PluginProbe
WebTotem Security / 2.4.2
WebTotem Security v2.4.2
3.0.2 3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 All 110 releases
← All changes | src/Common.php +87 -216 trunk2.4.2 View file →
@@ -1,243 +1,114 @@
1 1 <?php
2 2
3 3 if (!defined('WEBTOTEM_INIT') || WEBTOTEM_INIT !== true) {
4 - if (!headers_sent()) {
5 - header('HTTP/1.1 403 Forbidden');
6 - }
7 - die("Protected By WebTotem!");
8 -}
9 -
10 -add_action('upgrader_process_complete', 'wt_security_upgrade_complete', 10, 2);
11 -function wt_security_upgrade_complete($upgrader, $options)
12 -{
13 - /**
14 - * Creating a marker file after updating the plugin.
15 - */
16 - if ($options['type'] === 'plugin' && $options['action'] === 'update' && $upgrader->result['destination_name'] == 'wt-security') {
17 - WebTotemAgentManager::generateMarkerFile();
4 + if (!headers_sent()) {
5 + header('HTTP/1.1 403 Forbidden');
18 6 }
7 + die("Protected By WebTotem!");
19 8 }
20 9
21 -// WAF Include.
22 -WebTotemAgentManager::wafInclude();
23 -
10 +/**
11 + * Plugin's global variables.
12 + */
24 13 if (defined('WEBTOTEM')) {
25 14
26 - /**
27 - * Define which javascript and css files will be loaded in the header of the plugin pages.
28 - */
29 - $_page = WebTotemRequest::get('page');
30 - if (strpos($_page, 'wtotem') === 0) {
31 - add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1);
32 - }
15 + if(!session_id()) {
16 + session_start();
17 + }
33 18
34 - add_filter('pre_current_active_plugins', 'WebTotemInterface::registerDeletePrompt');
19 + /**
20 + * Remove the WordPress generator meta-tag from the source code.
21 + */
22 + remove_action('wp_head', 'wp_generator');
35 23
36 - /** Define role of current user */
37 - add_action('init', 'WebTotem::getUserRole');
24 + /**
25 + * Define which javascript and css files will be loaded in the header of the
26 + * plugin pages.
27 + */
28 + add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1);
38 29
39 - /** Execute pre-checks before every page */
40 - add_action('init', 'WebTotemInterface::startupChecks');
30 + /* Execute pre-checks before every page */
31 + add_action('wp_loaded', 'WebTotemInterface::startupChecks');
41 32
42 - /** Attach HTTP request handlers for the AJAX requests */
43 - add_action('wp_ajax_nopriv_wtotem_ajax', 'wtotem_public_ajax_callback');
44 - add_action('wp_ajax_wtotem_ajax', 'wtotem_ajax_callback');
33 + add_action( 'wp_insert_site', 'WebTotemInterface::addNewSite' );
45 34
46 - if (WebTotemOption::isActivated()) {
47 - if (WebTotemCaptcha::isEnabled() or WebTotemLogin::anyTwoFactorActivated()) {
48 - /** Login Page */
49 - add_action('login_enqueue_scripts', 'WebTotemInterface::loginEnqueueScripts');
50 - }
51 35
52 - /** Add authenticate filter */
53 - add_filter('authenticate', 'WebTotemInterface::wt_authenticate', 25, 3);
36 + /* Attach HTTP request handlers for the AJAX requests */
37 + add_action('wp_ajax_wtotem_ajax', 'wtotem_ajax_callback');
54 38
55 - /** Add lostpassword filter */
56 - add_action('lostpassword_errors', 'WebTotemInterface::wt_lost_password', 1, 2);
39 + /**
40 + * List an associative array with the sub-pages of this plugin.
41 + *
42 + * @return array List of sub-pages of this plugin.
43 + */
44 + function wtotemPages() {
45 + if( WebTotem::isMultiSite() ) {
46 + $pages['wtotem_all_sites'] = [ 'title' => __('All sites', 'wtotem'), 'slug' => 'wtotem'];
47 + }
48 + $slug = WebTotem::isMultiSite() ? 'wtotem_' : 'wtotem';
57 49
58 - /** Add site or new sites if it is multisite */
59 -// add_action('wp_insert_site', 'WebTotemInterface::addNewSite');
60 - }
50 + $pages['wtotem_dashboard'] = [ 'title' => __('Dashboard', 'wtotem'), 'slug' => $slug];
51 + $pages['wtotem_firewall'] = [ 'title' => __('Firewall', 'wtotem'), 'slug' => $slug];
52 + if(!WebTotem::isMultiSite() or is_super_admin()) {
53 + $pages['wtotem_antivirus'] = [ 'title' => __('Antivirus', 'wtotem'), 'slug' => $slug];
54 + $pages['wtotem_settings'] = [ 'title' => __('Settings', 'wtotem'), 'slug' => $slug];
55 + }
56 + $pages['wtotem_reports'] = [ 'title' => __('Reports', 'wtotem'), 'slug' => $slug];
57 + $pages['wtotem_documentation'] = [ 'title' => __('Documentation', 'wtotem'), 'slug' => 'wtotem'];
61 58
62 - if (WebTotemOption::getPluginSettings('hide_wp_version')) {
63 - /** Restore readme file before WP update, then after update hide readme file */
64 - add_filter('update_feedback', 'WebTotemInterface::restoreReadmeWhenUpdating');
59 + return $pages;
60 + }
65 61
66 - /** Remove the WordPress generator meta-tag from the source code. */
67 - remove_action('wp_head', 'wp_generator');
68 - }
62 + if (function_exists('add_action')) {
63 + /**
64 + * Display extension menu and submenu items in the correct interface.
65 + *
66 + * @return void
67 + */
68 + function wtotemAddMenu() {
69 69
70 - /** User Profile */
71 - global $pagenow;
72 - if ('profile.php' === $pagenow or 'user-edit.php' === $pagenow) {
73 - add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1);
74 - add_action('show_user_profile', 'WebTotemInterface::add2faProfileForm');
75 - add_action('edit_user_profile', 'WebTotemInterface::add2faProfileForm');
76 - }
70 + $page = ! WebTotemOption::isActivated() ? 'activation' : ( WebTotem::isMultiSite() ? 'all_sites' : 'dashboard' );
77 71
78 - /** Launch of the daily cron. */
79 - add_action('wp', 'webtotem_add_cron_');
80 - function webtotem_add_cron_()
81 - {
82 - if (!wp_next_scheduled('webtotem_daily_cron')) {
83 - wp_schedule_event(time(), 'daily', 'webtotem_daily_cron');
84 - }
85 - }
72 + add_menu_page(
73 + __('WebTotem Security', 'wtotem'),
74 + __('WebTotem Security', 'wtotem'),
75 + 'manage_options',
76 + 'wtotem',
77 + 'wtotem_' . $page . '_page',
78 + WebTotem::getImagePath('logo_17x17_w.png')
79 + );
86 80
87 - add_action('webtotem_daily_cron', 'WtotemDailyCron');
81 + if(WebTotemOption::isActivated()){
82 + $pages = wtotemPages();
83 + foreach ($pages as $sub_page_function => $sub_page) {
84 + add_submenu_page(
85 + $sub_page['slug'],
86 + $sub_page['title'],
87 + $sub_page['title'],
88 + 'manage_options',
89 + $sub_page_function,
90 + $sub_page_function . '_page'
91 + );
92 + }
88 93
89 - function WtotemDailyCron()
90 - {
91 - WebTotemOption::setOptions(['scan_init' => 1]);
92 - }
93 -
94 - /** Launch of the minute cron. */
95 - if (WebTotemOption::getOption('scan_init')) {
96 -
97 - // Register the n minute interval
98 - add_filter('cron_schedules', 'cron_add_some_min');
99 - function cron_add_some_min($schedules)
100 - {
101 - $schedules['some_min'] = array(
102 - 'interval' => 60,
103 - 'display' => __('Every few minutes', 'wtotem'),
104 - );
105 - return $schedules;
94 + } else {
95 + add_submenu_page(
96 + 'wtotem',
97 + __('Activation', 'wtotem'),
98 + __('Activation', 'wtotem'),
99 + 'manage_options',
100 + 'wtotem_activation',
101 + 'wtotem_activation_page'
102 + );
106 103 }
104 + }
107 105
108 - // Registering an event
109 - add_action('wp', 'wtotem_step_cron');
110 - function wtotem_step_cron()
111 - {
112 - if (!wp_next_scheduled('wtotem_step_init_cron')) {
113 - wp_schedule_event(time(), 'some_min', 'wtotem_step_init_cron');
114 - }
115 - }
106 + /* Attach HTTP request handlers for the internal plugin pages */
107 + if(WebTotem::isMultiSite()){
108 + add_action('network_admin_menu', 'wtotemAddMenu');
109 + }
110 + add_action('admin_menu', 'wtotemAddMenu');
116 111
117 - // Linking the function to the cron event/task
118 - add_action('wtotem_step_init_cron', 'WebTotemScan::initialize');
119 - }
120 -
121 - /**
122 - * List an associative array with the sub-pages of this plugin.
123 - *
124 - * @return array List of sub-pages of this plugin.
125 - */
126 - function wtotemPages()
127 - {
128 -
129 - $slug = 'wtotem';
130 -
131 - $pages['wtotem_dashboard'] = ['title' => __('Dashboard', 'wtotem'), 'slug' => $slug];
132 - $pages['wtotem_open_paths'] = ['title' => __('Open paths', 'wtotem'), 'slug' => $slug];
133 - $pages['wtotem_firewall'] = ['title' => __('Firewall', 'wtotem'), 'slug' => $slug];
134 - $pages['wtotem_antivirus'] = ['title' => __('Antivirus', 'wtotem'), 'slug' => $slug];
135 - $pages['wtotem_settings'] = ['title' => __('Settings', 'wtotem'), 'slug' => $slug];
136 - $pages['wtotem_documentation'] = ['title' => __('Documentation', 'wtotem'), 'slug' => 'wtotem'];
137 - $pages['wtotem_wpscan'] = ['title' => __('WP scan', 'wtotem'), 'slug' => 'wtotem'];
138 -
139 - return $pages;
140 - }
141 -
142 - if (function_exists('add_action')) {
143 - /**
144 - * Display extension menu and submenu items in the correct interface.
145 - *
146 - * @return void
147 - */
148 - function wtotemAddMenu()
149 - {
150 -
151 -// $page = !WebTotemOption::isActivated() ? 'activation' : (WebTotem::isMultiSite() ? 'all_sites' : 'dashboard');
152 - $page = !WebTotemOption::isActivated() ? 'activation' : 'dashboard';
153 -
154 -
155 - add_menu_page(
156 - __('WebTotem', 'wtotem'),
157 - __('WebTotem', 'wtotem'),
158 - 'manage_options',
159 - 'wtotem',
160 - 'wtotem_' . $page . '_page',
161 - WebTotem::getImagePath('logo_17x17_w.png')
162 - );
163 -
164 - if (WebTotemOption::isActivated()) {
165 - $pages = wtotemPages();
166 - foreach ($pages as $sub_page_function => $sub_page) {
167 - add_submenu_page(
168 - $sub_page['slug'],
169 - $sub_page['title'],
170 - $sub_page['title'],
171 - 'manage_options',
172 - $sub_page_function,
173 - $sub_page_function . '_page'
174 - );
175 - }
176 -
177 - } else {
178 - add_submenu_page(
179 - 'wtotem',
180 - __('Activation', 'wtotem'),
181 - __('Activation', 'wtotem'),
182 - 'manage_options',
183 - 'wtotem_activation',
184 - 'wtotem_activation_page'
185 - );
186 - }
187 - }
188 -
189 - /* Attach HTTP request handlers for the internal plugin pages */
190 - if (WebTotem::isMultiSite()) {
191 - add_action('network_admin_menu', 'wtotemAddMenu');
192 - }
193 - add_action('admin_menu', 'wtotemAddMenu');
194 - }
195 -
196 - /**
197 - * Event hooks.
198 - *
199 - */
200 - if (class_exists('WebTotemEventListener')) {
201 -
202 - add_action('add_user_to_blog', 'WebTotemEventListener::hookAddUserToBlog', 50, 4);
203 -
204 - add_action('add_user_to_blog', 'WebTotemEventListener::hookAddUserToBlog', 50, 4);
205 - add_action('remove_user_from_blog', 'WebTotemEventListener::hookRemoveUserFromBlog', 50, 2);
206 - add_action('login_form_resetpass', 'WebTotemEventListener::hookLoginFormResetpass', 50, 5);
207 - add_action('profile_update', 'WebTotemEventListener::hookProfileUpdate', 50, 5);
208 - add_action('retrieve_password', 'WebTotemEventListener::hookRetrievePassword', 50, 5);
209 - add_action('user_register', 'WebTotemEventListener::hookUserRegister', 50, 5);
210 - add_action('deleted_user', 'WebTotemEventListener::hookUserDelete', 50, 3);
211 - add_action('wp_login', 'WebTotemEventListener::hookLoginSuccess', 50, 5);
212 - add_action('wp_login_failed', 'WebTotemEventListener::hookLoginFailure', 50, 5);
213 - add_action('add_link', 'WebTotemEventListener::hookLinkAdd', 50, 5);
214 - add_action('edit_link', 'WebTotemEventListener::hookLinkEdit', 50, 5);
215 - add_action('create_category', 'WebTotemEventListener::hookCategoryCreate', 50, 5);
216 - add_action('publish_post', 'WebTotemEventListener::hookPublishPost', 50, 5);
217 - add_action('transition_post_status', 'WebTotemEventListener::hookPostStatus', 50, 3);
218 - add_action('xmlrpc_publish_post', 'WebTotemEventListener::hookPublishPostXMLRPC', 50, 5);
219 - add_action('before_delete_post', 'WebTotemEventListener::hookPostBeforeDelete', 50, 5);
220 - add_action('delete_post', 'WebTotemEventListener::hookPostDelete', 50, 5);
221 - add_action('wp_trash_post', 'WebTotemEventListener::hookPostTrash', 50, 5);
222 - add_action('publish_page', 'WebTotemEventListener::hookPublishPage', 50, 5);
223 - add_action('add_attachment', 'WebTotemEventListener::hookAttachmentAdd', 50, 5);
224 - add_action('activated_plugin', 'WebTotemEventListener::hookPluginActivate', 50, 2);
225 - add_action('deactivated_plugin', 'WebTotemEventListener::hookPluginDeactivate', 50, 2);
226 - add_action('switch_theme', 'WebTotemEventListener::hookThemeSwitch', 50, 5);
227 -
228 - add_action('admin_init', 'WebTotemEventListener::hookCoreUpdate');
229 - add_action('admin_init', 'WebTotemEventListener::hookOptionsManagement');
230 - add_action('admin_init', 'WebTotemEventListener::hookPluginDelete');
231 - add_action('admin_init', 'WebTotemEventListener::hookPluginEditor');
232 - add_action('admin_init', 'WebTotemEventListener::hookPluginInstall');
233 - add_action('admin_init', 'WebTotemEventListener::hookPluginUpdate');
234 - add_action('admin_init', 'WebTotemEventListener::hookThemeDelete');
235 - add_action('admin_init', 'WebTotemEventListener::hookThemeEditor');
236 - add_action('admin_init', 'WebTotemEventListener::hookThemeInstall');
237 - add_action('admin_init', 'WebTotemEventListener::hookThemeUpdate');
238 - add_action('admin_init', 'WebTotemEventListener::hookWidgetAdd');
239 - add_action('admin_init', 'WebTotemEventListener::hookWidgetDelete');
240 -
241 - }
112 + }
242 113
243 114 }