=== Malware Cleaner ===
Contributors: tohidurhasan
Tags: malware scanner, security, firewall, cleanup
Requires at least: 5.8
Tested up to: 7.0
Stable tag: 15.0.2
Requires PHP: 7.4
License: GPLv2 or later

Professional malware scanner, firewall, hardening, cleanup and security dashboard for WordPress.

== Changelog ==

= 15.0.2 =
* Fixed recursive WordPress capability check that could exhaust memory after activation.
* Added automatic redirect to the Malware Cleaner dashboard after plugin activation.

= 15.0.1 =
* Fixed activation memory exhaustion on large WordPress installs by deferring integrity baseline creation and capping file queues.
* Added safer recursive scanner handling for unreadable directories and very large file trees.

= 15.0.0 =
* Added advanced security policy controls for plugin/theme installation, file editors, REST API access, Application Passwords, admin account limits, admin email changes, admin login alerts and password reset alerts.
* Added real-time uploads executable quarantine/delete/disable actions with email notification.
* Added quarantine restore metadata and restore action.
* Added SaaS security policy endpoint and admin policy page for minimum-safe-version/security notices.

= 14.0.6 =
* Connected SaaS Cloud Rules to plugin file/content/database scans.
* Fixed license validation for deactivated sites.
* Synced plugin version metadata.
* Improved cleanup backups, report toggles, hardening file rules and integrity checks.
* Added security policy controls for plugin/theme install blocking, admin account limits, automatic uploads executable quarantine/delete alerts, quarantine restore and emergency lockdown preset.

= 13.2.6 =
* Fixed scanner table checkbox sizing and checkmark design.
* Improved settings layout with compact side-by-side controls.
* Redesigned View / Explain modal with a cleaner security finding layout.
* Reduced false positives for modern media uploads such as AVIF/HEIC.
* Improved upload scanner to flag executable PHP/scripts, double extensions, random PHP filenames and suspicious hidden uploads more reliably.
* Strengthened file malware patterns for web shells, encoded execution, remote downloaders, file writers, malicious htaccess redirects and known shell markers.
* Strengthened Page/Database scanner detection for adult/XXX spam, casino/slot spam, pharma/SEO spam, hidden links, iframe/script injection, redirects and encoded execution chains.
* Kept plain base64 from being flagged unless it is combined with execution behavior.
* Improved table scrolling, column widths, padding, modal sizing and popup compactness.

= 13.2.5 =
* Compact UI fixes, popup redesign, checkbox/toggle sizing improvements and responsive cleanup.

= 13.2.4 =
* Upload PHP detection, log CSS fixes, CMS hide toggles, extra firewall protections and cyber UI polish.

= 13.2.3 =
* Added separate Secure and Risk percentage cards and UI alignment polish.

= 13.2.2 =
* Added centered popup, live scan console and page scan completion improvements.

= 13.2.1 =
* Added page links, plugin self-scan exclusions, CMS hide improvements, progress bar and Security Score UI updates.

= 13.2.0 =
* Added Security Score, scheduled scans, email alerts, bulk actions, Turnstile/login fixes and uploads hardening.


== Changelog ==

= Version 14.0.2 =
* Fixed fatal error on plugin activation/admin dashboard caused by private hook callback visibility.
* Changed record_admin_activity() hook callback visibility from private to public for WordPress action compatibility.
* Kept v14.0.1 ignore system features unchanged.

= Version 14.0.1 =
* Added per-module Ignore List for File Scanner, Page Scanner and Database Scanner.
* Added single-row Ignore action for file/page/database findings.
* Added bulk Ignore action for scanner results.
* Ignored findings are hidden from future scan result views until removed from the ignore list.
* Added remove/restore control for ignored findings.

= Version 14.0.0 =
* Major security release.
* Added File Integrity Monitor with baseline and modified/new/deleted executable file detection.
* Added WordPress core checksum/security monitoring foundation.
* Added User Security Scanner for suspicious admin users, weak usernames, recent admin creation and duplicate emails.
* Added Admin Activity Log for login, user registration, role changes and Malware Cleaner admin actions.
* Added IP/WAF Rules module with rate limiting, bot protection, emergency lockdown and SQLi/XSS/LFI request blocking.
* Added Notification Center and Scan History.
* Added print/PDF-friendly security report and client report layout.
* Added optional auto-quarantine for critical malware and uploads PHP files.
* Added advanced security module toggles in Settings.
* Improved dashboard with advanced module metrics.
* Improved scheduled scan history tracking.
* Improved firewall engine and security scoring.
