PluginProbe
WebTotem Security / 2.3.14
WebTotem Security v2.3.14
3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 2.2.4 All 109 releases
← All changes | wt-security.php +210 -125 2.1.42.3.14 View file →
@@ -1,125 +1,210 @@
1 -<?php defined('ABSPATH') or die("Protected By WT!");
2 -
3 -/*
4 -Plugin Name: WT Security
5 -Description: WT is a SaaS which provides powerful tools for securing and monitoring your website in one place in easy and flexible way.
6 -Author: WT Security
7 -Version: 2.1.4
8 -*/
9 -
10 -define("WTSEC_PAGE_TITLE", 'Dashboard');
11 -define("WTSEC_MENU_TITLE", 'WT Security');
12 -define("WTSEC_PLUGIN_PATH", plugin_dir_path(__FILE__));
13 -define("WTSEC_PLUGIN_NAME", 'wt-security');
14 -define("WTSEC_PLUGIN_PREFIX", 'wtsec_');
15 -define("WTSEC_PAGE_PREFIX", WTSEC_PLUGIN_NAME . '-');
16 -define("WTSEC_FILE_URL", "https://api.wtotem.com/agent");
17 -define("WTSEC_ROOT", WP_PLUGIN_DIR . '/');
18 -define("WTSEC_MODULES_DIR", WTSEC_PLUGIN_PATH . 'uploads/');
19 -if (is_dir(WTSEC_MODULES_DIR) && is_writable(WTSEC_MODULES_DIR)) {
20 - define("WTSEC_INSTALLATION_DIR", WTSEC_MODULES_DIR);
21 - define("WTOTEMSEC_INSTALLATION_DIR", WTSEC_MODULES_DIR);
22 -} else {
23 - define("WTSEC_INSTALLATION_DIR", wp_upload_dir()['basedir'] . '/');
24 - define("WTOTEMSEC_INSTALLATION_DIR", wp_upload_dir()['basedir'] . '/');
25 -}
26 -define("WTSEC_PLUGIN_URL", plugins_url("", __FILE__));
27 -define("WTSEC_SITE_URL", str_replace(['http://', 'https://', 'www.', '//', '://'], '', get_site_url()));
28 -
29 -define("WTSEC_PLUGIN_INFORMATION_VERSION", "2.1");
30 -
31 -add_action('admin_init', 'wtsec_admin_init');
32 -add_action('wp_loaded', 'wtsec_init');
33 -
34 -function wtsec_init()
35 -{
36 - require_once WTSEC_PLUGIN_PATH . 'library/App.php';
37 - require_once WTSEC_PLUGIN_PATH . 'library/Request.php';
38 - if (!is_admin() && in_array(WTSEC_LIBRARY_App::getOption('waf_status'), ["start", "uninstalled"])) {
39 - if ($waf = WTSEC_LIBRARY_App::getOption(("waf_installed_file"))) {
40 - $path_to_waf = WTSEC_INSTALLATION_DIR . '/' . $waf;
41 - if (is_file($path_to_waf) && is_readable($path_to_waf)) {
42 - include $path_to_waf;
43 - }
44 - }
45 - }
46 - if (is_admin()) {
47 - require_once WTSEC_PLUGIN_PATH . 'library/WT.php';
48 - require_once WTSEC_PLUGIN_PATH . 'library/Localization.php';
49 - require_once WTSEC_PLUGIN_PATH . 'library/Idn.php';
50 - require_once WTSEC_PLUGIN_PATH . 'library/Session.php';
51 - require_once WTSEC_PLUGIN_PATH . 'routes.php';
52 - require_once WTSEC_PLUGIN_PATH . 'services.php';
53 - function wtsec_request()
54 - {
55 - return new WTSEC_LIBRARY_Request();
56 - }
57 - function wtsec_app()
58 - {
59 - return new WTSEC_LIBRARY_App();
60 - }
61 - function wtsec_filesystem_init($form_url, $method, $context, $fields = null)
62 - {
63 - global $wp_filesystem;
64 - if (!$creds = request_filesystem_credentials($form_url, $method, false, $context, $fields)) {
65 - return false;
66 - }
67 - if (!WP_Filesystem($creds)) {
68 - request_filesystem_credentials($form_url, $method, true, $context);
69 - return false;
70 - }
71 - return true;
72 - }
73 - function wtsec_locale($lmsg, $args = [])
74 - {
75 - return WTSEC_LIBRARY_Localization::lmsg($lmsg, $args);
76 - }
77 - function wtsec_getImagePath($image)
78 - {
79 - return plugins_url('/htdocs/images/' . $image, __FILE__);
80 - }
81 - function wtsec_SIS($arr, $key, $form = null)
82 - {
83 - $key = explode(".", $key);
84 - foreach ($key as $_key) {
85 - if (!isset($arr[$_key])) {
86 - $arr = "";
87 - break;
88 - }
89 - $arr = $arr[$_key];
90 - }
91 - return !empty($form) ? str_replace("$" . $key, $arr, $form) : $arr;
92 - }
93 - }
94 -}
95 -
96 -function wtsec_admin_init()
97 -{
98 - if (is_admin() && stripos(wtsec_request()->page, WTSEC_PLUGIN_NAME) !== false) {
99 - wp_register_style("css", plugins_url('/htdocs/css/src.c37ba8ac.css', __FILE__));
100 - wp_enqueue_style('css');
101 - wp_enqueue_script('chart', plugins_url('/htdocs/js/Chart.min.js', __FILE__), [], false, true);
102 - wp_enqueue_script('chart');
103 - wp_enqueue_script('app', plugins_url('/htdocs/js/src.e31bb0bc.js', __FILE__), [], false, true);
104 - wp_enqueue_script('app');
105 - $page = wtsec_request()->page;
106 - if ($page === wtsec_getRoute("login")) {
107 - if (WTSEC_LIBRARY_App::authorized()) {
108 - wp_safe_redirect(wtsec_getUrl('dashboard'));
109 - }
110 - } elseif ($page === wtsec_getRoute("logout")) {
111 - WTSEC_LIBRARY_App::logout();
112 - if (!WTSEC_LIBRARY_App::authorized()) {
113 - wp_safe_redirect(wtsec_getUrl('login'));
114 - }
115 - } elseif ($page === wtsec_getRoute("activate")) {
116 - if (WTSEC_LIBRARY_App::authorized()) {
117 - wp_safe_redirect(wtsec_getUrl('sites'));
118 - }
119 - } else {
120 - if (!WTSEC_LIBRARY_App::authorized()) {
121 - wp_safe_redirect(wtsec_getUrl('login'));
122 - }
123 - }
124 - }
125 -}
1 +<?php defined('ABSPATH') or die("Protected By WT!");
2 +
3 +/*
4 +Plugin Name: WT Security
5 +Description: WT is a SaaS which provides powerful tools for securing and monitoring your website in one place in easy and flexible way.
6 +Author: WT Security
7 +Version: 2.3.14
8 +*/
9 +
10 +define("WTSEC_PAGE_TITLE", 'Dashboard');
11 +define("WTSEC_MENU_TITLE", 'WT Security');
12 +define("WTSEC_PLUGIN_PATH", plugin_dir_path(__FILE__));
13 +define("WTSEC_PLUGIN_NAME", 'wt-security');
14 +define("WTSEC_PLUGIN_PREFIX", 'wtsec_');
15 +define("WTSEC_PAGE_PREFIX", WTSEC_PLUGIN_NAME . '-');
16 +define("WTSEC_FILE_URL", "https://api.wtotem.com/agent");
17 +define("WTSEC_ROOT", WP_PLUGIN_DIR . '/');
18 +define("WTSEC_MODULES_DIR", WTSEC_PLUGIN_PATH . 'uploads/');
19 +if (is_dir(WTSEC_MODULES_DIR) && is_writable(WTSEC_MODULES_DIR)) {
20 + define("WTSEC_INSTALLATION_DIR", WTSEC_MODULES_DIR);
21 + define("WTOTEMSEC_INSTALLATION_DIR", WTSEC_MODULES_DIR);
22 +} else {
23 + define("WTSEC_INSTALLATION_DIR", wp_upload_dir()['basedir'] . '/');
24 + define("WTOTEMSEC_INSTALLATION_DIR", wp_upload_dir()['basedir'] . '/');
25 +}
26 +define("WTSEC_PLUGIN_URL", plugins_url("", __FILE__));
27 +define("WTSEC_SITE_URL", str_replace(['http://', 'https://', 'www.', '//', '://'], '', get_site_url()));
28 +
29 +define("WTSEC_PLUGIN_INFORMATION_VERSION", "2.3");
30 +
31 +$curLang = substr(get_bloginfo('language'), 0,2);
32 +$language = (in_array($curLang,['ru','en','pl'])) ? $curLang : 'en' ;
33 +define("WTSEC_LANGUAGE", $language);
34 +
35 +
36 +add_action( 'deactivated_plugin', 'wtsec_DeactivatedPlugin', 1 );
37 +
38 +function wtsec_DeactivatedPlugin(){
39 + define("WTSEC_DEACTIVATED", true);
40 + require_once WTSEC_PLUGIN_PATH . 'library/App.php';
41 + $app = new WTSEC_LIBRARY_App;
42 + wtsec_DeleteAm();
43 +
44 + $app::_set('am_installed', false);
45 + $app::logout();
46 +}
47 +
48 +add_action('admin_init', 'wtsec_admin_init');
49 +add_action('wp_loaded', 'wtsec_init');
50 +
51 +add_action( 'authenticate', 'wtsec_login_check' );
52 +
53 +function wtsec_init()
54 +{
55 + require_once WTSEC_PLUGIN_PATH . 'library/App.php';
56 + require_once WTSEC_PLUGIN_PATH . 'library/Request.php';
57 +
58 + // WAF include (Если не админка и статус waf = "start", "uninstalled")
59 + // && in_array(WTSEC_LIBRARY_App::getOption('waf_status'), ["start", "uninstalled"])
60 + if (!is_admin()) {
61 + if ($waf = WTSEC_LIBRARY_App::getOption(("waf_installed_file"))) {
62 + $path_to_waf = $_SERVER['DOCUMENT_ROOT'] . '/_include_' . $waf;
63 + if (is_file($path_to_waf) && is_readable($path_to_waf)) {
64 + include_once $path_to_waf;
65 + }
66 + }
67 + }
68 +
69 + if (is_admin()) {
70 + require_once WTSEC_PLUGIN_PATH . 'library/WT.php';
71 + require_once WTSEC_PLUGIN_PATH . 'library/Localization.php';
72 + require_once WTSEC_PLUGIN_PATH . 'library/Idn.php';
73 + require_once WTSEC_PLUGIN_PATH . 'library/Session.php';
74 + require_once WTSEC_PLUGIN_PATH . 'routes.php';
75 + require_once WTSEC_PLUGIN_PATH . 'services.php';
76 + require_once WTSEC_PLUGIN_PATH . 'helpers.php';
77 +
78 + function wtsec_request()
79 + {
80 + return new WTSEC_LIBRARY_Request();
81 + }
82 + function wtsec_app()
83 + {
84 + return new WTSEC_LIBRARY_App();
85 + }
86 + function wtsec_filesystem_init($form_url, $method, $context, $fields = null)
87 + {
88 + global $wp_filesystem;
89 + if (!$creds = request_filesystem_credentials($form_url, $method, false, $context, $fields)) {
90 + return false;
91 + }
92 + if (!WP_Filesystem($creds)) {
93 + request_filesystem_credentials($form_url, $method, true, $context);
94 + return false;
95 + }
96 + return true;
97 + }
98 + function wtsec_locale($lmsg, $args = [])
99 + {
100 + return WTSEC_LIBRARY_Localization::lmsg($lmsg, $args);
101 + }
102 + function wtsec_getImagePath($image)
103 + {
104 + return plugins_url('/htdocs/img/' . $image, __FILE__);
105 + }
106 + function wtsec_SIS($arr, $key, $form = null)
107 + {
108 + $key = explode(".", $key);
109 + foreach ($key as $_key) {
110 + if (!isset($arr[$_key])) {
111 + $arr = "";
112 + break;
113 + }
114 + $arr = $arr[$_key];
115 + }
116 + return !empty($form) ? str_replace("$" . $key, $arr, $form) : $arr;
117 + }
118 + }
119 +}
120 +
121 +function wtsec_admin_init()
122 +{
123 + $rand = '?rand='.rand();
124 + if (is_admin() && stripos(wtsec_request()->page, WTSEC_PLUGIN_NAME) !== false) {
125 + wp_enqueue_script('subscriber', plugins_url('/htdocs/js/wtsec_subscriber.js'.$rand, __FILE__), [], false, true);
126 + wp_enqueue_script('d3-v4', plugins_url('/htdocs/js/wtsec_d3.v4.js', __FILE__), array( 'jquery' ), false, true);
127 + wp_enqueue_script('jsdelivr', plugins_url('/htdocs/js/wtsec_jsdelivr_chart.js', __FILE__), array( 'jquery' ), false, true);
128 + wp_enqueue_script('chart', plugins_url('/htdocs/js/wtsec_Chart.js'.$rand, __FILE__), [], false, true);
129 + wp_enqueue_script('circle-progress', plugins_url('/htdocs/js/wtsec_circle-progress.js', __FILE__), [], false, true);
130 + wp_enqueue_script('range-plugin', plugins_url('/htdocs/js/wtsec_rangePlugin.js', __FILE__), array( 'jquery' ), false, true);
131 + wp_enqueue_script('flatpickr', plugins_url('/htdocs/js/wtsec_flatpickr.js', __FILE__), array( 'jquery' ), false, true);
132 + wp_enqueue_script('filter-calendar', plugins_url('/htdocs/js/wtsec_filterCalendar.js', __FILE__), array( 'jquery' ), false, true);
133 + wp_enqueue_script('line-progress', plugins_url('/htdocs/js/wtsec_line-progress.js', __FILE__), [], false, true);
134 + wp_enqueue_script('main', plugins_url('/htdocs/js/wtsec_main.js'.$rand, __FILE__), [], false, true);
135 + wp_enqueue_script('ajax', plugins_url( '/htdocs/js/wtsec_ajax.js'.$rand, __FILE__ ), array( 'jquery' ),false, true );
136 + wp_enqueue_script('subscriber');
137 + wp_enqueue_script('print');
138 + wp_enqueue_script('d3-v4');
139 + wp_enqueue_script('jsdelivr');
140 + wp_enqueue_script('chart');
141 + wp_enqueue_script('circle-progress');
142 + wp_enqueue_script('line-progress');
143 + wp_enqueue_script('range-plugin');
144 + wp_enqueue_script('flatpickr');
145 + wp_enqueue_script('filter-calendar');
146 + wp_enqueue_script('main');
147 + wp_enqueue_script('ajax');
148 +
149 + wp_register_style('flatpickr-css', 'https://cdn.jsdelivr.net/npm/flatpickr/dist/flatpickr.min.css');
150 + wp_register_style('font', 'https://fonts.googleapis.com/css2?family=Inter:wght@400;500;700&display=swap');
151 + wp_register_style('main', plugins_url('/htdocs/css/wtsec_main.css'.$rand, __FILE__));
152 + wp_enqueue_style('flatpickr-css');
153 + wp_enqueue_style('font');
154 + wp_enqueue_style('print-css');
155 + wp_enqueue_style('main');
156 +
157 + $page = wtsec_request()->page;
158 + if ($page === wtsec_getRoute("login")) {
159 + if (WTSEC_LIBRARY_App::authorized()) {
160 + wp_safe_redirect(wtsec_getUrl('dashboard'));
161 + }
162 + } elseif ($page === wtsec_getRoute("logout")) {
163 + WTSEC_LIBRARY_App::logout();
164 + if (!WTSEC_LIBRARY_App::authorized()) {
165 + wp_safe_redirect(wtsec_getUrl('login'));
166 + }
167 + } elseif ($page === wtsec_getRoute("activate")) {
168 + if (WTSEC_LIBRARY_App::authorized()) {
169 + wp_safe_redirect(wtsec_getUrl('sites'));
170 + }
171 + } else {
172 + if (!WTSEC_LIBRARY_App::authorized()) {
173 + wp_safe_redirect(wtsec_getUrl('login'));
174 + }
175 + }
176 + }
177 +}
178 +
179 +function wtsec_login_check() {
180 + require_once WTSEC_PLUGIN_PATH . 'library/App.php';
181 + require_once WTSEC_PLUGIN_PATH . 'library/Localization.php';
182 + $app = new WTSEC_LIBRARY_App;
183 +
184 + function wtsec_locale($lmsg, $args = [])
185 + {
186 + return WTSEC_LIBRARY_Localization::lmsg($lmsg, $args);
187 + }
188 +
189 + $app->wtsec_login_check();
190 +}
191 +
192 +
193 +add_action('init', 'wtsec_StartSession', 1);
194 +add_action('wp_logout', 'wtsec_EndSession');
195 +add_action('wp_login', 'wtsec_EndSession');
196 +
197 +
198 +function wtsec_StartSession() {
199 + if(!session_id()) {
200 + session_start();
201 + }
202 +}
203 +
204 +function wtsec_EndSession() {
205 + require_once WTSEC_PLUGIN_PATH . 'library/App.php';
206 + session_destroy ();
207 +}
208 +
209 +
210 +