=== DecoyNest ===
Contributors: decoynest
Tags: security, honeypot, firewall, two-factor, vulnerability-scanner
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

A privacy-first WordPress security suite with deception sensors, MFA, SSO, firewall, scanning, hardening and audit logging.

== Description ==

DecoyNest combines decoy endpoints with two-factor authentication, Microsoft/Google/GitHub SSO, firewall and country blocking, vulnerability scanning, hardening checks, security headers, and an administrative audit log. Every install receives this detection and access-control stack without a paid license.

Encrypted scheduled backups, customer-owned cloud storage and SIEM integrations are available in the separately distributed DecoyNest Pro add-on. Learn more at https://decoynest.com/pricing/.

**Privacy first.** Honeypot events stay on your WordPress site by default. Remote features are activated only by a clear administrator action: running a vulnerability scan, enabling automatic scans, enabling geoblocking, configuring SSO, or opting into threat-intelligence sharing. See "External services" below for the exact data and destination involved in each feature.

= Detection and security features =

* Fake `/wp-adm1n/` login page
* Fake plugin `readme.txt` file (catches vulnerability scanners probing for outdated plugin versions)
* `xmlrpc.php` suspicious-call monitoring (brute-force / amplification attempts)
* TOTP MFA with one-time recovery codes
* OAuth/OIDC SSO for Microsoft, Google, and GitHub
* IP/CIDR and country blocking, rate limiting, XML-RPC and REST controls
* WordPress core, plugin, and theme vulnerability scanning
* Hardening score, security headers, and administrative audit evidence

== External services ==

DecoyNest can connect to the services below. The plugin does not load remote JavaScript, CSS, tracking pixels or advertisements.

= DecoyNest vulnerability service =

When an administrator clicks "Run Scan Now", the plugin sends the site URL, plugin version, and the installed WordPress core/plugin/theme inventory to `https://api.decoynest.com`. Inventory fields include software name, slug, version, author, activation state and plugin file identifier. The service compares those versions with vulnerability data and returns matching findings. A random installation identifier is sent during first use to issue a site-bound scanner credential; the raw credential is stored encrypted in WordPress and only its hash is stored by the service.

Automatic daily scans are disabled by default. If an administrator enables them in Scanner Settings, the same inventory is sent once per day through WP-Cron.

The DecoyNest backend may query the Wordfence Intelligence vulnerability feed using software slugs and types. It does not send the requesting site's URL to Wordfence.

* Service: https://api.decoynest.com
* DecoyNest privacy policy: https://decoynest.com/privacy-policy/
* DecoyNest terms: https://decoynest.com/terms-of-service/
* Wordfence privacy policy: https://www.wordfence.com/help/general-data-protection-regulation/
* Wordfence terms: https://www.wordfence.com/terms-of-use/

= DecoyNest threat-intelligence sharing =

This service is disabled by default and requires a separate administrator opt-in. When enabled, the plugin sends selected honeypot event metadata to `https://api.decoynest.com`: source IP address, user-agent string, event timestamp, request-path pattern, trap type and attack category. It does not send site content, submitted credentials, file contents or database contents. Disabling sharing stops future event delivery and deactivates the sensor credential.

* Service: https://api.decoynest.com
* Privacy policy: https://decoynest.com/privacy-policy/
* Terms: https://decoynest.com/terms-of-service/

= IPWhois geolocation =

Country-based wp-admin access control is disabled by default. If an administrator enables geoblocking, the visitor's IP address is sent over HTTPS to `https://ipwho.is` to obtain an ISO country code. The returned country code is cached locally for 24 hours. No request is made to this service while geoblocking is disabled.

* Service and API documentation: https://ipwhois.io/documentation
* Privacy policy: https://ipwhois.io/privacy
* Terms: https://ipwhois.io/terms

= Optional SSO providers =

Microsoft, Google and GitHub SSO are disabled until an administrator configures a provider. When a user chooses a configured SSO login, the browser and plugin communicate with that provider's OAuth/OIDC endpoints. The provider receives the normal OAuth request data, including the configured client ID, redirect URL, requested scopes and a PKCE challenge. DecoyNest then requests the authenticated account identifier, name and email needed to match or create the local WordPress user. Provider tokens are not sent to DecoyNest servers.

* Microsoft privacy and terms: https://privacy.microsoft.com/privacystatement and https://www.microsoft.com/servicesagreement
* Google privacy and API terms: https://policies.google.com/privacy and https://developers.google.com/terms
* GitHub privacy and terms: https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement and https://docs.github.com/site-policy/github-terms/github-terms-of-service

= WordPress.org checksum services =

When an administrator runs a file-integrity scan, the plugin requests official checksum manifests from `https://api.wordpress.org` and `https://downloads.wordpress.org`. Requests contain the installed WordPress version and locale, or a WordPress.org plugin/theme slug and version. File contents, local hashes, the site URL and user data are not sent. Weekly file-integrity scans are disabled by default and use the same services only after an administrator enables them.

* Services: https://api.wordpress.org and https://downloads.wordpress.org
* WordPress.org privacy policy: https://wordpress.org/about/privacy/

= Optional crawler verification services =

Crawler verification is disabled by default. If an administrator enables it, a decoy hit whose user-agent claims to be Googlebot or Bingbot may cause a background request for that provider's published crawler IP ranges. Claimed Google, Bing, DuckDuckGo, Yandex and Baidu crawlers may also be checked using forward-confirmed reverse DNS for the visitor IP. Results are cached locally for 30 days.

* Google crawler information and privacy: https://developers.google.com/search/docs/crawling-indexing/verifying-googlebot and https://policies.google.com/privacy
* Bing crawler information and privacy: https://www.bing.com/webmasters/help/how-to-verify-bingbot-3905dc26 and https://privacy.microsoft.com/privacystatement
* DuckDuckGo crawler information and privacy: https://duckduckgo.com/duckduckgo-help-pages/results/duckduckbot and https://duckduckgo.com/privacy
* Yandex privacy policy: https://yandex.com/legal/confidential/
* Baidu privacy policy: https://www.baidu.com/duty/yinsiquan-policy.html

== Installation ==

1. Upload the `decoynest` folder to `/wp-content/plugins/`, or install directly through the WordPress admin Plugins screen.
2. Activate the plugin through the 'Plugins' menu in WordPress.
3. Go to the "DecoyNest" menu item in your admin sidebar to view captured events and (optionally) enable threat-intelligence metadata sharing.

== Frequently Asked Questions ==

= Does this slow down my site? =

No. Traps only activate on specific decoy URLs that legitimate visitors and search engines never request. Normal site traffic is unaffected.

= Will this block real attackers? =

DecoyNest can restrict wp-admin access with IP/CIDR lists, optional country rules and login rate limiting. Its honeypot findings are primarily detection and intelligence signals; they are not a replacement for a network-level WAF and do not guarantee that every attack will be blocked.

= What happens to my data if I share it? =

Threat-intelligence sharing sends only the fields listed in its consent screen. Vulnerability scanning and optional geoblocking have separate data flows described in "External services" above; they are not bundled into the threat-intelligence consent checkbox.

= What happens to my data if I uninstall the plugin? =

Deactivating, deleting or reinstalling the plugin preserves security data by default. Administrators can explicitly opt into complete cleanup with the documented `DECOYNEST_REMOVE_DATA_ON_UNINSTALL` setting.

== Screenshots ==

1. Dashboard overview showing captured events.
2. Threat intelligence sharing consent screen.

== Changelog ==

= 1.0.4 =
* Added authenticated daily sensor heartbeats and post-update reconciliation so opted-in installations remain accurately represented in the threat-intelligence analysis service.
* Sensor credentials are validated only by the backend; raw credentials are never forwarded to the analysis VM.

= 1.0.3 =
* Cleared the remaining WordPress Plugin Check errors and warnings: SQL constants now go through placeholders or a narrowly-scoped, reasoned exception instead of a blanket file-level suppression; every nonce, sanitization and unslashing finding was individually reviewed rather than bulk-annotated; the plugin/theme file editor and uninstall directory removal now go through WP_Filesystem.
* Removed the unnecessary load_plugin_textdomain() call and the Domain Path header (WordPress.org loads translations automatically since 4.6).

= 1.0.2 =
* Resolved WordPress Plugin Check errors and warnings across admin views, logging, sensors, scanning, SSO, MFA, hardening and forensic export.
* Improved validation, escaping and compatibility with current WordPress and PHP releases.

= 1.0.1 =
* Added automatic, encrypted scanner credential provisioning on the first administrator-requested scan.
* Made recurring remote scans an explicit, disabled-by-default setting.
* Documented every external service and its data flow.
* Added suggested WordPress privacy-policy text.
* Replaced the non-commercial, HTTP-only geolocation integration with the HTTPS ipwho.is service.

= 1.0.0 =
* Prepared the complete free security plugin for WordPress.org distribution.
* Moved encrypted backups, cloud storage, licensing and SIEM integrations into the separate DecoyNest Pro add-on.
* Added a single contextual Upgrade to Pro page and plugin-row link.

= 0.8.2 =
* Preserve MFA secrets, settings, audit history, and license state during accidental plugin deletion. Full cleanup now requires an explicit wp-config.php opt-in.

= 0.1.0 =
* Initial MVP release: fake wp-admin trap, fake plugin file trap, xmlrpc monitoring, local event storage, opt-in consent for anonymized sharing, basic dashboard.

== Upgrade Notice ==

= 1.0.4 =
Keeps opted-in sensor registration state synchronized after plugin updates and during normal operation.

= 1.0.3 =
Completes the WordPress Plugin Check cleanup and moves sensitive file operations through WP_Filesystem.

= 1.0.2 =
Recommended maintenance update with WordPress Plugin Check and PHP compatibility fixes.

= 1.0.1 =
Remote vulnerability scans now require an explicit administrator action or an enabled automatic-scan setting, and all external services are documented.
