1.0.1
New: the executed-file watch. With PHP's auto_prepend_file pointing at the plugin's stub, every PHP file the site runs that WordPress did not ship as an entry point is recorded the moment it runs — the dropped webshell, in use — with its size, md5 and the request's address, and judged on the site's next request against what wordpress.org shipped. A file nobody shipped (under uploads, in the document root, foreign or modified under core or a wp.org plugin, hidden, or already deleted again) becomes an integrity finding in codesafe — the FILES ledger, an INBOX case, the mail and chat digest, removal advice — plus one security event (file_executed) carrying the address that ran it, so that address scores as an offender and joins the attack waves. wp-admin's own entries come from the core checksum list, never from a pattern; a plugin's own endpoint hit directly is judged shipped once and never recorded again. The request that is the site costs one string comparison. Read-only: nothing is blocked, deleted or changed.
No configuration change for a site already on the layer: the watch is on by default while the prepend is active, and the Executed-file watch box under Settings → ovos codesafe (or CODESAFE_ENTRY_WATCH in wp-config.php) switches it off. A site without the prepend line now sees the paste lines under Before WordPress with the Shield unticked too — the layer is worth having for the watch alone. The codesafe instance must know the entry report mode (its develop as of 2026-09-25); an older one refuses the report and the settings line says so.
Requires PHP 8.3 and WordPress 6.0+.
Full changelog: readme.txt · the feature in depth: docs/FEATURES.md