Skip to content

Releases: ovos/codesafe-client-wordpress

ovos codesafe 1.0.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 12:15
v1.0.1
a541440

1.0.1

New: the executed-file watch. With PHP's auto_prepend_file pointing at the plugin's stub, every PHP file the site runs that WordPress did not ship as an entry point is recorded the moment it runs — the dropped webshell, in use — with its size, md5 and the request's address, and judged on the site's next request against what wordpress.org shipped. A file nobody shipped (under uploads, in the document root, foreign or modified under core or a wp.org plugin, hidden, or already deleted again) becomes an integrity finding in codesafe — the FILES ledger, an INBOX case, the mail and chat digest, removal advice — plus one security event (file_executed) carrying the address that ran it, so that address scores as an offender and joins the attack waves. wp-admin's own entries come from the core checksum list, never from a pattern; a plugin's own endpoint hit directly is judged shipped once and never recorded again. The request that is the site costs one string comparison. Read-only: nothing is blocked, deleted or changed.

No configuration change for a site already on the layer: the watch is on by default while the prepend is active, and the Executed-file watch box under Settings → ovos codesafe (or CODESAFE_ENTRY_WATCH in wp-config.php) switches it off. A site without the prepend line now sees the paste lines under Before WordPress with the Shield unticked too — the layer is worth having for the watch alone. The codesafe instance must know the entry report mode (its develop as of 2026-09-25); an older one refuses the report and the settings line says so.

Requires PHP 8.3 and WordPress 6.0+.

Full changelog: readme.txt · the feature in depth: docs/FEATURES.md

ovos codesafe 1.0.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 09:46
v1.0.0
ee7b38f

1.0.0

The first public release of ovos codesafe for WordPress — error monitoring and cyberdefence, reporting to your own ovos codesafe.

Errors. PHP warnings, notices and fatals, batched and sent from the shutdown handler after the response went out; JavaScript errors, unhandled rejections and failed fetch/XHR calls from the bundled browser client, with breadcrumbs, a masked DOM snapshot and a shared trace id with the PHP error behind a failed request. Every error names the component that shipped its file — a plugin, a theme, a drop-in, core — or nobody, when the file is under uploads or shipped by no one.

Security events (opt-in). Failed logins from every door, rejected nonces, REST calls answered 401/403, sensitive admin changes, and the one login that succeeded after recent failures.

Traffic rollups (opt-in, APCu). Anonymous per-minute counters and request-duration histograms, so codesafe reads errors and probes as rates against real traffic.

Software inventory (opt-in) matched against public vulnerability feeds, and optionally WordPress' own auto-update switched on for exactly the plugins that are vulnerable and being probed.

Integrity scan. A read-only walk for the file nobody shipped — PHP under uploads, executable directives, foreign core and plugin files against wordpress.org checksums, suspicious database rows — plus the hardening posture. A Scan now button, and an opt-in background pass.

The Shield (opt-in, two switches). This site's exploit rules, pulled from codesafe for the CVEs it runs: match rules that observe or, once a person promoted them and blocking is ticked, answer 403; rate rules that count requests per address, per user or per route and answer 429 with Retry-After. At plugins_loaded, and optionally before WordPress via auto_prepend_file. Everything fails open.

Privacy. Credentials, tokens, cookies and nonces are dropped on the site; the request body is parsed and scrubbed (or off); nothing is ever deleted or changed on the site.

Coming from ovos-console. The plugin's directory is now ovos-codesafe (constants CODESAFE_*, options and filters ovos_codesafe*). Install it beside ovos-console and activate it: the settings are copied, the old plugin is deactivated on the next admin page, OVOS_CONSOLE_* constants, ovos_console() and the old filter names keep working, and an auto_prepend_file that still names wp-content/ovos-console/prepend.php keeps the Shield running until you point it at the new stub. Then delete ovos console under Plugins. Details: README.

Requires PHP 8.3 and WordPress 6.0+; APCu recommended.

Signed self-updates. New releases appear under Dashboard → Updates. Every release is signed (Ed25519), and the plugin verifies the signature before WordPress installs it. Public key: 0d91f295c416a035bcf3c8a3477fef635b8f306eb0f25e3d49b61ec24b919c04.

Setup: README · every feature in depth: docs/FEATURES.md