=== SiteMind Agent ===
Contributors: terryarthur
Tags: monitoring, maintenance, uptime, security, management
Requires at least: 6.0
Tested up to: 6.9
Requires PHP: 8.0
Stable tag: 1.7.8
License: GPL-2.0+
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Connects your WordPress site to SiteMind Hub for uptime monitoring, security scanning, updates, and health reports.

== Description ==

SiteMind Agent connects your WordPress site to the [SiteMind Hub](https://sitemind.terryarthurconsulting.com) for centralized monitoring and management. It is a companion plugin for the SiteMind managed WordPress service by [Terry Arthur Consulting](https://terryarthurconsulting.com).

= What It Does =

* **Uptime Monitoring** — Periodic heartbeat keeps the hub informed that your site is online
* **Server Metrics** — Collects CPU, memory, disk, and network usage data
* **Event Reporting** — Reports plugin activations, updates, failed logins, theme changes, and fatal errors to the hub in real time
* **Remote Commands** — Accepts authenticated commands from the hub to run updates, clear cache, toggle maintenance mode, trigger backups, and more
* **Security Scanning** — File integrity checks and malware signature scanning on demand
* **Database Maintenance** — Cleanup transients, revisions, spam, trash, orphaned data, and optimize tables
* **Client Dashboard** — Adds a status widget to your WordPress admin showing uptime, security, and expiry data

= Security =

* All communication between the agent and hub is authenticated via API key headers
* Incoming commands from the hub are verified with HMAC-SHA256 signatures
* Rate limiting protects against abuse
* The plugin never stores passwords or sensitive credentials beyond your API key

= Requirements =

* WordPress 6.0 or higher
* PHP 8.0 or higher
* An active SiteMind Hub account (provided by Terry Arthur Consulting)

== Installation ==

= Automated Setup =

1. Go to the SiteMind Hub at [sitemind.terryarthurconsulting.com](https://sitemind.terryarthurconsulting.com)
2. Click "Connect Site" and enter your WordPress URL
3. Follow the guided setup — the hub will configure the plugin automatically

= Manual Setup =

1. Upload the `sitemind-agent` folder to `/wp-content/plugins/`
2. Activate the plugin through the Plugins menu
3. Navigate to **Settings > SiteMind Agent**
4. Enter your Hub URL, API Key, and Site ID (provided by your SiteMind account)
5. Check "Enable monitoring agent" and click Save Settings
6. Click "Test Connection" to verify

== Frequently Asked Questions ==

= Does this plugin slow down my site? =

No. The agent runs on WordPress cron at configurable intervals (default: every 5 minutes). Data collection is lightweight and does not affect page load times for visitors.

= What data does the plugin send? =

The plugin sends WordPress version info, plugin/theme lists, server resource metrics (CPU, memory, disk), and event notifications (updates, login failures, errors). It does not send post content, user data, or passwords.

= Can I use this without the SiteMind Hub? =

The plugin requires a SiteMind Hub account to function. Without hub credentials, the plugin remains dormant and does not send any data.

= Is the plugin safe to use? =

Yes. All hub communication uses HMAC-SHA256 signature verification. The plugin follows WordPress coding standards and has passed the official Plugin Check with zero errors.

== Screenshots ==

1. Settings page — configure your hub connection
2. Client dashboard widget — at-a-glance site health status
3. Full status page — detailed uptime, security, and resource data

== Changelog ==

= 1.7.8 =
* Added internal self-update channel: agent now checks `https://sitemind.terryarthurconsulting.com/updates/info.json` and feeds the result into WordPress's standard plugin update transient. Sending `update_plugin sitemind-agent` from the SiteMind hub now works without any reliance on wp.org. Update info is cached 12h on success / 5min on failure.

= 1.7.7 =
* Added bot defense: blocks known WordPress webshell-probe paths (xmlrpc.php, single-letter dropper kits, /hellopress/, wp_filemanager.php, top-level .php files in wp-content) at the `plugins_loaded` priority 1 hook. Returns 403 + exit before WordPress query/template work runs. Saves ~95% of CPU under bot 404-storms.
* Allow-list preserves legitimate plugin/theme/mu-plugin/uploads paths.

= 1.7.6 =
* Added wp-config.php constants fallback for sites behind WAFs that strip form-saved settings.
* Added diagnostic panel in admin settings.
* Added per-field error messages on save.
* Added heartbeat-based connected indicator.

= 1.7.5 =
* Fixed cron scheduling race condition — custom interval registration now happens in init() before wp_schedule_event() calls, preventing silent scheduling failures after cron table clears.
* Fixed potential fatal error in user registration event when get_userdata() returns false.
* Removed version and site_id exposure from the unauthenticated /status REST endpoint.
* Fixed XSS vector in admin settings JavaScript — AJAX responses now use .text() instead of .html().
* Fixed incorrect menu location in installation instructions (Settings, not Tools).
* Added deactivation hook to clean up cron events when plugin is disabled.
* Fixed dashboard CSS not loading — enqueue hook was never registered.
* Added server-side heartbeat interval clamp (60-3600s) — prevents DoS via zero interval.
* Error log reading now uses tail instead of loading entire file into memory.
* Added uninstall.php — cleans up all plugin options and transients on deletion.
* Removed dead code (collect_server, get_ssl_expiry) superseded by SiteMind_Server_Collector.
* Fixed broken skip-directory logic in file integrity scanner.
* Hardened self-toggle protection to use plugin_basename instead of string match.
* Narrowed REST authentication bypass to /status and /command routes only.
* API key field now uses password input type.
* Dashboard metrics cached in 60-second transient to avoid expensive re-collection.
* Malware scanner skips files over 1MB to prevent memory exhaustion.
* Wrapped delete-all-transients query in $wpdb->prepare().

= 1.7.3 =
* Replaced hardcoded ABSPATH path references with WP_CONTENT_DIR, WPINC, and wp_normalize_path() for cross-platform compatibility.
* Added Guideline 8 management service documentation to all remote command methods.

= 1.7.2 =
* Added SECURITY.md and Dependabot configuration for automated dependency updates.
* Removed WordPress version exposure from the public status endpoint.

= 1.7.1 =
* Updated Plugin URI and Contributors for WordPress.org review.
* Enqueued inline CSS and JavaScript to external files per WordPress.org guidelines.

= 1.7.0 =
* Added MindBot AI Advisor widget and full-page advisory section.

= 1.4.0 =
* Prepared for wordpress.org submission.
* Fixed unescaped database parameter in optimize query.
* Used $wpdb->prepare() for SHOW TABLES query.

= 1.3.0 =
* Added remote maintenance commands: cleanup transients, revisions, spam comments, trash, auto-drafts, orphaned data, and database optimization.
* Added "Run All Maintenance" command for one-click full cleanup.

= 1.2.0 =
* Fixed all WordPress coding standard violations.
* Replaced direct filesystem calls with WP_Filesystem API.
* Sanitized all superglobal access.
* Escaped all output in HTML attributes.

= 1.1.1 =
* Added malware scanner false-positive whitelist for WordPress core files.

= 1.1.0 =
* Added UpdraftPlus backup status and trigger commands.
* Added update checking and bulk update commands.
* Added client dashboard widget and status page.

= 1.0.0 =
* Initial release with heartbeat, metrics, events, and remote commands.

== Upgrade Notice ==

= 1.7.2 =
Security hardening — removes version exposure from status endpoint. Adds Dependabot for automated dependency monitoring.

= 1.4.0 =
Recommended update. Fixes database query escaping and prepares for wordpress.org distribution.
