# WordSentinel

**Contributors:** victorlago, maxouhell, guerricm
**Tags:** security, WordPress, headers, CSP, SSL  
**Requires at least:** 5.8  
**Tested up to:** 6.8
**Stable tag:** 1.2.0
**Requires PHP:** 7.0  
**License:** GPLv3
**License URI:** https://www.gnu.org/licenses/gpl-3.0.html


Secure your WordPress website with advanced headers configuration, including Content Security Policy (CSP) and SSL analysis.

---

## Description

The **Word**Sentinel WordPress plugin enhances the security of your WordPress website by enabling configurable HTTP security headers and providing security grading from two popular services:

- **Mozilla Observatory**: Analyze your website's HTTP headers.

### Features:
- Configure advanced HTTP headers like:
  - Content Security Policy (CSP)
  - Strict-Transport-Security (HSTS)
  - X-Frame-Options
  - Referrer-Policy
  - Permissions-Policy
- Security grading with a visually appealing dashboard.
- Real-time analysis using external APIs.
- Retry functionality with cooldown to prevent API abuse.
- Easy-to-use interface with toggles for header configuration.

---

## Languages Supported
- English (default)
- Français (fr_FR)
- Deutsch (de_DE)
- Italiano (it_IT)
- Español (es_ES)
- Português Brasileiro (pt_PT)

---

## Installation

1. Upload the plugin files to the `/wp-content/plugins/wordsentinel/` directory or install the plugin through the WordPress plugins screen directly.
2. Activate the plugin through the 'Plugins' screen in WordPress.
3. Navigate to the **Word**Sentinel menu in the WordPress admin dashboard to configure your security headers.

---

## Frequently Asked Questions

### **1. What are HTTP security headers?**
HTTP security headers are a way to enhance the security of your website by instructing the browser on how to handle various types of requests.

### **2. Do I need coding skills to use this plugin?**
No! This plugin offers an intuitive user interface, making it easy to configure security settings.

### **3. Why does the "Scan" button have a cooldown?**
The cooldown prevents excessive API calls, ensuring compliance with the external services' rate limits.

---

## Changelog

### **1.0**
- Initial release.
- Dashboard integration with Mozilla Observatory APIs.
- Retry functionality with countdown.

### **1.0.1**
- Skipped

### **1.0.2**
- Confirmed compatibility with WordPress 6.8.

### **1.1.0**
* Major update: Introduced premium features and licensing system.
* Advanced CSP (Content Security Policy) management now available for premium users.
* Security scanning enhancements and automated reports.
* Integrated license key validation, secure JWT handling.
* Improved user interface: CSP tab now displays locked message and upgrade call-to-action when premium features are unavailable.
* Localized all plugin assets—no CDN or remote resource dependencies.
* Enhanced security: all inputs sanitized, all AJAX actions nonce-verified, all outputs escaped.
* Improved admin notices and warning dismissal.
* Compatible with latest WordPress and PHP 8.x.

### **1.2.0**

* Added support for hashing inline style tags in CSP policies.
* Improved admin interface with asynchronous panel loading and loading animations.
* Centralized all license management in the WS_License_Manager class.
* Implemented 24-hour caching for license validation to minimize API calls.
* Enhanced license validation flow and user feedback messages.
* Ensured Divi Builder admin pages are excluded from CSP enforcement for better compatibility.
* Adopted Mozilla Observatory color palette for grade visuals and improved button/hover styling.
* Completed and synchronized translations across six languages (EN, FR, DE, ES, IT, PT-BR).
* Improved execution order and structure in admin-script.js.
* See our website for a full feature comparison and upgrade details.

---

## Upgrade Notice

No upgrade notices available yet.

---

## License

This plugin is licensed under the GPLv2 or later. See the [GPLv2 License](https://www.gnu.org/licenses/gpl-2.0.html) for details.

---

## Support

For support, please visit [Nexsol Technologies](https://nexsol-tech.ch).
