIR . 'class-backup-manager.php';
721 require_once VIGILANTE_INCLUDES_DIR . 'class-activator.php';
722
723 Vigilante_Activator::activate();
724 }
725 register_activation_hook( __FILE__, 'vigilante_activate' );
726
727 /**
728 * Plugin deactivation hook
729 */
730 function vigilante_deactivate() {
731 require_once VIGILANTE_INCLUDES_DIR . 'class-database.php';
732 require_once VIGILANTE_INCLUDES_DIR . 'class-settings.php';
733 require_once VIGILANTE_INCLUDES_DIR . 'class-backup-manager.php';
734 require_once VIGILANTE_INCLUDES_DIR . 'class-deactivator.php';
735
736 Vigilante_Deactivator::deactivate();
737 }
738 register_deactivation_hook( __FILE__, 'vigilante_deactivate' );
739
740 /**
741 * Initialize plugin after WordPress loads
742 */
743 add_action( 'plugins_loaded', 'vigilante_load_plugin' );
744
745 /*
746 * The hidden wp-admin is answered as early as the request can be judged with
747 * certainty, before the theme and the other plugins load. The modules are built
748 * on init priority 1, so until 2.9.9 a request that was going to be refused had
749 * already paid for the whole boot.
750 */
751 add_action( 'plugins_loaded', 'vigilante_block_hidden_admin_early', 1 );
752
753 /**
754 * Cheap gate for the early hidden wp-admin rejection
755 *
756 * Everything that can be decided without loading a single plugin class is
757 * decided here, so the usual request pays nothing more than a couple of
758 * comparisons and one option read that WordPress has already cached.
759 *
760 * @since 2.9.9
761 */
762 function vigilante_block_hidden_admin_early() {
763 if ( ! is_admin() ) {
764 return;
765 }
766
767 $method = isset( $_SERVER['REQUEST_METHOD'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REQUEST_METHOD'] ) ) : 'GET';
768
769 // POST is how remote managers authenticate, and the later path lets it through too.
770 if ( 'GET' !== $method ) {
771 return;
772 }
773
774 $options = get_option( 'vigilante_options', array() );
775
776 if ( ! is_array( $options )
777 || empty( $options['modules']['login_security'] )
778 || empty( $options['login_security']['custom_login_url'] ) ) {
779 return;
780 }
781
782 require_once VIGILANTE_INCLUDES_DIR . 'class-ip-utils.php';
783 require_once VIGILANTE_INCLUDES_DIR . 'class-login-security.php';
784
785 Vigilante_Login_Security::maybe_block_hidden_admin_early( $options );
786 }
787
788 /**
789 * Helper function to get plugin instance
790 *
791 * @return Vigilante_Main
792 */
793 function vigilante() {
794 return Vigilante_Main::get_instance();
795 }