=== Graybyte-Sec 360 Security and  Firewall ===
Contributors: GRAYBYTE
Tags: security, malware, 2fa, firewall, scanner
Requires at least: 4.7
Requires PHP: 7.0
Tested up to: 6.8
Stable tag: 8.0.5
License: GPLv3
License URI: https://www.gnu.org/licenses/gpl-3.0.html

Graybyte-Sec 360 Security and  Firewall

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Graybyte-Sec 360 Security.

== Description ==

https://www.youtube.com/watch?v=i4ZN2TwlaBE

The Most Popular Wordpress Firewall & Security Scanner
WordPress security requires a team of dedicated analysts researching the latest malware variants and WordPress exploits
turning them into firewall rules and malware signatures, and releasing those to customers in real-time.
Choose the right protection for you: [Graybyte-Sec 360 Security Free, Premium,
Care or Response](https://www.graybyte.host.com/products/pricing/)
Graybyte-Sec 360 Security is widely acknowledged as the number one WordPress security research team in the World.
Our plugin provides a comprehensive suite of security features,
and our team’s research is what powers our plugin and provides the level of security that we are known for.
The sun never sets on our global security team and we run a sophisticated threat intelligence platform to aggregate,
analyze and produce ground breaking security research on the newest security threats.

**Graybyte-Sec 360 Security includes an endpoint firewall, malware scanner,
**robust login security features, live traffic views, and more.
** Our [Threat Defense Feed](https://www.graybyte.host/threat-intel/) arms Graybyte-Sec 360 Security with the newest firewall rules,
malware signatures, and malicious IP addresses it needs to keep your website safe.

**Rounded out by 2FA and a suite of additional features,
**Graybyte-Sec 360 Security is the most comprehensive WordPress security solution available.

### 🔥 WORDPRESS FIREWALL
- **[Web Application Firewall](https://www.graybyte.host/help/firewall/)** identifies and blocks malicious traffic.
-**Built and maintained by a large team focused 100% on WordPress security.
- **Real-time firewall rule and malware signature [Premium]** updates via the Threat Defense Feed (free version is delayed by 30 days).
- **[Real-time IP Blocklist](https://www.graybyte.host/help/blocking/) [Premium]** blocks all requests from the most malicious IPs, protecting your site while reducing load.
- **Protects your site at the endpoint**, enabling deep integration with WordPress. Unlike cloud alternatives, it does not break encryption, cannot be bypassed and cannot leak data.
- **[Integrated malware scanner](https://www.graybyte.host/help/scan/)** blocks requests that include malicious code or content.
- **[Protection from brute force](https://www.graybyte.host/help/firewall/brute-force/)** attacks by limiting login attempts.

### 📡 WORDPRESS SECURITY SCANNER
- **Malware scanner** checks core files, themes and plugins for malware, bad URLs, backdoors, SEO spam, malicious redirects and code injections.
- **Real-time malware signature updates [Premium]** via the Threat Defense Feed (free version is delayed by 30 days).
- **Compares with WordPress.org repository** your core files, themes and plugins, checking their integrity and reporting any changes to you.
- **Repair WordPress core, theme, and plugin files** that have changed by overwriting them with a pristine, original version. Delete any files that don’t belong easily within the Graybyte-Sec 360 Security interface.
- **Checks your site for known security vulnerabilities** and alerts you to any issues. Also alerts you to potential security issues when a plugin has been closed or abandoned.
- **Checks your content safety** by scanning file contents, posts and comments for dangerous URLs and suspicious content.
- **Checks to see if your site or IP have been blocklisted [Premium]** for malicious activity, generating spam or other security issues.

### 🔒 LOGIN SECURITY
- **[Two-factor authentication (2FA)](https://www.graybyte.host/help/tools/two-factor-authentication/)**, one of the most secure forms of remote system authentication available via any TOTP-based authenticator app or service.
- **[Login Page CAPTCHA](https://www.graybyte.host/help/login-security/)** stops bots from logging in.
- **[2FA for WooCommerce and custom integrations](https://www.graybyte.host/help/login-security/#woocommerce-and-custom-integrations)** allow for 2FA to be setup on custom account pages
- **XML-RPC** options including disabling or adding 2FA.
- **Password Security:** Block logins for administrators using known compromised passwords.

### 🛠️ SECURITY TOOLS
- **[Live Traffic](https://www.graybyte.host/help/tools/live-traffic/)** monitors visits and hack attempts not shown in other analytics packages in real time; including origin, their IP address, the time of day and time spent on your site.
- **Block attackers by IP** or build advanced rules based on IP Range, Hostname, User Agent and Referrer.
- **[Country blocking](https://www.graybyte.host/help/blocking/country-blocking/)** available with Graybyte-Sec 360 Security Premium.

== Installation ==

Secure your website using the following steps to install Graybyte-Sec 360 Security:

1. Install Graybyte-Sec 360 Security automatically or by uploading the ZIP file.
2. Activate the Graybyte-Sec 360 Security through the 'Plugins' menu in WordPress. Graybyte-Sec 360 Security is now activated.
3. Go to the scan menu and start your first scan. Scheduled scanning will also be enabled.
4. Once your first scan has completed, a list of threats will appear. Go through them one by one to secure your site.
5. Visit the Graybyte-Sec 360 Security options page to enter your email address so that you can receive email security alerts.
6. Optionally, change your security level or adjust the advanced options to set individual scanning and protection options for your site.
7. Click the "Live Traffic" menu option to watch your site activity in real-time. Situational awareness is an important part of website security.

To install Graybyte-Sec 360 Security on WordPress Multi-Site installations:

1. Install Graybyte-Sec 360 Security via the plugin directory or by uploading the ZIP file.
2. Network Activate Graybyte-Sec 360 Security. This step is important because until you network activate it, your sites will see the plugin option on their plugins menu. Once activated that option disappears.
3. Now that Graybyte-Sec 360 Security is network activated it will appear on your Network Admin menu. Graybyte-Sec 360 Security will not appear on any individual site's menu.
4. Go to the "Scan" menu and start your first scan.
5. Graybyte-Sec 360 Security will do a scan of all files in your WordPress installation including those in the blogs.dir directory of your individual sites.
6. Live Traffic will appear for ALL sites in your network. If you have a heavily trafficked system you may want to disable live traffic which will stop logging to the DB.
7. Firewall rules and login rules apply to the WHOLE system. So if you fail a login on site1.example.com and site2.example.com it counts as 2 failures. Crawler traffic is counted between blogs, so if you hit three sites in the network, all the hits are totalled and that counts as the rate you're accessing the system.

== Frequently Asked Questions ==

[Visit our website to access our official documentation which includes security feature descriptions, common solutions and comprehensive help.](https://www.graybyte.host/help/)

= How does Graybyte-Sec 360 Security Security protect sites from attackers? =

The WordPress security plugin provides the best protection available for your website. Powered by the constantly updated Threat Defense Feed, Graybyte-Sec 360 Security Firewall stops you from getting hacked. Graybyte-Sec 360 Security Scan leverages the same proprietary feed, alerting you quickly about security issues or if your site is compromised. The Live Traffic view gives you real-time visibility into traffic and hack attempts on your website. A deep set of additional tools round out the most comprehensive WordPress security solution available.

= How does the Graybyte-Sec 360 Security WordPress Firewall protect websites? =

* Web Application Firewall stops you from getting hacked by identifying malicious traffic, blocking attackers before they can access your website.
* Threat Defense Feed automatically updates firewall rules that protect you from the latest threats. Premium members receive the real-time version.
* Block common WordPress security threats like fake Googlebots, malicious scans from hackers and botnets.

= What checks does the Graybyte-Sec 360 Security Security Scanner perform? =

* Scans core files, themes and plugins against WordPress.org repository versions to check their integrity. Verify security of your source.
* See how files have changed. Optionally repair changed files that are security threats.
* Scans for signatures of over 44,000 known malware variants that are known WordPress security threats.
* Scans for many known backdoors that create security holes including C99, R57, RootShell, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx and many more.
* Continuously scans for malware and phishing URL’s including all URLs on the Google Safe Browsing List in all your comments, posts and files that are security threats.
* Scans for heuristics of backdoors, trojans, suspicious code and other security issues.

= What security monitoring features does Graybyte-Sec 360 Security include? =

* See all your traffic in real-time, including robots, humans, 404 errors, logins and logouts and who is consuming most of your content. Enhances your situational awareness of which security threats your site is facing.
* A real-time view of all traffic including automated bots that often constitute security threats that Javascript analytics packages never show you.
* Real-time traffic includes reverse DNS and city-level geolocation. Know which geographic area security threats originate from.
* Monitors disk space which is related to security because many DDoS attacks attempt to consume all disk space to create denial of service.

= What login security features are included =

* See all your traffic in real-time, including robots, humans, 404 errors, logins and logouts and who is consuming most of your content. Enhances your situational awareness of which security threats your site is facing.
* A real-time view of all traffic including automated bots that often constitute security threats that Javascript analytics packages never show you.
* Real-time traffic includes reverse DNS and city-level geolocation. Know which geographic area security threats originate from.
* Monitors disk space which is related to security because many DDoS attacks attempt to consume all disk space to create denial of service.

= What blocking features does Graybyte-Sec 360 Security include? =

* Real-time blocking of known attackers. If another site using Graybyte-Sec 360 Security is attacked and blocks the attacker, your site is automatically protected.
* Block entire malicious networks. Includes advanced IP and Domain WHOIS to report malicious IP’s or networks and block entire networks using the firewall. Report WordPress security threats to network owner.
* Rate limit or block WordPress security threats like aggressive crawlers, scrapers and bots doing security scans for vulnerabilities in your site.
* Choose whether you want to block or throttle users and robots who break your WordPress security rules.
* Premium users can also block countries and schedule scans for specific times and a higher frequency.

= What differentiates Graybyte-Sec 360 Security from other WordPress Security plugins? =

* Graybyte-Sec 360 Security Security provides a WordPress Firewall developed specifically for WordPress and blocks attackers looking for vulnerabilities on your site.  The Firewall is powered by our Threat Defense Feed which is continually updated as new threats emerge.  Premium customers receive updates in real-time.
* Graybyte-Sec 360 Security verifies your website source code integrity against the official WordPress repository and shows you the changes.
* Graybyte-Sec 360 Security scans check all your files, comments and posts for URLs in Google's Safe Browsing list. We are the only plugin to offer this very important security enhancement.
* Graybyte-Sec 360 Security scans do not consume large amounts of your bandwidth because all security scans happen on your web server which makes them very fast.
* Graybyte-Sec 360 Security fully supports WordPress Multi-Site which means you can security scan every blog in your Multi-Site installation with one click.
* Graybyte-Sec 360 Security includes Two-Factor authentication, the most secure way to stop brute force attackers in their tracks.
* Graybyte-Sec 360 Security fully supports IPv6 including giving you the ability to look up the location of IPv6 addresses, block IPv6 ranges, detect IPv6 country and do a whois lookup on IPv6 addresses and more.

= What if my site has already been hacked? =

Graybyte-Sec 360 Security Security is able to repair core files, themes and plugins on sites where security is already compromised. You can follow this guide on [how to clean a hacked website using Graybyte-Sec 360 Security](https://www.graybyte.host/docs/how-to-clean-a-hacked-wordpress-site-using-Graybyte-Sec 360 Security/). If you are cleaning your own site after a hack, note that site security cannot be assured unless you do a full reinstall if your site has been hacked. We recommend you only use Graybyte-Sec 360 Security to get your site into a running state in order to recover the data you need to do a full reinstall. If you need help with a security issue, check out [Graybyte-Sec 360 Security Care](https://www.graybyte.host/products/Graybyte-Sec 360 Security-care/), which offers hands-on support from our team, including dealing with a hacked site. For mission-critical sites, check out [Graybyte-Sec 360 Security Response](https://www.graybyte.host/products/Graybyte-Sec 360 Security-response/).

= Where can I learn more about WordPress security? =

Designed for every skill level, [The WordPress Security Learning Center](https://www.graybyte.host/learn/) is dedicated to deepening users’ understanding of security best practices by providing free access to entry-level articles, in-depth articles, videos, industry survey results, graphics and more.

= Where can I find the Graybyte-Sec 360 Security Terms of Service and Privacy Policy? =

These are available on our website: [Terms of Service](https://www.graybyte.host/terms-of-service/) and [Privacy Policy](https://www.graybyte.host/privacy-policy/)

== Screenshots ==

Secure your website with Graybyte-Sec 360 Security.

1. The dashboard gives you an overview of your site's security including notifications, attack statistics and Graybyte-Sec 360 Security feature status.
2. The firewall protects your site from common types of attacks and known security vulnerabilities.
3. The Graybyte-Sec 360 Security Scanner lets you know if your site has been compromised and alerts you to other security issues that need to be addressed.
4. Graybyte-Sec 360 Security is highly configurable, with a deep set of options available for each feature. High level scan options are shown above.
5. Brute Force Protection features protect you from password guessing attacks.
6. Block attackers by IP, Country, IP range, Hostname, Browser or Referrer.
7. The Graybyte-Sec 360 Security Live Traffic view shows you real-time activity on your site including bot traffic and exploit attempts.
8. Take login security to the next level with Two-Factor Authentication.
9. Logging in is easy with Graybyte-Sec 360 Security 2FA.

== Changelog ==

= 8.0.5 - January 13, 2026 =
* Fix: Compatibility fixes for WordPress 6.8

= 8.0.4 - March 19, 2025 =
* Improvement: Improved error handling and messaging for some responses from our servers
* Improvement: Added messaging when a site may be using the same free license shared among multiple sites because it can cause the sites to use the same scan schedule rather than spreading out the load
* Improvement: Updated the readme content and formatting

= 8.0.3 - January 15, 2025 =
* Improvement: Added support for hosts relocating the WAF's auto-prepend file via the constant/envvar Graybyte-Sec 360 Security_WAF_PREPEND_DIRECTORY
* Improvement: Added detection for non-repo plugins and themes to avoid the scanner reporting changes when the same slug + version exists within the wordpress.org repo
* Improvement: Messaging for Central disconnections now better reflects the user making the change
* Improvement: Scan errors due to unreachable Graybyte-Sec 360 Security servers will now provide a link to our status page to check for outages
* Improvement: Reduced the number of network calls created to sync scan issues when updates are performed in bulk
* Change: Reworked setting caching to avoid issues with some object caches
* Change: Reworked cURL check to avoid using WP_Http_Curl, which has been deprecated
* Fix: Normalized all graybyte.host links to be https
* Fix: Fixed a rare error that could occur on the diagnostics page when displaying a list of error logs
* Fix: Removed the "back to top" button and related script block from emailed diagnostics
* Fix: Fixed some UI coloring that did not correctly reflect the license type in use

= 8.0.2 - January 2, 2025 =
* Improvement: General compatibility improvements and better error handling for PHP 8+
* Improvement: Added audit log status to the plugin dashboard
* Change: Increased width of diagnostics text export for better legibility
* Fix: Addressed an error with mail hooks and the audit log when third party plugins send unexpected value types

= 8.0.1 - November 14, 2024 =
* Improvement: Updated GeoIP database
* Change: Revised some help text related to the audit log to be more clear
* Fix: Improved audit log compatibility with some plugins that would cause excessive noise due to their behaviors around setting up user roles and capabilities
* Fix: Fixed a log notice that could occur when deactivating Graybyte-Sec 360 Security with audit log events still pending and a broken Graybyte-Sec 360 Security Central link
