=== Arb Security ===
Contributors: arb
Tags: security, firewall, waf, malware scanner, two-factor, bot protection, brute force, hardening
Requires at least: 5.5
Tested up to: 6.7
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later

All-in-one, owner-safe WordPress security: Bot Shield, WAF, malware/file-integrity scanner, email-OTP two-factor, hardening, security headers, live visitor intelligence, and an optional AI security advisor.

== Description ==
Arb Security protects any WordPress / WooCommerce site with multiple layers that block on BEHAVIOR, never identity — so real visitors, foreigners and VPN users are never blocked, and your own admin IP is auto-allow-listed so you are never locked out.

Modules:
* Bot Shield — flood/rate-limit, brute-force login protection, bad-User-Agent & datacenter-bot blocking, honeypot, geo (off by default), attack auto-lockdown.
* WAF firewall — blocks SQLi / XSS / path-traversal / RCE / sensitive-file probes at request time.
* Malware & File-Integrity Scanner — daily + on-demand scan for backdoor signatures and executable PHP hidden in uploads; emails you when something is found.
* Two-Factor (email OTP) — requires an emailed code for admin logins from UNRECOGNIZED IPs only (your known IPs skip it). Off by default.
* Hardening — disables the theme/plugin file editor, hides the WP version, blocks user-enumeration.
* Security Headers — X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
* Live Visitors — real-time visitor + threat intelligence.
* AI Security Advisor (optional) — add an OpenAI API key for on-demand advice + a daily security digest.

Ships with big-store MEDIUM defaults so it is safe to switch on immediately.

== Installation ==
1. Plugins -> Add New -> Upload Plugin -> choose arb-security-1.0.0.zip -> Install -> Activate.
2. (Optional) Arb Security -> API & Alerts -> paste an OpenAI API key to enable the AI advisor.
3. Review Arb Security -> Overview. Everything is ON by default except Two-Factor.

== Changelog ==
= 1.0.0 =
* Initial release: Bot Shield, WAF, Malware/File-integrity scanner, Email-OTP 2FA, Hardening, Security headers, Live Visitors, AI Security Advisor, owner auto-allow-list, MEDIUM big-store defaults. Universal & self-contained.
